Administration
Everything in this chapter is administrators only.
Almost all of it lives in Settings (Ustawienia), the last entry of the panel’s navigation, which opens on an overview of every section with a search field (The panel). This chapter goes through its three groups in the order the list on its left shows them, then through what sits outside it: correcting phrases, monitoring and the activity log.
Every section has an address of its own — /admin/settings/branding, /admin/settings/mail and so on — and a section that is one form over the site’s settings keeps Zapisz at its foot, in view however long the form is.
Site (Witryna)
Section titled “Site (Witryna)”Branding (Identyfikacja)
Section titled “Branding (Identyfikacja)”One form over the one thing every page reads.
| Field | Means |
|---|---|
| Nazwa serwisu | Shown in the header and on the browser tab. Empty means the application’s own name. Not translated: a name is a name |
| Slogan | The description of pages that have none of their own. One field per language, each naming its own (“Slogan · English”) |
| Tekst w stopce | Empty means a copyright line with the current year. One field per language as well |
| Przełącznik języka | What the language switch shows for each language: Własna nazwa języka (the default), Kod języka, Flaga, Flaga i nazwa or Flaga i kod. Offered only once the site speaks more than one language (Languages) |
| Logo | PNG, WebP, JPEG or SVG, up to 2 MB; an SVG is cleaned of anything that could run before it is stored. Replaces the site name in the header. The logo and the favicon stay outside the media library |
| Favicon | PNG, square, at least 32 by 32 pixels |
Saving takes effect straight away, everywhere.
Styles (Style)
Section titled “Styles (Style)”How the site looks — colours, fonts, text sizes, corners, spacing, shadows, motion and a few choices of layout — as styles you make, preview on the real site and activate for everybody. HiLMS WCAG, the theme’s own look, is the active style of a new site. The e-mails the site sends take the active style’s colours too. It has a chapter of its own — Styles — which also covers Fonts (Fonty), the page beside it where the site keeps fonts of its own.
Site pages (Strony serwisu)
Section titled “Site pages (Strony serwisu)”Three links HiLMS draws itself, and which page each of them is:
| Field | Means |
|---|---|
| Strona główna | The page read at the root of the site |
| Lista kursów | Where “all courses” links, and where a category takes a visitor |
| Uczestnicy lądują na | Where somebody without a panel goes after signing in |
Each offers every published page and Nie wybrano. Leaving one empty is a real answer: the link is then simply not drawn, and nothing breaks. See Pages.
Languages (Języki)
Section titled “Languages (Języki)”Which languages the site speaks, which one is the default, and the order of the language switch. It has a chapter of its own — Languages.
Region and time (Region i czas)
Section titled “Region and time (Region i czas)”One setting: Strefa czasowa, the clock this installation keeps. The list is every time zone there is, each with the offset it is on today, so Europe/Warsaw (UTC+02:00) is easy to find.
It is the clock the panel shows its times in and reads typed ones back from. Set it to Warsaw and an editor who types 17:14 as a publication date has the course go live at 17:14 in Warsaw, and reads 17:14 back. It is also the clock a visitor who has set none of their own sees every date on — and a person who has set one of their own (Moje konto → Profil → Strefa czasowa) sees their own instead.
Nothing that is already stored moves when you change it. HiLMS keeps every date and time as an instant, in UTC, and this setting only decides how that instant is written out and read in. So changing the zone in March moves no course, no expiry and no record, and the hour that repeats every autumn is never ambiguous.
hilms:install asks for the zone once when the site is first set up; a site installed without being asked — a container, for instance — starts on UTC and this section is where it is set. The section sits beside Języki in the Site group, because which clock an installation keeps is the same kind of answer as which languages it speaks.
The one thing that does not follow it is the AI assistants’ preferred window, which a background worker applies with nobody present: those two fields are UTC and say so (see AI assistants).
People (Ludzie)
Section titled “People (Ludzie)”Sign-up (Rejestracja)
Section titled “Sign-up (Rejestracja)”Whether visitors may create an account of their own. One switch: Otwarta rejestracja.
Turn it off and the sign-up links disappear from the header, the home page and the login page, /register redirects with a notice, and signing in with Google or Facebook no longer creates a new account — existing ones still work. The panel, the API and the console are unaffected, so you can still create accounts yourself.
