## Summary Splits admin-panel resolvers off the shared `/metadata` GraphQL endpoint onto a dedicated `/admin-panel` endpoint. The backend plumbing mirrors the existing `metadata` / `core` pattern (new scope, decorator, module, factory), and admin types now live in their own `generated-admin/graphql.ts` on the frontend — dropping 877 lines of admin noise from `generated-metadata`. ## Why - **Smaller attack surface on `/metadata`** — every authenticated user hits that endpoint; admin ops don't belong there. - **Independent complexity limits and monitoring** per endpoint. - **Cleaner module boundaries** — admin is a cross-cutting concern that doesn't match the "shared-schema configuration" meaning of `/metadata`. - **Deploy / blast-radius isolation** — a broken admin query can't affect `/metadata`. Runtime behavior, auth, and authorization are unchanged — this is a relocation, not a re-permissioning. All existing guards (`WorkspaceAuthGuard`, `UserAuthGuard`, `SettingsPermissionGuard(SECURITY)` at class level; `AdminPanelGuard` / `ServerLevelImpersonateGuard` at method level) remain on `AdminPanelResolver`. ## What changed ### Backend - `@AdminResolver()` decorator with scope `'admin'`, naming parallels `CoreResolver` / `MetadataResolver`. - `AdminPanelGraphQLApiModule` + `adminPanelModuleFactory` registered at `/admin-panel`, same Yoga hook set as the metadata factory (Sentry tracing, error handler, introspection-disabling in prod, complexity validation). - Middleware chain on `/admin-panel` is identical to `/metadata`. - `@nestjs/graphql` patch extended: `resolverSchemaScope?: 'core' | 'metadata' | 'admin'`. - `AdminPanelResolver` class decorator swapped from `@MetadataResolver()` to `@AdminResolver()` — no other changes. ### Frontend - `codegen-admin.cjs` → `src/generated-admin/graphql.ts` (982 lines). - `codegen-metadata.cjs` excludes admin paths; metadata file shrinks by 877 lines. - `ApolloAdminProvider` / `useApolloAdminClient` follow the existing `ApolloCoreProvider` / `useApolloCoreClient` pattern, wired inside `AppRouterProviders` alongside the core provider. - 37 admin consumer files migrated: imports switched to `~/generated-admin/graphql` and `client: useApolloAdminClient()` is passed to `useQuery` / `useMutation`. - Three files intentionally kept on `generated-metadata` because they consume non-admin Documents: `useHandleImpersonate.ts`, `SettingsAdminApplicationRegistrationDangerZone.tsx`, `SettingsAdminApplicationRegistrationGeneralToggles.tsx`. ### CI - `ci-server.yaml` runs all three `graphql:generate` configurations and diff-checks all three generated dirs. ## Authorization (unchanged, but audited while reviewing) Every one of the 38 methods on `AdminPanelResolver` has a method-level guard: - `AdminPanelGuard` (32 methods) — requires `canAccessFullAdminPanel === true` - `ServerLevelImpersonateGuard` (6 methods: user/workspace lookup + chat thread views) — requires `canImpersonate === true` On top of the class-level guards above. No resolver method is accessible without these flags + `SECURITY` permission in the workspace. ## Test plan - [ ] Dev server boots; `/graphql`, `/metadata`, `/admin-panel` all mapped as separate GraphQL routes (confirmed locally during development). - [ ] `nx typecheck twenty-server` passes. - [ ] `nx typecheck twenty-front` passes. - [ ] `nx lint:diff-with-main twenty-server` and `twenty-front` both clean. - [ ] Manual smoke test: log in with a user who has `canAccessFullAdminPanel=true`, open the admin panel at `/settings/admin-panel`, verify each tab loads (General, Health, Config variables, AI, Apps, Workspace details, User details, chat threads). - [ ] Manual smoke test: log in with a user who has `canImpersonate=false` and `canAccessFullAdminPanel=false`, hit `/admin-panel` directly with a raw GraphQL request, confirm permission error on every operation. - [ ] Production deploy note: reverse proxy / ingress must route the new `/admin-panel` path to the Nest server. If the proxy has an explicit allowlist, infra change required before cutover. ## Follow-ups (out of scope here) - Consider cutting over the three `SettingsAdminApplicationRegistration*` components to admin-scope versions of the app-registration operations so the admin page is fully on the admin endpoint. - The `renderGraphiQL` double-assignment in `admin-panel.module-factory.ts` is copied from `metadata.module-factory.ts` — worth cleaning up in both.
