4.7 KiB
ACL and Import Backend Implementation Plan
For agentic workers: REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (
- [ ]) syntax for tracking.
Goal: Complete ACL management and activate every existing administration import workflow.
Architecture: Use the normalized ACL tables as the single authorization source and map emulator ranks to rank_<id> roles. Port the proven import core and services from habbo-next, expose them through locale-free API routes guarded server-side, and verify DB plus filesystem outputs.
Tech Stack: Next.js 16 route handlers, React 19, TypeScript, Prisma/MariaDB, Vitest, Node filesystem and streams.
Global Constraints
- Work directly in
E:\Users\simol\Desktop\EpicNext-cms; no worktree or subagents. - Preserve and never stage the existing
package.jsonmodification. - Pull
mainbefore publication and never force-push. - Do not copy generated Prisma files.
- Every import API requires
admin.assets.import; destructive catalog operations also requireadmin.catalog.edit. - Import success requires database and required filesystem/FurnitureData outputs.
Task 1: Lock ACL and route coverage with failing contracts
Files:
-
Create:
src/lib/admin/acl-management-contract.test.ts -
Create:
src/lib/import-backend-contract.test.ts -
Assert that permission mutations use
adminActionwithPERMS.PERMISSIONS_MANAGE, write normalized ACL tables, and do not write legacy housekeeping permission tables. -
Assert that every API referenced by
src/app/admin/import/**exists and contains a server-sidePERMS.ASSETS_IMPORTguard. -
Run both tests and verify they fail on the missing management/API implementation.
-
Commit with
test: define acl and import backend contracts.
Task 2: Normalize ACL persistence and management
Files:
-
Modify:
src/actions/permissions.ts -
Modify:
src/app/admin/permissions/page.tsx -
Modify:
src/app/admin/permissions/[id]/page.tsx -
Modify:
src/app/admin/permissions/[id]/rank-edit-client.tsx -
Use:
src/lib/services/permission-ranks.ts -
Create:
prisma/migrations/0014_complete_acl_and_import_permissions.sql -
Add focused failing tests for rank service and ACL assignment behavior.
-
Replace legacy writes with emulator rank service and normalized ACL assignments.
-
Seed and migrate roles/permissions idempotently, using
RoleandUserdiscriminator casing. -
Invalidate permission cache, update RCON, and log each mutation.
-
Run ACL tests and migration contract tests; commit with
fix: complete acl management.
Task 3: Port shared import core and domain services
Files:
-
Create:
src/lib/services/import/core/*.ts -
Create:
src/lib/services/{clone-import,clothing-set-import,effect-import,figure-import,furni-import,nitro-assets,pet-import}.ts -
Modify:
src/lib/services/furni-asset-dirs.ts -
Modify:
src/lib/services/furni-data.ts -
Test: matching
*.test.tsfiles -
Port tests first and verify failures from missing modules.
-
Port reference implementations, adapting Prisma model names and EpicNext settings.
-
Preserve Windows absolute-path handling and live Nitro mirroring.
-
Run all import service tests; commit with
feat: add asset import services.
Task 4: Add guarded import route handlers
Files:
-
Create:
src/app/api/admin/import/**/route.ts -
Create:
src/app/api/nitro-assets/bundled/furniture/[...path]/route.ts -
Add badge, clone, clothing, effects, furni, pets, and repair handlers used by the existing clients.
-
Apply server-side API context plus
PERMS.ASSETS_IMPORTto every handler. -
Require
PERMS.CATALOG_EDITfor deletion, repair, resync, and catalog-mutating operations. -
Run route contract, API authorization, and service tests; commit with
feat: add guarded asset import api.
Task 5: Align pages, actions, and permissions
Files:
-
Modify:
src/app/admin/import/**/page.tsx -
Modify:
src/actions/import-badges.ts -
Modify:
src/actions/import-furni.ts -
Modify:
src/lib/permission-slugs.ts -
Make every import page use
PERMS.ASSETS_IMPORTconsistently. -
Replace stub cleanup/deletion behavior with guarded service calls.
-
Run contract tests and TypeScript; commit with
fix: connect admin import workflows.
Task 6: Complete verification and publish
Files:
-
Verify all committed files; exclude
package.json. -
Run
git diff --check origin/main...HEAD. -
Run
pnpm test,pnpm typecheck, andpnpm build. -
Confirm
git status --shortcontains onlyM package.json. -
Fetch
origin/main, require it to be an ancestor ofHEAD, and pushmainwithout force.