Secure admin access
This is the admin entry point for admin.hekusa.com. It is intentionally not connected to live users, uploads, verification, or database records until server-side admin authentication is enabled.
Admin foundation
This is the admin entry point for admin.hekusa.com. It is intentionally not connected to live users, uploads, verification, or database records until server-side admin authentication is enabled.
| Area | Status | Next connection |
|---|---|---|
| Website | Live | GA summary and public content status |
| App | Live | User sessions and Live Card records |
| Admin | Foundation | Protected auth and backend API |
| Database | Pending | Users, cards, uploads, verifications |
Use the Google Analytics Data API through the backend to show website versus app users, realtime counts, top pages, devices, and countries here.
| Control | Status | Requirement |
|---|---|---|
| Admin subdomain | Ready for DNS | Point admin.hekusa.com to the load balancer and add SSL cert. |
| Server-side auth | Required | Enable IAP/Firebase/backend session checks before live data. |
| API secrets | Not embedded | Keep database and GA API credentials server-side only. |
| Audit logs | Pending backend | Log admin view, approve, reject, export, and delete actions. |