Skip to content

Site administration ​

Every site has an admin panel for its settings, accounts, roles, content structure and moderation queues. This document follows the panel's menu and sets out the rules and consequences of each screen, then explains how pages are kept out of search and how several sites share one instance. How permissions are decided is described in Roles and permissions.

The interface is currently in Chinese. Each element is described below by its English name.

Simplified Chinese

Opening the admin panel ​

The panel is at /-/admin/ on the site's domain, for example https://wiki.example.org/-/admin/. The panel has no sign-in page of its own: signed-out visitors are sent to the site's sign-in page, and Sign out signs you out of the whole site.

Superusers, and accounts holding a role on this site with Can enter the admin panel checked, can enter the panel. Entering is only the first step. Every screen needs its own permission (see Menu and required permissions). The menu shows only the screens you may use, and the address of any other screen answers "not found".

Every screen shows notices about pwikit updates at the top. Superusers can update now, postpone or skip the release from there; see Updating.

The first administrator ​

A new instance has no accounts. Create the first administrator on the command line:

sh
pwikit admin create -name "Site Admin"

If you are importing a Wikidot site, import it first and then run pwikit admin create with your Wikidot name, so the imported account and its pages stay yours. See Command line and Importing from Wikidot. pwikit admin grant and pwikit admin revoke give and remove superuser rights on existing accounts.

Note Soon after signing in, set Role after sign-up and Role after claiming; on a new site you can pick the member role it starts with. See Registration and accounts. Members who join before that hold only registered and cannot edit pages. Adjust the member and admin roles a new site starts with to match your site's rules soon as well; see Built-in roles.

Superusers and roles ​

SuperuserAccount with roles
ScopeEvery site on the instanceOnly the site where the roles are held
PermissionsAll of them, regardless of rolesThe sum of its roles' permissions
Admin panelAlways allowed inNeeds a role with Can enter the admin panel
Sign-in and address recordsCan see an account's last login, latest IP and Suspicious activityHidden, whatever the permissions
Full conversations behind message reportsCan read every private message between the two accounts in User reportsSee only the messages the reporter chose to send
Can be edited byOnly another superuser can change the superuser flag or its rolesAnyone with the needed permissions and a higher rank
Made withpwikit admin create / admin grant, or the Superuser checkbox on a user's screenThe Users screen

A superuser has every permission only while the account is active. A deactivated superuser has none.

The permission names below are the labels shown in the permission matrix; the full list is in The permission list.

GroupScreenRequired permission
—DashboardNone
SiteSite settingsManage site
ThemesManage site
PagesEdit pages
Page categoriesManage categories
TagsManage tags
Tag categoriesManage tags
MembersUsersManage users
RolesManage roles
Role categoriesManage roles
Invite linksManage users
ForumForum sectionsManage forum
Forum categoriesManage forum
Recent postsManage forum
QueueUser reportsView user reports
Support ticketsView user tickets
Membership applicationsReview membership applications
RecordsAdmin logView admin log
Suspicious activitySuperusers only

Several screens contain parts that grant rights: permission matrices, category overrides, role checkboxes and the role fields of the site settings. Those parts appear only to accounts with Manage permission settings, because assigning a role is the same as granting its permissions.

The admin panel checks permissions for the site as a whole. Category overrides do not affect which screens you can open.

Site settings ​

Site settings is one form, and all of its boxes are saved together. If any value is rejected, nothing is saved.

Site information ​

  • Site identifier takes letters, digits, - and _ only. Command-line options such as -site refer to it. Inline themes are stored per site identifier, so after changing it, open each inline theme and save it again.
  • Domain and Media domain are the host names requests arrive at, without a scheme or path. A port is allowed, such as localhost:8080. See Changing the domain.
  • Site language is used only when the account has chosen no language and the browser does not ask for another available one.

Visitors always see times in their own local time; Site time zone does not change that. The site time zone is used in only two places: where a day begins and ends when modules such as [[module ListPages]] filter pages by date, and the times shown on a page before the browser's script runs. The date range of the site search counts days in UTC. Enter an IANA time zone name, such as Asia/Shanghai or UTC.

