OrgConsole (BizConsole)
Org-level admin console. Internally called BizConsole in the codebase
and permission scheme (org:apps:bizconsole:access) — the repo/route name
OrgConsole and the internal name BizConsole are the same app.
Overview
React 18 + React Router 6 SPA, Vite 8 + TypeScript, Zustand for state, TanStack React Query, Radix/shadcn UI + Tailwind, react-hook-form + zod for forms, axios for HTTP.
Served under base path /biz-console/ (vite.config.ts), root /
redirects to /:orgSlug/console/directory/members.
Main sections
From src/pages/console/ConsoleLayout.tsx, gated by OrgPermissionGuard:
- Directory — Workspaces (list + detail), Roles & Permissions, Members, Teams, Invitations, Access Policies
- Assets — Sites/Facilities, Spaces (list + detail), Endpoints, Events, Location Taxonomy, PoPs, Asset Registry, Policies & Standards, Configuration
- Catalog — Products, Pricing, Access Grants, Offers
- Integrations — profile list/detail (
/integrations/:category[/:slug]) — this is the email/POS/payment profile creation UI (profiles are picked per-product in SpatioViewAdmin, created here) - Settings — Enabled Capability Apps, Product Suite Anchors, Localization
Unmatched routes under /console/* render a "Coming Soon..." placeholder rather than 404ing.
Running locally
npm run dev # Vite dev server, port 8080
Env vars
No .env.example ships in this repo — consumed directly via import.meta.env, no fallback/validation at build time:
| Var | Used for |
|---|---|
VITE_AUTH_API_URL |
Cookie-based auth check (AuthGuard) |
VITE_CORE_API_URL |
Bearer-token CoreAPI calls |
VITE_AUTH_URL |
TellyID hosted login redirect target |
VITE_PREFS_COOKIE_DOMAIN |
Cookie domain for stored prefs |
VITE_TELLYBOARD_URL / VITE_TELLYCONNECT_URL / VITE_PLAYOUT_URL / VITE_SPATIO_URL / VITE_PLATFORM_URL |
Cross-app sidebar links only |
⚠️ Known issue: auth guard fails open
AuthGuard.tsx — if VITE_AUTH_API_URL is unset at build time, the auth
check effect returns immediately and marks the app ready without ever
calling getMe(). A missing/blank env var doesn't block access, it
silently ships a console with no client-side auth check at all (server-side
API calls still 401 independently, but the SPA shell and any locally
cached state render unguarded). No error, no console warning — this is
easy to ship by accident.
See Changelog for real, dated feature history.