Skip to content

PlatformConsole

Platform-level admin console. Scaffolded from Lovable.dev and heavily copy-pasted from OrgConsole/other consoles — most of this app is not real, see below.

Overview

Same stack as OrgConsole: React 18 + Vite 5 + TypeScript, React Router 6, TanStack Query, Zustand, shadcn/Radix + Tailwind, axios.

npm run dev → port 8080. Docker build bakes 5 VITE_* args at build time and serves via nginx.

What's actually real vs. mock — verified, not estimated

Only 3 files in the entire src tree import the API client at all (AuthGuard.tsx, PlatformPermissionGuard.tsx, src/stores/tenantsStore.ts), and only 3 backend calls exist:

Call Endpoint
identityService.getMe() GET /identity/users/me
orgService.listOrgs() GET /tenancy/organizations
orgService.updateStatus() PUT /tenancy/organizations/{orgId}/status

Of 94 page files, only 4 consume tenantsStore at all (TenantDirectory, TenantApprovals, TenantDetail, ManualRegisterOrg). Within those:

  • Approve — genuinely wired, calls updateOrgStatus.
  • Reject / Request-info — toast-only. The code's own comments admit it: TenantApprovals.tsx literally says "not modeled in this demo" / "Would email the applicant."
  • Manual org registration (ManualRegisterOrg.tsx) — a pure Zustand set() call. No HTTP request happens at all, despite looking like a real form.

Every other section — assets, directory, integrations, platform infra, and the entire playout/tellyboard/tellyid sidebar trees (~90 of 94 page files) — is local seed-data/Zustand state only. No network calls. Sidebar advertises far more than this actually does.

Running locally

npm run dev   # port 8080

Env vars

No .env.example. Only 3 of the env vars the build args expect are actually read anywhere in code:

Var Used for
VITE_AUTH_API_URL Auth client base URL
VITE_CORE_API_URL The 3 real API calls above
VITE_AUTH_URL TellyID login redirect
VITE_TELLYCONNECT_URL One sidebar link — the only consumer
VITE_TELLYBOARD_URL Dead build arg — zero consumers anywhere in code

⚠️ Known issue: auth guard fails open (same bug as OrgConsole)

Both AuthGuard and PlatformPermissionGuard render their children with no check at all if VITE_CORE_API_URL is unset — no error, no console warning. Combined with no .env.example to catch a missing var at setup time, a misconfigured build can silently ship an unprotected admin console.

Repo status

Last commit 5a029cb, 2026-08-18 — dormant since. Only 15 commits total in the whole repo's history.

See Changelog for the full real history.