Skip to content

API consolidation (M6 + M11) ​

Unified Admin app calls one backend. Shared handlers use tenantIdFromJwt(); staff-only business rules (e.g. assigned orders) live in services, not duplicate URLs.

Canonical task-list API (Admin + Staff JWT) ​

MethodPathRoles
GET/task-listAdmin, SuperAdmin, Staff
POST/task-listAdmin, SuperAdmin, Staff
PUT/task-list/:idAdmin, SuperAdmin, Staff
DELETE/task-list/:idAdmin, SuperAdmin, Staff

Tenant scope comes from tenantIdFromJwt() (user_id on admin tokens, idold on staff tokens).

Legacy staff aliases (deprecated, still mounted) ​

These paths delegate to the same handlers as the canonical routes above. Keep until logs show no traffic:

  • GET /task-list/stafflistdata
  • POST /task-list/createlist
  • PUT /task-list/edit-list/:id
  • DELETE /task-list/delete-list/:id

Canonical task history ​

MethodPathRoles
POST/task-historyAdmin, SuperAdmin, Staff

Legacy: POST /task-history/staffhistory (alias).

Canonical CRM enquiry archive (M11) ​

MethodPathRoles
PUT/leads/archive-inquiriesAdmin, SuperAdmin, Staff
PUT/leads/unarchive-inquiriesAdmin, SuperAdmin, Staff

Implementation: Backend/service/enquiryArchive.service.js (property_id = tenant from JWT).

Legacy aliases (same handler): /leads/staffarchive-inquiries, /leads/staffunarchive-inquiries.

Canonical order archive (M11) ​

MethodPathRoles
PUT/payment/archive-orderAdmin, SuperAdmin, Staff
PUT/payment/unarchive-orderAdmin, SuperAdmin, Staff

Staff: only assigned order IDs (via AssignOrders + idnew). Admin: all tenant orders.

Implementation: Backend/service/orderArchive.service.js.

Legacy aliases: /payment/staffarchive-order, /payment/staffunarchive-order.

CRM remarks (/note) and order notes (/ordernote) — M12 ​

AreaCanonicalStaff rule
POST createPOST /note, POST /ordernoteTenant from JWT; order notes require assignment
List by tenantGET /note/allSame handler as admin
List by orderGET /ordernote/all/:orderIdStaff must be assigned to order
CRM filterGET /note/crmnotesStaff allowed (property_id = tenant)

Legacy aliases: POST /note/staff, GET /note/staff/all, POST /ordernote/staff, GET /ordernote/staff/all/:id, etc.

Route order fix: GET /note/all registered before GET /note/:id so all is not treated as an id.

CRM enquiry create (M13) ​

MethodPathRoles
POST/leads/adminAdmin, SuperAdmin, Staff

Staff submissions auto-create AssignLeads (self-assign). Admin submissions log AdminActivity.

Legacy alias: POST /leads/staff → same createWorkspaceEnquiry handler.

Canonical task workspace API (M21) ​

Shared service: Backend/service/taskWorkspace.service.js (tenantIdFromJwt, staffCanViewTask / staffCanMutateTask).

MethodPathRoles
GET/task/allAdmin, SuperAdmin, Staff (staff = visible assigned/watched tasks)
PUT/task/:idAdmin, SuperAdmin, Staff (staff = assignee mutate)
PUT/task/change/:idAdmin, SuperAdmin, Staff
PATCH/task/update/:idAdmin, SuperAdmin, Staff
DELETE/task/:idAdmin, SuperAdmin, Staff (staff = assignee-owned)
POST/task/reorderAdmin, SuperAdmin, Staff

Staff create (self/complaint): POST /task/create-task (Staff only). Admin create: POST /task.

Legacy aliases (deprecated, same handlers): GET /task/stafftask, PUT /task/stafftask/:id, PUT /task/changetask/:id, PATCH /task/updatetask/:id, DELETE /task/stafftask/:id, POST /task/reorder-staff.

Still separate ​

AreaPathWhy
CRM createLegacy POST /leads/staff aliasUse POST /leads/admin
Notes / remarksLegacy /note/staff*, /ordernote/staff* aliasesCanonical paths in M12 section

Frontend ​

  • Canonical client: Admin/src/shared/tasks/api/taskListApi.js, taskApi.js, and path map taskApiPaths.js (history uses /task-history for all roles).
  • Legacy clients: may still call deprecated staff URL aliases; canonical paths above are preferred.

Beentara — Business management made simple.