Appearance ​

With — chosen as Site theme or System page theme, no theme is loaded and pages use the built-in styles. Icons must be PNG, JPEG, GIF, WebP or ICO, up to 2 MB; uploading a new file replaces the icon, and only Clear current icon removes it. Footer license text is wikitext in which only [[module time]] is rendered; other modules are shown as plain text.

Content defaults ​

Rating system and Allow users to create tags always name a value at site level. They apply to every page whose category does not say otherwise. A category left on Follow the site changes with them.

When users may not create tags, a tag typed on a page that does not already exist is dropped when the tags are saved. Create such tags on the Tags screen first.

Registration and accounts ​

Role after sign-up and Role after claiming are shown only with Manage permission settings. If they are empty, new accounts hold only registered. registered has no permissions by default, so these members cannot edit pages, comment or rate. The role is given only at the moment of sign-up or claiming; assign it to accounts that joined earlier one by one under Users.

Every sign-up requires an email address, and a verification email is sent to it. Email verification requirement decides what an unverified account can do:

OptionEffect
OptionalNew accounts are signed in right away. Verifying the address changes nothing about permissions
RequiredNew accounts are signed in right away, but until the address is verified they cannot create, edit, rate, tag, move, lock or delete pages, manage attachments or authors, reset ratings, comment, post or change anything in the forum, or send private messages
Required at sign-upNew accounts are not signed in after signing up. The same restrictions as Required apply until the address is verified

The policy applies to existing unverified accounts as soon as it is saved. Without a mail server configured, emails are written to pwikit's log instead of being delivered, so nobody receives a verification link; see Configuration.

Membership by password ​

This box is shown only with Manage permission settings. Visitors enter the password through [[module MembershipByPassword]] on a page of your choice (see Modules), and a signed-in account that enters it correctly receives Role after joining. Joining works only when Membership by password is checked, a password is set and a role is chosen.

The membership password is stored, and shown on this screen, as plain text.

Changing the domain ​

  • The change applies on save. The site answers only at the new domain, and the old one shows a page saying that no site is bound to that name. You are not redirected, and you need to sign in again at the new address.
  • Point the new name's DNS at this server before saving.
  • If pwikit already serves HTTPS automatically, a new public domain gets its certificate on the first visit. If it served plain HTTP because no public domain was bound, restart pwikit to switch to HTTPS. See Deployment.
  • If the site can no longer be reached, fix the domain with pwikit site rebind.

Use a media domain that differs from the domain, such as wiki.example.org and files.example.org. Separate domains are a security boundary: uploaded HTML then cannot act as the site. Using the same name for both works, at the cost of uploaded HTML sharing the site's origin. When the two differ, requests for files on the page domain, and requests for pages on the media domain, are redirected to the right one. A media domain can belong to only one site on the instance.

Pages ​

Pages lists every page on the site. Checked pages can be acted on together, and each page can be edited or renamed on its own.

Actions on selected pages ​

ActionEffect
DeleteDeletes the pages with their history, attachments and ratings. Cannot be undone
Exclude from searchKeeps the pages out of search results. See Search exclusions
Include in searchReturns the pages to search results
RevertTakes each page back the given number of revisions, from 1 to 50. Title, tags, parent page, ratings and attachments are restored along with the source

Deleting and reverting show a confirmation page first, and the result is reported for each page.

Editing one page ​

Deleting, reverting, editing and renaming are done as your account, and each is checked against your permissions on that page, as on the page itself: deleting needs Delete pages, renaming needs Move pages in both the old and the new category. Edits, renames and reverts appear in the page history under your name.

Page categories ​

A page category is the part of a page name before the colon: forum:start is in the forum category. Pages without a prefix are in _default. A category gets an entry on this screen the first time it is saved; until then it uses the site's content defaults and has no overrides.

