b6b345f245
- Refactor email verification and password reset utilities to use new email service. - Introduce email delivery queue and notification delivery model for better tracking. - Enhance file validation and storage services for improved security and ownership management. - Add cron job for cleaning inactive notifications with retention policy. - Update document worker to handle document generation and storage more efficiently. - Implement logging improvements in activity and log workers. - Create comprehensive documentation for new API endpoints and services. - Add unit tests for file validation and notification policies to ensure robustness.
1.6 KiB
1.6 KiB
ZUMRI Cross-Cutting Services API
All paths also exist below /api; clients should use /api/v1. Protected routes accept the Phase 1 access cookie or bearer token. Examples use placeholders and never expose storage keys.
Media
POST /api/v1/upload— multipart fieldfile, optional text fielduse_for; creates a private owner-bound upload.GET /api/v1/upload/signed-url/:id— returns{ id, url, expiresIn }after ownership/permission checks.DELETE /api/v1/upload/:id— marks an owned/authorized upload deleted and removes its object best-effort.GET /api/v1/profile/me/avatarand/background— signed self profile media access. Legacy owner-checked ID routes remain.
Notifications
POST /api/v1/notification—notifications.manage; body includes headline, description,USER|ANNOUNCEMENT, anduserIdsfor USER messages.GET /api/v1/notification/announcementsGET /api/v1/notification/mePATCH /api/v1/notification/:notificationId/readPATCH /api/v1/notification/read-all
Documents
GET /api/v1/document/typesGET /api/v1/document/savedPOST /api/v1/document/draftPOST /api/v1/document/generatewith{ "document":"<registered-type>", "documentType":"pdf", "documentData":{} }; returns HTTP 202 and persisted status.GET /api/v1/document/jobs/:jobIdGET /api/v1/document/:docIdGET /api/v1/document/:docId/download— returns a short-lived URL; it does not delete the artifact.DELETE /api/v1/document/job/:jobId
The legacy reference-number GET returns 410 because reads must not consume sequences. References are assigned as part of resource creation.