# ENGINEERING_SPEC — ECR-006 运营后台 Phase A 权威设计:`docs/BACKEND_DESIGN/ECR-006-ops-admin-phase-a.md` 产品:`.ai/product/feature-spec/ops-admin.md` ## Implement order 1. Migration `000010_admin_ops` + ERD 同步 2. `repository/admin_repo.go` 3. `service/admin`(auth · users · orders · grant · audit) 4. `middleware.AdminAuth` + `handler` 注册(**独立** Group,勿挂 DeviceAuth) 5. config bootstrap + `config.example.yaml` 6. OpenAPI `/admin/*` 最小路径 7. `apps/admin-h5` Vite Vue3:login + shell + 四页 8. root scripts:`dev:admin` / `build:admin` 9. 测试:service 或 integration 10. 更新 architecture / go-services / feature-map / TRACEABILITY ## Constraints - 函数 ≤50 行 · 文件 ≤400 行 - 密码 bcrypt;session token 随机 opaque - admin-h5 禁止页面内裸拼绝对 API URL - 不提交 `config.local.yaml` ## Done when ECR Acceptance 勾完 + DoD Review Report