  • With Include in index unchecked, pages in the category are left out of search and carry a noindex tag for search engines.
  • Rating system, Allow users to create tags and Theme can be set to Follow the site, which uses the site's value; new categories start that way. For the first two, Follow the site names the value it currently resolves to. A category with its own theme no longer loads the site theme.
  • An empty Top bar page or Side bar page uses nav:top or nav:side.
  • With Manage permission settings, the form also has a Permissions box for overriding a role's permissions in this category. Ticking Own settings changes no permission by itself; only entries set to Allow or Deny take effect in this category.

Deleting a category removes its settings and overrides. Its pages are not deleted; they use the site's content defaults again.

Themes ​

A theme is either inline CSS or an external link. An inline theme is served at /-/theme/<identifier>.css and is updated as soon as it is saved. A theme takes effect once it is chosen as the site theme or system page theme in Site settings; a category can also use a theme of its own, set in Page categories.

Deleting a theme the site uses leaves the site with no theme, and categories using it follow the site again.

Tags ​

With Include in index unchecked, every page with the tag is left out of search.

On a page, a tag written name belongs to the tag category whose identifier is _default, and slug:name belongs to the tag category with identifier slug. A tag with no category cannot be added from a page, so give each tag a category. Tags created here keep their case, while tags typed on a page are lowercased before matching, so use lowercase names.

Deleting a tag removes it from every page. When users may create tags, a tag no longer on any page is removed the next time any page's tags are saved.

Tag categories ​

A tag category's Identifier is the prefix used in page tags (slug:name). Categories with a smaller Priority come first in a page's tag list, and two categories on a site cannot share a priority.

Deleting a category keeps its tags but leaves them without a category.

Users ​

Accounts belong to the whole instance, so Users lists accounts from every site; roles are assigned per site. The email column needs View sensitive information.

Editing an account ​

A superuser can open any account. Anyone else can open only accounts ranked below them: the account's Rank number must be larger than their own. Rank is the smallest order number among the account's roles on this site; an account with no roles shows 2147483647.

The screen has three parts: the account itself, which only a superuser may change; what this site has done to the member; and the roles held on this site. See Roles and permissions for why the split runs where it does.

  • Only a superuser can change account details such as username, display name, email and bio; anyone else sees the current values. Email is shown and saved only with View sensitive information. Everyone who can open the screen can read the API key.
  • Last login and Latest IP are shown to superusers only. Latest IP is the most recently used of the addresses recorded for Suspicious activity, so it can also come from rating or checking notifications.
  • Sanctions on this site: ban, silence, no editing and no rating. Each row appears only to accounts holding the matching permission. End time is read in your own local time; leave it empty for a sanction that lasts until lifted. What each sanction removes is listed in Sanctions.
  • Roles: checkboxes for this site's roles, shown only with Manage permission settings. The roles of a superuser can be changed only by a superuser.

State and restrictions is shown to superusers only. Its settings are written on the account and apply on every site of the instance; to restrict a member on this site alone, use a sanction.

  • With Account active unchecked, the account cannot sign in and its open sessions stop working.
  • When Deactivated until has a date, the account is treated as signed out until then and works again afterwards, but sign-in still requires Account active. For a suspension that ends on its own, set the date and leave Account active checked.
  • Forum active and Forum inactive until restrict forum posting the same way on every site; the effect is described in Locks, authors and the forum.
  • With Can send private messages unchecked, the account cannot send private messages. Sending also needs the Send private messages permission.

Creating accounts and inviting people ​

  • New user: creates an account with a password, which the user can change later.
  • Mail invitation: creates a deactivated placeholder account and mails an invitation link to the address given; the account becomes active when the person completes the link.
  • Generate invite link: the same, but the link is shown on screen instead of mailed. It is shown only once, so copy it.
  • Generate claim link: creates a link for an imported Wikidot account nobody has claimed. Whoever uses it takes over the account and keeps its Wikidot username. The account is unchanged until the claim succeeds.
  • Activate account, on an account's screen: binds an email address to the account and mails an acceptance link; for an imported Wikidot account the link is a claim link.
  • New bot: see Bot accounts.

All of these need Invite members, except New bot, which needs Manage bot accounts. Roles can be chosen at the same time, which needs Manage permission settings. An email address that already belongs to an account is refused. Invite and claim links are valid for three days and work once.

