Remove legacy admin UI from RollCalc

This commit is contained in:
2026-07-07 12:20:09 +02:00
parent ac6840c759
commit ffa34815cd
6 changed files with 38 additions and 634 deletions
+7 -20
View File
@@ -42,7 +42,7 @@ If port `5000` is already occupied, start through Flask's CLI without changing f
flask --app app run --host 127.0.0.1 --port 5001
```
The app uses HTTP Basic Auth. Current credentials are defined in `BETA_USERS` and `ADMIN_USERS` in `app.py`.
The app uses HTTP Basic Auth. Current credentials are defined in `BETA_USERS` in `app.py`.
## Project Layout
@@ -57,8 +57,7 @@ The app uses HTTP Basic Auth. Current credentials are defined in `BETA_USERS` an
├── fix_article_data.py
├── service-worker.js
├── templates/
│ ├── roll_calculator.html
│ └── admin.html
│ └── roll_calculator.html
├── static/
│ ├── article-data.json
│ ├── config.json
@@ -88,10 +87,9 @@ Implemented routes:
| `/` | `GET` | Basic Auth | Renders `templates/roll_calculator.html`. |
| `/static/<path:filename>` | `GET` | Basic Auth | Intended protected static-file serving from `static/`. |
| `/api/health` | `GET` | Basic Auth | Returns app health and version. |
| `/api/user` | `GET` | Basic Auth | Returns current authenticated user and admin flag. |
| `/admin/logs` | `GET` | Basic Auth plus admin check | Returns `access_log.json` contents. |
| `/api/user` | `GET` | Basic Auth | Returns current authenticated user info. |
Authentication is implemented with `Flask-HTTPAuth`. The current code merges `BETA_USERS` and `ADMIN_USERS` and performs direct plaintext string comparison.
Authentication is implemented with `Flask-HTTPAuth`. The current code checks `BETA_USERS` and performs direct plaintext string comparison.
Access logging is handled by `log_access()`, which reads `access_log.json`, appends a record, and writes the whole file back.
@@ -243,20 +241,9 @@ These provide or describe range calculations for material thickness, area weight
### Admin UI
There are admin-oriented HTML files:
RollCalc no longer contains an admin UI or admin API. Login/access logging remains in the backend, but logs are not exposed through a RollCalc admin screen.
- `templates/admin.html`
- `admin.html`
- `admin_simple.html`
The backend currently exposes `/admin/logs`, but `templates/admin.html` expects:
```text
/api/admin/stats
/api/admin/logs
```
Those `/api/admin/*` routes are not implemented in `app.py` at the time this README was written. There is also no route currently rendering `templates/admin.html`.
Administration and maintenance of `article-data.json` is planned for a separate application. RollCalc should continue to consume `static/article-data.json` read-only.
## Static Assets and Data Files
@@ -293,7 +280,7 @@ Utility script that updates relative frontend fetch/register paths to Flask-styl
- `access_log.json` is not safe for concurrent writes.
- `access_log.json` grows without rotation or retention limits.
- The custom `/static/<path:filename>` route is intended to protect static files, but Flask also creates a default static route unless disabled. Verify effective route behavior before relying on static-file protection.
- Admin frontend and backend routes are currently inconsistent.
- RollCalc no longer includes an admin UI/API; article data administration belongs in a separate application.
- There is no visible automated test suite.
- The main template is large and mixes layout, styling, data loading, calculations, and UI behavior.
- The disclaimer confirmation is client-side only and is not persisted or audited server-side.