# Milestone 02 — Google Auth and Admin Shell ## Reference Read `plans/wedding-bootstrap-plan.md` first. Also confirm the current Next.js/Auth.js setup before implementation because this project uses Next.js 16. ## Goal Add Google login restricted to the couple and create a protected `/admin` shell using shadcn/ui components only. ## Scope Implement only: - Google OAuth authentication. - Admin email allowlist via `ADMIN_EMAILS`. - Route protection for `/admin` and `/admin/*`. - Basic `/admin` dashboard shell. - Sign-in/sign-out UI. - shadcn/ui setup and required admin shell components. ## Non-goals Do not implement: - Invitation creation forms. - Invitation list/detail functionality. - Guest invite pages. - RSVP submission. - MinIO uploads. - Song/toast/message workflows. ## Required constraints - `/admin` and `/admin/*` require authenticated admin access. - Only emails in `ADMIN_EMAILS` can access admin pages. - Guest pages must not require login. - Admin UI must use shadcn/ui components only. - Do not introduce another admin component library. - If a component is needed, add it through the shadcn workflow. ## Implementation tasks - Add/configure Auth.js/NextAuth Google provider. - Add `auth.ts` or equivalent auth config. - Add `app/api/auth/[...nextauth]/route.ts` or current-version equivalent. - Add middleware or route-level protection for `/admin`. - Add forbidden/unauthorized handling. - Initialize shadcn/ui if not already initialized. - Add required shadcn components for the admin shell, likely: - button - card - dropdown-menu - avatar or badge if useful - alert - Create `/admin` page with basic dashboard placeholder cards. - Add sign-in/sign-out controls. ## Verification Run: ```bash npm run lint npm run build ``` Manual checks: - Unauthenticated user cannot access `/admin`. - Allowed Google email can access `/admin`. - Non-allowlisted Google email is denied. - Public/guest routes remain accessible without login. - Admin page uses only shadcn/ui components. ## Acceptance criteria - Admin auth works with Google OAuth and email allowlist. - `/admin` is protected. - Admin shell exists and builds. - No non-shadcn admin UI component library was added. - No future milestone features were implemented.