// the complete manifest

Every feature in 0xCMS

A detailed, no-hand-waving inventory of what ships in the Worker — read straight from the source. Authentication, capability-based access control, structured multilingual content, versioning, real-time co-editing, adapter-based publishing, plugin auto-republish, taxonomy, advanced search with queued bulk actions, private media, bulk import/export, runtime-editable schemas, trash, a full plugin platform with credit billing & quota limits, and runtime system settings — each section tagged with the size of the source that implements it.

Cloudflare Workers Hono D1 × 2 R2 Durable Objects Queues Liquid views Web Crypto JWT

// contents · four groups

// every section is tagged with the size of the source implementing it — ≈723 kB of worker TypeScript + SQL, plus ≈481 kB of admin views & client assets (incl. a 115 kB vendored Liquid engine). Shared files are counted once, under their primary section.

// group 1 / 4

Ⅰ · Content authoring

The editorial surface — how content is modeled, edited, versioned, and co-edited live.

🧬

// 01

Content model

worker 27 kB · views 25 kB
✍️

// 02

Page editor

worker 97 kB · views 47 kB
🗂️

// 03

Versioning & history

worker 4 kB +shared
🛰️

// 04

Real-time co-editing

worker 10 kB · views 14 kB

// group 2 / 4

Ⅱ · Managing & publishing

Organizing, finding, moving, and shipping content out to every reader.

⛓️

// 05

Publishing

worker 19 kB
🏷️

// 06

Taxonomy & tags

worker 19 kB · views 15 kB
🗄️

// 08

Media

worker 7 kB
📥

// 09

Import & export integration

Plugin API
🧱

// 10

Runtime page & block types

worker 28 kB · views 17 kB
♻️

// 11

Trash & recovery

worker 13 kB · views 8 kB

// group 3 / 4

Ⅲ · Access & identity

Who gets into the CMS, and exactly what each account is allowed to do.

🔐

// 12

Authentication & identity

worker 45 kB · views 4 kB
🛡️

// 13

Access control & permissions

worker 28 kB · views 14 kB

// group 4 / 4

Ⅳ · Platform & extensibility

The plugin platform, credit billing & quotas, admin shell, runtime system settings, security hardening, and the edge infrastructure underneath.

🧩

// 14

Plugin system

worker 82 kB · views 19 kB

Each plugin is a separate Cloudflare Worker reached over HTTPS at {url}/__plugin/…. The CMS validates and caches its bounded manifest, then forwards signed-in user context plus that registration's dedicated secret on outbound calls. A plugin can add nine things:

// registry & safety

🔁

// 15

Plugin write-back API /__cms

worker 55 kB

A reverse, server-to-server channel (authenticated by the per-plugin secret, outside the browser auth stack) so guest-facing flows on a plugin's own domain — public RSVP submit, QR check-in, bulk contact import — can read and write the CMS pages they own or are delegated.

💳

// 16

Credits & quota limits

worker 26 kB · views 7 kB

Meter or monetize what plugins let users do. A plugin's manifest declares chargeable actions and quota limits, an admin configures the prices and caps, and the host enforces them on every page-create path — the admin editor and the write-back API alike, so neither door can be used to sidestep the other.

🖥️

// 17

Admin experience

worker 86 kB · views 268 kB
🎛️

// 18

System settings & branding

worker 17 kB · views 10 kB
🔒

// 19

Security hardening

worker 9 kB +shared
🌐

// 20

Data & infrastructure

worker 46 kB
⚙️

// 21

Background jobs & ops

worker 8 kB

// see it running

Every one of these is live on the edge.

Don't trust the list — verify it yourself.