Files
web_sport/docs/adr/0004-the-admin-dashboard-has-no-database-access.md

1.3 KiB

ADR-0004: The admin dashboard has no database access

  • Status: Accepted
  • Date: 2026-08-11

Context

The admin is a Next.js application and could trivially import Prisma and query PostgreSQL from a Server Action. It would be faster to write. It would also create a second write path in which RBAC, validation and audit logging are re-implemented — or forgotten.

Decision

The admin has no database driver, no Prisma client, no Redis client and no storage credentials. Every read and write goes through the REST API via @sport/api-client. The rule is enforced by ESLint (no-restricted-imports on @prisma/client and ioredis in both frontends) and by the absence of DATABASE_URL from the admin's environment.

Consequences

Authorization is checked in exactly one place. The audit log cannot be bypassed. The API surface stays honest, because the admin is its most demanding consumer — and a future mobile app or partner integration inherits a proven API rather than a thin one.

The cost is an extra network hop for back-office screens, which is irrelevant at back-office traffic levels.

Alternatives considered

Direct database access from Server Actions — rejected for the reasons above. A separate "admin API" service — rejected: two APIs over one database is the same problem with more deployment.