Files
Zumri-Backend/Documentation/API_CROSS_CUTTING_SERVICES.md
T
Sathira Sri Sathara b6b345f245 feat: Implement Phase 2 cross-cutting services with email and notification enhancements
- Refactor email verification and password reset utilities to use new email service.
- Introduce email delivery queue and notification delivery model for better tracking.
- Enhance file validation and storage services for improved security and ownership management.
- Add cron job for cleaning inactive notifications with retention policy.
- Update document worker to handle document generation and storage more efficiently.
- Implement logging improvements in activity and log workers.
- Create comprehensive documentation for new API endpoints and services.
- Add unit tests for file validation and notification policies to ensure robustness.
2026-09-03 14:22:34 +05:30

32 lines
1.6 KiB
Markdown

# ZUMRI Cross-Cutting Services API
All paths also exist below `/api`; clients should use `/api/v1`. Protected routes accept the Phase 1 access cookie or bearer token. Examples use placeholders and never expose storage keys.
## Media
- `POST /api/v1/upload` — multipart field `file`, optional text field `use_for`; creates a private owner-bound upload.
- `GET /api/v1/upload/signed-url/:id` — returns `{ id, url, expiresIn }` after ownership/permission checks.
- `DELETE /api/v1/upload/:id` — marks an owned/authorized upload deleted and removes its object best-effort.
- `GET /api/v1/profile/me/avatar` and `/background` — signed self profile media access. Legacy owner-checked ID routes remain.
## Notifications
- `POST /api/v1/notification` — `notifications.manage`; body includes headline, description, `USER|ANNOUNCEMENT`, and `userIds` for USER messages.
- `GET /api/v1/notification/announcements`
- `GET /api/v1/notification/me`
- `PATCH /api/v1/notification/:notificationId/read`
- `PATCH /api/v1/notification/read-all`
## Documents
- `GET /api/v1/document/types`
- `GET /api/v1/document/saved`
- `POST /api/v1/document/draft`
- `POST /api/v1/document/generate` with `{ "document":"<registered-type>", "documentType":"pdf", "documentData":{} }`; returns HTTP 202 and persisted status.
- `GET /api/v1/document/jobs/:jobId`
- `GET /api/v1/document/:docId`
- `GET /api/v1/document/:docId/download` — returns a short-lived URL; it does not delete the artifact.
- `DELETE /api/v1/document/job/:jobId`
The legacy reference-number GET returns 410 because reads must not consume sequences. References are assigned as part of resource creation.