Without a mail server configured, invitations are written to pwikit's log instead of being sent, although the screen reports them as sent. Use generated links, or configure mail in Configuration.

Bot accounts ​

A bot account gives a script a fixed identity on the site. It has no password and cannot sign in on the sign-in page.

  1. On the Users screen, click New bot and enter a username. This needs Manage bot accounts. The API key is shown on the bot's screen.
  2. The script sends Authorization: Bearer <API key> with every request. A request carrying it is handled as the bot, without the CSRF check. With a wrong key, or once the bot is deactivated, the request is handled as signed out.
  3. What a bot may do depends on its roles, as for any account. A new bot holds only the built-in everyone and registered. To let it edit pages or post, check the roles on its screen. Roles work only on the site that granted them.
  • Everyone who can open the bot's screen can read its API key.
  • To stop a bot at once, a superuser unchecks its Account active or sets Deactivated until.
  • The API key cannot be regenerated yet. If it leaks, deactivate the bot and create a new one.
  • Exporting a site clears the API keys of bot accounts; see Exporting a single site.

Resetting votes ​

Reset ratings needs Reset member ratings. Confirming deletes every vote the account has cast on this site, and the ratings of the affected pages change at once. Votes the account cast on the instance's other sites are kept. This cannot be undone.

View activity on an account's screen lists the account's edits, votes and posts on this site. Vote times are shown only with View vote times.

Roles ​

A smaller Order number ranks higher. Rank decides which accounts and roles a non-superuser may edit, which role of a role category is displayed, and which role a vote is grouped under. A non-superuser cannot open a role whose order number is smaller than the smallest order number among their own roles.

  • Group votes: every vote is filed under one grouping role: registered or everyone if that role has it checked, otherwise the voter's highest-ranked role that has it.
  • Badges and icons: within one role category, only the highest-ranked role is displayed for each style next to a name, and only one role of the category appears on a profile. Roles without a category are all displayed.
  • The list's Management permissions column shows Yes when the role allows any permission under Tickets, Member actions or Admin panel.
  • The Permissions box is shown only with Manage permission settings. Every permission has Allow, Inherit and Deny; see What a role holds.

NoteInherit means the role says nothing and the member's other roles decide; Deny overrides every allow from every other role. When this role should simply not give a permission, use Inherit, not Deny.

Deleting a role removes it from every account and every category override. Site settings that named it are cleared, and votes grouped under it lose their group.

Built-in roles ​

Every site has two built-in roles. They cannot be deleted, their identifiers cannot be changed, and they are not assigned by hand.

RoleHeld byOn a new site
everyoneEvery visitor, signed in or notView pages, page comments, forum sections, forum categories, threads and posts
registeredEvery signed-in accountNo permissions

To change what anonymous visitors or all members can do, edit these roles. Other roles are assigned on the Users screen, through the sign-up and claim role settings, membership by password, invite links and approved membership applications.

Sites created with pwikit createsite also start with two ordinary roles. They are no different from roles you create yourself and can be changed or deleted. They are only a generic starting point; adjust them to match your site's rules soon.

RoleNameSettings
adminThe word for administrator in the default interface languageOrder 0; Can enter the admin panel checked; every permission set to Allow; profile display Status
memberThe word for member in the default interface languageOrder 1; permissions in the pages, forum and member interaction groups set to Allow, except Lock pages, Reset page ratings, Manage page authors, Delete forum posts, Create forum threads, Edit forum threads, Pin forum threads, Lock forum threads and Move forum threads, which stay on Inherit; the tickets, member sanctions and admin panel groups all stay on Inherit; profile display Status

On a new site, Role after sign-up and Role after claiming are both empty, so member is not given automatically. Set both to member, or to another role, under Registration and accounts.

Role categories ​

Role categories group roles so that an account shows one role per category. A category that still holds roles cannot be deleted.

Invite links lists every invitation and claim link and whether it has been used. Unused links can be revoked; used links cannot.

