Admin Panel
The admin panel lives at admin.nortonshop.net. It has ten tabs across the top: Welcome, Pages, Drafts, Hours, Promotions, Media, Directory, Jobs, Board, and Settings. Some tabs contain collapsible sections — click a section header to expand it.
First login — guided tour
The first time you log in, you'll see a short guided tour that walks you through each tab. It highlights one tab at a time with a brief explanation of what it does. Click Next to move through the steps, or Skip tour to jump straight in. The tour only appears once — after that you'll go straight to the Welcome tab.
Logging in
Login happens at auth.nortonshop.net/login. After you authenticate, you are redirected to the admin panel at admin.nortonshop.net.
When an account is created, you choose a login method: authenticator app, security key, or both. There is no password — instead you verify your identity with the method you chose. You can change or add methods at any time from the Settings tab → My Account section.
The available login methods are:
- Authenticator app — enter the 6-digit code from a free authenticator app on your phone. Open source options include Aegis (Android) and Ente Auth (iOS). Google Authenticator and Proton Pass also work.
- Security key — tap a security key or passkey, or use Touch ID. Ask your admin if this has been enabled.
- YubiKey — tap a YubiKey registered for login. Ask your admin if this has been enabled.
- Recovery code — if you lose access to all other methods, use one of the 12 one-time recovery codes you were given when your account was set up. Each code only works once.
We recommend using both an authenticator app and a security key — that way if you lose one, you still have the other. But either method works fine on its own, and you can always add the other later.
Admin tabs overview
The admin panel has ten tabs across the top. Some tabs are grouped — when you click them, you'll see collapsible sections inside. Click a section header to expand it and see the form inside. All sections start collapsed so you can see what's available at a glance.
Welcome
The Welcome tab is the first thing you see after logging in. It contains this editing guide — a plain-English reference for everything you can do in the admin panel. Come back to it any time you need a reminder.
Pages
Edit page content using Markdown. Select the page you want to edit — the available pages are Home, About, Post Office, Community, CLT, Housing, Membership, Directory, Board, Jobs, Contact, and Privacy. Make your changes in the text editor and click Publish to make them live, or Save as draft to save your work without publishing. Use the toolbar for formatting — bold, italic, headings, links, lists, tables, and more. Click the Preview button to see how it will look before saving, or click the ? button for a quick Markdown cheatsheet.
Pages that haven't had any content added yet show a loading animation. Once you publish content through the admin panel, it appears on the live site straight away.
Hours
Edit opening hours for both the shop and the Post Office. Each has its own table — just type the day name and the hours for each row. You can add or remove rows if needed (for example, combining "Monday – Friday" into one row during a holiday period, or adding a special "Christmas Eve" row).
The Hours Notice field at the top lets you add a banner message that appears above the hours tables on the home page and Post Office page. Use this for bank holidays, seasonal changes, or anything temporary — for example "Closed on all bank holidays" or "Reduced hours 23–27 December — see notice in shop". Leave it empty to hide the banner.
Promotions (grouped tab)
This tab groups three sections: Offers, Seasonal, and News & Events. Click a section header to expand it.
- Offers — each row is one product in the offers table on the homepage. Fill in the product name, price, and an optional note (e.g. "Use by 28 Sept — 6 bottles left"). Click + Add item to add more, Remove to delete one, and Save offers when done.
- Seasonal — each group is a seasonal category (e.g. "Easter Treats"). Give it a title, an optional availability note (e.g. "Until 21 April"), and list items one per line. Click Save seasonal when done.
- News & Events — each entry appears on the homepage. Give it a title, an optional date (just type it however you like, e.g. "5 October 2025, 10am-4pm"), and a description. Click Save news when done.
Media (grouped tab)
This tab groups four sections: Gallery, Site Images, Videos, and CDN Files. Click a section header to expand it.
- Gallery — upload images (JPEG, PNG, WebP — max 5 MB) to any of the photo galleries. Each gallery has its own section. You can preview and resize images before uploading. Drag gallery items to reorder them, then click Save order. Click Edit to change captions or alt text, and Delete to remove an image.
The galleries are: About Page (main carousel at the top of the about page), Shop Photos (carousel at the top of the home page), Village History (about page under "Village History"), Affordable Housing (housing page), Village Photos (carousel on the about page), and Community Land Trust (CLT page). - Site Images — replace the static images used across the site — the shop front photo on the homepage, the about page hero image, the Post Office logo, the Amazon Hub logo, the free delivery badge, and others. Upload a new image to replace the current one, or click the × button to delete an image and revert to the default. Each slot shows a preview of the current image.
