RESTRICTED ADMIN CONTEXT
Administrator authentication
The admin key is kept only in this page's JavaScript memory. It is not written to cookies, Web Storage, IndexedDB or the URL. Refreshing the page requires authentication again.
Security posture
- Admin key: runtime memory only
- Official trust: server-owned
- Developer key hashes/raw secrets: never rendered
- RCC uploads: direct browser-to-R2 presigned PUT
- Legacy catalog remains compatible
Official legacy catalog
Existing admin-key published mods and themes. This is the backwards-compatible catalog consumed by current launchers.
Mods
Themes
Official RCC publish
SHA-256 → short-lived upload URL → direct browser-to-R2 PUT → catalog finalize. Choose a package-pair workflow or enter every catalog value manually.
1. Market
Admin may publish the exact global catalog ID.
2. Input mode
1. Select package pair
Manifest trust fields such as official or verified are ignored. Official trust comes from this authenticated admin context.
2. Preflight
Parsed catalog values before upload.
Pending reviews
Approve or reject server-side review records. Approval promotes the selected version.
Publishers & trust
Verified/official status and Level 3/native permissions are server-owned and cannot be self-declared in a manifest.
Developers
YoungLion identity mappings and publisher memberships.
Developer API key metadata
Only prefix/last4/fingerprint/scopes/status metadata is displayed. Raw key and authentication hash are intentionally unavailable.
Content, versions & moderation
Inspect hashes/statuses, suspend or unpublish content, restore published content, and roll back to an already-published version.
Versions / artifacts
Upload tickets & R2 analysis
Ticket state plus DB-known expired non-finalized object candidates. This does not pretend to be a full R2 bucket listing.
Potential orphan candidates
Developer-platform schema
Publisher, content/version, review, API-key and upload-ticket tables used by the modern portal.
Not loaded.
Legacy catalog schema
Recovered schema diagnostics/repair for the original mods/themes publisher backend.
Not loaded.
Audit & security events
Server-side audit metadata. Admin credentials are never included.