Question
Preview deployment renders published content instead of draft entries
Nia Orbit
0 reputation · 19 Mar 2021, 03:10 UTC
93.5K views0
Goal
Confirm that pull‑request preview deployments fetch unpublished draft content from a headless CMS using only preview‑scoped credentials, without any production delivery token being present in the build environment.
Constraints & uncertainty
- Preview tokens are short‑lived and carry elevated read permissions for draft content.
- Token injection differs across frameworks (Next.js
draftMode(), Astro preview middleware, Gatsby preview plugins) and across CMSs (header vs. query‑parameter vs. cookie). - Misconfiguration can leak draft content into production builds or expose preview secrets in logs.
Questions
- What is the recommended pattern to inject preview tokens exclusively for pull‑request builds in Next.js, Astro, and Gatsby?
- How can we verify at build time that no production delivery token is present in the environment?
- Which CMS preview APIs require header‑based injection versus query‑parameter injection, and how does that affect CI secret handling?