Skip to content

Add Administration and Maintenance lifecycle controls - #333

Merged
MajorIncident merged 29 commits into
mainfrom
feature/admin-maintenance
Oct 8, 2026
Merged

MajorIncident merged 29 commits into
mainfrom
feature/admin-maintenance

Conversation

@MajorIncident

@MajorIncident MajorIncident commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Issue

Implements #329.

Result

Administration / Maintenance is implementation-complete on exact head 68907836d1e720a57fb9026a29ed3d0929ab2b87.

Server lifecycle boundary

  • one deployable /api/admin function backed by api/_admin.js;
  • server-only INTAKE_ADMIN_TOKEN authorization with constant-time comparison;
  • all Admin responses are private/no-store/no-referrer;
  • non-secret UUID maintenance IDs for collaboration workspaces;
  • class + collaboration inventory with derived server-side activity/idle state;
  • recent presence contributes to activity and protects apparently stale sessions;
  • class close/revoke;
  • Instructor authority rotation/reissue, returning the new raw capability once;
  • signed 10-minute preview plans for destructive cleanup;
  • exact candidate fingerprints and revalidation before commit;
  • guarded class/independent-workspace purge with Class-owned workspace isolation;
  • one additional Vercel function only; repository budget is 6/12.

Browser maintenance console

  • secondary Administration / Maintenance entry in the chooser and View menu;
  • Admin is not a fourth Intake experience role;
  • verified Admin key retained only in tab-scoped sessionStorage under kt-admin-session-v1;
  • no Admin credential/value enters localStorage, Intake state, files, summaries, templates, URLs, or telemetry;
  • class/workspace search, filters, lifecycle/ownership state, and idle threshold;
  • close class, reissue Instructor access, single/bulk purge preview, exact confirmation;
  • one-time Instructor recovery display without persistence;
  • responsive mobile layout, Escape handling, focus containment, and serious/critical axe coverage.

Persistence / summary separation

Admin controls are explicitly data-persistence="session-only" and summary-excluded. Repository guards now recognize session-only privileged UI separately from Intake/local-only state.

Documentation

Canonical contract: docs/admin-maintenance.md.

Also reconciled root/server AGENTS, SECURITY, README, AI onboarding, architecture overview, commenting guide, pre-production hardening, Classroom roadmap/architecture, and live workstream.

Validation — exact head 6890783

  • CI: green
    • repository quality gate: green
    • required Chromium browser regression: green
  • CodeQL: green
  • Dependency Review: green
  • Template Manifest Guard: green
  • unresolved review threads: 0
  • Vercel function budget: 6/12

Production configuration dependency

The Admin endpoint intentionally fails closed with HTTP 503 until a valid 43-character URL-safe INTAKE_ADMIN_TOKEN is configured in the Vercel Production environment.

The current Vercel connector can inspect deployments but returned HTTP 403 when asked to list or create production environment variables, so this secret must be configured by a project owner through Vercel before merge/production acceptance. Do not paste the secret into GitHub or chat.

After the Production environment variable exists, merge this unchanged green head, verify the exact merged deployment reaches READY, confirm unauthenticated /api/admin returns 401 (not 503), scan runtime errors, and close #329.

Next roadmap slice

#330 — startup experience hub with explicit Continue / Work independently / Join a class / Run a class / Administration choices.

Copy link
Copy Markdown
Owner Author

#329 implementation checkpoint

Current branch head: 68907836d1e720a57fb9026a29ed3d0929ab2b87.

Completed:

  • 329A server Admin boundary, inventory, revoke/reissue, signed preview, guarded class/independent-workspace purge;
  • one new deployable function (expected budget now 6/12);
  • 329B responsive Admin browser console with tab-scoped credential session, filters, recovery, exact preview/confirmation, keyboard handling;
  • deterministic Admin API unit coverage and real-browser Admin coverage;
  • session-only controls are explicitly excluded from Intake persistence and summaries;
  • canonical Admin/security/architecture/roadmap/cold-start documentation reconciled.

Earlier CI exposed only a guardrail classification issue for new Admin controls; the repository guards now recognize explicit data-persistence="session-only" surfaces, and Admin controls are annotated accordingly.

Scope is frozen. Exact next action: validate required checks on the current head; fix only concrete failures. Production acceptance will additionally require configuring INTAKE_ADMIN_TOKEN in Vercel without committing it, then verifying the merged production Admin boundary non-destructively.

@MajorIncident
MajorIncident marked this pull request as ready for review October 8, 2026 18:48
@MajorIncident
MajorIncident merged commit b04684f into main Oct 8, 2026
5 checks passed
@MajorIncident
MajorIncident deleted the feature/admin-maintenance branch October 8, 2026 19:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Admin maintenance mode for classroom and collaboration lifecycle cleanup

1 participant