diff --git a/AGENTS.md b/AGENTS.md index 3c038d0..39d9b1f 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -24,9 +24,19 @@ Primary files: - Do not add Python packages without approval. - Do not change existing APIs, route paths, data formats, or authentication behavior without approval. - Do not manually edit generated product data unless the user explicitly asks for data maintenance. +- Do not add new article-data administration features to RollCalc; propose a separate app or integration boundary instead. +- Preserve login/access logging unless the user explicitly asks to change or remove it. - Preserve the current Flask/vanilla JavaScript architecture unless the task is specifically a refactor. - Prefer documenting observed behavior over assuming intended behavior. +## Planned Direction + +- The existing admin UI/API in RollCalc is planned for removal. +- Do not expand or repair the admin area unless explicitly requested as a temporary measure. +- Keep login/access logging in RollCalc. +- Administration and maintenance of `article-data.json` should move to a separate application. +- Treat `templates/admin.html` and `/api/admin/*` expectations as legacy/transitional, not as target architecture. + ## Code Style - Python should follow PEP 8. @@ -63,7 +73,7 @@ These credentials are hardcoded and are a known risk; do not introduce more secr - Access logging writes to `access_log.json` by reading and rewriting the whole file. - The active UI logic is largely inline in `templates/roll_calculator.html`. - Several `static/*.js` files appear to be older, alternative, or integration modules. Confirm script inclusion before modifying them. -- The admin template and backend admin routes are inconsistent at the moment. +- The admin template and backend admin routes are inconsistent and scheduled for removal rather than expansion. - The disclaimer confirmation is client-side only. ## Safety Notes diff --git a/ROADMAP.md b/ROADMAP.md index 2b8adef..ad161e2 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -6,8 +6,12 @@ ## Version 0.4 -- Benutzermanagement auf sichere Methode umstellen, keine Klartext Passworte mehr -- Produktionsdaten aus SQL per Query direkt beziehen +- Benutzermanagement auf sichere Methode umstellen, keine Klartext-Passworte mehr +- Login-/Zugriffslogging beibehalten und robuster machen +- Bestehenden Admin-UI-/Admin-API-Teil aus RollCalc entfernen +- Pflege der `article-data.json` in eine eigenständige Administrations-App auslagern +- Produktionsdaten perspektivisch aus SQL per Query direkt beziehen ## Version 0.5 -- +- Schnittstelle bzw. Import-/Deployment-Prozess zwischen externer Artikelverwaltungs-App und RollCalc definieren +- Rollen-/Berechtigungskonzept für Zugriff auf RollCalc und externe Artikelverwaltung klären