Skip to program ledger

Living Program Ledger

Frauthy/Project Management

v37 · 2026-07-28

Repository dossier

admin

Operator portal (web) + admin TUI

At risk
Branch
master
Commit
d8332a2ca8ed7242b006f1927228a8beb598504e
Worktree
Clean
SDK
@frauthy/admin-ui 1.1.0-next.0 source; 1.0.0-next.0 published and Brand-admitted

stack

SolidJS · Bun + Ink TUI · shared client lib

ci

green (exact-head Admin CI run 29756414021: typecheck, coverage, client and UI SDK builds, packed-consumer verification, production authentication boundary, Monaco route, accessibility, and reusable dispatch caller)

deploy

none

coverage

client 76%, web 100%, and TUI 23% floors pass; the repository coverage ratchet remains enforced

What it is. The operator surface: a SolidJS web portal and a Bun + Ink terminal UI over a shared AdminClient library with three bindings (in-memory, SpiceDB HTTP, Cloud). Relationship inspection, manual Check with debug traces, schema tools, key rotation, watch stream, audit log.

What’s proven. The relationship inspector and check console are real in both frontends, backed by a MemStore with genuine graph traversal and a SpiceDB client that extracts debug trace paths. ~328 test references across 14 files.

Where it falls short. The portal has no authentication whatsoever — the spec defines a full Frauthy-on-Frauthy OIDC + RBAC model and none of it exists. The watch stream is a polling placeholder (and throws on cloud). The schema editor has no Monaco and no LSP client — every startLSP() throws. Three of six TUI panels are “deferred to M2/M3” placeholder text. The web app hardcodes the in-memory client, so it cannot actually administer a real deployment. There is no Keto binding despite the declared store type.

The plan. admin/specs/GAP-CLOSURE-2026-07-12.md (ADM-1 … ADM-9): authentication first (the other half of DOGFOOD-FRAUTHY), the real SpiceDB Watch stream, runtime backend selection, the three missing TUI panels — adopting cui’s interaction grammar (number-key tabs, / search, f filter) — then the Keto binding, the LSP bridge to protocol’s frauthy-lsp, and CI with build, coverage, and Playwright.

full spec: admin/specs/GAP-CLOSURE-2026-07-12.md · port :41017