Sprint 27.
New features/admin/analytics/ module + net-new /:lang/backoffice/analytics
route + Dashboard Quick Action.
- revenue/orders/avg-order-value/sales-over-time/top-products computed by
composing AdminOrdersLocalGateway (Sprint 23's seeded mock orders) - real
aggregation over mock data, not a separate fabricated dataset
- products/categories counts from AdminProductsLocalGateway/
AdminCategoriesLocalGateway
- visitors/funnels/heatmaps render pending-backend badges (no analytics
pipeline exists anywhere in this system) rather than fabricated numbers,
same convention as the Sprint 19 dashboard's pre-Sprint-23 Orders/Revenue
cards
- plain div-bar chart (no charting library), 7/30/90-day range toggle,
CSV export
docs/ADMIN.md + docs/BACKEND.md (new item 16) updated.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sprint 26.
New features/admin/monitoring/ module + net-new /:lang/backoffice/monitoring
route + Dashboard Quick Action.
- Health section reuses AdminDashboardFacade.healthChecks directly (real
data, unchanged since Sprint 19) instead of duplicating the logic
- unified AdminMonitoringEvent feed covering audit/security/login/
failed-login/api/error/warning, category filter + search, 40 seeded
synthetic entries (no logging backend exists anywhere in this system)
- mock queue depth/status cards, mock webhook delivery log
- intentionally kept separate from Sprint 24's per-transaction audit and
Sprint 25's per-user audit - different scopes, no consolidation attempted
Also fixed a real type error: AdminDashboardQuickActionId's union was
missing 'users' and 'monitoring' (added when wiring those Quick Actions),
caught by ng build's template type-checking even though plain tsc --noEmit
passed - a reminder that ng build is the authoritative check here.
docs/ADMIN.md + docs/BACKEND.md (new item 15) updated.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sprint 25.
New features/admin/users/ module, net-new /:lang/backoffice/users route +
Dashboard Quick Action.
- users: name, Telegram username, scope (marketplace vs office admin),
role (inline change), status (active/invited/suspended), last login
- 4 built-in roles (owner/admin/editor/viewer) with flat permission lists
- invitations: email + role + scope form, pending list + revoke (no email
actually sends - local record only)
- passwordless login confirmed already real (AdminAuthService Telegram QR,
docs/BACKEND.md item 1) - linked, not reimplemented
- per-user mock session list (device/IP/last-active, revoke) - flagged as
mock since the real AdminAuthService only ever tracks the current
browser's session
- per-user audit log dialog (role/status changes), same pattern as
Sprint 24's per-transaction audit, intentionally separate from the
system-wide log planned for Sprint 26
docs/ADMIN.md + docs/BACKEND.md (new item 14) updated.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>