v0.18.0
Password-protected private paths and subdomains on Cloudflare Pages, with independent password groups and secure sessions.
Private password access
Private collections can now enforce password access on Cloudflare Pages. Add an [access] section, mark collections private = true, and use access_group when different paths need different passwords.
[access]
mode = "password"
session_hours = 168
[[collections]]
name = "docs"
private = true
access_group = "staff"
url_prefix = "/docs"
seite build generates a Cloudflare Pages Worker that protects the configured paths. A private root collection protects the whole domain, and a private subdomain collection protects the whole subdomain output. More-specific paths take precedence, so separate groups can use separate passwords.
Use seite access groups to inspect the mapping and seite access set-password [GROUP] to upload the password and session secret securely through Wrangler. Passwords are prompted interactively and are never stored in seite.toml or passed as command-line arguments.
Files under static/private/<group>/ are emitted under the protected /private-assets/<group>/ route. Existing private = true configurations without [access] retain their discovery-only behavior.
Maintenance
- Refreshed the Rust lockfile to the reviewed dependency set from Dependabot.
- Updated the release and CI workflows to the current Dependabot-selected GitHub Actions versions.