Skip to content

History / Admin Access Control

Revisions

  • Add Admin Access Control technical deep-dive (issue #34 / #781) Developer-facing page on how the System module is restricted to admins: the is_admin flag, the three helpers (analystIsAdmin / sessionIsAdmin self-heal / requireAdminJson), the two enforcement layers (page gate + 41-endpoint API gate), the deliberate scoping (what's NOT guarded and why, incl. db_verify pre-login and the teams-vs-departments boundary), the one-time grandfather back-fill, last-admin protection, and a contributor checklist. Linked under Security in the sidebar.

    @edmozley edmozley committed Jul 11, 2026