Quick actions
Common store tasks.
Store readiness
Items required before scaling paid traffic.
- ✓Frontend UX refreshV3 polish implemented
- ✓Bank TransferCheckout UI integrated
- ✓Central order databaseSupabase-backed order operations implemented
- ✓Secure admin authorizationSupabase staff roles + server authorization implemented
- ✓Server-authoritative pricingAtomic order RPC validates catalogue totals
Catalogue snapshot
Live public catalogue with static fallback if the API is unavailable.
Sign in to load live orders
Approved staff can manage guest and account orders, payment verification, fulfilment, notification retries and audit history from this screen.
Required order workflow
The final backend should use these explicit states.
1. Choose products
Select snacks and quantities for the box.
2. Build your box
Set the customer-facing name and price.
No products selected yet.
Drafts remain in this review browser only. Publishing must go through the secure admin API.
3. Existing boxes
Boxes you've already created. Click Edit to modify.
Loading…
Homepage sections
Final backend should allow ordering and visibility controls.
Hero controls
Backend-managed content fields planned for Muse.
Sign in to load customers
Authorized staff can review customer order context without exposing customer data to unauthorized roles.
Sign in to moderate reviews
Only genuine shared reviews are shown. Authorized staff can approve or reject submissions; the storefront never fabricates ratings.
Sign in to load the media library
Authorized content staff can upload validated image types to controlled storage and copy their public URLs into product records.
What should Copilot help with?
Runs through the protected free Cloudflare Workers AI binding. AI output is always a draft/insight and never auto-published.
Draft output
AI output is never auto-published.
Choose a shortcut or write an instruction. Free AI is optional; store operations never depend on it.
Payments
Public receiving details may be shown; secrets must never be placed here.
Shipping
Current customer-facing rules.
Required production protection
- Implemented Supabase Auth verifies an approved staff role
- Implemented RLS blocks unauthorized catalogue/order access
- Implemented `/api/admin/*` re-verifies authorization server-side
- Implemented Archive/restore replaces routine hard deletion
- Implemented Sensitive admin changes are audit logged
- Staging verify Cloudflare/admin route protection and headers
Audit log
Who changed what and when.