Surface Google, email, phone, and Telegram on login (mocked), polish the brand panel and fixes for Button/Menu, and keep the backend spec sheet aligned. Co-authored-by: Cursor <cursoragent@cursor.com>
1.9 KiB
1.9 KiB
Endpoints index
REST-style API contract for Gishen-B2B. All paths prefixed with /v1 unless noted.
Workspace: /Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B
Domain groups
| Group | Doc | Description |
|---|---|---|
| Auth | auth.md | Demo login + planned Google/email/phone/Telegram, session, locale, /me/profile |
| Organisation | org.md | Org profile, registration, departments, verification |
| Members | members.md | CRUD, import, invites, join, pharmacy ID card |
| Packages | packages.md | Benefit plans |
| Migration | migration.md | Bulk import jobs |
| Finance | finance.md | Spend, statements, approvals |
| Prescriptions | prescriptions.md | Member Rx upload/status |
Conventions
Auth header
Authorization: Bearer <token>
Mock phase: session cookie gishen_b2b_session.
Org scope
Implicit from session org_id. Public routes (registration) omit org scope.
Response envelope
Single resource:
{ "data": { ... } }
List (see OVERVIEW.md):
{ "data": [ ... ], "pagination": { ... } }
Clinical withhold
Endpoints returning prescription or order clinical detail check session roles. HR_ADMIN / FINANCE without SUPER_USER receive redacted payloads or 403 CLINICAL_WITHHELD.
Public vs authenticated
| Path pattern | Auth |
|---|---|
/v1/auth/login |
Public |
/v1/auth/demo-profiles |
Public |
/v1/org/register* |
Public |
/v1/invite/:token (GET) |
Public |
/v1/join (POST) |
Public or member session |
All other /v1/* |
Required |
Error reference
See OVERVIEW.md.
Mock implementation
Frontend mocks in src/mocks/ and adapters in src/lib/api/ must match these contracts exactly.