Forum sections ​

Forum sections are the top level of the forum. A section marked Hidden is left out of the forum's section list unless the reader chooses to show hidden sections, and a direct link still opens it. A section marked Staff only can be seen only by accounts with View hidden forum sections.

Deleting a section that still has categories fails. Move or delete its categories first.

Forum categories ​

Forum categories hold threads and must belong to a section. A category marked Holds page comments lists the comment threads of pages, and readers cannot start threads in it.

Deleting a category that still has threads fails.

Recent posts ​

Recent posts lists the site's newest forum posts, with or without page comments.

User reports ​

User reports come from private messages: a member selects messages in a conversation and reports them with a reason. Every member who can open this screen is notified of a new report.

The full conversation between the two accounts is shown only to superusers. Private messages belong to no single site, so site administrators see only the messages the reporter chose to send. Setting any status other than Pending records you as the handler and the time.

Support tickets ​

Support tickets are submitted by signed-in members through [[module ApplicationForm]] on a page (see Modules). Every member who can open this screen is notified of a new ticket, and the same goes for membership applications. Setting any status other than Pending records you as the handler and the time.

Membership applications ​

Membership applications are submitted through [[module ApplicationForm type="membershipapply"]] and handled like Support tickets. When you save an application as approved with a Role granted on approval chosen, the applicant receives the role in the same step. Choosing the role needs Manage permission settings.

Admin log ​

Admin log records every creation, change and deletion made in the admin panel of this site: who did it, when, on which screen and to what. The log is read only.

Suspicious activity ​

Suspicious activity opens only for superusers. It helps find accounts run by the same person. pwikit records the network addresses an account uses when it signs in, rates pages and checks notifications, at most once per hour per address. The screen draws a graph linking accounts to the addresses they share.

Using the screen

  1. Leave out the addresses many people share first. Schools, offices, public Wi-Fi and mobile networks put many unrelated accounts behind one address; in the graph such an address links to a crowd of accounts.
  2. Look at the links that remain. Two accounts sharing one address says little. Accounts that share several different addresses are worth a closer look.
  3. A wider mask such as /24 groups the addresses of one network, which finds accounts that moved to a new address. It also groups unrelated people, so weigh it against other signs.
  4. Filter by an account name to see the addresses and accounts it links to. The latest address of a single account is also shown as Latest IP on its screen.

The graph only shows that accounts used the same address; it does not prove they are the same person.

Clear IP records deletes every recorded address on the instance. Records build up again as accounts sign in or act, and existing links disappear with them.

Search exclusions ​

Three switches keep pages out of the site's search. A page is left out if any of them applies:

ExcludesWhere
All pages in a categoryUncheck Include in index on the Page categories screen
All pages with a tagUncheck Include in index on the Tags screen
Individual pagesSelect them on the Pages screen and choose Exclude from search; Include in search undoes it

Exclusions affect search only. Excluded pages still open normally and still appear in page lists built with modules. Pages in an excluded category also tell search engines not to index them.

Multiple sites ​

One instance can run several sites. Create each with pwikit createsite; the admin panel cannot create sites. Open a site's admin panel at /-/admin/ on that site's own domain.

Separate for each siteShared across the instance
Domain and media domainAccounts: usernames, passwords, email, and the State and restrictions fields on the Users screen
All site settings, including language, time zone and email policySuperusers, who manage every site
Themes, page categories, tags and tag categoriesRecorded addresses on the Suspicious activity screen
Roles, role categories and each account's roles
Sanctions on members, and the votes cleared by Reset ratings
Pages, forum, user reports, tickets, applications, invite links and admin log

An account signed up on one site can sign in on another, but holds only everyone and registered there until it is given roles on that site. The User list on any site shows every account on the instance; changes to an account's own details apply everywhere, while sanctions apply only on the site that set them. Which is which is set out in Roles and permissions.

A new site starts with:

  • the built-in roles only, and no role marked Can enter the admin panel, so only superusers can administer it at first;
  • no themes;
  • home page main, time zone UTC, email verification requirement Optional, rating system Upvote/downvote and Allow users to create tags set to Not allowed.