This repository has been archived on 2026-08-11. You can view files and clone it, but cannot push or open issues or pull requests.
Gishen-B2B/docs/backend/endpoints/README.md
kirukib 3778801ef5 Ship Gishen B2B institutional portal with polished layout and mock-backed flows.
Deliver role-aware shell (sidebar, breadcrumbs, quick search, tables, detail/create layouts), locale-ready pages, shared backend/feature docs, and Vercel project config so HR, finance, and members can demo against typed mocks.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 21:18:23 +03:00

68 lines
1.7 KiB
Markdown

# Endpoints index
REST-style API contract for Gishen-B2B. All paths prefixed with `/v1` unless noted.
**Workspace:** `/Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B`
## Domain groups
| Group | Doc | Description |
|-------|-----|-------------|
| Auth | [auth.md](auth.md) | Login, session, locale |
| Organisation | [org.md](org.md) | Org profile, registration, departments, verification |
| Members | [members.md](members.md) | CRUD, import, invites, join |
| Packages | [packages.md](packages.md) | Benefit plans |
| Migration | [migration.md](migration.md) | Bulk import jobs |
| Finance | [finance.md](finance.md) | Spend, statements, approvals |
| Prescriptions | [prescriptions.md](prescriptions.md) | Member Rx upload/status |
## Conventions
### Auth header
```
Authorization: Bearer <token>
```
Mock phase: session cookie `gishen_b2b_session`.
### Org scope
Implicit from session `org_id`. Public routes (registration) omit org scope.
### Response envelope
Single resource:
```json
{ "data": { ... } }
```
List (see [OVERVIEW.md](../OVERVIEW.md#pagination)):
```json
{ "data": [ ... ], "pagination": { ... } }
```
### Clinical withhold
Endpoints returning prescription or order clinical detail check session roles. HR_ADMIN / FINANCE without SUPER_USER receive redacted payloads or `403 CLINICAL_WITHHELD`.
## Public vs authenticated
| Path pattern | Auth |
|--------------|------|
| `/v1/auth/login` | Public |
| `/v1/org/register*` | Public |
| `/v1/invite/:token` (GET) | Public |
| `/v1/join` (POST) | Public or member session |
| All other `/v1/*` | Required |
## Error reference
See [OVERVIEW.md](../OVERVIEW.md#error-model).
## Mock implementation
Frontend mocks in `src/mocks/` and adapters in `src/lib/api/` must match these contracts exactly.