Skip to content

Admin repo hygiene: docs, env example, unused deps, favicon - #32

Closed
theobong wants to merge 16 commits into
mainfrom
chore/admin-campaign-01-repo-hygiene
Closed

theobong wants to merge 16 commits into
mainfrom
chore/admin-campaign-01-repo-hygiene

Conversation

@theobong

Copy link
Copy Markdown
Member

What changed

Repo hygiene for the operator dashboard, with no application logic changed:

  • The README, env example, wrangler and deploy-workflow notes now describe the real setup: Cloudflare Access sign-in, a same-origin API, and main to staging with a release to production.
  • Four unused dependencies, an unreferenced pin icon and a next start script are gone.
  • The env ignore rules are tighter.
  • CI now also runs on stacked PRs.
  • The admin tab finally shows a favicon.

Visible in: admin (the favicon only).

Before you start

  • Where: staging, admin.civfix.dev, after this merges to main
  • Sign in as: operator (Cloudflare Access)

Verify

[Admin]

  1. Open admin.civfix.dev in a desktop browser. Expect: the browser tab shows a green map-pin icon next to "civfix Operations", where before there was a blank or default icon.
  2. Open admin.civfix.dev/favicon.svg directly. Expect: the same green pin renders; the page does not fall back to the dashboard.

Regression

Signing in and the home dashboard: [Admin]

  1. Open admin.civfix.dev. Expect: "Loading operations..." shows briefly, then the "Dashboard" home loads with its section tiles. There is no "Operator sign in" or "Not authorized" screen for an allowlisted operator.
  2. Scroll to the bottom of the home page and click "Source code (AGPL-3.0)". Expect: it opens the civfix-admin repository on GitHub, at a commit.
  3. Look at the live map on the home page. Expect: the CARTO basemap tiles and the report/event pins render exactly as before. Hovering a pin shows its tooltip.

Page styling: [Admin]

  1. Click through "Jurisdictions", "Reports", "Events", "Mail", "Users", "Moderation", "Analytics", "Organizations", "Host messaging" and "Signup pages" from the home tiles.
  2. On each page, compare buttons, links, inputs and lists with production admin.civfix.org. Expect: identical spacing, borders, fonts and colors. The only CSS removed is the animation plugin's unused keyframes, one unused utility, and two unused helper classes.
  3. On "Jurisdictions", pick a jurisdiction. Expect: its boundary map renders with the outline.

Signing out: [Admin]

  1. Click "Sign out" in the top bar. Expect: you leave the dashboard through the Cloudflare Access logout, as before.

Not covered

  • The CI trigger change (stacked PRs now get CI) is only observable on GitHub; the next stacked PR in this campaign exercises it.
  • Docs, comments, the lockfile and .gitignore have no in-app surface.

Findings addressed

  • Stale README: retired sibling repos, a ^0.1.0 shared range, "Email-OTP" sign-in, the retired documents link, no pnpm test, em dashes.
  • Two near-identical .env.example files. The kept one claimed the API "defaults to the local backend" and showed a fake production URL.
  • Stale headers in wrangler.jsonc (submodule, documents repo), deploy.yml (a self-contradicting NEXT_PUBLIC_API_URL note; "every push to main" implied production) and next.config.mjs ("from the workspace").
  • tailwind.config.ts:
    • the header named text-ink3;
    • the content globs pointed at ./app and ./components, which don't exist;
    • it used require() in an ESM config;
    • the tailwindcss-animate plugin was unused.
  • Unused dependencies clsx, lucide-react, tailwind-merge and tailwindcss-animate. Checked by grep across src, CSS, configs and tests.
  • Dead .cf-spin and .no-scrollbar utilities in globals.css, whose comment referenced the removed lucide.
  • public/ds/pin-cleanup.svg was unreferenced: pins are built only from the 7 report categories, and "cleanup" isn't one. public/favicon.svg was never linked.
  • next start script: meaningless for output: "export".
  • .gitignore did not ignore .env.production or other .env.* files.

Decisions for the reviewer

  • Favicon: the existing public/favicon.svg (green pin) is now linked from the layout metadata. This is a visible change; swap the file to use a different icon.
  • CI trigger: ci.yml drops branches: [main] from pull_request, so a PR stacked on another branch gets the same "lint / typecheck / build / test" job. The job name is unchanged, so the "Main Branch" ruleset still matches it. The job uses no secrets.
  • One env example: the root copy is deleted and apps/admin/.env.example is kept, next to where a developer's .env.local goes. NEXT_PUBLIC_API_URL is now shown commented out, because staging and production leave it unset.
  • Tailwind kept: Tailwind stays, supplying only its reset. Removing it would mean vendoring the MIT-licensed reset (a notice plus a REUSE entry) and two raw hex colors.

Verification

  • Node v22.23.2, pnpm 9.12.0.
  • pnpm lint, pnpm typecheck, pnpm build and pnpm test (33 files, 182 tests) all pass.
  • The built CSS was compared before and after the Tailwind change. The only removals are the unused enter/exit keyframes, the .running utility, and the cf-spin keyframes.
  • out/index.html carries <link rel="icon" href="/favicon.svg">.
  • git ls-files -ci --exclude-standard is empty, so no tracked file became ignored.
  • pnpm licenses list: every dependency is MIT, Apache-2.0, ISC, BSD, BlueOak, 0BSD, CC0, CC-BY-4.0 (caniuse data), MPL-2.0, LGPL-3.0-or-later or Python-2.0. There is nothing incompatible with AGPL-3.0.
  • An adversarial review (correctness, security, conventions) found two blockers, both fixed:
    • the deploy header still described a main push as production;
    • a stale lucide comment and dead utilities remained in globals.css.

🤖 Generated with Claude Code

@greptile-apps

greptile-apps Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

Safe to merge: the remaining issue is a non-blocking Inbox display inconsistency.

What we checked:

  • T-Rex produced a proof for a posted P2 finding and attached two artifacts: the Inbox selection reproduction script and the zero-result search output log. T-Rex
  • T-Rex validated the inbox search behavior by running the authored harness that opened Mail with an Inbox email selected, entered no-such-message and waited for the debounce; before search, listCount was 1 and detailVisible was true; after the search, listCount was 0, emptyVisible was true, and detailVisible remained true. T-Rex

Reviews (2) · Last reviewed commit: "merge origin/main"

@greptile-apps

greptile-apps Bot commented Sep 24, 2026

Copy link
Copy Markdown

Comments Outside Diff

These findings sit on lines the diff does not cover, so they could not be posted inline. Each one leaves this list once its file changes.

  • P2 Clear empty-view selection apps/admin/src/features/mail/mail-page.tsx:574 ▶

    When an operator searches or filters the Inbox to zero results, this early return preserves the previously selected email. The queue then shows “Nothing matches” while the reader still displays a message that is not in the active view. Clear the selection when the active list is empty so the queue and reader stay consistent.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants