- API (api/src/admin.ts, admins only): user list and search; password reset generates a temporary
password shown once and ends the user's sessions; disable/enable (ends sessions, blocks sign-in);
roles reader/admin; delete; an admin cannot disable, demote or delete themself. Every action is
written to audit_log (kept when users are deleted).
- First admin from the server: npm run make-admin -- <email> (after signing up).
- Site: /admin (users) and /admin/audit; 'ایڈمن' link in the header for admins.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>