feat(admin): streamline group management
This commit is contained in:
@@ -12,7 +12,8 @@ Player account management, administrator navigation, dashboard metrics and chart
|
||||
- Darkened the accent color so accent text reaches at least 4.5:1 contrast on both canvas and panel backgrounds.
|
||||
- Preserved reduced-motion behavior and disabled decorative cursor animation when requested.
|
||||
- Added labels or accessible names to search, Minecraft username, settings, group, and event-filter controls.
|
||||
- Added per-user group dropdowns with immediate-change instructions, keyboard submission fallback, and live success or error feedback.
|
||||
- Added reusable per-user group dropdowns that open labelled confirmation dialogs, restore the prior selection on cancellation, prevent dismissal while pending, and provide live progress and result feedback.
|
||||
- Group creation, policy, editing, and deletion use native modal dialogs with keyboard cancellation, focus management, descriptive confirmation text, and disabled pending controls.
|
||||
- Added `fieldset` and `legend` semantics to multi-select event-type filters.
|
||||
- Added table captions, column scopes, and row scopes to administrator data tables.
|
||||
- Added `role=status` with polite announcements for successful nickname changes and `role=alert` with assertive announcements for errors.
|
||||
|
||||
@@ -26,7 +26,8 @@ Next.js portal and APIs, Discord bot, PostgreSQL persistence, Keycloak admin aut
|
||||
- Velocity and its API fail closed.
|
||||
- Registered players require an enabled effective group; explicit assignments replace rather than combine with the protected, disabled-by-default `everyone` fallback.
|
||||
- Confirmed VPN, proxy, and Tor game connections are denied unless that same effective group has an explicit exception; `everyone` and new groups default to no exception.
|
||||
- Group, VPN-policy, and membership mutations re-check the Keycloak administrator role server-side; registry assignments, VPN-policy changes, message settings, and destructive group deletion commit atomically with their audit events.
|
||||
- Group, VPN-policy, identity, and membership mutations re-check the Keycloak administrator role server-side; registry assignments, policy changes, group edits, creation, deletion, and message settings commit atomically with their audit events.
|
||||
- Group identity creation/rename and membership assignment/deletion use compatible PostgreSQL advisory and row locks to prevent duplicate names, stale audit records, or membership/deletion races. The protected default name and deletion restriction are enforced server-side.
|
||||
- Every bearer-authenticated Velocity login uses cached IP intelligence before identity resolution, preventing account-creation races from bypassing network policy; malformed provider proxy signals classify as unknown.
|
||||
- Event filters accept only event types already present in the ledger, and event detail routes remain role-protected.
|
||||
- The administrator-only map defaults to bundled Natural Earth boundaries. OpenStreetMap tile requests begin only after an explicit operator opt-in; marker coordinates are not transmitted as data, but the requested tiles disclose the viewed geographic extent along with the administrator's IP and portal origin.
|
||||
|
||||
Reference in New Issue
Block a user