Deliver role-aware shell (sidebar, breadcrumbs, quick search, tables, detail/create layouts), locale-ready pages, shared backend/feature docs, and Vercel project config so HR, finance, and members can demo against typed mocks. Co-authored-by: Cursor <cursoragent@cursor.com>
3.7 KiB
Endpoints: Prescriptions
Member prescription upload, status tracking, and refill reminders.
Workspace: /Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B
Entity: ../entities/prescription.md
GET /v1/prescriptions
List prescriptions for current member.
| Auth | Required |
| Roles | MEMBER (own), SUPER_USER (any member via ?member_id=) |
Query
?page=1&status=submitted
Response 200
Full Prescription for MEMBER/SUPER_USER.
Clinical withhold
HR_ADMIN / FINANCE: 403 FORBIDDEN
POST /v1/prescriptions
Create draft prescription.
| Auth | Required |
| Roles | MEMBER, SUPER_USER |
Request
{
"notes": "Renewal for chronic medication"
}
Response 201
{
"data": {
"id": "rx_01HNEW",
"status": "draft",
"pages": []
}
}
GET /v1/prescriptions/:id
Prescription detail.
| Auth | Required |
| Roles | MEMBER (own), SUPER_USER |
Clinical withhold
HR/Finance: 403 or redacted stub (id, status, dates only) if explicitly granted read metadata — default deny.
POST /v1/prescriptions/:id/pages
Upload page (multipart).
| Auth | Required |
| Roles | MEMBER (own), SUPER_USER |
Request
multipart/form-data: file (jpeg/png/pdf), page_number
Response 201
Updated prescription with new page.
Validation
| Rule | Code |
|---|---|
| Max 10 pages | VALIDATION_FAILED |
| Max 10 MB | VALIDATION_FAILED |
| Allowed mime types | VALIDATION_FAILED |
DELETE /v1/prescriptions/:id/pages/:pageId
Remove page from draft.
| Auth | Required |
| Roles | MEMBER (own draft), SUPER_USER |
POST /v1/prescriptions/:id/submit
Submit for pharmacist review.
| Auth | Required |
| Roles | MEMBER (own), SUPER_USER |
Response 200
status: "submitted"
Errors
| Code | HTTP | When |
|---|---|---|
VALIDATION_FAILED |
400 | No pages |
MEMBER_INACTIVE |
422 |
Event
prescription.submitted
POST /v1/prescriptions/:id/respond
Member response to query (upload additional pages / message).
| Auth | Required |
| Roles | MEMBER (own) |
Request
{
"message": "Added clearer photo of page 2"
}
Sets status → under_review.
GET /v1/prescriptions/refill-reminders
Upcoming refills for member.
| Auth | Required |
| Roles | MEMBER |
Response 200
{
"data": [
{
"prescription_id": "rx_01H001",
"refill_due_at": "2026-03-25",
"days_remaining": 5,
"status": "approved"
}
]
}
No medicine names in reminder list (optional generic label only).
GET /v1/members/:id/prescriptions (SUPER_USER only)
Support view of member prescriptions.
| Auth | Required |
| Roles | SUPER_USER |
Full clinical payload.
Clinical withhold
Explicitly SUPER_USER only. HR/Finance: 403.
UI routes
| Route | Endpoint(s) |
|---|---|
/prescriptions |
GET /v1/prescriptions |
/prescriptions/new |
POST + page upload + submit |
/prescriptions/[id] |
GET detail + respond / mock pharmacist actions (SUPER_USER) |
/me |
Refill reminders widget |
/me/orders/[id] |
Order detail (Ecom pointer; mock) |
Admin integration
Pharmacist review queue is in Gishen-Admin. B2B consumes prescription.review_updated events to refresh status.
Platform notes
- Web: multi-page file upload
- Mobile: edge-detection camera (Gishen-Mob)
- No handwritten OCR