Skip to content

PreviewBanner: approval-key gating, drop PR/GitHub surface - #7

Merged
clord merged 3 commits into
mainfrom
feat/preview-banner-approval-key
Jul 26, 2026
Merged

clord merged 3 commits into
mainfrom
feat/preview-banner-approval-key

Conversation

@clord

@clord clord commented Jul 26, 2026

Copy link
Copy Markdown
Member

What

  • Approve & Deploy / Reject are gated on the approval key: an inline script reads ?k= from the page URL, fills a hidden k form field, and unhides the actions. Without k (or without JavaScript) the banner is view-only ("You're viewing a preview of a proposed change."). The orchestrator verifies k server-side regardless — hiding is UX, the server is the gate.
  • No PR/GitHub language: removed the Details section (PR number, branch, sha, GitHub link) and the PR #n fallback title. The banner shows only the change description. Customer-facing surfaces shouldn't advertise the repo.
  • Bump to 0.3.0.

Companion

pliosoft/sites-app adds server-side k verification on /_preview/approve|reject and appends ?k= to shared preview URLs (slug-scoped HMAC(PREVIEW_JWT_SECRET, "preview-approval:" + slug)). Deploy order is safe either way: old banner + new orchestrator → clear error page on action; new banner + old orchestrator → k ignored.

Verified against a real customer-site build: actions hidden by default, script present, zero github.com/branch/sha strings in output; production builds (vars unset) still emit nothing.

🤖 Generated with Claude Code

clord and others added 3 commits July 25, 2026 23:52
….meta.env

Vite only exposes .env-file vars and PUBLIC_-prefixed shell vars on
import.meta.env, so the PLIOSOFT_PREVIEW_* variables the sites-app build
pipeline passes through the environment were always undefined and the
banner silently rendered nothing on every preview deploy. Frontmatter
executes in Node at build time (static output), so process.env sees them.

Verified against a real customer site build: banner + JWT now bake into
preview HTML; production builds (vars unset) still emit nothing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Approve/Reject now render only when the page URL carries the approval
key (?k=...) from the link Pliosoft Sites shared with the customer; the
key is forwarded as form data next to the JWT for server-side
verification. Visitors who merely guess the preview hostname get a
view-only banner, and without JavaScript the banner stays view-only.

The banner also stops speaking GitHub: no PR number, branch, sha, or
repository link — just the change description. Reviewers see a Pliosoft
surface, not a pull request.

Companion change in pliosoft/sites-app verifies k server-side and
appends it to shared preview URLs.

Bump to 0.3.0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…pproval-key

# Conflicts:
#	package-lock.json
#	package.json
@clord
clord merged commit 11c74e1 into main Jul 26, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant