Web Management UI #543

Open
opened 2026-09-29 19:04:15 +01:00 by Smithy-bot · 0 comments
Member

Summary

Ship a React management UI so bot admins can manage runtime settings, maintain the card catalog on the local filesystem, and run ops actions without Discord or direct file access.

Anchored by decision #542:

  • React SPA (TypeScript / Vite)
  • Same bot process (expand existing Express into a Management API; serve the SPA from it)
  • Discord OAuth; only BOT_ADMINS in v1
  • Cards: read/write $DATA_DIR/cards (metadata + images); Drive remains optional sync
  • Roles/resources designed; only Admin enforced in v1

Acceptance Criteria

  • Given a Discord user in BOT_ADMINS, when they complete OAuth, then they can access the management UI and API
  • Given a Discord user not in BOT_ADMINS, when they attempt OAuth or call management routes, then they are rejected
  • Given an unauthenticated caller, when they hit management API routes (including /api/reload-db), then they receive 401/403
  • Given an admin, when they open Settings, then they can view/update allowlisted Config keys (e.g. safemode) and see non-secret env as read-only; secrets are not editable
  • Given an admin, when they use the card browser, then they can list series/cards and create/edit card metadata plus upload images under $DATA_DIR/cards
  • Given an admin, when they use Ops, then they can reload card metadata, trigger Drive sync, and view/toggle safe mode
  • Given the codebase, when v1 ships, then route/resource checks are structured for future roles even though only Admin is wired

Out of scope (v1)

  • Editing secrets via the UI
  • Moving the card catalog into the database
  • Using Google Drive as the editor write target
  • Multi-role RBAC beyond Admin / BOT_ADMINS
  • Separating the web UI into its own deployable service

Tasks

  • #544 Management API foundation
  • #545 Discord OAuth + session for BOT_ADMINS
  • #546 React app shell
  • #547 Settings page
  • #548 Card browser
  • #549 Card create/edit + image upload
  • #550 Ops page
  • #551 Roles & resources model
  • #552 Deprecate /gdrivesync and /resync commands
  • #553 Docs: management UI deploy and OAuth

Future Tasks

  • Roles and resources for non bot admins
  • Remove /gdrivesync and /resync commands

Notes

  • Decision: #542
  • Existing Express entry: src/webhooks.ts
  • Card layout docs: docs/cards.md / BookStack Cards page
  • Prefer packaging the React app under something like web/ with a build step that copies assets for Express to serve
  • Milestone: 0.14.0
## Summary Ship a React management UI so bot admins can manage runtime settings, maintain the card catalog on the local filesystem, and run ops actions without Discord or direct file access. Anchored by decision [#542](https://git.vylpes.xyz/External/card-drop/issues/542): - React SPA (TypeScript / Vite) - Same bot process (expand existing Express into a Management API; serve the SPA from it) - Discord OAuth; only `BOT_ADMINS` in v1 - Cards: read/write `$DATA_DIR/cards` (metadata + images); Drive remains optional sync - Roles/resources designed; only Admin enforced in v1 ## Acceptance Criteria - Given a Discord user in `BOT_ADMINS`, when they complete OAuth, then they can access the management UI and API - Given a Discord user not in `BOT_ADMINS`, when they attempt OAuth or call management routes, then they are rejected - Given an unauthenticated caller, when they hit management API routes (including `/api/reload-db`), then they receive 401/403 - Given an admin, when they open Settings, then they can view/update allowlisted `Config` keys (e.g. safemode) and see non-secret env as read-only; secrets are not editable - Given an admin, when they use the card browser, then they can list series/cards and create/edit card metadata plus upload images under `$DATA_DIR/cards` - Given an admin, when they use Ops, then they can reload card metadata, trigger Drive sync, and view/toggle safe mode - Given the codebase, when v1 ships, then route/resource checks are structured for future roles even though only Admin is wired ## Out of scope (v1) - Editing secrets via the UI - Moving the card catalog into the database - Using Google Drive as the editor write target - Multi-role RBAC beyond Admin / `BOT_ADMINS` - Separating the web UI into its own deployable service ## Tasks - [ ] #544 Management API foundation - [ ] #545 Discord OAuth + session for `BOT_ADMINS` - [ ] #546 React app shell - [ ] #547 Settings page - [ ] #548 Card browser - [ ] #549 Card create/edit + image upload - [ ] #550 Ops page - [ ] #551 Roles & resources model - [ ] #552 Deprecate `/gdrivesync` and `/resync` commands - [ ] #553 Docs: management UI deploy and OAuth ### Future Tasks - Roles and resources for non bot admins - Remove `/gdrivesync` and `/resync` commands ## Notes - Decision: #542 - Existing Express entry: `src/webhooks.ts` - Card layout docs: `docs/cards.md` / BookStack Cards page - Prefer packaging the React app under something like `web/` with a build step that copies assets for Express to serve - Milestone: 0.14.0
Vylpes added this to the 0.14.0 milestone 2026-09-29 19:05:18 +01:00
Vylpes removed their assignment 2026-09-29 19:10:22 +01:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
External/card-drop#543
No description provided.