3 ms·
Unfortunately, GitHub's API does not provide per-repo permissions, so in order to read/write to any repo, the CMS has to get permission to read/write to all of
by benaiah 10y ago
Unfortunately, GitHub's API does not provide per-repo permissions, so in order to read/write to any repo, the CMS has to get permission to read/write to all of them. This is a fundamental limitation of the GitHub API [0] - we'd love to be able to request more fine-grained permissions. This is a pretty frequent complaint about any application built with GitHub's API.
The r/w access to public keys is specific to setting up continuous deployment from a GitHub repo to Netlify's static hosting service. You can read more about why Netlify requests those permissions for continuous deployment here: https://www.netlify.com/docs/github-permissions/ https://www.netlify.com/docs/github-permissions/.
While Netlify's continuous deployment is (obviously) the deployment strategy we recommend, you can use the CMS for any static site, as it's totally build/deploy agnostic. You can use the CMS to edit your content and then build that content with Hugo and host on a VPS if you wish. You can also use Netlify to host your content without continuous deployment - it supports updating content with both an in-browser interface and a REST API [1].
The CMS is entirely open source, so you're free to inspect or fork the code - you can find the repository at https://github.com/netlify/netlify-cms/ https://github.com/netlify/netlify-cms/
[0]: https://developer.github.com/v3/oauth/#scopes https://developer.github.com/v3/oauth/#scopes
[1]: https://www.netlify.com/docs/api/ https://www.netlify.com/docs/api/
- wwalser 10y agoI have another question based on the instructions. Why does a Netlify user have to create an oAuth application of their own? > … in order to use the CMS, you’ll need to set up authentication with GitHub. That's the opposite of how oAuth is typically used and I notice that at this point in the process the user has already gone through an oAuth flow when they clicked "Sign in with Github".
- seanwilson 10y agoSo the best you can really do in terms of not giving access to all your other projects is to create a new GitHub user just for your site?
- dsmithatx 10y agoI'm no Github expert however, I have contributed to other repos without having write access. Could the software fork a repo and submit a PR rather than giving it write access? I guess I answered my own question. A person could fork a repo and give write access to the fork, preserving their initial copy.
- splatcollision 10y agoWhat about supporting github read/write deploy keys? Those can be generated with permissions for a single repo, no?
- beat 10y agoThat was my first thought, too. Why not do it that way?