Decision: Web Management UI #542
Labels
No labels
question
blocked
duplicate
needs
approval
needs
criteria
needs
estimate
needs
tests
question
step
doing
step
review
step
testing
step
todo
step
uat
type
admin
type
alert
type
bug
type
change
type
defect
type
dependencies
type
epic
type
idea
type
incident
type
investigation
type
spike
type
story
wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
External/card-drop#542
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Status
Accepted — 2026-09-29
Supersedes the original idea. Implementation tracked by epic #543.
Context
Operating Card Drop today means editing env/files, Discord slash commands (
/resync,/gdrivesync,/give), and Google Drive sync. That does not scale for settings management, card catalog edits, or multi-person admin.Today:
BOT_ADMINS(comma-separated Discord user IDs)Configkey/value in the DB (notablysafemode)$DATA_DIR/cards, optionally synced from Google Drive via rcloneEXPRESS_PORT) with an unauthenticatedPOST /api/reload-dbOriginal idea goals:
Decision
1) UI framework
Build a React SPA (TypeScript, Vite) for the management UI.
2) Process shape
Run the management UI/API in the same bot process. Expand the existing Express app into a Management API and serve (or reverse-proxy) the React build from that process. One deployable for v1.
3) Authentication
Discord OAuth. Only Discord users listed in
BOT_ADMINSmay access the UI/API in v1.4) Authorization / roles
v1 enforces a single Admin capability (membership in
BOT_ADMINS). Design API routes and resource checks so finer-grained roles/resources can be added later without rewriting the surface.5) Settings
Allow admins to view/update safe DB
Configkeys (e.g.safemode) via the UI. Show non-secret env as read-only. Do not allow editing secrets (tokens, DB passwords, webhooks) through the UI.6) Card source of truth
The UI reads and writes the local filesystem under
$DATA_DIR/cards(series metadata JSON + image upload). Google Drive remains an optional sync path (/gdrivesync/ UI ops action), not the editor’s write target in v1.7) Ops actions
Expose admin ops in the UI: reload card metadata, trigger Drive sync, view/toggle safe mode. Protect existing webhook routes (including
/api/reload-db) behind the same auth.Alternatives considered
Consequences
Positive
BOT_ADMINStoward roles/resourcesTradeoffs
Original idea notes
Build using react
Web Management UIto Decision: Web Management UIAccepted decision closed. Implementation epic: #543