Profile fields (Pola profilu)
Section titled “Profile fields (Pola profilu)”What each role is asked for, beyond a name, an email and a photo. A reorderable list, each row:
| Field | Means |
|---|---|
| Klucz | Lowercase letters, digits and underscores. It names the stored value and does not change later |
| Typ | Jedna linia tekstu, Adres WWW, or Kilka linii tekstu |
| Etykieta | What the person sees. One input per language the site speaks, each naming its own; only the default language’s is required |
| Widoczne dla | The roles this field belongs to |
Out of the box an instructor is asked for a job title, a short biography, a website, LinkedIn, X and YouTube. Those values become the instructor cards on a course page: a web address is shown as a link, anything else as a label and its value.
Two rows may not share a key. Taking a role away from a field hides it; it never erases what people had written in it.
Roles and permissions (Role i uprawnienia)
Section titled “Roles and permissions (Role i uprawnienia)”What each role may do in the panel, entity by entity — see Users and roles and Roles.
Integrations (Integracje)
Section titled “Integrations (Integracje)”Media and storage (Media i przechowywanie)
Section titled “Media and storage (Media i przechowywanie)”Where uploaded files are kept, and two ways of protecting video. Everything the media library holds lives wherever this section says. Searching the settings for bucket, S3, R2, Bunny Stream or znak wodny finds it.
Dokąd trafiają nowe pliki says where new uploads go, in one of three ways:
- This server — files stay on this server’s disk: course material in a private directory, everything else in the public one. Nothing else to set up, and both are in the nightly backup. Press Skonfiguruj kubełek to keep files in a storage bucket instead.
- A bucket — course material goes to a private bucket with a storage provider and is still handed out only through HiLMS’s own link, which checks access first. Public files — course covers, avatars, the logo, page pictures, stored fonts — follow only when the bucket has a public bucket of its own; otherwise they stay on this server. The section names the provider and both buckets, and when the bucket was last checked (“Sprawdzono przed chwilą: wszystko działa”, or what failed). Sprawdź ponownie checks it again, Zmień… opens the guide below on the saved settings, and Przestań używać kubełka sends new uploads back to this server.
- This server, with a bucket kept — after you stop using a bucket its settings stay, so files can go back to it, and the section says how many files are still in it. Używaj kubełka ponownie checks the bucket and sends new uploads there again. Zapomnij kubełek removes the provider, the bucket names and the keys from the site — nothing in the bucket itself is deleted — and is offered only once none of the site’s files are in it.
Skonfiguruj kubełek (and Zmień…) opens a guide of six short steps. Nothing is saved until the last one, and only after the bucket has been checked.
- Dostawca — who keeps the files: Cloudflare R2 (polecany), Amazon S3, Backblaze B2, Hetzner Object Storage, DigitalOcean Spaces, or Inny zgodny z S3 for anything else. If you have no account anywhere yet, Cloudflare R2 is the easiest start.
- Połączenie — only what the chosen provider needs to find your account (for R2 the Account ID and the jurisdiction, for the others a region or a location), then the key and its secret, called the way the provider calls them, each with a line on where to find it. The secret is stored encrypted and never shown again; when changing a bucket, leaving it empty keeps it.
- Materiały kursowe — the name of the private bucket course material goes to, with the provider’s steps for creating one.
- Pliki publiczne — optional. Switch on Trzymaj w kubełku także pliki publiczne to keep public files in a second bucket, and give its public address. For most providers the address fills itself in; for Cloudflare R2 copy it from the bucket’s settings — the
r2.devaddress is for trying things out, and a live site connects its own domain. Never the course-material bucket: some providers open a whole bucket to anyone once it has a public address, so the guide refuses the same name twice. - Zezwól witrynie — the one setting you make in the provider’s own console: a rule (called CORS) that lets this site play videos and load files from the bucket. The guide shows the rule with this site’s address already in it, a Kopiuj button, and where to paste it for your provider. Without it, videos kept in the bucket do not play.
- Sprawdź i zapisz — the site writes a tiny test file to each bucket, reads it back, opens it the way a student’s player would, makes sure nobody can read course material without HiLMS’s link, and deletes the file. Each check is listed: Udało się, Nie udało się — trzeba naprawić, or Nie udało się — można mimo to zapisać, with the reason and what to do in the provider’s console. A failure that must be fixed keeps the save button off until Sprawdź ponownie passes; one that may be saved anyway asks you to tick “Zapisz mimo to — rozumiem, że …”, which says what will not work.
