Recipe: an admin area (sketch)
Sketch; not implemented in this kit. There is no admin flag, route or page here. The Rails kit has none either.
When: staff need to see users, fix data, or impersonate for support. Rails: an admin namespace with a before_action :require_admin, or a gem like Avo / Administrate.
Shape
- Who is an admin:
cargo loco generate migration AddAdminToUsers admin:bool!(default false), thencargo loco db migrate && cargo loco db entities. Grant it with a task (cargo loco generate task grant_admin), never through a web form. - Guard: a
RequireAdminextractor insrc/auth.rs, built likeAuthenticated(which it wraps), that answers 404 for non-admins so the area isn't discoverable. - Routes:
/admin/...constants insrc/route_table.rs, handlers insrc/controllers/admin/(a module likecontrollers/settings/), pages infrontend/pages/admin/, a separate layout if it should look different. - CRUD:
cargo loco generate scaffoldthen move the controller underadmin/and swapAuthenticatedforRequireAdmin; the scaffold's pages work as they are. - Audit: log every admin write (who, what, before/after) to an
admin_eventstable.
Impersonation, if needed: create a session for the target user flagged with the admin's id, and show a banner from a shared prop; never reuse the admin's session.
Verify (when you build it)
Request tests: a normal user gets 404 on every /admin route; an admin gets 200; writes create an audit row.