Editor access
Roles
admin— GitHub owner of the repo. Can: invite, setgithub_token, edit schema, delete project, manage members.editor— Google invitee. Can: edit content (pages, collections, globals), upload media. Cannot: edit schema, manage members, set tokens.
Project membership is (project_id, user_id, role) in project_users. Only one role per user per project.
Editor profiles
(planned, not yet in DB)
builder— GitHub/local. Full access. Default for admins.author— can add blocks, change layout, edit fields. Cannot edit schema.content— can edit fields. Cannot add blocks or change layout.minimal— can edit only simple text fields. Used for content reviewers.
isBuilder is derived from login method: GitHub/local → true, Google → false. Google's UI respects this regardless of role.
Invitations
invitations table: (token, project_id, email, expires_at, used_at). Admin creates invite, copy/pastes a magic URL containing the token. Invitee opens, signs in with Google, auto-joined as editor for the named project.
Tokens expire in 7 days. safeReturnTo ensures the post-login redirect stays on the configured WEB_APP_URL host.