PawScapes runs as two Cloudflare Pages projects. PawScapes Studio is the admin: highseam, the config, the editor. The public site at pawscapes.com.au is a separate SvelteKit app. Both bind the same D1 database and the same media bucket.
The public site doesn't run the CMS engine. It reads D1 with its own SQL and imports five small modules from highseam:
highseam/previewto verify preview tokenshighseam/PreviewBanner.sveltefor the "you're looking at a draft" barhighseam/core/richtext.jsfor rich-text node typeshighseam/core/media.jsto turn a stored focal point into CSShighseam/core/link.jsto resolve link fields to URLs
So the admin can deploy without the site, and the other way round. The catch is preview: an editor writing a draft in Studio wants to see it on the real site, which only shows published content.
A signed token instead of a shared session
Each collection tells the admin where its preview lives. The function runs on the server, so the admin never needs to know the site's route shapes beyond this one line:
preview: {
url: (doc, token) =>
`${siteBase}/preview/venues/${doc.id}?token=${token}`,
},The admin mints a short-lived token signed with CMS_SECRET. Both Pages projects carry the same secret, so the public site can check the token without talking to the admin at all:
const claims = await verifyPreviewToken(secret, url.searchParams.get("token"));
if (!claims || claims.collection !== params.collection || String(claims.id) !== params.id) {
throw error(403, "Invalid or expired preview token");
}
setHeaders({ "cache-control": "private, no-store", "x-robots-tag": "noindex, nofollow" });The route also checks that the token's claims match the URL, so a token for one draft can't be replayed against another. Then it renders the newest draft snapshot with the same page component the live site uses, uncached and noindexed.
PawScapes has three of these routes: venues, destinations, and one shared by the editorial collections (diary, guides, trip plans, news and pages).
The pane, not a new tab
highseam 1.7.4 turned the preview into a resizable pane beside the form. Drag the divider, or toggle a 390px phone width. Rich-text fields get a full-screen mode that keeps the preview alongside. The preview reloads after each autosave, and the site keeps its scroll position across those reloads, so an editor watching paragraph twelve stays on paragraph twelve.
1.7.4 also brought version compare: every save lists the fields it changed, and a review panel shows word-level diffs between any two versions, with restore.
PawScapes Studio took all of it on 25 September 2026, the day 1.7.4 shipped, in three commits re-copying the doc-page templates. The public site needed one change: keeping the scroll position.