Gdzie są twoje pliki shows how many files, and how much, lie on this server and in the bucket. Files keep working where they are, so moving them is optional: after a switch, new uploads go to the new place and older files are still served from where they were. When files wait to move, one button says exactly what it will do — Przenieś 16 plików (8,6 MB) do Cloudflare R2, or … z powrotem na ten serwer. After you confirm, each file is copied, checked to have arrived whole and only then removed from where it was, one at a time in the background, so students keep watching and downloading meanwhile. The section shows how far it got (“Przenoszę… gotowe 7 z 16 plików, nieudane: 0.”); you may close the page, and it picks the move up again when you come back. A file that could not be moved stays where it was and is listed with the reason, and the button offers to try the remaining ones again. If moves wait because the queue worker is not running, the section says so.
While files are in a bucket, its provider, account, location and name cannot be changed — the site would lose them — and the guide shows these fields locked with the number of files. The keys and the public address can still be changed. To switch provider: stop using the bucket, move the files back to this server, then set up the new one.
Wideo z zewnętrznego serwisu — Klucz tokenu Bunny Stream, the Token Authentication key of your Bunny Stream library. With it every Bunny video on the site carries a token that expires within the hour, so a saved page cannot replay the video. Stored and kept like the secret above.
Ochrona — Znak wodny na przesłanych filmach. Turn it on and every video uploaded to the library shows the signed-in viewer’s e-mail address drifting across the picture, in full screen too, so a screen recording names whoever made it (Browsing and learning). Off by default. It does not stop a recording, and a determined viewer can hide it; YouTube, Vimeo and Bunny videos are their host’s to protect.
The health page checks the bucket every few minutes while it is in use or still holds files. Files kept in a bucket are not in the nightly backup: the provider keeps them. What each provider needs, and how to check the result end to end, is in the operator’s guide (docs/install/storage.md).
Mail (Poczta)
Section titled “Mail (Poczta)”How mail leaves this installation. Password resets, verification links, enrolment messages — all of it goes through whatever you choose here.
Nadawca: the sender address and name.
Przekieruj każdą wiadomość na: a safety pin for a test installation. While it is filled, every message goes to that one address instead of the person it names — which is exactly what makes a copy of a live site safe to work on, and exactly what silently cuts every student off if you leave it set. The section shows a red warning for as long as it is filled.
Jak poczta opuszcza tę instalację: Serwer SMTP, Brevo (API), Resend (API), Postmark (API), Mailgun (API) or Amazon SES. Choosing one reveals only the fields it needs — host, port, encryption, user and password for SMTP; an API key for the three API providers; a key, a sending domain and an endpoint for Mailgun; the three AWS values for SES.
Secrets are stored encrypted and never shown again: blank keeps what is stored, typing replaces it, and Usuń zapisany sekret removes it.
If the server was configured with something the panel does not offer, the section says so and leaves it alone; choosing one of the six replaces it.
Wyślij wiadomość testową (in the header) sends one message and tells you where it really went — including when the redirect took it somewhere other than the address you typed. If it never arrives after that, the provider dropped it after HiLMS handed it over.
AI assistants (Asystenci AI)
Section titled “AI assistants (Asystenci AI)”The provider, the model, the key, the monthly budget and when the assistants may run — see AI assistants.
API clients (Klienci API)
Section titled “API clients (Klienci API)”Machines that talk to HiLMS: a shop that grants access after a payment, and AI agents that author course material.
The list shows the name, the copyable client id, the scopes, whether it has been revoked, the creation date and the kind — Maszyna (działa jako ona sama) or Agent (działa jako osoba).
Dodaj klienta asks for a name and the permissions (Uprawnienia) it may hold:
- Odczyt kursów — read the course list, so a shop can match its products to courses.
- Odczyt uprawnień — read the grants it made itself.
- Przyznawanie i cofanie uprawnień — grant and revoke course access.
A client never receives a token wider than the permissions you gave it, and it only ever sees the grants it made itself — never another shop’s, never the ones you made in the panel.
After creating one, Pokaż dane dostępowe shows the client id and the secret. The secret is shown once; copy it into the shop straight away. Nowy sekret issues a new one and kills the old one immediately. Cofnij dostęp stops the client and all its tokens. Nothing here is ever deleted.
Agents
Section titled “Agents”An AI agent that authors courses connects differently. It registers itself, then sends whoever set it up to an approval page in the browser:
- Only somebody who can enter the panel may approve an agent. A student is refused.
- The page names the agent, what it is asking for, and the address your access will be sent to. Read that address. Approve only a connection you started yourself, in software you trust.