314 lines
7.5 KiB
JSON
314 lines
7.5 KiB
JSON
{
|
|
"name": "twenty-front",
|
|
"$schema": "../../node_modules/nx/schemas/project-schema.json",
|
|
"projectType": "application",
|
|
"tags": [
|
|
"scope:frontend"
|
|
],
|
|
"targets": {
|
|
"build": {
|
|
"outputs": [
|
|
"{options.outputPath}"
|
|
],
|
|
"options": {
|
|
"outputPath": "{projectRoot}/build"
|
|
},
|
|
"dependsOn": [
|
|
"^build"
|
|
]
|
|
},
|
|
"build:sourcemaps": {
|
|
"outputs": [
|
|
"{options.outputPath}"
|
|
],
|
|
"options": {
|
|
"outputPath": "{projectRoot}/build"
|
|
},
|
|
"dependsOn": [
|
|
"^build"
|
|
]
|
|
},
|
|
"serve": {
|
|
"executor": "nx:run-commands",
|
|
"options": {
|
|
"command": "npx serve -s {projectRoot}/build"
|
|
}
|
|
},
|
|
"start": {
|
|
"executor": "@nx/vite:dev-server",
|
|
"options": {
|
|
"buildTarget": "twenty-front:build",
|
|
"hmr": true
|
|
}
|
|
},
|
|
"preview": {
|
|
"executor": "@nx/vite:preview-server",
|
|
"options": {
|
|
"buildTarget": "twenty-front:build",
|
|
"port": 3001,
|
|
"open": true
|
|
}
|
|
},
|
|
"reset:env": {
|
|
"executor": "nx:run-commands",
|
|
"inputs": [
|
|
"{projectRoot}/.env.example"
|
|
],
|
|
"outputs": [
|
|
"{projectRoot}/.env"
|
|
],
|
|
"cache": true,
|
|
"options": {
|
|
"cwd": "{projectRoot}",
|
|
"command": "cp .env.example .env"
|
|
}
|
|
},
|
|
"typecheck": {},
|
|
"lint": {
|
|
"executor": "nx:run-commands",
|
|
"cache": true,
|
|
"dependsOn": ["twenty-oxlint-rules:build", "twenty-shared:build"],
|
|
"inputs": [
|
|
"{projectRoot}/src/**/*.{ts,tsx}",
|
|
"{projectRoot}/tsconfig*.json",
|
|
"{workspaceRoot}/tsconfig.base.json",
|
|
"{projectRoot}/.oxlintrc.json",
|
|
"{workspaceRoot}/packages/twenty-oxlint-rules/dist/oxlint-plugin.mjs"
|
|
],
|
|
"options": {
|
|
"cwd": "{projectRoot}",
|
|
"command": "npx oxlint --type-aware -c .oxlintrc.json src/ && (prettier src/ --check --cache --cache-location ../../.cache/prettier/{projectRoot} --cache-strategy metadata || (echo 'ERROR: Prettier formatting check failed! Fix with: npx nx lint twenty-front --configuration=fix' && false))"
|
|
},
|
|
"configurations": {
|
|
"fix": {
|
|
"command": "npx oxlint --type-aware --fix -c .oxlintrc.json src/ && prettier src/ --write --cache --cache-location ../../.cache/prettier/{projectRoot} --cache-strategy metadata"
|
|
}
|
|
}
|
|
},
|
|
"lint:diff-with-main": {
|
|
"executor": "nx:run-commands",
|
|
"options": {
|
|
"cwd": "{projectRoot}",
|
|
"command": "FILES=$(git diff --name-only --relative --diff-filter=d main...HEAD -- src/ | grep -E '\\.(ts|tsx)$'); [ -z \"$FILES\" ] && echo 'No changed files.' || (npx oxlint --type-aware -c .oxlintrc.json $FILES && (prettier --check $FILES || (echo 'ERROR: Prettier formatting check failed! Fix with: npx nx lint:diff-with-main twenty-front --configuration=fix' && false)))"
|
|
},
|
|
"configurations": {
|
|
"fix": {
|
|
"command": "FILES=$(git diff --name-only --relative --diff-filter=d main...HEAD -- src/ | grep -E '\\.(ts|tsx)$'); [ -z \"$FILES\" ] && echo 'No changed files.' || (npx oxlint --type-aware --fix -c .oxlintrc.json $FILES && prettier --write $FILES)"
|
|
}
|
|
}
|
|
},
|
|
"fmt": {
|
|
"options": {
|
|
"files": "src"
|
|
},
|
|
"configurations": {
|
|
"fix": {}
|
|
}
|
|
},
|
|
"test": {},
|
|
"storybook:build": {
|
|
"options": {
|
|
"env": {
|
|
"NODE_OPTIONS": "--max_old_space_size=8000"
|
|
}
|
|
},
|
|
"configurations": {
|
|
"docs": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "ui-docs"
|
|
}
|
|
},
|
|
"modules": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "modules"
|
|
}
|
|
},
|
|
