Appearance
Access, roles and logins
Signing in
Everyone signs in at fest.qurtuba.in/login with the username or email they were given. The credential decides the panel:
- An address that is a platform account → Administrator console, if that account passes the
festsuper-admin page check. - Anything else → a fest manager login, whose role decides the panel:
| Role | Lands on | Sees |
|---|---|---|
admin and other staff roles | /admin | The organiser console |
judge | /judge | Only their assigned programmes |
team_manager | /team | Only their own team |
Signing in from a deep link returns you to it (/login?next=/admin/reports). Signing out revokes the session immediately.
Who issues which login
| Login | Issued by | Where |
|---|---|---|
| Organisers | Administrator | Super Admin → Fests, with a role preset and a per-permission matrix |
| Judges, team captains | Organiser | Access → Panel logins, because the organiser knows who judges what |
| Other staff (media, desk…) | Organiser | Access → Managers |
Judges can be appointed straight from the institution's teachers and staff, with their phone number carried over.
Roles
Access → Roles manages roles built from a catalogue of about sixty permissions. They cover setup, participants, programmes, scheduling, judging, results, media and content, and governance. System roles are seeded for every festival, and you can add your own. Besides the organiser console there are Judge, Team and Media panels.
What each login can reach
- A fest manager reaches only its own festival, or, when issued without one, every fest of its institution plus every shared fest that invited it.
- A team captain reaches their team across every sub-fest of the festival (Arts and Sports).
- A judge reaches only the programmes assigned to them.
- Passwords are hashed on the server. Password hashes, invitation tokens and sessions can't be read through the API by anyone.
- The student roster is searchable only through a fixed, safe projection: name, class, institution. Never passwords or addresses.