- Videos — upload short video clips (MP4, up to 50 MB) that appear on any page. Give each video a title and choose which page it belongs to. By default, uploaded videos appear at the bottom of the chosen page. If you want a video to appear in a specific place within the page text, see Placing a video in a specific spot below.
- CDN Files (admin/owner only) — upload static files (images, documents) to CDN directories. This is useful for hosting files that are linked from page content or shared externally. Select a directory, choose the file, and click Upload.
Directory
Manage the local business directory. Each business has a name, category (e.g. Plumber, Electrician, Mechanic), contact details, a short description, and a listing expiry date. Businesses pay an annual fee for their listing.
Add a new business using the form at the top. Existing listings are shown in a table — click Edit to update details or Remove to delete one. Expired listings are greyed out in the admin panel and hidden from the public directory page automatically.
The category field suggests categories that already exist, so you get consistent naming (e.g. always "Plumber" rather than sometimes "Plumbing"). You can type a new category at any time.
Jobs
Manage the community jobs and services board. The shop acts as a middleman — no personal details are published on the website. Anyone interested in a listing pops into the shop to enquire.
There are four categories: Jobs (hiring), Gigs (one-off paid work), Available (people looking for work), and Volunteers (unpaid help wanted or offered). Available and Volunteers listings are free; Jobs and Gigs have a custom fee set when the listing is created.
Add a new listing using the form at the top — fill in the title, category, description, and expiry date. For Jobs and Gigs, set the listing fee and tick Paid once payment has been received (unpaid listings are hidden from the public page). Click Send push notification to alert subscribers when a new listing goes live.
Active listings are shown in a table with their fee, payment status, and days until expiry. Click Edit to update details, Delete to remove a listing, or Renew to extend an expired listing by another 30 days.
Board (grouped tab)
This tab groups sections for board-related content, plus team management and site configuration. Click a section header to expand it.
- Documents — upload board minutes and reports as PDFs (max 10 MB). Select the year and month, choose the PDF file, and click Upload. These appear automatically on the Board page. You can also attach a report (e.g. Annual Report) to an existing month's entry.
- Meetings — configure the recurring board meeting schedule. Set the rule (e.g. "Third Thursday of each month at 7:30 PM") and the location. Meeting dates are generated automatically. You can cancel or remove individual dates — cancelled meetings show as struck through, removed meetings are hidden entirely.
- Team — manage the key people who run the shop. These appear on the About page in a card grid. For each person you can set a name, role, short bio, and upload a photo (JPG, PNG, or SVG). If no photo is uploaded, their initials are shown instead. Drag cards to reorder, then click Save order. Click Edit to update details or replace the photo, and Remove to delete someone.
- Site Config (owner only) — edit site configuration values — shop name, phone, email, address, tagline, Post Office details, and technical settings like the CDN and API URLs. A backup of the config file is created automatically every time you save.
Placing a video in a specific spot
When you upload a video (in the Media tab → Videos section), it normally appears at the bottom of its page. To place it in a specific position within the page text, add a video marker in the page editor where you want it to appear:
<!-- video:Star Wars Kid -->
Replace Star Wars Kid with the exact title you gave the video when you uploaded it (capitalisation doesn't matter). The video player will appear at that spot instead of at the bottom of the page.
You can place as many videos as you like — just add a marker for each one. Any uploaded videos that don't have a matching marker still appear at the bottom as usual.
## Welcome to the shop
Here's a classic to brighten your day:
<!-- video:Star Wars Kid -->
And here's another favourite:
<!-- video:sneezing panda -->
Each video appears exactly where you put the marker.
Embedding external videos and content
You can embed videos from YouTube, Facebook, Vimeo, and other services directly into page text. Go to the video on the external site, find the Share or Embed option, and copy the embed code (it starts with <iframe). Then paste it into the page editor where you want the video to appear:
<iframe width="560" height="315"
src="https://www.youtube.com/embed/dQw4w9WgXcQ"
title="YouTube video" frameborder="0"
allowfullscreen></iframe>
The website automatically applies some privacy and safety protections:
- YouTube embeds are switched to the "no-cookie" version so viewers aren't tracked
- Recommended videos at the end are hidden
- Autoplay is removed so videos don't start playing on their own
- Embeds are sandboxed for security
You don't need to do anything to get these protections — they happen automatically when the page loads.
Supported services include YouTube, Facebook, Instagram, LinkedIn, Vimeo, Dailymotion, TikTok, Pinterest, Spotify, SoundCloud, and Google Maps. Embed codes from other sources are ignored for security.
