Persyaratan akses
Panel hanya dapat diakses oleh pengguna terautentikasi dengan role admin atau super_admin. Seluruh route admin dilindungi verifikasi dua faktor. Gunakan domain admin, bukan path /admin pada host API.
Pada development, buka http://admin.localhost:3333/login. Alamat production mengikuti konfigurasi ADMIN_URL environment.
Alur masuk
- Masukkan email dan password akun admin.
- Opsional: pilih Remember me hanya pada perangkat pribadi.
- Pilih tombol masuk.
- Masukkan kode TOTP dari aplikasi authenticator bila diminta.
- Jika authenticator tidak tersedia, gunakan satu recovery code yang belum pernah dipakai. Tombol Show password mengungkap input sementara; pilih kembali untuk menyembunyikannya sebelum masuk.
Recovery code hanya dapat dipakai satu kali. Jangan menampilkan TOTP atau recovery code pada screenshot, tiket bantuan, atau pesan internal.
public/screenshots/id/login.pngpublic/screenshots/id/two-factor-verify.pngNavigasi dan pola halaman
Sidebar desktop selalu terlihat. Pada layar kecil, tombol panel membuka drawer navigasi. Header menampilkan pemilih bahasa, pesan hasil tindakan, dan tombol keluar.
- Figure strip: angka ringkasan yang dapat berfungsi sebagai filter.
- Filter bar: pencarian, status, relasi, tanggal, atau urutan yang ditulis ke URL.
- Ledger: tabel operasional; baris dapat dibuka dengan klik atau Enter.
- Inspector: fakta di kiri, status, timeline, dan form tindakan di rail kanan.
Mengganti bahasa
Pilih ID, EN, atau ZH pada header Admin Web. Pilihan disimpan pada server, localStorage, dan cookie. Bahasa bawaan adalah Bahasa Indonesia. Nama tier membership tetap berbahasa Inggris.
public/screenshots/id/locale-switcher.pngKeluar
Gunakan tombol keluar pada header. Pada perangkat bersama, pastikan halaman login sudah tampil sebelum meninggalkan perangkat.
Video panduan
Rekaman Admin Web berbahasa Inggris dari data demo terisolasi, diperlambat agar langkah mudah diikuti. Nilai rahasia disamarkan. Tidak ada pembayaran atau pengiriman penyedia eksternal yang dilakukan.
Direkam:
admin signs in and signs out 0:04
Langkah yang dicakup (Inggris)
- Open the admin login page, enter the E2E admin email and password, select Remember me, submit, and reach the dashboard.
- Sign out and confirm the login page returns.
admin rejects invalid credentials 0:03
Langkah yang dicakup (Inggris)
- Submit deliberately incorrect demo credentials and verify the sign-in error is shown.
consumer credentials do not grant admin access 0:05
Langkah yang dicakup (Inggris)
- Attempt admin access with the demo consumer account and verify protected admin pages return to sign-in.
admin login can reveal and hide the password 0:03
Langkah yang dicakup (Inggris)
- Enter a harmless placeholder into the password field, reveal it, and hide it again before sign-in.
admin opens the mobile navigation drawer and follows a register link 0:05
Langkah yang dicakup (Inggris)
- Resize to a mobile-width viewport, open the admin navigation drawer, select Clients, and confirm the drawer closes on navigation.
admin changes interface locale and persists the preference 0:05
Langkah yang dicakup (Inggris)
- Switch the header locale through Indonesian, Chinese, and English; verify each selection is pressed and persisted in the user record, localStorage, and locale cookie.
admin updates an assigned booking status through the permitted transition 0:07
Langkah yang dicakup (Inggris)
- Open an assigned booking inspector, verify its current state, change the status through an allowed transition, and verify the persisted status.
temporary admin enrolls, regenerates recovery codes, verifies TOTP, and disables 2FA 0:13
Langkah yang dicakup (Inggris)
- Enroll a disposable administrator by copying the manual setup key, entering a generated TOTP and password, and confirm that ten unique recovery codes appear.
- Copy the recovery codes, regenerate them with password confirmation, and verify the previous set is invalidated.
- Sign out, complete login with a generated TOTP, then disable 2FA with password confirmation.
temporary admin recovery code is single-use and authenticator fallback completes 2FA 0:12
Langkah yang dicakup (Inggris)
- Enroll a disposable administrator and log in using one recovery code.
- Confirm the recovery code cannot be used again, switch to authenticator verification, complete TOTP login, and disable 2FA.
admin dashboard filters status figures, opens today's live booking, and follows a register 0:11
Langkah yang dicakup (Inggris)
- Verify the desktop sidebar is visible, open the current-day Now in the field booking, apply booking status and Live figure filters, and follow a Clients register shortcut.
admin filters and sorts the client roster, including an empty search result 0:11
Langkah yang dicakup (Inggris)
- Search, apply a lifecycle filter and sort, confirm the filter URL and matching ledger row, then verify the empty state for a missing client.
Batas pengujian (Inggris)
- Authenticator enrollment and recovery-code storage in a password manager are external-app tasks; the E2E journey uses generated TOTP and checks the in-page copy state rather than storing secrets outside the admin UI.