Cover image for project: Gerenciador de Workspaces IN PROGRESS

Technical summary

Gerenciador de Workspaces is the NEXUS multi-tenant system: segregated environments per team, project or area (Marketing, Dev, SecOps, Finance), with members and roles (Owner, Admin, Member, Viewer) per workspace, instant 1-click switching (no re-login) and a per-workspace plugin ecosystem — all backed by a lazy 3-table schema and the core/workspaces.php core.

Executed scope

  • plugin.json: v1.0.0, slug nexus-workspaces (no legacy_slugs), name "Gerenciador de Workspaces", "Administração & Equipes" category, is_core: false, author "NEXUS Core".
  • Core (core/workspaces.php, 377 lines, strict_types) — workspaces_install() (lazy, static $installed, try/catch) creates 3 tables: nexus_workspaces (UNIQUE slug, icon/color, owner_username, is_default, status, idx_owner/idx_status), nexus_workspace_members (role default member, JSON permissions, UNIQUE uk_ws_user, FK CASCADE) and nexus_workspace_plugins (plugin_slug, is_active, config_json, UNIQUE uk_ws_plugin, FK CASCADE).
  • Automatic seed — when empty, creates the "geral" (Workspace Principal) with owner admin and is_default 1.
  • Config (nexus_workspaces_settings) — allow_user_create (true), default_workspace_slug (geral) and isolation_mode (soft/strict validated, soft fallback).
  • Session context — workspace_current(): session → first accessible → default → first → id 1 fallback; workspace_switch() validates status + member association (except admin/owner).
  • Role-based listing — admin sees all workspaces with member_count; other users only the ones they belong to (JOIN); is_active flag.
  • CRUD — workspace_save() (name required, automatic slug, collision → rand(100,999) suffix, creator becomes Owner), workspace_delete() (blocks default deletion, resets session).
  • Members — workspace_member_save() validates the user in users, roles owner/admin/member/viewer (invalid → member), REPLACE INTO (upsert); workspace_member_remove() by user.
  • Plugin backend (82 lines) — workspaces_user_search (LIKE username/email, LIMIT 10, avatar initials), workspaces_get_members (JOIN users for email/avatar, role-ordered) and workspaces_stats (active/member totals).
  • API: 11 actions — workspaces_list, workspaces_current, workspaces_switch, workspaces_save ($_GET+$_POST merge), workspaces_delete, workspaces_members, workspaces_user_search, workspaces_member_save, workspaces_member_remove, workspaces_settings, workspaces_settings_save.
  • UI (tab.php, 660 lines, sky/slate theme, layers icon, "Administração & Equipes" group) — 3 sub-tabs:
  • - Workspaces — stats (Active Workspace, Total, Your Role) + card grid (slug, description, member_count, owner, 🟢 ATIVO badge, ENTRAR NO WORKSPACE button, edit/delete — delete hidden on the default). - Members — AJAX autocomplete with 250ms debounce (avatar or initials + role + email), role selector (Administrator/Member/Viewer), table with colored badges (owner amber, admin sky, others slate) and "Remove" hidden for owner. - Settings (mandatory tab) — allow_user_create, default_workspace_slug + "How the NEXUS Workspace System works" info box.

  • Own modal (x-teleport) — create/edit workspace with name, description, icon (layers/folder/briefcase/shield/cpu) and color (sky/emerald/indigo/amber/rose).
  • HTTP security — Alpine sends X-CSRF-Token + csrf_token + Authorization: Bearer (API Key) on every call.
  • Fastr — /workspaces → workspaces_list. No cron.

Stack and tools

  • PHP 8 (no framework, strict_types in core and backend)
  • MySQL 8 (3 lazy tables: nexus_workspaces, nexus_workspace_members, nexus_workspace_plugins)
  • Alpine.js + Tailwind CSS (premium light, sky/slate)
  • REST API (api.php?action=...) with CSRF + Bearer
  • NEXUS plugin system (PluginManager: tabs, docs, API actions, Fastr)

Operational tags

  • Workspaces
  • Multi-tenant
  • Equipes
  • Projetos
  • Permissões
  • Segregação
  • Administração
  • Membros
  • Papéis
  • Plugin NEXUS

Operational result

  • Isolated environments without new instances: each team/project gets its own workspace with its own data and permissions.
  • 1-click switching: the active workspace lives in the session and changes without re-login.
  • Per-member roles: Owner, Admin, Member and Viewer with user-existence validation.
  • Configurable isolation: soft/strict mode + default workspace for new users.
  • Per-workspace plugin ecosystem: nexus_workspace_plugins table with is_active and config_json per environment.
  • Secure by default: unique slug, non-deletable default, CSRF + Bearer on every call.
  • Fast user search: autocomplete with avatar/initials and 250ms debounce.
  • /workspaces chat command.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Workspace isolation and environment governance module in NEXUS. Enables creating and switching segmented workspaces per client or project, with granular access control over tasks, reports, and team permissions.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.