Skip to content

The dashboard ​

The first screen after signing in. It summarises the site and links to whatever needs attention.

ScreenRouteMinimum role
Dashboard /adminEditor
Sign in /admin/loginPublic
Two-factor challenge /two-factor/challengeSigned in

Signing in ​

The admin panel lives at the prefix set by CMS_ADMIN_PREFIX in .env, which is /admin until you change it. Nothing on the public site links to it.

The admin sign-in screen with email and password fields

Login is rate limited by email address and by IP separately: five attempts in five minutes. The two limits are deliberate — one attacker hammering your address cannot lock you out, because their IP hits its own limit first.

If two-factor authentication is on for your account, the password check signs you in but leaves the session marked unconfirmed. Every request is then held at the challenge screen until you enter a valid code.

The two-factor challenge screen asking for a six-digit code, with a link to use a recovery code instead

A six-digit code from your authenticator, or one of your eight recovery codes. Each recovery code works exactly once. Codes are accepted within a ±30 second window to tolerate clock drift.

The dashboard itself ​

The dashboard showing counts for content and orders, recent activity, and any outstanding system warnings

What appears depends on which modules are on:

PanelShown whenContains
Content countsAlwaysPages, and posts if the blog is on
Shop summaryShop module onRecent orders, revenue, low stock warnings
Recent activityAlwaysThe latest entries from the activity log
System warningsWhen something is wrongLinks straight to the screen that fixes it
Comments awaiting approvalBlog module onA count linking to the moderation queue
Contact submissionsContact module onUnread count

The sidebar ​

The sidebar only lists sections belonging to modules that are switched on, and only those your role can reach. If a section you expect is missing, check Modules first and your role second.

Some sections are administrator-only regardless of module state, because they are ways of changing what the site's code does rather than what it says:

SectionMinimum roleWhy
UsersAdministratorCreating an account or clearing someone's second factor is a way to become another user
Payment gatewaysAdministratorCredentials are secrets
ThemesAdministratorA theme is Blade, and Blade is compiled and executed — installing one is deploying code
ModulesAdministratorChanges which routes exist across the whole site
SettingsAdministratorEditors stop at content
System & UpdatesAdministratorUpdates rewrite the application's own code

See Users & roles for what each role can do.

Keyboard shortcuts ​

/ focuses the search field on any list screen. Inside the visual builder there are several more — see Visual builder.

Radius is open source under the MIT licence. Security issues go to the address in SECURITY.md, not the public issue tracker.