Remove legacy admin UI from RollCalc
This commit is contained in:
+5
-17
@@ -14,12 +14,11 @@ Backend:
|
||||
|
||||
- `app.py` creates the Flask app.
|
||||
- HTTP Basic Auth is implemented with `Flask-HTTPAuth`.
|
||||
- Users are currently hardcoded in `BETA_USERS` and `ADMIN_USERS`.
|
||||
- Users are currently hardcoded in `BETA_USERS`.
|
||||
- `/` renders the active calculator template.
|
||||
- `/static/<path:filename>` is intended to serve static files behind Basic Auth.
|
||||
- `/api/health` returns health/version information.
|
||||
- `/api/user` returns the authenticated user and admin flag.
|
||||
- `/admin/logs` returns access logs for admin users.
|
||||
- `/api/user` returns the authenticated user.
|
||||
- Access events are appended to `access_log.json`.
|
||||
|
||||
Frontend:
|
||||
@@ -184,25 +183,14 @@ This is client-side only. It is not persisted, logged, or enforced server-side.
|
||||
|
||||
## Admin Area State
|
||||
|
||||
Current backend route:
|
||||
RollCalc no longer contains an admin UI or admin API. The previous `/admin/logs` route and `templates/admin.html` have been removed.
|
||||
|
||||
```text
|
||||
/admin/logs
|
||||
```
|
||||
|
||||
Current `templates/admin.html` expects:
|
||||
|
||||
```text
|
||||
/api/admin/stats
|
||||
/api/admin/logs
|
||||
```
|
||||
|
||||
Those `/api/admin/*` endpoints are not currently implemented in `app.py`, and there is no route rendering `templates/admin.html`.
|
||||
Login/access logging remains part of RollCalc, but log viewing and article-data administration should not be implemented inside this app. Maintenance of `article-data.json` is planned for a separate application.
|
||||
|
||||
## Known Technical Risks
|
||||
|
||||
- Hardcoded plaintext credentials in `app.py`.
|
||||
- Basic Auth only; no sessions or role framework beyond user dictionaries.
|
||||
- Basic Auth only; no sessions or role framework beyond the user dictionary.
|
||||
- `access_log.json` is rewritten on every logged request and is not concurrency-safe.
|
||||
- No log rotation or retention policy is implemented.
|
||||
- Flask's default static route may conflict with the intended authenticated `/static/<path:filename>` behavior; verify effective routing before relying on protected static files.
|
||||
|
||||
Reference in New Issue
Block a user