"pages": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "pages"
|
|
}
|
|
},
|
|
"performance": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "performance"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"storybook:serve:dev": {
|
|
"options": {
|
|
"port": 6006
|
|
},
|
|
"configurations": {
|
|
"docs": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "ui-docs"
|
|
}
|
|
},
|
|
"modules": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "modules"
|
|
}
|
|
},
|
|
"pages": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "pages"
|
|
}
|
|
},
|
|
"performance": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "performance"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"storybook:serve:static": {
|
|
"options": {
|
|
"port": 6006
|
|
},
|
|
"configurations": {
|
|
"docs": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "ui-docs"
|
|
}
|
|
},
|
|
"modules": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "modules"
|
|
}
|
|
},
|
|
"pages": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "pages"
|
|
}
|
|
},
|
|
"performance": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "performance"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"storybook:coverage": {
|
|
"configurations": {
|
|
"text": {},
|
|
"docs": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "ui-docs"
|
|
}
|
|
},
|
|
"modules": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "modules"
|
|
}
|
|
},
|
|
"pages": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "pages"
|
|
}
|
|
},
|
|
"performance": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "performance"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"storybook:test": {
|
|
"configurations": {
|
|
"docs": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "ui-docs"
|
|
}
|
|
},
|
|
"modules": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "modules"
|
|
}
|
|
},
|
|
"pages": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "pages"
|
|
}
|
|
},
|
|
"performance": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "performance"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"storybook:test:no-coverage": {
|
|
"configurations": {
|
|
"docs": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "ui-docs"
|
|
}
|
|
},
|
|
"modules": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "modules"
|
|
}
|
|
},
|
|
"pages": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "pages"
|
|
}
|
|
},
|
|
"performance": {
|
|
"env": {
|
|
"STORYBOOK_SCOPE": "performance"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"graphql:generate": {
|
|
"executor": "nx:run-commands",
|
|
"defaultConfiguration": "data",
|
|
"options": {
|
|
"cwd": "{projectRoot}",
|
|
"command": "dotenv graphql-codegen -- --config={args.config}"
|
|
},
|
|
"configurations": {
|
|
"data": {
|
|
"config": "codegen.cjs"
|
|
},
|
|
"metadata": {
|
|
"config": "codegen-metadata.cjs"
|
|
},
|
|
"admin": {
|
|
"config": "codegen-admin.cjs"
|
|
}
|
|
}
|
|
},
|
|
"mock:generate": {
|
|
"executor": "nx:run-commands",
|
|
"options": {
|
|
"cwd": "{projectRoot}",
|
|
"command": "dotenv npx vite-node scripts/generate-mock-data.ts"
|
|
}
|
|
},
|
|
"chromatic": {
|
|
"configurations": {
|
|
"ci": {}
|
|
}
|
|
},
|
|
"lingui:extract": {
|
|
"executor": "nx:run-commands",
|
|
"dependsOn": ["^build"],
|
|
"options": {
|
|
"cwd": "{projectRoot}",
|
|
"command": "lingui extract --overwrite --clean"
|
|
}
|
|
},
|
|
"lingui:compile": {
|
|
"executor": "nx:run-commands",
|
|
"dependsOn": ["^build"],
|
|
"options": {
|
|
"cwd": "{projectRoot}",
|
|
"command": "lingui compile --typescript"
|
|
}
|
|
}
|
|
}
|
|
}
|