33 lines
1.3 KiB
Markdown
33 lines
1.3 KiB
Markdown
# ADR-0004: The admin dashboard has no database access
|
|
|
|
- **Status:** Accepted
|
|
- **Date:** 2026-08-11
|
|
|
|
## Context
|
|
|
|
The admin is a Next.js application and could trivially import Prisma and query
|
|
PostgreSQL from a Server Action. It would be faster to write. It would also create a second
|
|
write path in which RBAC, validation and audit logging are re-implemented — or forgotten.
|
|
|
|
## Decision
|
|
|
|
The admin has no database driver, no Prisma client, no Redis client and no storage
|
|
credentials. Every read and write goes through the REST API via `@sport/api-client`. The rule
|
|
is enforced by ESLint (`no-restricted-imports` on `@prisma/client` and `ioredis` in both
|
|
frontends) and by the absence of `DATABASE_URL` from the admin's environment.
|
|
|
|
## Consequences
|
|
|
|
Authorization is checked in exactly one place. The audit log cannot be bypassed.
|
|
The API surface stays honest, because the admin is its most demanding consumer — and a future
|
|
mobile app or partner integration inherits a proven API rather than a thin one.
|
|
|
|
The cost is an extra network hop for back-office screens, which is irrelevant at back-office
|
|
traffic levels.
|
|
|
|
## Alternatives considered
|
|
|
|
Direct database access from Server Actions — rejected for the reasons above.
|
|
A separate "admin API" service — rejected: two APIs over one database is the same problem with
|
|
more deployment.
|