Sprint 23. New features/admin/orders/ module, same container/facade/service split as admin/products and admin/categories. - AdminOrder model + AdminOrdersLocalGateway seeding 24 deterministic synthetic orders (no real order data source exists anywhere in this repo - explicitly a placeholder, not a mock of production volume) - list: search, status filter, pagination, CSV export (client-side Blob download) - detail: customer/payment/shipping, itemized total, status timeline, change-status dropdown, refund request + cancel (window.confirm-gated), separate customer-facing vs internal notes, print invoice via window.print() with @media print hiding non-invoice chrome - wired into /:lang/backoffice/orders(/:id), replacing the coming-soon placeholder docs/ADMIN.md + docs/BACKEND.md updated; dashboard's Orders/Revenue cards (Sprint 19) remain intentionally un-wired to this mock and still render pending-backend. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
19 KiB
Marketplace Admin Dashboard - Sprint 19
Scope
Sprint 19 adds the production Admin Dashboard and makes it the default landing
page for the admin area. It also wires the previously-unrouted admin/products
feature and adds route placeholders for backoffice sections that don't have a
feature built yet.
Routing
All admin routes live under /:lang/backoffice/** (app.routes.ts), guarded
by the existing adminAuthGuard (core/admin-auth/admin-auth.guard.ts):
/:lang/backoffice -> redirects to dashboard
/:lang/backoffice/dashboard -> AdminDashboardPageComponent
/:lang/backoffice/products -> AdminProductsListPageComponent
/:lang/backoffice/products/create -> AdminProductEditorPageComponent
/:lang/backoffice/products/:id/edit -> AdminProductEditorPageComponent
/:lang/backoffice/products/:id/duplicate -> AdminProductEditorPageComponent
/:lang/backoffice/categories -> AdminCategoriesListPageComponent
/:lang/backoffice/categories/create -> AdminCategoryEditorPageComponent
/:lang/backoffice/categories/:id/edit -> AdminCategoryEditorPageComponent
/:lang/backoffice/static-pages -> BackofficeComingSoonPageComponent
/:lang/backoffice/transactions -> BackofficeComingSoonPageComponent
/:lang/backoffice/orders -> BackofficeComingSoonPageComponent
/:lang/backoffice/media -> BackofficeComingSoonPageComponent
admin/products (features/admin/products/) was already fully implemented
in an earlier sprint but was never wired into app.routes.ts and its internal
navigation hardcoded the ru locale segment. Both are fixed in this sprint:
routes are wired, and admin-products-list-page.component.ts /
admin-product-editor-page.component.ts now build the locale segment from
LanguageService.currentLanguage().
Dashboard as default admin page: on successful admin Telegram QR login,
TelegramLoginComponent (mode="admin") navigates to
/:lang/backoffice/dashboard (components/telegram-login/telegram-login.component.ts).
The backoffice route's empty path also redirects to dashboard, so any bare
/:lang/backoffice link lands there too.
Architecture
src/app/features/admin/dashboard/
models/ admin-dashboard.model.ts
services/ admin-dashboard-metrics.gateway.interface.ts
admin-dashboard-metrics.local.gateway.ts
admin-dashboard-metrics-gateway.token.ts
admin-dashboard-history.service.ts
facade/ admin-dashboard.facade.ts
components/ admin-dashboard-card.component.*
admin-dashboard-quick-actions.component.*
admin-dashboard-activity.component.*
admin-dashboard-health.component.*
pages/ admin-dashboard-page.component.*
src/app/features/backoffice/shared/
backoffice-coming-soon-page.component.*
Follows the existing container/facade/service split (ADR-006, ADR-007):
AdminDashboardPageComponent is the container, AdminDashboardFacade owns
orchestration, presentational card/quick-actions/activity/health components
take only @Input()s and have no HttpClient/localStorage/route access.
Data sources (future-ready)
Cards never read ConfigService, localStorage, or an HTTP client directly -
everything routes through AdminDashboardFacade, which composes:
ProjectEditorFacade(already existed) -bootstrap,status,lastSavedAt,lastPublishedAt(new, see below),validationIssues,homepageWidgets. Backs Marketplace Status, Project Name, Current Theme, Languages, Last Publish, Last Draft Save, Bootstrap Version, Active Layout, Enabled Widgets, and the System Health checks.ADMIN_DASHBOARD_METRICS_GATEWAY(newInjectionToken, same swap pattern asBACKOFFICE_DATA_PROVIDER) - defaults toAdminDashboardMetricsLocalGateway, which composesBackofficeDataService.loadCategories()/loadProducts()(already used byAdminProductsLocalGateway) into counts. Backs Categories Count and Products Count. Swapping to a real dashboard-metrics endpoint later means implementingAdminDashboardMetricsGatewayand rebinding the token - the facade and cards don't change.AdminDashboardHistoryService(new) - localStorage-backed activity log, scoped per tenant, same pattern asProjectEditorDraftStorageService. The facade appends an entry wheneverlastSavedAt/lastPublishedAtchange (detected via aneffect(), primed on first read so the initial bootstrap load doesn't get logged as an activity event). Backs Recent Activity.
