Repository navigation
feat: super-admin panel with platform stats, users and API traffic - #168
Merged
Merged
Conversation
Adds two separately deployed apps, kept out of Docker and CI/CD: - apps/admin-server: Express admin API (Render). Single env-defined admin login, JWT with its own secret, login lockout after 5 failures. - apps/admin: React panel (Vercel). Overview, sessions, quizzes, users (with CSV export) and API traffic pages. Supporting changes: - http-server logs every request to ApiRequestLog in batches, prunes rows after 30 days, flushes on shutdown, and records User.lastLoginAt. - New CANCELLED session status; the panel can cancel abandoned sessions, and ws-server no longer revives a cancelled or finished session. - Migration 20260929100000_admin_panel_tracking. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Adds a super-admin panel for tracking the whole platform. It is two new apps, deployed by hand (Render + Vercel) and deliberately kept out of Docker and CI/CD:
apps/admin-server: Express admin API that reads the shared Postgres database.apps/admin: React panel with these pages:Supporting changes in existing services:
ApiRequestLogtable. Writes are buffered and batched every 5s, so request latency is unaffected.REQUEST_LOG_RETENTION_DAYS).User.lastLoginAton login.CANCELLEDvalue to theSessionStatusenum. The panel can only cancel sessions idle for more than 3h; live ones are refused.quiz:startno longer revives a cancelled or already-finished session.adminandadmin-server, and.dockerignoreexcludes both, so existing images are unchanged.Security:
Usertable, so no app user can be promoted into it.JWT_SECRET) and expire after 12h.Related issue
No issue. This is a new feature, requested so the owner can track quiz activity, signups, users and API traffic in one place.
Type of change
Which services does this touch?
apps/frontendapps/http-serverapps/ws-serverapps/genAIpackages/db(schema or Prisma changes)apps/admin,apps/admin-serverHow did you test this?
prisma migrate diffagainstschema.prismareports no difference./api/v1/quizzes/:quizId), the client IP is taken fromx-forwarded-for, and the user id is set on authenticated routes. On SIGTERM within 1s of a request, the buffered rows are written and the process exits in about 70ms.node_modules./healthand served data.VITE_ADMIN_API_URLis unset.http-server,ws-server,admin-serverandadminall passtsc/vite build.Not tested: the ws-server
quiz:startguard against a live Redis + ws-server (it is a one-lineupdateManycondition), and a fulldocker-compose up.Checklist
pnpm run lint(the new apps have no lint script)pnpm run check-types(type-checked each touched package individually instead)pnpm run build(per package: http-server, ws-server, admin-server, admin)docker-compose up(not run; images are unchanged apart from the http-server and ws-server source edits).envfile, API key or other secret (only.env.exampletemplates)Schema change: migration
20260929100000_admin_panel_trackingadds theApiRequestLogtable,User.lastLoginAt, and theCANCELLEDenum value. It needs no manual step: the backend container applies pending migrations on startup. Deploy http-server before the admin API. Traffic data only starts accumulating from that deploy.After merge: deploy
apps/admin-serverto Render andapps/adminto Vercel following apps/admin-server/README.md. The production database must be reachable from Render.🤖 Generated with Claude Code