Skip to content

Admin Console

Sample app for the bundled admin shell: one Kumiko instance with a tenant-admin and a platform workspace, both built from owner-feature screens, and role gating that decides which workspace a signed-in user sees.

With auth: email/password login, three seeded users with different roles. For an auth-free sample, see samples/apps/marketing-demo/.

Terminal window
bun kumiko dev # Postgres + Redis
cd samples/apps/admin-console && bun dev
# → http://localhost:4177

Port 4177 is hardcoded in the dev script. The server reads the root .env (--env-file=../../../.env).

All three log into the dev tenant “Admin Console Demo” (tenant key demo). Passwords are in src/app/auth-constants.ts.

EmailRoleSees
[email protected]global SystemAdmin, tenant Admintenant-admin and platform workspaces
[email protected]tenant TenantAdmintenant-admin workspace only
[email protected]tenant Userno admin workspace

The SystemAdmin comes from the auth.admin bootstrap in src/app/server.ts; the other two are created by seedRoleUsers in src/app/seed-users.ts.

src/run-config.ts lists the server features: localeDe, secrets, audit, delivery, jobs, tier-engine, admin-shell and a small home feature. The client (src/app/client.tsx) adds the matching web parts: email/password login, admin shell, tenant, audit, jobs and tier engine.

  • /tenant-admin/: tenant overview dashboard, members (with invite), audit log
  • /platform/: platform overview dashboard, only for SystemAdmin
  • The workspace switcher only offers the workspaces the user’s roles allow

Every admin-shell screen is role gated, but createKumikoApp needs an open default screenQn. The home feature registers one dormant custom screen without access.roles (home:screen:home). A signed-in user without any admin role lands there and reads “No workspace available for your account.”

src/app/shell.tsx wraps WorkspaceShell with a brand tile and the default topbar actions (light/dark toggle via lucide icons).

Terminal window
cd samples/apps/admin-console
bun x playwright test --config=playwright.config.ts # server on 4183
  • e2e/role-gating.spec.ts: TenantAdmin lands on the tenant overview and never sees the platform tab; the invite role picker offers only User, Editor and Admin; the API answers tenant:list for a TenantAdmin with 403. SystemAdmin sees both workspaces and can switch to the platform overview. A regular user sees no workspace tabs.
  • e2e/audit-log-toolbar.spec.ts: on a narrow viewport the date range facet of the audit log toolbar wraps below the search input; on a wide viewport both stay on one line.

The CI e2e job runs this config together with the other sample apps.

  • Custom business entities (see apps/marketing-demo/)
  • Config keys and the settings hub (see apps/config-demo/)
  • Every bundled feature at once (see apps/use-all-bundled/)

📄 On GitHub: samples/apps/admin-console