Orders / Revenue
No backend or local data model exists for orders or revenue anywhere in the
codebase (features/backoffice/orders is an empty placeholder folder). These
two cards render an honest pending-backend card state ("Awaiting backend
integration") rather than fabricated numbers - not a "no data" empty state,
since the gap is structural, not a temporarily-empty dataset.
Card states
AdminDashboardCardComponent (components/admin-dashboard-card.component.ts)
renders one of: loading (skeleton), empty, error, pending-backend, or
the ready value + optional subtitle. The container computes each card's status
per data source (bootstrap not yet loaded -> loading; metrics gateway error
-> error; no supported locales -> empty; Orders/Revenue -> always
pending-backend).
System Health
ProjectValidator (features/project-editor/services/project-validator.service.ts)
already covered 5 of the 6 required checks. This sprint added two more:
translationIssues()- flags a supported non-default locale missing a header nav label translation or a static-pagetranslationsentry.layoutIssues()- flagsbootstrap.layout.typeor any section'slayout.strategythat isn't one of the known enum values (PlatformLayoutType/SectionLayoutStrategy). Runtime validation matters here because bootstrap JSON isn't type-checked at load time.
Dashboard mapping (AdminDashboardFacade.healthChecks):
| Dashboard label | Validator code |
|---|---|
| Bootstrap valid | structural: bootstrap !== null && schemaVersion set |
| Configuration valid | no validation issues at all |
| Missing translations | missing-translations (new) |
| Invalid colors | invalid-colors (existing) |
| Invalid widget references | missing-widget (existing - a homepage widget with no type) |
| Invalid layouts | invalid-layouts (new) |
Quick Actions
Static list in AdminDashboardFacade (route arrays relative to the lang
root); the page component prefixes the current locale
(LanguageService.currentLanguage()) before binding routerLink. Categories,
Static Pages, Transactions, Orders, and Media Library currently land on
BackofficeComingSoonPageComponent since those features aren't built yet -
this is a routing placeholder, not a dashboard card placeholder.
lastPublishedAt (ProjectEditorFacade change)
Before this sprint, publish() only updated lastSavedAt, so "last draft
save" and "last publish" were indistinguishable after a publish. Added
lastPublishedAt: number | null to ProjectEditorState /
ProjectEditorFacade, set only inside publish(). lastSavedAt behavior is
unchanged (still updated by both save() and publish()).
Sprint 20 - Category Management
features/admin/categories/ (model/gateway/facade/pages/components), same
container/facade/service split as admin/products and admin/dashboard:
src/app/features/admin/categories/
models/ admin-category.model.ts
services/ admin-categories-gateway.interface.ts
admin-categories-local.gateway.ts
admin-categories-form.factory.ts
facade/ admin-categories.facade.ts
guards/ admin-category-dirty.guard.ts
components/ admin-categories-list.component.*
admin-category-form.component.*
pages/ admin-categories-list-page.component.ts
admin-category-editor-page.component.ts
- Hierarchy:
AdminCategory.parentId(nullable). List page renders a flattened, indented tree (AdminCategoriesFacade.rootCategories()/childrenOf(id)); the editor's parent<select>excludes the category itself and its descendants to prevent cycles. - Reordering: native HTML5 drag-and-drop in
admin-categories-list.component.ts(draggable,dragstart/drop), persists viaAdminCategoriesFacade.reorder()which just rewritesorder. - Delete/restore: soft delete (
deletedAttimestamp). Blocked client-side (facade.canDelete()) if the category has children oritemsCount > 0; list has an "include deleted" filter with a Restore action for soft-deleted rows. - Draft/publish:
status: 'draft' | 'published', set by the editor's "Save Draft" vs "Publish" buttons (AdminCategoriesFacade.saveDraft(publish)). - Local draft recovery + unsaved-changes guard: every
updateDraft()call persists the in-progress category tolocalStorageunderadmin-category-draft:<id>(via the existingLocalStorageService, same pattern as Project Editor autosave); the editor reloads that draft ahead of the saved value if present, and is cleared on save.adminCategoryDirtyGuard(mirrorsprojectEditorDirtyGuard) blocks navigation away from an unsaved edit withwindow.confirm. - Image: reuses the existing
MediaPickerComponent(same one used by Media Manager) rather than a free-text URL field. - Seed data:
AdminCategoriesLocalGatewayseeds its in-memory cache fromBackofficeDataService.loadCategories()(CategoryCardConfig, currently flat/no hierarchy) - same swappable-provider pattern asAdminProductsLocalGateway. - Not yet wired:
admin/products' category<select>still usesAdminProductsGateway.loadCategories()(its ownAdminProductCategoryOptionseed), notAdminCategoriesGateway- unifying them is Sprint 21 scope (docs/SPRINT-PLAN.md).
