Admin foundation

Operate HEKUSA from one secured place.

Auth backend pending

Secure admin access

This is the admin entry point for admin.hekusa.com. It is intentionally not connected to live users, uploads, verification, or database records until server-side admin authentication is enabled.

Before live data is connected

1
Protect the admin hostUse IAP, Firebase Auth, or a backend session allowlist before exposing real records.
2
Keep secrets server-sideDatabase keys, GA Data API credentials, and Cloud APIs must never be shipped in browser code.
3
Audit every actionModeration, verification, export, and delete actions should write immutable admin logs.
Users-Waiting for backend
Live Cards-Waiting for database
Verifications-Waiting for workflow
Uploads-Waiting for storage

Operations snapshot

AreaStatusNext connection
WebsiteLiveGA summary and public content status
AppLiveUser sessions and Live Card records
AdminFoundationProtected auth and backend API
DatabasePendingUsers, cards, uploads, verifications

Build order

A
Admin authOwner-only login and session checks.
B
Data modelUsers, Live Cards, uploads, verification queue, reports.
C
Analytics APIGA summaries through a backend proxy, not an iframe.

Users

User records will appear here after the backend identity store is connected.

Live Cards

Created cards, categories, reports, and moderation actions will live here.

Verification queue

Phone, email, creator, business, and safety verification reviews will be connected through the backend.

Analytics

Google Analytics cannot be safely mirrored by iframe

Use the Google Analytics Data API through the backend to show website versus app users, realtime counts, top pages, devices, and countries here.

Security checklist

ControlStatusRequirement
Admin subdomainReady for DNSPoint admin.hekusa.com to the load balancer and add SSL cert.
Server-side authRequiredEnable IAP/Firebase/backend session checks before live data.
API secretsNot embeddedKeep database and GA API credentials server-side only.
Audit logsPending backendLog admin view, approve, reject, export, and delete actions.