The /admin landing page.
It is built to be the page ANY authenticated visitor can safely be sent to, whatever their permissions. Two halves:
- a welcome block, rendered for everyone, greeting the visitor by name;
- the operator overview (
PhoenixKitWeb.Components.Core.DashboardOverview), every block of which is permission-gated byPhoenixKitWeb.Live.Dashboard.Overview.
A visitor holding no permissions sees the welcome block and nothing else — no statistics, no System Information, no cards, and (because the overview decides before it queries) not one operator query or PubSub subscription on their behalf. That is what makes the page safe as a universal landing.
Reaching it is not the same as being allowed to see all of it. The route sits
in the ordinary admin live_session, alongside every other /admin/* page,
so admin navigation to and from it stays a live patch rather than a full page
reload. What admits a permission-less visitor is the GATE:
:phoenix_kit_ensure_admin recognises this view via
PhoenixKitWeb.Users.Auth.landing_view?/1 and skips the admin-area and
per-view permission checks for it alone — authentication, the account gate
and the locale hook still run. The overview's own gates are what keep the
operator blocks away from whoever gets in.
Because nobody is ever evicted from this page, it has to survive a permission
change in place: PhoenixKitWeb.Users.Auth's scope-refresh hook skips its
eviction for the landing view and instead calls
phoenix_kit_scope_changed/1, which re-runs
PhoenixKitWeb.Live.Dashboard.Overview.assign_scope_gates/1. A demoted
operator watches the cards and statistics disappear (and the subscriptions
behind them close) without leaving the page or reloading it.
/dashboard is a SEPARATE page (PhoenixKitWeb.Live.Dashboard.Index),
deprecated since 2026-07-27 and sharing nothing with this one.
Summary
Functions
Callback implementation for Phoenix.LiveView.render/1.
The welcome half of /admin — the part with no permission gate at all, and
therefore the whole page for a visitor holding nothing.
Functions
Callback implementation for Phoenix.LiveView.render/1.
The welcome half of /admin — the part with no permission gate at all, and
therefore the whole page for a visitor holding nothing.
Deliberately an <h2>, not an <h1>: the page's one header is the
LayoutWrapper breadcrumb, and this sits at the same level as the operator
overview's own section headings.
The greeting reuses the EXISTING "Welcome back" msgid (it is
lib/phoenix_kit_web/users/login.html.heex's), so it arrives already
translated in every shipped locale. The name is appended in markup rather
than interpolated into a new "Welcome back, %{name}" msgid, which would
ship untranslated everywhere. It is a function component rather than mount
assigns so that gettext runs at RENDER time: a locale switch that only
patches params (handle_params, after mount) still reaches it.
Attributes
scope(:any) (required) - the visitor'sPhoenixKit.Users.Auth.Scope, ornil.