Skip to content

Administration

The administration area lives under /admin/... in the client and is reached from the main layout. It groups everything a self-hoster or an administrator changes after the instance is running: who can log in, how assets are typed and licensed, what the menu and pages look like, and how the product catalogue is wired to files.

The routes below are declared in client/src/router/index.ts. The sidebar labels and sections come from client/src/layouts/LayoutAdmin.vue.

RouteSidebar labelSectionWhat it managesWho sees it
/admin/settingsGlobal Settings(top level)Instance-wide settings screenadmin
/admin/menu-itemsMenuContent ManagementThe navigation tree shown to users: collections, pages, text links, dividers, home itemadmin
/admin/collectionsCollectionsContent ManagementThe public collection tree: create, edit, deleteadmin
/admin/pages and /admin/pages/:idPagesContent ManagementStandalone pages and their block layoutadmin
/admin/assets/:id?AssetsAsset ManagementThe folder tree synced from cloud storage; assign asset type and license per folderadmin
/admin/asset-typesAsset TypesAsset ManagementCategories of files with display and search defaultsadmin
/admin/licensesLicensesAsset ManagementUsage licenses with dates, scopes and allowed regionsadmin
/admin/usersUsersUser ManagementSign-ups, approval, roles, groups, removaladmin, manager
/admin/groupsGroupsUser ManagementGroups used to restrict collectionsadmin
/admin/regionsRegionsUser ManagementRegions with a default group eachadmin
/admin/authorized-domainsAuthorized DomainsUser ManagementEmail domains whose sign-ups are approved automaticallyadmin
/admin/products and /admin/products/importProductsPIMProduct rows imported from CSVadmin
/admin/products/attributesAttributesPIMWhich product columns are searchable, facetable or displayedadmin

Each screen is documented on its own page:

The sidebar renders the whole User Management section for the roles admin and manager, but inside it only the Users link is shown to managers. Groups, Regions and Authorized Domains are wrapped in an admin check. Every other section (Global Settings, Content Management, Asset Management, PIM) is rendered only for admin.

A manager who opens /admin/users is further limited to the users of their own region. The rules are detailed in Users and approval.

client/src/router/index.ts only checks that a visitor is authenticated: an unauthenticated visitor is redirected to /login, and an authenticated one is kept away from the auth pages. Nothing in the router compares the route to the user’s role.

Role enforcement happens on the server. Every tRPC procedure behind an admin screen is wrapped in authMiddleware(...) with one of the predicates defined in server/src/trpc/index.ts:

PredicatePasses when
userApprovedapproved and emailVerified are both true
userAdminrole is admin
userManagerOrAdminrole is admin or manager
userMemberrole is admin, manager or member (excludes guest)

A member who types an admin URL by hand gets the screen shell, and the data calls fail with UNAUTHORIZED. See Roles and access for the role model.

All admin screens talk to the tRPC API under server/src/trpc/router/. Most of the work described in these pages is done synchronously in the request, but a few actions push jobs to pg-boss queues (collection synchronization, archive creation, emails). Those queues and their crons are listed in Background jobs, and the variables that shape them in Environment variables.