Files
web_sport/docs/adr/0004-the-admin-dashboard-has-no-database-access.md
T

33 lines
1.3 KiB
Markdown

# ADR-0004: The admin dashboard has no database access
- **Status:** Accepted
- **Date:** 2026-08-11
## Context
The admin is a Next.js application and could trivially import Prisma and query
PostgreSQL from a Server Action. It would be faster to write. It would also create a second
write path in which RBAC, validation and audit logging are re-implemented — or forgotten.
## Decision
The admin has no database driver, no Prisma client, no Redis client and no storage
credentials. Every read and write goes through the REST API via `@sport/api-client`. The rule
is enforced by ESLint (`no-restricted-imports` on `@prisma/client` and `ioredis` in both
frontends) and by the absence of `DATABASE_URL` from the admin's environment.
## Consequences
Authorization is checked in exactly one place. The audit log cannot be bypassed.
The API surface stays honest, because the admin is its most demanding consumer — and a future
mobile app or partner integration inherits a proven API rather than a thin one.
The cost is an extra network hop for back-office screens, which is irrelevant at back-office
traffic levels.
## Alternatives considered
Direct database access from Server Actions — rejected for the reasons above.
A separate "admin API" service — rejected: two APIs over one database is the same problem with
more deployment.