Drafts
Most content areas (Offers, Seasonal, News, and Pages) support drafts. When you click Save as draft, your changes are saved but not published — only you and other admins can see them. A yellow banner appears at the top of the form showing that a draft exists. From there you can Publish the draft (makes it live) or Discard it (throws it away and goes back to the live version).
The Drafts tab (next to Pages) shows all unpublished drafts at a glance. Each draft is labelled with where it came from — for example "Promotions › Offers" or "Pages › Home" — so you can quickly see what's waiting to be published.
This is useful when you want to prepare content in advance — for example, writing up next week's offers on a quiet afternoon, then publishing them on Monday morning.
Markdown is a simple way to format text. Here are the basics:
# Big heading
## Smaller heading
### Even smaller heading
**Bold text**
*Italic text*
[Link text](https://example.com)
- Bullet point
- Another bullet point
1. Numbered item
2. Another numbered item
Settings (grouped tab)
This tab groups account and administration sections. The My Account section is available to all users. Users, Visitor Analytics, and Audit Log are visible to admins and the owner. Server is owner only. Click a section header to expand it.
- My Account — manage your own login methods. You can have more than one active at the same time — for example, an authenticator app and a hardware key. We recommend setting up at least two so you always have a way in. You can add or remove methods at any time, but the system won't let you remove your last one. Options include: set up or reset an authenticator app, register a security key or YubiKey (if enabled by your admin), and remove a method you no longer use.
- Users (admin/owner only) — add and manage user accounts. Admins can manage editors; the owner can manage everyone including admins, plus promote/demote roles and lock/unlock accounts. New accounts are restricted to
@nortonshop.netemail addresses. When adding a user, you choose their role and initial login method. - Server (owner only) — server management tools for the live site. Includes Deploy now, Restart containers, Clear cache, Container status, Recent logs, and Disk usage. Code changes pushed to Codeberg deploy automatically within 60 seconds, so you usually don't need the Deploy button.
- Audit Log (admin/owner only) — a chronological record of everything that happens in the admin panel — logins, content saves, user management, server actions, and settings changes. Shows who did what, when, and from which IP address. The most recent 2,000 entries are stored. Below the audit log is the Version History — a timeline of all content changes with expandable details.
Community Metrics
Admin panel → Settings tab → expand Community Metrics. Set the current number of volunteers and members. These numbers appear on the public About page (volunteers) and Membership page (members) — for example, "23 volunteers help keep the shop running for the community." If a count is zero or empty, the metric is hidden on the public site.
Visitor Analytics
Admin panel → Settings tab → expand Visitor Analytics (admin/owner only). View website traffic data from the self-hosted visitor counter — no third-party analytics services are used. See daily visitors, returning visitors, top pages, and country breakdown. Use the range selector to switch between 7 days, 30 days, year to date, and all time.
Push Notifications
The website can send push notifications to visitors who have subscribed (via the "Enable notifications" prompt). Notifications are sent automatically when you tick Send push notification on a new Jobs listing, or when triggered by other admin actions. Subscribers receive a small alert on their phone or computer that links directly to the relevant page.
Visitors opt in from their browser — you don't need to collect email addresses or phone numbers. Notifications work even when the website isn't open, as long as the visitor's browser is running.
Volunteer sign-up form
The Membership page includes a collapsible "Volunteer with us" button that reveals an embedded Tally form. Visitors can sign up directly on the website. Form submissions go to the Tally dashboard — no admin panel action needed. The form loads only when the visitor expands the section, so it doesn't slow down the page.
Roles
There are three roles:
- Editor — can edit all content and manage their own account.
- Admin — can do everything an editor can, plus manage editors and their login methods.
- Owner — full control. Can do everything an admin can, plus: manage other admins, promote and demote roles, lock and unlock accounts, edit site settings (phone number, email, address, etc.) from the admin panel, manage the server (deploy, restart containers, clear cache, view logs), and view the audit log of all actions.
Recovery codes
When your account is created (or when you reset your authenticator), you're shown 12 recovery codes. You can download these as a .txt file. Keep them somewhere safe — they are only shown once and each one works only once.
Owner recovery phrase
When the owner account is first created, a 24-word recovery phrase is generated. This is the master key — if the owner loses access to their authenticator, security keys, and all 12 recovery codes, the recovery phrase is the last resort.
To use it: go to the login page, enter the owner username, switch to the Recovery phrase tab, and type all 24 words separated by spaces. This resets the authenticator and generates a new QR code and fresh recovery codes.
.txt file during setup.