- Approving hands the agent everything your own account can do, under your name in the audit trail.
Once approved, the agent appears in this list marked as an agent. It has no secret, so there is nothing to regenerate; Cofnij dostęp disconnects it. Deleting the account that approved it disconnects it too.
What an agent can and cannot do: it can read courses and lessons, create courses, sections and lessons, and write their text and quizzes. It cannot publish anything — a course it creates is a draft until a person publishes it — and it cannot add pictures, video, audio or files, or touch students, access, users or settings.
Phrases (Zwroty)
Section titled “Phrases (Zwroty)”Correcting any sentence the application says, in any language, is not configuration but everyday work, so Zwroty has an entry of its own in the main navigation rather than a section in Settings. See Languages.
Monitoring
Section titled “Monitoring”| Page | Shows |
|---|---|
| Kondycja | Every health check with its result: the database, Redis, the cache, the queues, the schedule, disk space, backups, the PHP extensions and binaries the server needs, whether mail can leave at all, whether the storage bucket answers (when one is used), whether the active theme resolves and still draws a proper page, and whether every page and lesson could still be saved by the editor who opens it |
| Kopie zapasowe | The backup archives, with buttons to make one now, download one or delete one |
| Horizon (kolejki) | The queue dashboard: jobs running, waiting and failed. Opens in a new tab |
| Pulse (wydajność) | Slow requests, slow queries and busy jobs. Opens in a new tab |
| Telescope (debugowanie) | Only on a developer’s machine |
A warning on the health page is worth reading; a failure is worth acting on. If the server is set up to send operational mail, failures are emailed as well. The page also turns to a failure when its own checks stop running — fifteen minutes without one means the server’s schedule has stopped — rather than showing the last good result for ever.
When Redis is away. Redis is the server’s fast memory for the cache and the queue. If it stops or fills up, the site keeps working: pages open at their usual speed, nobody is signed out, sign-in and its limits work, and mail such as a password reset still goes, a moment later than usual. The health page shows Redis, the queues and Horizon failing. Two things wait for it to come back, each with a message saying so: an assistant request, because it is a paid call that may run for minutes, and moving files between this server and a bucket. When Redis returns everything settles by itself within a minute; nothing needs restarting.
One of the checks is a warning and never a failure: blocks that need attention. A block can end up missing something required — a picture that was never chosen, a block that gained a new field in a newer version of HiLMS — and the site serves such a page perfectly well, so only the editor who opens it would ever find out. The check counts them and names the first one; open that page in the panel and the block is marked on the canvas (Lessons and blocks). Somebody with server access can list every one of them at once.
Backups run nightly: the database plus the files uploaded to this server and the API signing keys. Files kept in a storage bucket are not in the backup; the provider keeps them. Older copies are thinned out over time and none is kept beyond a few months, so somebody who asked to be deleted does not live on in an archive nobody looks at.
Activity log (Dziennik zdarzeń)
Section titled “Activity log (Dziennik zdarzeń)”Who changed what, and when.
Columns: Kiedy, Zdarzenie (Utworzono, Zmieniono, Usunięto, Przywrócono, Nadano rolę, Odebrano rolę), Obiekt with its type, and Kto. Adding or changing a language, correcting a phrase, editing a menu, and changing or activating a style are recorded here like everything else — though dragging menu entries into a different order is not, because a single drag would otherwise fill the log with one row per entry. Filter by the kind of object, by the event, or by a date range. Szczegóły opens what changed, before and after.
The causer is the person who did it, the API client behind a machine, or System for something run on the server. Provisioning — installing, upgrading, seeding — is not recorded: it is not a change anybody made.
One thing to know: while somebody is being impersonated, their name is what the trail records. It cannot tell that apart from something they did themselves.
Entries are kept a year and then removed.
Things that are deliberately not in the panel
Section titled “Things that are deliberately not in the panel”- Themes. How the site looks is a theme on the server, not an upload. Your developer or whoever hosts the site changes it.
- Page layouts. A page’s Szablon offers what the theme provides, which out of the box is one. Adding another is a developer’s job.
- Selling. HiLMS takes no money. A paid course points at the shop that sells it, and the shop grants access through the API.
- The design catalogue. On a development installation,
/designdraws every page of the site with sample content, in light and dark, plus the colour palette and every block. It is off on a live site.
HiLMS is MIT-licensed. No replicants were harmed in the writing of these books.