Files
Zumri-Backend/Documentation/API_CROSS_CUTTING_SERVICES.md
T
Sathira Sri Sathara b6b345f245 feat: Implement Phase 2 cross-cutting services with email and notification enhancements
- Refactor email verification and password reset utilities to use new email service.
- Introduce email delivery queue and notification delivery model for better tracking.
- Enhance file validation and storage services for improved security and ownership management.
- Add cron job for cleaning inactive notifications with retention policy.
- Update document worker to handle document generation and storage more efficiently.
- Implement logging improvements in activity and log workers.
- Create comprehensive documentation for new API endpoints and services.
- Add unit tests for file validation and notification policies to ensure robustness.
2026-09-03 14:22:34 +05:30

1.6 KiB

ZUMRI Cross-Cutting Services API

All paths also exist below /api; clients should use /api/v1. Protected routes accept the Phase 1 access cookie or bearer token. Examples use placeholders and never expose storage keys.

Media

  • POST /api/v1/upload — multipart field file, optional text field use_for; creates a private owner-bound upload.
  • GET /api/v1/upload/signed-url/:id — returns { id, url, expiresIn } after ownership/permission checks.
  • DELETE /api/v1/upload/:id — marks an owned/authorized upload deleted and removes its object best-effort.
  • GET /api/v1/profile/me/avatar and /background — signed self profile media access. Legacy owner-checked ID routes remain.

Notifications

  • POST /api/v1/notification — notifications.manage; body includes headline, description, USER|ANNOUNCEMENT, and userIds for USER messages.
  • GET /api/v1/notification/announcements
  • GET /api/v1/notification/me
  • PATCH /api/v1/notification/:notificationId/read
  • PATCH /api/v1/notification/read-all

Documents

  • GET /api/v1/document/types
  • GET /api/v1/document/saved
  • POST /api/v1/document/draft
  • POST /api/v1/document/generate with { "document":"<registered-type>", "documentType":"pdf", "documentData":{} }; returns HTTP 202 and persisted status.
  • GET /api/v1/document/jobs/:jobId
  • GET /api/v1/document/:docId
  • GET /api/v1/document/:docId/download — returns a short-lived URL; it does not delete the artifact.
  • DELETE /api/v1/document/job/:jobId

The legacy reference-number GET returns 410 because reads must not consume sequences. References are assigned as part of resource creation.