4.1 KiB
Phase 10: Admin Role & Settings - Discussion Log
Audit trail only. Do not use as input to planning, research, or execution agents. Decisions are captured in CONTEXT.md — this log preserves the alternatives considered.
Date: 2026-06-12 Phase: 10-admin-role-settings Areas discussed: Admin bootstrap, Admin UI entry, App-password/credential scope, Shared-calendar designation, Provider scope, Credential ownership
Admin bootstrap
| Option | Description | Selected |
|---|---|---|
| Env-pinned OIDC sub | ADMIN_OIDC_SUB marks operator identity as admin |
|
| First-login-wins | First user to log in is auto-admin | ✓ |
| Everyone admin for now | Flag all members admin, defer gating | |
| Manual DB seed | Keep setting is_admin by hand |
User's choice: First-login-wins Notes: Chosen because Phase 12's setup wizard precedes it — the first login after setup completes becomes admin. Must stay member-count-agnostic.
Admin UI entry
| Option | Description | Selected |
|---|---|---|
| Extend SettingsSheet | Add an Admin section to the existing avatar sheet | |
| New /admin route | Dedicated gated route, redirect non-admins | ✓ |
| Settings route + sheet stays | Separate gated /admin, keep notifications sheet |
User's choice: New /admin route
Notes: Existing notifications SettingsSheet stays; /admin gives Phase 12's wizard room on the same surface.
App-password / credential scope
| Option | Description | Selected |
|---|---|---|
| Per-member rows, admin edits any | Per-user credentials, admin rotates any | (see provider redirect) |
| Per-member, self-only + admin override | Members manage own; admin overrides | |
| Single shared credential | One household credential |
User's choice: Redirected — "treat Fastmail like a provider; design generically enough to plug in Gmail/other providers later." Resolved in the Provider-scope and Credential-ownership follow-ups below. Notes: Ties into backlog 999.1 (treat-fastmail-as-a-provider).
Shared-calendar designation
| Option | Description | Selected |
|---|---|---|
| Exclusive single-select | Pick exactly one shared calendar; clears prior | ✓ |
| Multi-select toggles | Mark multiple calendars shared |
User's choice: Exclusive single-select Notes: Matches the "one shared family calendar" core value.
Provider scope (follow-up)
| Option | Description | Selected |
|---|---|---|
| Generic shape, Fastmail-only impl | Add provider field + generic UI; implement only Fastmail/CalDAV | ✓ |
| Fastmail-only, refactor later | Narrow build now, full refactor in 999.1 | |
| Full provider abstraction now | Build pluggable layer + 2nd provider |
User's choice: Generic shape, Fastmail-only impl Notes: Gmail/others = wiring left for backlog 999.1. Keeps Phase 10 shippable without scope creep.
Credential ownership (follow-up)
| Option | Description | Selected |
|---|---|---|
| Per-member provider credential | Per-user rows + provider field, N-member ready | ✓ |
| Household-level credential | One record for the household |
User's choice: Per-member provider credential Notes: Today both rows hold the same shared Fastmail account (D-16) but model stays N-member/N-provider ready; admin can rotate any member's.
Claude's Discretion
- Migration packaging — ship the full v1.1 bundle (
is_admin,app_config,reminder_lead_minutes) in one Phase-10 migration (generate+migrate, not push). app_configtable shape — create with at leastsetup_complete; add keys as needed./api/admin/*route layout and therequireAdminserver middleware shape.- How the dev-bypass user (id 1) acquires
is_adminfor local verification.
Deferred Ideas
- Full multi-provider support (Gmail/other) — backlog 999.1.
- Self-service credential onboarding — backlog 999.5.
- Admin audit log / health dashboard / user CRUD — out of scope (REQUIREMENTS.md).
- Multiple reminders per event — v1.2 stretch.