feat(admin): streamline group management
CI / validate (push) Successful in 4m16s
Release / release (push) Failing after 9m14s

This commit is contained in:
dmg
2026-08-02 11:06:55 -04:00
parent 71856bb869
commit d4afb71798
24 changed files with 1588 additions and 379 deletions
+1
View File
@@ -32,6 +32,7 @@ This OKF bundle is the product record for implemented and proposed behavior. Sto
* [US-016 — Build and publish versioned releases](us-016-automated-releases.md) - Gitea Actions publish the Velocity JAR and web and migration images.
* [US-017 — Control admission with groups](us-017-group-access.md) - Each user has one effective group that explicitly controls Minecraft access.
* [US-018 — Monitor community account activity](us-018-admin-dashboard.md) - Administrators review daily users, confirmed connections, locations, denials, and risky networks.
* [US-019 — Manage groups efficiently](us-019-admin-group-management.md) - Administrators manage group identity, policies, membership, and creation through focused confirmed workflows.
# Tracking
+1
View File
@@ -2,6 +2,7 @@
## 2026-08-02
* **Refine**: Replace admin group cards with a policy table, confirmed modal workflows, editable group details, and reusable effective-member management.
* **Add**: Provide Users-page group assignment, effective-group VPN/proxy/Tor exceptions for game admission, and independent configurable denial messages.
* **Fix**: Treat malformed ProxyCheck proxy signals as unknown and classify every authenticated Velocity login before identity resolution.
* **Fix**: Replace the dashboard's pre-enrichment network label with enriched company, ASN, connection type, Proxy/VPN status, and risk fields.
+6 -1
View File
@@ -3,7 +3,7 @@ type: User Story
title: Manage users as an administrator
description: Authorized operators search users and maintain their names, linked accounts, primaries, and Discord nicknames.
tags: [admin, users, minecraft, discord]
timestamp: 2026-08-02T14:12:43Z
timestamp: 2026-08-02T15:03:59Z
story_id: US-013
status: verified
---
@@ -28,6 +28,10 @@ As an administrator, I want to manage a user's identity and Minecraft accounts,
- [x] Selecting a group immediately applies the assignment; selecting `everyone` removes the explicit assignment.
- [x] Group changes preserve the active user search and show accessible success or error feedback.
- [x] Registry assignment changes revalidate administrator authorization, user existence, and group existence, and audit the previous and new effective groups.
- [x] User rows and group-assignment controls are reusable between the Users registry and group-member details.
- [x] Group details show only the group's effective members with identity, Discord, primary-account, account-count, status, and group columns.
- [x] Changing a user's group requires modal confirmation and choosing `everyone` removes the explicit assignment.
- [x] Moving a member to another group removes that user from the current effective-member list after confirmation.
# Implementation
@@ -35,6 +39,7 @@ As an administrator, I want to manage a user's identity and Minecraft accounts,
- [`apps/web/src/app/admin/(console)/users/[userId]/page.tsx`](../apps/web/src/app/admin/%28console%29/users/%5BuserId%5D/page.tsx)
- [`apps/web/src/app/admin/(console)/users/actions.ts`](../apps/web/src/app/admin/%28console%29/users/actions.ts)
- [`apps/web/src/components/user-group-select.tsx`](../apps/web/src/components/user-group-select.tsx)
- [`apps/web/src/components/admin-user-table.tsx`](../apps/web/src/components/admin-user-table.tsx)
# Validation
+5 -1
View File
@@ -3,7 +3,7 @@ type: User Story
title: Control Minecraft admission with groups
description: Administrators assign users to groups and enable Minecraft access through explicit group policy.
tags: [admin, groups, authorization, velocity, security]
timestamp: 2026-08-02T14:12:43Z
timestamp: 2026-08-02T15:03:59Z
story_id: US-017
status: verified
---
@@ -29,6 +29,10 @@ As an administrator, I want to organize registered users into access groups, so
- [x] Confirmed VPN, proxy, or Tor game connections are denied unless the user's single effective group allows anonymized networks.
- [x] Clear and hosting classifications are not denied by this group policy, and unavailable intelligence does not independently deny a registered player.
- [x] VPN policy changes are authorized server-side and audited.
- [x] Group creation can explicitly initialize Minecraft and VPN/proxy/Tor policies while retaining deny-by-default controls.
- [x] List and detail policy changes use the same confirmation workflow.
- [x] Effective member counts include unassigned users who fall back to `everyone`.
- [x] Group names and descriptions are validated and editable server-side.
# Implementation
+45
View File
@@ -0,0 +1,45 @@
---
type: User Story
title: Manage groups efficiently
description: Administrators use concise policy tables, focused group details, and confirmed modal workflows to manage access groups.
tags: [admin, groups, usability, authorization]
timestamp: 2026-08-02T15:03:59Z
story_id: US-019
status: verified
---
# User Story
As an administrator, I want a concise group policy table and focused group details, so that I can manage access without navigating cumbersome controls.
# Acceptance Criteria
- [x] The main Groups page lists name, Minecraft access, VPN/proxy/Tor access, and effective member count with the default group first and remaining names ordered alphabetically.
- [x] Policy controls show their current state and require confirmation in an accessible modal before mutation.
- [x] Selecting a group name opens a detail page with its description, policies, and effective members.
- [x] Add group opens an accessible modal asking for name, description, Minecraft access, and VPN/proxy/Tor access.
- [x] New-group policies default to denied and can be enabled before creation.
- [x] Administrators manage only the display name; an internal collision-safe slug is generated automatically.
- [x] Administrators can edit group name and description; the protected `everyone` name remains fixed while its description remains editable.
- [x] Non-default groups can be deleted only after modal confirmation, returning all affected users to `everyone`.
- [x] Group identity, policy, creation, and deletion mutations commit atomically with their audit events.
- [x] Modal controls support keyboard operation, focus management, cancellation, and clear pending state.
# Implementation
- [`apps/web/src/app/admin/(console)/groups/page.tsx`](../apps/web/src/app/admin/%28console%29/groups/page.tsx)
- [`apps/web/src/app/admin/(console)/groups/[groupId]/page.tsx`](../apps/web/src/app/admin/%28console%29/groups/%5BgroupId%5D/page.tsx)
- [`apps/web/src/app/admin/(console)/groups/actions.ts`](../apps/web/src/app/admin/%28console%29/groups/actions.ts)
- [`apps/web/src/components/admin-modal-form.tsx`](../apps/web/src/components/admin-modal-form.tsx)
- [`apps/web/src/components/group-policy-control.tsx`](../apps/web/src/components/group-policy-control.tsx)
- [`apps/web/src/lib/group-management.ts`](../apps/web/src/lib/group-management.ts)
# Validation
Native-dialog interaction and pending-state behavior are covered by [`apps/web/src/components/admin-modal-form.test.tsx`](../apps/web/src/components/admin-modal-form.test.tsx). Slug, return-path, protected-name, and effective-membership behavior are covered by [`apps/web/src/lib/group-management.test.ts`](../apps/web/src/lib/group-management.test.ts). TypeScript, lint, accessibility review, Semgrep, production build, and OKF validation pass.
# Related Stories
- [Manage users as an administrator](us-013-admin-user-management.md)
- [Control Minecraft admission with groups](us-017-group-access.md)
- [Preserve an audit trail](us-010-audit-events.md)