Admin shell
admin supplies a small compiled same-origin HTTPS shell; each owning Module supplies its real forms and operations. It has no Core registry, database, roles, alternative authentication or business authorization. Products register a finite set of Surface values with New, serve Handler() under the fixed /admin namespace and mount the existing identity.Web independently at the configured AuthPath (for example /auth). Pass identity/admin.Authenticator(web) plus the product Application as Authorizer. Identity owns cookie/CSRF validation; the shell separately authorizes each surface's navigation capability/target and each operation still calls its owning public Service.
A navigation grant is an explicit product choice, never an account-wide domain grant. Request.Allowed is only a presentation hint. Trusted compiled surfaces render an html/template definition named content through Request.Render; request/domain strings must stay template data. Rendering finishes into bounded 128 KiB buffers before writing. Module templates are trusted code, not user-installed templates. Surface IDs stay stable while Text selects English/Persian labels. The shell uses semantic layout/navigation/forms, a skip link, keyboard focus feedback, logical responsive CSS and lang/dir; domain values are neither normalized nor translated.
The first Identity-owned surface is identity/admin.New(service): create an account, inspect one opaque ID or separately authorized exact login, conditionally set status/password and revoke all sessions. Exact-login read reconciles an unknown create response without automatic replay; the product separately grants identity.AccountLookup against the exact validated login. AccountRead with an empty target gates this surface's navigation; actual ID reads still authorize their exact IDs. Password/status forms use the current revision as an exact decimal string through JSON/DOM, never a JavaScript number; RevokeAll uses the existing non-CAS API. No list, profiles or product role model is supplied.
The second real surface is media/admin: a bounded private file library whose upload hints follow the composed Media format selection with module-owned upload, metadata pages, known-ID status, authenticated attachment download and confirmed conditional deletion. Its List collection grant is separate from exact-ID Read/Delete; it exposes no maintenance grant or static paths. Native FormData and delegated form handlers support actual upload and refreshed rows without a frontend framework.
Call ConfigureServer before TLS serving to apply bounded header/total read/write/idle/header-size defaults. The product owns TLS keys/listener, trusted proxy topology if any, and graceful ingress shutdown before Application/Module shutdown. The shell additionally admits at most 16 requests without a queue, bounds bodies to 12 MiB (room for a 10 MiB Media file plus bounded multipart framing), derives a 10 second context and sets actual read/write deadlines through http.ResponseController no later than the caller's deadline. Unsupported writer wrappers fail closed; wrappers must support deadlines or expose Unwrap. Identity's JSON forms further bound reads to 2 KiB/two seconds.
Sensitive responses use no-store, nosniff, no-referrer, frame denial and a same-origin CSP without inline scripts/styles. HSTS belongs to the deployment profile; there is no CORS. Exact TLS/Host, empty query/raw paths, strict JSON and same-origin mutation admission remain required. Existing Identity/Web endpoints own non-simple header/CSRF behavior. The CSRF GET explicitly supplies only the same-origin root referrer with a request-local same-origin policy, refuses cross-origin requests/redirects and preserves Identity's exact origin checks; document responses retain no-referrer. Initial JavaScript uses only a request-local CSRF value, never persistent browser storage; each operation has one finite 15 second AbortController wait, no automatic retry. Password fields clear after completion/failure. An interrupted mutation reports an unknown outcome; inspect the retained exact login or known ID before another action. A not-found read does not prove that an earlier in-flight transaction can never commit.
Focused package tests cover registration, permission/error separation, escaping, browser headers, bounded admission/deadlines and owning Service dispatch. The normal pinned independent consumer and actual TLS/browser proof own end-to-end session, two-surface, keyboard/RTL and payload evidence; no source copy or module replacement is a supported proving path. This shell belongs to the pre-v1 v0.2 source dependency. Product deployment and the real-product lifecycle proof remain separately owned and gated.