75848ff8ea
## Summary Splits admin-panel resolvers off the shared `/metadata` GraphQL endpoint onto a dedicated `/admin-panel` endpoint. The backend plumbing mirrors the existing `metadata` / `core` pattern (new scope, decorator, module, factory), and admin types now live in their own `generated-admin/graphql.ts` on the frontend — dropping 877 lines of admin noise from `generated-metadata`. ## Why - **Smaller attack surface on `/metadata`** — every authenticated user hits that endpoint; admin ops don't belong there. - **Independent complexity limits and monitoring** per endpoint. - **Cleaner module boundaries** — admin is a cross-cutting concern that doesn't match the "shared-schema configuration" meaning of `/metadata`. - **Deploy / blast-radius isolation** — a broken admin query can't affect `/metadata`. Runtime behavior, auth, and authorization are unchanged — this is a relocation, not a re-permissioning. All existing guards (`WorkspaceAuthGuard`, `UserAuthGuard`, `SettingsPermissionGuard(SECURITY)` at class level; `AdminPanelGuard` / `ServerLevelImpersonateGuard` at method level) remain on `AdminPanelResolver`. ## What changed ### Backend - `@AdminResolver()` decorator with scope `'admin'`, naming parallels `CoreResolver` / `MetadataResolver`. - `AdminPanelGraphQLApiModule` + `adminPanelModuleFactory` registered at `/admin-panel`, same Yoga hook set as the metadata factory (Sentry tracing, error handler, introspection-disabling in prod, complexity validation). - Middleware chain on `/admin-panel` is identical to `/metadata`. - `@nestjs/graphql` patch extended: `resolverSchemaScope?: 'core' | 'metadata' | 'admin'`. - `AdminPanelResolver` class decorator swapped from `@MetadataResolver()` to `@AdminResolver()` — no other changes. ### Frontend - `codegen-admin.cjs` → `src/generated-admin/graphql.ts` (982 lines). - `codegen-metadata.cjs` excludes admin paths; metadata file shrinks by 877 lines. - `ApolloAdminProvider` / `useApolloAdminClient` follow the existing `ApolloCoreProvider` / `useApolloCoreClient` pattern, wired inside `AppRouterProviders` alongside the core provider. - 37 admin consumer files migrated: imports switched to `~/generated-admin/graphql` and `client: useApolloAdminClient()` is passed to `useQuery` / `useMutation`. - Three files intentionally kept on `generated-metadata` because they consume non-admin Documents: `useHandleImpersonate.ts`, `SettingsAdminApplicationRegistrationDangerZone.tsx`, `SettingsAdminApplicationRegistrationGeneralToggles.tsx`. ### CI - `ci-server.yaml` runs all three `graphql:generate` configurations and diff-checks all three generated dirs. ## Authorization (unchanged, but audited while reviewing) Every one of the 38 methods on `AdminPanelResolver` has a method-level guard: - `AdminPanelGuard` (32 methods) — requires `canAccessFullAdminPanel === true` - `ServerLevelImpersonateGuard` (6 methods: user/workspace lookup + chat thread views) — requires `canImpersonate === true` On top of the class-level guards above. No resolver method is accessible without these flags + `SECURITY` permission in the workspace. ## Test plan - [ ] Dev server boots; `/graphql`, `/metadata`, `/admin-panel` all mapped as separate GraphQL routes (confirmed locally during development). - [ ] `nx typecheck twenty-server` passes. - [ ] `nx typecheck twenty-front` passes. - [ ] `nx lint:diff-with-main twenty-server` and `twenty-front` both clean. - [ ] Manual smoke test: log in with a user who has `canAccessFullAdminPanel=true`, open the admin panel at `/settings/admin-panel`, verify each tab loads (General, Health, Config variables, AI, Apps, Workspace details, User details, chat threads). - [ ] Manual smoke test: log in with a user who has `canImpersonate=false` and `canAccessFullAdminPanel=false`, hit `/admin-panel` directly with a raw GraphQL request, confirm permission error on every operation. - [ ] Production deploy note: reverse proxy / ingress must route the new `/admin-panel` path to the Nest server. If the proxy has an explicit allowlist, infra change required before cutover. ## Follow-ups (out of scope here) - Consider cutting over the three `SettingsAdminApplicationRegistration*` components to admin-scope versions of the app-registration operations so the admin page is fully on the admin endpoint. - The `renderGraphiQL` double-assignment in `admin-panel.module-factory.ts` is copied from `metadata.module-factory.ts` — worth cleaning up in both.