Sprint 21 - Product Management completion
- Categories now real:
AdminProductsLocalGatewayseeds its category dropdown fromAdminCategoriesLocalGateway.loadCategories()(Sprint 20) instead of rawBackofficeDataService.loadCategories()- productcategoryIdnow points at real admin-managed categories. - Archive/restore:
AdminProduct.archived(soft, distinct fromvisible). List has an "include archived" filter + per-row Archive/Restore action; archived products excluded by default (mirrors categories'deletedAt/restore pattern). - Barcode: added alongside
sku. - Variants: lightweight
AdminProductVariant[](name/price/quantity), edited asname|price|quantitylines (same textarea-parse convention asspecifications/attributes). Not a full options-matrix variant system - scoped to what the model/backend contract actually needs today. - Related products:
relatedProductIds: string[], checkbox picker in the editor sourced fromAdminProductFormComponent'sallProductsinput - which isAdminProductsFacade.products(), i.e. whatever page is currently loaded in the facade (usually primed by navigating from the list). Not a full catalog search; fine for the current mock-data scale, worth revisiting ifAdminProductsLocalGatewayis ever swapped for a real API with more than a page of products. - Gallery:
media.gallerynow built via the sharedMediaPickerComponent(add/remove thumbnails) instead of a raw URL textarea;media.images/media.videosunchanged (still textarea, out of this ticket's scope). - Preview: simple read-only line in the editor showing computed discounted price.
- Infinite scroll:
AdminProductsFacade.infiniteScrolltoggle - when on,loadMore()appends the next page toproducts()instead of replacing it; pagination UI swaps for a "Load more" button. Off by default (existing paginated behavior unchanged).
Sprint 22 - Media System hardening
core/media/ (MediaRepository abstraction, MockMediaRepository IndexedDB
implementation) + features/backoffice/media/ + the shared
shared/media/media-picker/:
- Folders: flat
folder?: stringtag onMediaAsset(no nesting) - "New folder" just sets the active filter to a name typed viawindow.prompt(mirrors thewindow.confirmpattern already used for destructive actions elsewhere); the folder is created implicitly the next time something uploads into it.MediaRepository.listFolders()derives the folder list from existing records rather than a separate folder entity - intentionally light, matches the flat-storage reality of an IndexedDB mock. - Tags: already existed on
MediaAsset; added an edit affordance (window.prompt, comma-separated) andMediaLibraryFacade.updateTags(). - Validation:
MockMediaRepository.validateFile()rejects anything over 10MB or outside the allow-list (jpeg/png/webp/gif/svg+xml/pdf); errors now propagate as real messages throughMediaLibraryFacade.error(bothmedia-library-pageandmedia-pickerdisplay it - previously upload failures were swallowed into a generic string). - SVG sanitization:
sanitizeSvg()strips<script>tags andon*="..."attributes from uploaded SVG markup before storing it, since SVG is the one accepted format that can carry inline script. - Compression/resize: raster images (not SVG/GIF) are downscaled to a
2000px max dimension and re-encoded (JPEG/PNG, quality 0.85) via
<canvas>before being stored - client-side only, no crop UI. A full interactive cropper was out of scope for this ticket; revisit if a real design need for manual cropping shows up. - Reuse confirmed:
MediaPickerComponentis now wired into Category images (Sprint 20), Product gallery (Sprint 21), and Project Editor branding (logo / compact logo / favicon, this sprint) - one media library for the whole platform, per the sprint goal. Static Pages editor has no image fields to wire (confirmed, not a gap). Hero image: no dedicated hero-image field exists inBootstrapConfigtoday - nothing to wire. - Storage abstraction: already existed via
MediaRepository(abstract class + DI tokenprovidedIn: 'root'onMockMediaRepository) - swapping to a real CDN/backend means implementingMediaRepositoryagainst a real API and rebinding the provider; no consumer (MediaLibraryFacade,MediaPickerComponent, or any of the pickers above) changes.
