mirror of
https://github.com/melgarafael/DeskcommCRM.git
synced 2026-10-02 01:28:34 +08:00
Foundation for the Super-Admin Platform sub-product: - requirePlatformAdmin server helper: getUser → check platform_admins row + AAL2 (MFA recente). Redirects /admin/forbidden or /login/mfa. - middleware.ts branches on host=admin.* OR path=/admin/* (early redirect to /login if no auth cookie). DB check stays server-side. - AdminShell + PlatformModeBanner (sticky amber banner, role=region) + AdminSidebar (14 entries with distinct Phosphor icons). - /admin redirects to /admin/dashboard (stub for S-11.02). - /admin/forbidden 403 page outside the protected layout group. In dev: works via http://localhost:3000/admin/* (no hosts file needed). In prod: admin.deskcomm.com sub-domain via Vercel rewrites (deferred). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>