129 lines
4.0 KiB
JSON
129 lines
4.0 KiB
JSON
{
|
|
"$schema": "./node_modules/oxlint/configuration_schema.json",
|
|
"plugins": ["react", "typescript", "unicorn", "import"],
|
|
"jsPlugins": ["../twenty-oxlint-rules/dist/oxlint-plugin.mjs"],
|
|
"categories": {
|
|
"correctness": "off"
|
|
},
|
|
"ignorePatterns": [
|
|
"node_modules",
|
|
"src/generated",
|
|
"src/generated-metadata",
|
|
"src/generated-admin",
|
|
"src/locales/generated",
|
|
"src/testing/mock-data",
|
|
"**/__mocks__/**",
|
|
"**/*.stories.ts",
|
|
"**/*.stories.tsx",
|
|
"build",
|
|
"coverage",
|
|
"storybook-static"
|
|
],
|
|
"rules": {
|
|
"func-style": ["error", "declaration", { "allowArrowFunctions": true }],
|
|
"no-console": ["warn", { "allow": ["group", "groupCollapsed", "groupEnd"] }],
|
|
"no-script-url": "error",
|
|
"no-control-regex": "off",
|
|
"no-debugger": "error",
|
|
"no-duplicate-imports": "error",
|
|
"no-undef": "off",
|
|
"no-unused-vars": "off",
|
|
"no-redeclare": "off",
|
|
"no-restricted-imports": ["error", {
|
|
"patterns": [
|
|
{
|
|
"group": ["../*"],
|
|
"message": "Relative parent imports are not allowed. Use @/ alias instead."
|
|
},
|
|
{
|
|
"group": ["@tabler/icons-react"],
|
|
"message": "Please import icons from `twenty-ui`"
|
|
},
|
|
{
|
|
"group": ["react-hotkeys-web-hook"],
|
|
"importNames": ["useHotkeys"],
|
|
"message": "Please use the custom wrapper: `useScopedHotkeys` from `twenty-ui`"
|
|
},
|
|
{
|
|
"group": ["lodash"],
|
|
"message": "Please use the standalone lodash package (for instance: `import groupBy from 'lodash.groupby'` instead of `import { groupBy } from 'lodash'`)"
|
|
}
|
|
]
|
|
}],
|
|
|
|
"import/no-duplicates": "error",
|
|
|
|
"react/no-unescaped-entities": "off",
|
|
"react/prop-types": "off",
|
|
"react/jsx-key": "off",
|
|
"react/display-name": "off",
|
|
"react/jsx-uses-react": "off",
|
|
"react/react-in-jsx-scope": "off",
|
|
"react/jsx-no-useless-fragment": "off",
|
|
"react/jsx-no-script-url": "error",
|
|
"react/jsx-props-no-spreading": ["error", { "explicitSpread": "ignore" }],
|
|
|
|
"react-hooks/rules-of-hooks": "error",
|
|
"react-hooks/exhaustive-deps": "warn",
|
|
|
|
"typescript/no-redeclare": "error",
|
|
"typescript/ban-ts-comment": "error",
|
|
"typescript/consistent-type-imports": ["error", {
|
|
"prefer": "type-imports",
|
|
"fixStyle": "inline-type-imports"
|
|
}],
|
|
"typescript/explicit-function-return-type": "off",
|
|
"typescript/explicit-module-boundary-types": "off",
|
|
"typescript/no-empty-object-type": ["error", {
|
|
"allowInterfaces": "with-single-extends"
|
|
}],
|
|
"typescript/no-empty-function": "off",
|
|
"typescript/no-explicit-any": "off",
|
|
"typescript/no-unused-vars": ["warn", {
|
|
"vars": "all",
|
|
"varsIgnorePattern": "^_",
|
|
"args": "after-used",
|
|
"argsIgnorePattern": "^_"
|
|
}],
|
|
|
|
"typescript/strict-boolean-expressions": ["error", {
|
|
"allowNullableBoolean": true,
|
|
"allowNullableObject": true,
|
|
"allowString": true,
|
|
"allowNumber": true,
|
|
"allowNullableString": true,
|
|
"allowNullableNumber": true,
|
|
"allowNullableEnum": true,
|
|
"allowAny": true
|
|
}],
|
|
|
|
"twenty/effect-components": "error",
|
|
"twenty/no-hardcoded-colors": "error",
|
|
"twenty/matching-state-variable": "error",
|
|
"twenty/sort-css-properties-alphabetically": "error",
|
|
"twenty/styled-components-prefixed-with-styled": "error",
|
|
"twenty/no-state-useref": "error",
|
|
"twenty/component-props-naming": "error",
|
|
"twenty/no-navigate-prefer-link": "error",
|
|
"twenty/no-jotai-store-in-selector": "error",
|
|
"twenty/no-direct-atom-family-in-selector": "error",
|
|
"twenty/folder-structure": "error",
|
|
"twenty/enforce-module-boundaries": ["error", {
|
|
"depConstraints": [
|
|
{
|
|
"sourceTag": "scope:frontend",
|
|
"onlyDependOnLibsWithTags": ["scope:shared", "scope:frontend"]
|
|
}
|
|
]
|
|
}]
|
|
},
|
|
"overrides": [
|
|
{
|
|
"files": ["**/constants/*.ts", "**/*.constants.ts"],
|
|
"rules": {
|
|
"twenty/max-consts-per-file": ["error", { "max": 1 }]
|
|
}
|
|
}
|
|
]
|
|
}
|