TechnicalCollectible prompt
Lock down your admin area with server checks and logs
Act as a senior security engineer. Lock down the admin area of my {{tech_stack}} app. Roles: {{user_roles}}. Admin features: {{features}}. Keep the current routes and components. Before changing anything, list every admin page, API route, server function and database rule, and how each decides who's allowed in.
Access:
- Every admin endpoint and server function checks the role on the server on each request. Hidden links and client-side route guards are not protection
- Roles live in a separate table only owners can change, never in profile fields or user-editable metadata; database access rules enforce the same roles
- Least privilege: split admin powers if one role does too much, such as support, billing and owner
- Two-step sign-in required for every admin role, with shorter sessions
- Ask for the password again before destructive actions: deleting users, refunds, role changes and data exports
- Admin pages send noindex and are rate limited
Audit log:
- One append-only table: who, which action, which record, before and after values for changed fields, when, and the request ID
- Written only by a server function or trigger; nobody, admins included, can edit or delete entries from the app
- Secrets and sensitive values masked in the before and after data
- A simple admin view to filter by person, action and date
- Entries kept at least a year, or as long as our rules require
Also: a safe way to create the first admin, an alert on every role change, and a list of current admins I can review monthly.
Test it: as a normal user, call every admin endpoint directly through the API and confirm each returns 403.
Finish with a table of who can do what, the files changed, and anything you assumed.
Technicalnvoka.com/library/nvoka-admin-area-lockdown-with-audit-logScan to open
Technical
Lock down your admin area with server checks and logs
Check admin roles on the server for every action, require two-step sign-in, and log what changes.
Curated by Nvoka
Claude CodeCursorLovableCodex
Make it yours
Fill in the blanks and change any word. Only your copy changes, never the card.
Fill in the blanks
0 of 3 filledYour prompt
Act as a senior security engineer. Lock down the admin area of my {{tech_stack}} app. Roles: {{user_roles}}. Admin features: {{features}}. Keep the current routes and components. Before changing anything, list every admin page, API route, server function and database rule, and how each decides who's allowed in.
Access:
- Every admin endpoint and server function checks the role on the server on each request. Hidden links and client-side route guards are not protection
- Roles live in a separate table only owners can change, never in profile fields or user-editable metadata; database access rules enforce the same roles
- Least privilege: split admin powers if one role does too much, such as support, billing and owner
- Two-step sign-in required for every admin role, with shorter sessions
- Ask for the password again before destructive actions: deleting users, refunds, role changes and data exports
- Admin pages send noindex and are rate limited
Audit log:
- One append-only table: who, which action, which record, before and after values for changed fields, when, and the request ID
- Written only by a server function or trigger; nobody, admins included, can edit or delete entries from the app
- Secrets and sensitive values masked in the before and after data
- A simple admin view to filter by person, action and date
- Entries kept at least a year, or as long as our rules require
Also: a safe way to create the first admin, an alert on every role change, and a list of current admins I can review monthly.
Test it: as a normal user, call every admin endpoint directly through the API and confirm each returns 403.
Finish with a table of who can do what, the files changed, and anything you assumed.