Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Introduction

Tablo is an admin toolkit for Rust. You declare, once per database model, its table, its form and who may see and change it; Tablo serves the list, create, edit, detail and delete pages for it, rendered on the server.

Tablo is a layer over two upstream projects:

  • Topcoat renders the HTML and owns routing, the request context Cx, reactivity, assets, cookies and sessions. The panel’s pages are Topcoat views, and your own pages use the same view!, #[component] and #[layout].
  • Toasty is the ORM. Tablo queries your Toasty models directly, so the model is the single source of truth for columns, relations and nullability.

What you get

  • Server-rendered pages, no SPA. There is no client build step and no WASM bundle. Search, sort, filters and pagination work without JavaScript; the scripts add in-place updates.
  • Typed declarations. Columns, form fields and filters are built from Toasty field lenses such as User::fields().email(), so a renamed or retyped column is a compile error.
  • Checks at startup. Mounting the panel validates every declaration — a form struct that disagrees with its schema, two resources on one URL, a tenant-owned resource with no tenant column — and returns an error naming the mistake before the server takes a request.
  • Safe defaults. Every policy predicate denies until you allow it, authentication is on, every panel POST verifies a CSRF token, and a tenant-owned resource is scoped to the request’s tenant at every query.

What it is not

  • Not a client framework. Anything that reads the database renders on the server.
  • Not tested across databases. The test suites and benchmarks run on Toasty’s SQLite driver.

How to read this guide

Your first panel builds a complete, runnable admin in one file. Each later chapter covers one part of it:

ChapterCovers
Panel and routingthe panel builder, the routes it serves, custom and public pages
Resourcesthe Resource trait: naming, query scoping, writes
Tablescolumns, search, sort, filters, export, live updates, deletes
Formsthe record form, controls, validation, uploads, embedded values
Detail pagesthe read-only record page and related tables
Policy, auth, tenancywho may see and change what
Data accessquerying Toasty from your own pages
Securitythe defaults and what your deployment must provide
Testing and benchmarkstesting a panel over HTTP

The runnable reference is examples/showcase: every feature in this guide is exercised there. Terms are defined in CONTEXT.md and design decisions are recorded in docs/adr/. If this guide disagrees with the code, the code is right: please open an issue.