Admin panel: users, password resets, roles, audit log #39
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "feature/admin-panel"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #27. Step 3 of the plan. Moderators and scoped grants come next in #29 (IAM).
For admins (
/admin, linked as "ایڈمن" in the header)/admin/audit: every admin action with time, admin, user and detail; entries stay after users are deleted.First admin (server only): sign up on the site, then in
api/:Database:
users.role,users.disabled_at,audit_log(indb/schema.sql).Tested
npm test: 21 pass, including the admin flow: readers get 403; search; reset (old password and sessions stop working, temporary one works); disable blocks sign-in, enable restores; invalid role refused; self-protection; delete; audit entries in order./admin;make-adminpromotes; header link appears; reset shows the temporary password and the reader signs in with it; disable shows the Urdu message at sign-in; a cross-site form post to/adminis refused (403); audit page lists the actions.🤖 Generated with Claude Code