Skip to content

OrgConsole (BizConsole)

Org-level admin console. Internally called BizConsole in the codebase and permission scheme (org:apps:bizconsole:access) — the repo/route name OrgConsole and the internal name BizConsole are the same app.

Overview

React 18 + React Router 6 SPA, Vite 8 + TypeScript, Zustand for state, TanStack React Query, Radix/shadcn UI + Tailwind, react-hook-form + zod for forms, axios for HTTP.

Served under base path /biz-console/ (vite.config.ts), root / redirects to /:orgSlug/console/directory/members.

Main sections

From src/pages/console/ConsoleLayout.tsx, gated by OrgPermissionGuard:

  • Directory — Workspaces (list + detail), Roles & Permissions, Members, Teams, Invitations, Access Policies
  • Assets — Sites/Facilities, Spaces (list + detail), Endpoints, Events, Location Taxonomy, PoPs, Asset Registry, Policies & Standards, Configuration
  • Catalog — Products, Pricing, Access Grants, Offers
  • Integrations — profile list/detail (/integrations/:category[/:slug]) — this is the email/POS/payment profile creation UI (profiles are picked per-product in SpatioViewAdmin, created here)
  • Settings — Enabled Capability Apps, Product Suite Anchors, Localization

Unmatched routes under /console/* render a "Coming Soon..." placeholder rather than 404ing.

Running locally

npm run dev   # Vite dev server, port 8080

Env vars

No .env.example ships in this repo — consumed directly via import.meta.env, no fallback/validation at build time:

Var Used for
VITE_AUTH_API_URL Cookie-based auth check (AuthGuard)
VITE_CORE_API_URL Bearer-token CoreAPI calls
VITE_AUTH_URL TellyID hosted login redirect target
VITE_PREFS_COOKIE_DOMAIN Cookie domain for stored prefs
VITE_TELLYBOARD_URL / VITE_TELLYCONNECT_URL / VITE_PLAYOUT_URL / VITE_SPATIO_URL / VITE_PLATFORM_URL Cross-app sidebar links only

⚠️ Known issue: auth guard fails open

AuthGuard.tsx — if VITE_AUTH_API_URL is unset at build time, the auth check effect returns immediately and marks the app ready without ever calling getMe(). A missing/blank env var doesn't block access, it silently ships a console with no client-side auth check at all (server-side API calls still 401 independently, but the SPA shell and any locally cached state render unguarded). No error, no console warning — this is easy to ship by accident.

See Changelog for real, dated feature history.