Developer notes

Host app, embeddable package, Composer wiring, and boundaries.

Two products.

  • Host app — the standalone CMS (auth, Control Panel, theme, deploy). Use it for customer websites. Default host DB is SQLite. Clients normally receive a versioned install archive, not a public Composer package.

  • Package code44/coaptive-cms — embeddable page engine for other Laravel apps (for example Coaptive GME). Do not require GME packages on a pure CMS install.

Embed via Composer path repository (typical on a shared development server):

"repositories": [
  {
    "type": "path",
    "url": "../coaptive-cms/packages/coaptive/cms",
    "options": { "symlink": true }
  }
],
"require": {
  "code44/coaptive-cms": "*"
}

If the consumer’s PHP open_basedir cannot reach the sibling tree, set "symlink": false so Composer mirrors the package into vendor/, then re-run composer update code44/coaptive-cms after package changes. Release archives always ship with a mirrored copy.

Optional publishes:

php artisan vendor:publish --tag=coaptive-cms-config
php artisan vendor:publish --tag=coaptive-cms-assets

Useful APIs.

  • Coaptive\Cms\PageRepository — read/write pages by site + slug

  • CmsPage, SiteSettings, License::enabled('cms') for feature gates

  • Page Builder — Coaptive\Cms\PageBuilder\* (PageSectionsRepository, MapDisplay, SectionTypes)

  • Coaptive\Cms\Support\SiteTranslation — navLabel(), resolvedNavLabels(), locale sidecars

  • Coaptive\Cms\Support\ThemeContrastHints — CP-only WCAG hints (does not mutate theme)

  • Coaptive\Cms\Support\FormWebhookNotifier — optional HTTPS POST after form save (failures logged, visitor still succeeds)

  • config('coaptive-cms.google_maps_api_key') from GOOGLE_MAPS_API_KEY — never persist map keys in .sections.json

  • Blade editor: <x-coaptive-cms::editor />

Boundaries. The package must not depend on GME program models. Account Settings (avatar, profile, header dropdown) are a host concern. Form file uploads and CAPTCHA / mail secrets stay in host private storage — never commit them. Webhook URLs are stored on form definitions; validate HTTPS only server-side.

License. Proprietary software from Code 44 LLC. Redistribution as a competing standalone CMS requires consent. Feature enablement uses env keys and/or a signed license file.