wako / plugin-admin-toolbar
Admin Toolbar for Shopware Storefront
Package info
github.com/WariKoda/WakoPluginAdminToolbar
Type:shopware-platform-plugin
pkg:composer/wako/plugin-admin-toolbar
Requires
- shopware/administration: ~6.7.0
- shopware/core: ~6.7.0
- shopware/storefront: ~6.7.0
Requires (Dev)
- phpstan/phpstan: ^2.1
- phpunit/phpunit: ^11.5
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
A Shopware 6 plugin that connects the storefront and Administration in both directions. Eligible administration users can edit the current storefront entity without first searching for it, and the Administration logo can open the storefront in a new tab.
Requirements
- Shopware 6.7
- Shopware Storefront and Administration
Version 2.0.0 and newer no longer support Shopware 6.6.
Installation
Run this command from the Shopware root:
composer req wako/plugin-admin-toolbar
Alternatively, extract the release archive into custom/plugins. Then install and activate the plugin:
bin/console plugin:install --activate WakoPluginAdminToolbar
Screenshots
Screenshot 1
Context buttons for products, variants, and shopping experiences
Customer context
What it does
The toolbar provides:
- quick links into Shopware Administration
- context-aware edit links for product/category/CMS/landing page related storefront pages
- variant lookup for variant products
- customer context info for the current sales channel session
- active rule visibility
- copy-to-clipboard helpers
- cache clear action
- optional Storefront shortcut on the Administration sidebar logo
- optional cache clear and theme compile buttons in the Administration page header
- global feature switches for product links, category links, and CMS/layout links
- per-user feature preferences for product links, category links, CMS/layout links, and customer context
Security and permissions
The plugin uses Shopware Administration roles and privileges. Hiding a control in the storefront does not authorize the underlying action.
Required rules
- The server enforces every privileged action
- UI visibility is a convenience, not authorization
- The user custom field
wako_admin_toolbar_enabledonly opts the user in - Per-user preferences and global plugin switches restrict features but do not authorize them
- Toolbar access also requires Shopware ACL privileges
- New privileged features must integrate with ACL end-to-end
Base access requirement
The toolbar is available only when all of these conditions are met:
- a valid Shopware admin session exists
- the user enabled the toolbar via
wako_admin_toolbar_enabled - the user has the plugin privilege
wako_admin_toolbar:use
The plugin registers the role permission wako_admin_toolbar.viewer, which grants wako_admin_toolbar:use.
The public storefront HTML contains only an empty toolbar bootstrap element. The auth endpoint returns and JavaScript mounts the full Twig-rendered toolbar only after these checks succeed. Disabled users and anonymous crawlers therefore receive no toolbar text, SVG sprite, or Administration links in the page source.
Feature-to-privilege mapping
| Feature | Required privilege(s) | Additional gates |
|---|---|---|
| Use toolbar at all | wako_admin_toolbar:use |
Per-user toolbar opt-in |
| Clear cache from the storefront toolbar | system:clear:cache |
None |
| Clear cache from the Administration page header | system:clear:cache |
Button enabled globally; system_config:read to read that setting |
| Compile theme from the Administration page header | theme:update, theme:read, sales_channel:read |
Button enabled globally; system_config:read to read that setting; the sales channel needs an assigned theme |
| Load variants | product:read |
Product links enabled globally and for the user |
| Edit product | product:update |
Product links enabled globally and for the user |
| Edit category | category:update |
Category links enabled globally and for the user |
| Edit CMS page / layout / shopping experience / page | cms_page:update |
CMS/layout links enabled globally and for the user |
| Edit landing page | cms_page:update + landing_page:update |
CMS/layout links enabled globally and for the user |
| View customer context | customer:read |
Customer context enabled for the user and at least one customer context data field enabled globally |
| View active rules / rule links | rule:read |
Customer context enabled for the user and active rules enabled globally |
| Open storefront from the Administration logo | system_config:read, sales_channel:read |
Logo link enabled globally and a storefront domain available |
Adding privileged features
For every new action, endpoint, or toolbar button:
- Define the required Shopware core or plugin privilege.
- Enforce it in the PHP backend.
- Expose only the capability flags required by the storefront or Administration UI.
- Hide or disable the corresponding UI.
- Register Administration labels and snippets for plugin-specific privileges.
User settings
The current user can configure the toolbar under Administration > Settings > Plugins > Admin Toolbar.
The module allows users to:
- enable or disable the storefront toolbar for their account
- configure personal visibility preferences for product links, category links, CMS/layout links, and customer context
- show disabled feature toggles when the user lacks the required ACL permission or a feature is disabled globally
Opening the module requires user.update_profile.
Changing toolbar activation or feature preferences requires:
user_change_mewako_admin_toolbar:use- the corresponding feature ACL permission when enabling a feature
Toolbar activation is no longer part of the Shopware profile page. The plugin stores preferences on the current user and enforces them on the server when it builds the available toolbar capabilities.
Plugin configuration
The plugin configuration contains:
logoStorefrontLinkEnabledto make the Administration sidebar logo open the storefrontlogoStorefrontSalesChannelIdto select the target sales channeladminCacheClearButtonEnabledto show the cache clear button in the Administration page headeradminThemeCompileButtonEnabledto show the theme compile button in the Administration page headeradminBasePathfor the Administration base path- global toolbar feature switches for product links, category links, and CMS/layout links
- customer context data controls for email, customer number, and active rules
When no target sales channel is selected, the logo link uses the first active storefront sales channel with a configured domain. Shopware's domainLinkService chooses the domain that best matches the current Administration language. If the current user cannot read the plugin configuration or sales channels, or no storefront domain exists, the logo remains unchanged and does not become a link.
The Administration reads the page header button switches once per session. Reload the Administration after changing them.
The theme compile button opens a dialog to select a storefront sales channel and compiles the theme already assigned to it. Depending on the shop configuration, Shopware compiles in the background and reports the result through its notifications.
The customer context dropdown only renders sections whose data fields are enabled in the plugin configuration.
Relevant files
src/WakoPluginAdminToolbar.phpsrc/Controller/AdminToolbarAuthController.phpsrc/Controller/AdminToolbarProfileController.phpsrc/Controller/AdminToolbarThemeController.phpsrc/Service/Toolbar/ToolbarThemeCompileService.phpsrc/Resources/views/storefront/component/admin-toolbar-bootstrap.html.twigsrc/Resources/views/storefront/component/admin-toolbar.html.twigsrc/Resources/app/storefront/src/js/admin-toolbar/admin-toolbar.plugin.jssrc/Resources/app/administration/src/acl/index.jssrc/Resources/app/administration/src/extension/sw-admin-menu/src/Resources/app/administration/src/extension/sw-page/src/Resources/app/administration/src/component/wako-admin-toolbar-theme-compile/src/Resources/app/administration/src/service/admin-toolbar-config.jssrc/Resources/app/administration/src/module/wako-admin-toolbar-settings/src/Resources/app/administration/src/snippet/en-GB.jsonsrc/Resources/app/administration/src/snippet/de-DE.json


