PhoenixKitWeb.Live.Dashboard (phoenix_kit v2.2.0)

Copy Markdown View Source

The /admin landing page.

It is built to be the page ANY authenticated visitor can safely be sent to, whatever their permissions. Two halves:

A visitor holding no permissions sees the welcome block and nothing else — no statistics, no System Information, no cards, and (because the overview decides before it queries) not one operator query or PubSub subscription on their behalf. That is what makes the page safe as a universal landing.

Reaching it is not the same as being allowed to see all of it. The route sits in the ordinary admin live_session, alongside every other /admin/* page, so admin navigation to and from it stays a live patch rather than a full page reload. What admits a permission-less visitor is the GATE: :phoenix_kit_ensure_admin recognises this view via PhoenixKitWeb.Users.Auth.landing_view?/1 and skips the admin-area and per-view permission checks for it alone — authentication, the account gate and the locale hook still run. The overview's own gates are what keep the operator blocks away from whoever gets in.

Because nobody is ever evicted from this page, it has to survive a permission change in place: PhoenixKitWeb.Users.Auth's scope-refresh hook skips its eviction for the landing view and instead calls phoenix_kit_scope_changed/1, which re-runs PhoenixKitWeb.Live.Dashboard.Overview.assign_scope_gates/1. A demoted operator watches the cards and statistics disappear (and the subscriptions behind them close) without leaving the page or reloading it.

/dashboard is a SEPARATE page (PhoenixKitWeb.Live.Dashboard.Index), deprecated since 2026-07-27 and sharing nothing with this one.

Summary

Functions

Callback implementation for Phoenix.LiveView.render/1.

The welcome half of /admin — the part with no permission gate at all, and therefore the whole page for a visitor holding nothing.

Functions

render(assigns)

Callback implementation for Phoenix.LiveView.render/1.

welcome_block(assigns)

The welcome half of /admin — the part with no permission gate at all, and therefore the whole page for a visitor holding nothing.

Deliberately an <h2>, not an <h1>: the page's one header is the LayoutWrapper breadcrumb, and this sits at the same level as the operator overview's own section headings.

The greeting reuses the EXISTING "Welcome back" msgid (it is lib/phoenix_kit_web/users/login.html.heex's), so it arrives already translated in every shipped locale. The name is appended in markup rather than interpolated into a new "Welcome back, %{name}" msgid, which would ship untranslated everywhere. It is a function component rather than mount assigns so that gettext runs at RENDER time: a locale switch that only patches params (handle_params, after mount) still reaches it.

Attributes