Sprint 22 - Media System hardening
core/media/ (MediaRepository abstraction, MockMediaRepository IndexedDB
implementation) + features/backoffice/media/ + the shared
shared/media/media-picker/:
- Folders: flat
folder?: stringtag onMediaAsset(no nesting) - "New folder" just sets the active filter to a name typed viawindow.prompt(mirrors thewindow.confirmpattern already used for destructive actions elsewhere); the folder is created implicitly the next time something uploads into it.MediaRepository.listFolders()derives the folder list from existing records rather than a separate folder entity - intentionally light, matches the flat-storage reality of an IndexedDB mock. - Tags: already existed on
MediaAsset; added an edit affordance (window.prompt, comma-separated) andMediaLibraryFacade.updateTags(). - Validation:
MockMediaRepository.validateFile()rejects anything over 10MB or outside the allow-list (jpeg/png/webp/gif/svg+xml/pdf); errors now propagate as real messages throughMediaLibraryFacade.error(bothmedia-library-pageandmedia-pickerdisplay it - previously upload failures were swallowed into a generic string). - SVG sanitization:
sanitizeSvg()strips<script>tags andon*="..."attributes from uploaded SVG markup before storing it, since SVG is the one accepted format that can carry inline script. - Compression/resize: raster images (not SVG/GIF) are downscaled to a
2000px max dimension and re-encoded (JPEG/PNG, quality 0.85) via
<canvas>before being stored - client-side only, no crop UI. A full interactive cropper was out of scope for this ticket; revisit if a real design need for manual cropping shows up. - Reuse confirmed:
MediaPickerComponentis now wired into Category images (Sprint 20), Product gallery (Sprint 21), and Project Editor branding (logo / compact logo / favicon, this sprint) - one media library for the whole platform, per the sprint goal. Static Pages editor has no image fields to wire (confirmed, not a gap). Hero image: no dedicated hero-image field exists inBootstrapConfigtoday ('hero' only appears as aSectionLayoutStrategyenum value) - nothing to wire. - Storage abstraction: already existed via
MediaRepository(abstract class + DI tokenprovidedIn: 'root'onMockMediaRepository) - swapping to a real CDN/backend means implementingMediaRepositoryagainst a real API and rebinding the provider; no consumer (MediaLibraryFacade,MediaPickerComponent, or any of the pickers above) changes.
Sprint 23 - Orders (mock/local)
features/admin/orders/ (model/gateway/facade/pages), same
container/facade/service split as the rest of admin/*:
- No real data source exists for orders anywhere in this repo (already
called out in Sprint 19's dashboard gap and
docs/BACKEND.mditem 7) -AdminOrdersLocalGatewayseeds 24 deterministic synthetic orders in memory (cycling through all statuses/customers) rather than reading fromBackofficeDataService, since there is nothing there to read. This is explicitly a placeholder to unblock the admin UI, not a real mock of production order volume. - List: search (order number/customer/email), status filter, pagination,
CSV export (client-side
Blobdownload, no server round-trip). - Detail: customer/payment/shipping info, itemized line items + total,
status timeline, change-status dropdown, refund request and cancel
(both
window.confirm-gated), customer-visible notes vs internal-only notes (two separate free-text logs), print invoice viawindow.print()with a@media printrule hiding all non-invoice chrome (.no-print) - no PDF generation library, deliberately minimal. - Wired into
/:lang/backoffice/ordersand/:lang/backoffice/orders/:id, replacing the coming-soon placeholder.
Known gaps / backend needs
- Dashboard metrics endpoint. Categories/Products counts are computed
client-side from
BackofficeDataService(itself mock/API-switchable viaBACKOFFICE_DATA_PROVIDER). A dedicated/builder/dashboard/summary-style endpoint would letAdminDashboardMetricsGatewayreturn richer data (real-time counts, trend deltas) without touching the facade or cards. - Orders/Revenue have no backend at all (see above) - needs an order domain and revenue aggregation before these cards can show real data.
- Recent Activity is local-only, scoped to the browser/tenant via
localStorage (
adminDashboard.activityHistory.v1), same limitation as the existing draft-save local storage. It will not show another editor's activity until a real audit-log endpoint exists. - Admin authorization is still not enforced server-side (see
Project-Editor.md- "Admin Authentication" section); this sprint does not change that. Nothing new here beyond routing/dashboard.