02 · Edge · architecture
Edge SSO for Private Environments
A two-stage Cloudflare Worker pipeline that locks a customer's non-production sites to their own organisation's SSO — with session handling that survives a 60-minute token expiry and an instant offboarding kill-switch.
- 2
- stage edge pipeline
- 60 min
- token expiry, decoupled from session
- 0
- trailing access after offboarding
The problem
Regulated customers need staging and preview environments locked to their own staff — without shipping auth code into every project, and without the platform team maintaining per-customer configuration.
The awkward constraint was Contentstack's 60-minute OAuth token expiry. Applied naively at the edge, that means kicking a signed-in user out of a site every hour.
What I built
The routing pipeline is two stages: an edge proxy in front of an edge-SSO worker, giving zero-config site access control gated by the customer's Contentstack organisation SSO and OAuth. Nothing changes in the customer's code.
I decoupled the API token from the session: the edge holds a domain-scoped session cookie, separate from the upstream token. Phase one ships a fixed 60-minute edge session with silent background OAuth redirects, so the hourly re-auth is invisible. Phase two is a sliding-window session using client-side encrypted refresh tokens — AES-GCM through the Cloudflare Web Crypto API — so the redirect loop disappears entirely. The whole thing is covered by an end-to-end suite for private environments.
Security properties
Two properties fall out of the design rather than being bolted on. Private Access and Password Protection are made mutually exclusive at the worker itself, not by trusting that configuration never puts both on one environment. And offboarding is instant: the worker compares the cookie's issue time against the organisation's last security event in KV, so a removed employee's live session dies on the next request instead of trailing until it expires.
Alongside it I built the competitor feature matrix against Vercel and Netlify that set the follow-on roadmap — CI/CD bypass headers for E2E testing, shareable preview links, granular project RBAC and IP allowlisting.