1.3 KiB
ADR-0004: The admin dashboard has no database access
- Status: Accepted
- Date: 2026-08-11
Context
The admin is a Next.js application and could trivially import Prisma and query PostgreSQL from a Server Action. It would be faster to write. It would also create a second write path in which RBAC, validation and audit logging are re-implemented — or forgotten.
Decision
The admin has no database driver, no Prisma client, no Redis client and no storage
credentials. Every read and write goes through the REST API via @sport/api-client. The rule
is enforced by ESLint (no-restricted-imports on @prisma/client and ioredis in both
frontends) and by the absence of DATABASE_URL from the admin's environment.
Consequences
Authorization is checked in exactly one place. The audit log cannot be bypassed. The API surface stays honest, because the admin is its most demanding consumer — and a future mobile app or partner integration inherits a proven API rather than a thin one.
The cost is an extra network hop for back-office screens, which is irrelevant at back-office traffic levels.
Alternatives considered
Direct database access from Server Actions — rejected for the reasons above. A separate "admin API" service — rejected: two APIs over one database is the same problem with more deployment.