Remove legacy admin UI from RollCalc

This commit is contained in:
2026-07-07 12:20:09 +02:00
parent ac6840c759
commit ffa34815cd
6 changed files with 38 additions and 634 deletions
+5 -17
View File
@@ -14,12 +14,11 @@ Backend:
- `app.py` creates the Flask app.
- HTTP Basic Auth is implemented with `Flask-HTTPAuth`.
- Users are currently hardcoded in `BETA_USERS` and `ADMIN_USERS`.
- Users are currently hardcoded in `BETA_USERS`.
- `/` renders the active calculator template.
- `/static/<path:filename>` is intended to serve static files behind Basic Auth.
- `/api/health` returns health/version information.
- `/api/user` returns the authenticated user and admin flag.
- `/admin/logs` returns access logs for admin users.
- `/api/user` returns the authenticated user.
- Access events are appended to `access_log.json`.
Frontend:
@@ -184,25 +183,14 @@ This is client-side only. It is not persisted, logged, or enforced server-side.
## Admin Area State
Current backend route:
RollCalc no longer contains an admin UI or admin API. The previous `/admin/logs` route and `templates/admin.html` have been removed.
```text
/admin/logs
```
Current `templates/admin.html` expects:
```text
/api/admin/stats
/api/admin/logs
```
Those `/api/admin/*` endpoints are not currently implemented in `app.py`, and there is no route rendering `templates/admin.html`.
Login/access logging remains part of RollCalc, but log viewing and article-data administration should not be implemented inside this app. Maintenance of `article-data.json` is planned for a separate application.
## Known Technical Risks
- Hardcoded plaintext credentials in `app.py`.
- Basic Auth only; no sessions or role framework beyond user dictionaries.
- Basic Auth only; no sessions or role framework beyond the user dictionary.
- `access_log.json` is rewritten on every logged request and is not concurrency-safe.
- No log rotation or retention policy is implemented.
- Flask's default static route may conflict with the intended authenticated `/static/<path:filename>` behavior; verify effective routing before relying on protected static files.