Skip to content
MagiCMS

Security and production

Keep secrets server-side

OAuth client secrets, JWT_SECRET, database credentials and GitHub credentials belong in the Bunny Edge Function environment. Never commit them, place them in VITE_* variables or include them in a browser URL.

The API exchanges OAuth callbacks through a short-lived one-time code. Refresh sessions use Secure HttpOnly cookies, and provider credentials are stored server-side.

Browser access and permissions

Set ALLOWED_ORIGINS to the exact web origins that may call the API. Include the protocol and port where relevant; do not include a path.

Project membership and role are enforced by the API. Editors are restricted to content paths. Administrator-only operations include project credentials, schema/scaffold changes, invites and merges.

Before production

  1. Apply the current database schema, including OAuth state and authorization-code tables.
  2. Set WEB_APP_URL, FUNCTION_URL and ALLOWED_ORIGINS.
  3. Test GitHub and Google OAuth over HTTPS.
  4. Verify editor and administrator access with separate accounts.
  5. Confirm that preview and production origins are not mixed.
Vi bruker cookies for å forbedre din opplevelse.