Sveltia Identity Translator
A translated-identity proxy for Sveltia CMS. Editors sign in with their existing identity provider (Google Workspace, Microsoft, Okta); a single service-account Personal Access Token at the git host holds the only credential that ever touches the API; commits attribute correctly to the editor via git’s author/committer split. Editors save changes without ever creating a GitLab account.
The default git-backed CMS auth model assumes a 1:1 mapping between editor and git-host user. For schools, nonprofits, and other small orgs whose editors live in their existing IdP and shouldn’t be onboarded onto another platform, that assumption breaks. The translator pattern keeps the git host out of the editor’s day entirely while preserving correct git history attribution.
Highlights
- ~700 LOC TypeScript. Runs on Cloudflare Workers’ free tier.
- Pluggable
Authorizerhook; default impl loads from a YAML allowlist versioned in git. - 19-case smoke harness covering OAuth, JWT, REST, GraphQL, and allowlist enforcement.
- Comprehensive setup walkthrough for Google OAuth, GitLab service account, Cloudflare deploy, and Sveltia config wiring.
- MIT licensed. Built in collaboration with Andrew DeJong (@adejong5).
The full architectural reasoning, the load-bearing decisions, and the upstream contribution plan are in Enabling Editors to Use Git Without Knowing.