docs: define admin operations port
This commit is contained in:
1 parent
c0ffc74f9b
commit
f5ba556e29
1 file changed
+47
@@ -0,0 +1,47 @@
|
||||
# Admin operations design
|
||||
|
||||
## Goal
|
||||
|
||||
Add complete administration verticals for moderation and calls for help, detailed logs, analytics, DevOps, and online users. Each vertical includes its data source, mutations or API handlers, ACL enforcement, themed UI, and tests.
|
||||
|
||||
## Delivery order
|
||||
|
||||
1. Moderation dashboard, actions, CFH list/detail, and moderation team.
|
||||
2. Audit, chat, command, and trade logs.
|
||||
3. Analytics overview, activity, economy, and export.
|
||||
4. DevOps overview/errors/health and online users.
|
||||
|
||||
Each group must compile and pass its focused contract before the next group begins.
|
||||
|
||||
## Data architecture
|
||||
|
||||
Use existing emulator and CMS tables where they already contain the required data. Queries must adapt to EpicNext's Prisma model names and live-schema conventions; generated Prisma files are never copied. When a reference page assumes a column absent from EpicNext, use a compatible projection or raw query rather than changing the emulator schema without evidence.
|
||||
|
||||
Moderation reads support CFH topics/categories, bans, users, and staff ranks. Mutations validate target identity and duration, call the emulator/RCON only after authorization, and write staff audit activity. Log pages are read-only and paginate/filter server-side. Analytics aggregates database data and exports only fields already visible to the authorized administrator. DevOps health exposes non-secret operational state and never returns credentials, connection strings, or raw environment variables.
|
||||
|
||||
## Authorization
|
||||
|
||||
Page guards and server-side actions/API handlers use:
|
||||
|
||||
- `admin.moderation.view` and `admin.moderation.edit`
|
||||
- `admin.logs.view`
|
||||
- `admin.analytics.view` and `admin.analytics.export`
|
||||
- `admin.devops.view` and `admin.devops.edit`
|
||||
|
||||
Online-user administration uses `admin.users.view`; any mutation additionally requires its specific user/moderation permission. Authorization fails closed, and denied or failed privileged operations are logged.
|
||||
|
||||
## UI and theme
|
||||
|
||||
All new routes are locale-free under `/admin`. Components use the semantic `--admin-*` palette and existing shared admin components. Status colors use semantic admin status tokens; no public structural theme variables or hard-coded palette utilities are introduced.
|
||||
|
||||
## Error handling
|
||||
|
||||
Missing optional emulator tables produce an explicit unavailable/empty state rather than crashing the entire admin panel. Invalid filters return validation errors. RCON failures are reported separately from successful database changes, and destructive moderation actions never report success when the emulator operation fails.
|
||||
|
||||
## Verification
|
||||
|
||||
Contract tests assert route presence, ACL guards, and source-theme compliance. Focused tests cover moderation validation, log filters, analytics export authorization, and DevOps response redaction. Final verification runs every test, TypeScript, migration contracts, and the production build.
|
||||
|
||||
## Scope boundary
|
||||
|
||||
This block does not add public feed, forum, social, finance, betting, album/gallery, staff-login, PIN, or security pages. Those remain later public-facing phases.
|
||||
Reference in new issue
Block a user