Skip to content

Admin maintenance mode for classroom and collaboration lifecycle cleanup #329

Description

@MajorIncident

Goal

Add a deliberate, server-authorized Administration / Maintenance experience for inspecting and cleaning stale Classroom and collaboration data before production and during ongoing operation.

This is not an Intake experience role and must not weaken Standalone/Student/Instructor authorization.

Admin entry and authorization

  • provide an Administration/Maintenance entry from the startup experience hub or another explicit app entry;
  • require a high-entropy server-configured admin credential (environment-managed; never bundled in browser assets);
  • keep the credential out of Intake persistence, exports, summaries, URLs, logs, and long-lived localStorage;
  • prefer tab/session-scoped browser retention only after explicit entry;
  • all admin responses are private/no-store/no-referrer.

Inventory view

Show separate, filterable inventories for:

Classrooms

  • public class ID/title;
  • status: active / revoked / expired;
  • created / updated / expiry timestamps;
  • most recent participant/presence activity;
  • participant/workspace counts;
  • current staged exercise state where relevant;
  • derived idle age.

Standalone/ad-hoc collaboration workspaces

  • public workspace/session identifier;
  • created / updated / expiry timestamps;
  • most recent presence/activity;
  • participant count;
  • derived idle age;
  • whether the workspace is class-owned or independent.

Do not expose raw bearer capabilities.

Cleanup actions

Support explicit preview-before-delete operations:

  • revoke/close a class immediately;
  • purge one expired/revoked class and its class-owned subordinate records;
  • bulk purge classes idle/expired beyond a selected threshold;
  • purge standalone collaboration workspaces idle/expired beyond a selected threshold;
  • show the exact rows/objects that will be removed before confirmation.

Cleanup must be transactional/fail-closed where practical, respect foreign-key ownership, and must never delete an apparently active workspace merely because its snapshot is old if recent presence says it is active.

Retention model

Use server timestamps as authority. Define deterministic idle rules from workspace/class update time plus most-recent presence/activity. Existing CLASS_EXPIRY_DAYS remains a creation-time expiry policy; Admin cleanup is the intentional physical purge mechanism.

Consider a future scheduled purge only after the manual Admin flow is proven. Do not introduce autonomous deletion in this slice.

Recovery

Because the pre-production compatibility reset removes the public Instructor access-code recovery form, Admin should provide an explicit class recovery action if needed (for example rotate/reissue Instructor authority) without exposing historical raw credentials.

Tests

  • admin auth rejection and no capability leakage;
  • class/workspace inventory isolation;
  • idle/active classification;
  • dry-run/preview matches committed deletion;
  • cascade integrity;
  • no deletion of active/recent-presence sessions;
  • mobile/keyboard/axe coverage for the Admin UI;
  • Serverless Function budget remains within repository limits.

Done when

An authorized maintainer can see what is occupying the database, understand why an item is considered stale, and safely clean selected or bulk idle/expired Classroom and collaboration data without direct database access.

Activity

  1. MajorIncident commented on Oct 8, 2026

    @MajorIncident
    OwnerAuthor

    #329 complete.

    Merged PR #333 to main as b04684f2432aa474cb84874aa26aa08a5f4c5ab7.

    Production:

    • Vercel deployment dpl_36mCJ4BsuRxCMjoU34y8nz7fTFsE is READY for exact merged SHA b04684f...;
    • production alias mapped successfully;
    • 30-minute runtime error scan: 0 errors;
    • warning/error/fatal log scan on the exact deployment: clean;
    • user confirmed INTAKE_ADMIN_TOKEN is configured in the Production environment.

    Acceptance limitation:

    • automated HTTP verification of the app-level unauthenticated /api/admin 401 is blocked by the existing Vercel Authentication layer before the request reaches Intake;
    • the authenticated Vercel share-link path is also blocked for this production protection configuration;
    • Deployment Protection was intentionally not weakened or modified to make the probe pass.

    Repository acceptance before merge:

    • CI + required browser regression: green;
    • CodeQL: green;
    • Dependency Review: green;
    • Template Manifest Guard: green;
    • unresolved review threads: 0.

    Next product slice: #330 startup experience hub.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions