The admin is Thymeleaf too: no JavaScript framework left in the repo

The last React went with this. /admin and /admin/catering are pages of forms; every write is a POST and
a redirect back, so the back button and reload do what they look like they do, a double-tap cannot
repeat an upload, and there is no client-side state to lose — a reload is always the truth. The
/api/admin/** endpoints went too: they existed for the React screen, and their logic now lives in
Catalogue (extracted from the two deleted JSON controllers) and CateringMenu, which the pages call.

THE TABLE EDITOR IS THE INTERESTING PART, because a catering table cannot be edited a field at a time
— a column heading, its price and the entries beneath it only mean anything together. One form holds
the whole table and every button submits it; `name="do"` says which was pressed and its value carries
the position (`remove-column:2`). "Add a column" therefore arrives with every cell the editor has
typed, adds the column to what arrived plus an empty entry on every line, and re-renders. Nothing
typed is lost, and only Save writes — so a half-built table with a blank heading never reaches the
live page. A failed save comes back the same way, with the work still in the form and the reason above
it; a redirect would throw the work away and leave them guessing which cell the message was about.
Spring binds `lines[2].values[1]` into the right cell, which flat repeated parameters could not
promise.

Reordering moved to the server, where it always belonged: the browser used to compute the new order
and send the whole list back, and now "move this up" arrives as an action. Same for arranging photos —
one endpoint takes the key and -1/1/0 (earlier, later, remove), because those three buttons are the
same edit.

frontend/ became styles/: node, Tailwind and nothing else. It exists because Tailwind needs a
compiler and the alternative is a hand-written stylesheet; there is no bundler and no framework. The
admin's controls are @utility classes (v4 will only let you @apply a registered utility, and only a
utility can take the `file:` variant the photo pickers use) — the same buttons the React screen had,
from the same class strings it composed. Also fixed .gitignore, which still named frontend/: with
styles/ unlisted, `git add -A` staged 1,626 files of node_modules.

Verified against a running container, not only in tests: pressing "+ Column" returns the draft with an
unsaved cell intact, a new column and a matching new entry on the line, "Not saved yet" — and the live
page unchanged; Save then writes both columns with the price parsed from "48". Renaming and moving an
item land on the products page. Deleting a category that is in use is refused with the sentence naming
it. Removing the only photo of an item is refused, and that button is already disabled in the page.

51 tests (10 new): the form binding, the flash on success and on refusal, a structural button writing
nothing, and the whole admin surface closed to anonymous visitors. PlatformContractTest's routing
assertion now says what is true — an unknown path 404s, and so does /admin when no identity provider
is configured, because AdminController only exists under OIDC.
This commit is contained in:
2026-07-26 16:47:10 -05:00
parent 70af2922f5
commit 5045ccc7c8
34 changed files with 1625 additions and 3299 deletions
+23
View File
@@ -0,0 +1,23 @@
/*
* The stylesheet for the server-rendered site.
*
* Compiled by the Tailwind CLI (`npm run build:css`) straight into target/classes/static/css: it is a
* source file, not a resource, and the generated stylesheet belongs in the build output rather than in
* src/main/resources next to it.
*
* This directory is the whole asset pipeline, and Tailwind is all that is left of it: the site and the
* admin are both server-rendered HTML, so there is no bundler, no framework and one stylesheet. It has
* to live here because Tailwind resolves `@import "tailwindcss"` by walking up from the CSS file looking
* for node_modules — and node_modules is here.
*
* @source points Tailwind at every template (public pages and admin alike) and at gallery.js — the
* product-card arrows are created in script, so their classes are only written down there. A utility
* exists in the output only if Tailwind saw it in one of these files, which is why a class name must
* never be assembled from pieces at runtime.
*/
@import "tailwindcss";
@import "./tokens.css";
@import "./admin.css";
@source "../src/main/resources/templates";
@source "../src/main/resources/static/js";