Appearance
API consolidation (M6 + M11)
Unified Admin app calls one backend. Shared handlers use tenantIdFromJwt(); staff-only business rules (e.g. assigned orders) live in services, not duplicate URLs.
Canonical task-list API (Admin + Staff JWT)
| Method | Path | Roles |
|---|---|---|
| GET | /task-list | Admin, SuperAdmin, Staff |
| POST | /task-list | Admin, SuperAdmin, Staff |
| PUT | /task-list/:id | Admin, SuperAdmin, Staff |
| DELETE | /task-list/:id | Admin, SuperAdmin, Staff |
Tenant scope comes from tenantIdFromJwt() (user_id on admin tokens, idold on staff tokens).
Legacy staff aliases (deprecated, still mounted)
These paths delegate to the same handlers as the canonical routes above. Keep until logs show no traffic:
GET /task-list/stafflistdataPOST /task-list/createlistPUT /task-list/edit-list/:idDELETE /task-list/delete-list/:id
Canonical task history
| Method | Path | Roles |
|---|---|---|
| POST | /task-history | Admin, SuperAdmin, Staff |
Legacy: POST /task-history/staffhistory (alias).
Canonical CRM enquiry archive (M11)
| Method | Path | Roles |
|---|---|---|
| PUT | /leads/archive-inquiries | Admin, SuperAdmin, Staff |
| PUT | /leads/unarchive-inquiries | Admin, SuperAdmin, Staff |
Implementation: Backend/service/enquiryArchive.service.js (property_id = tenant from JWT).
Legacy aliases (same handler): /leads/staffarchive-inquiries, /leads/staffunarchive-inquiries.
Canonical order archive (M11)
| Method | Path | Roles |
|---|---|---|
| PUT | /payment/archive-order | Admin, SuperAdmin, Staff |
| PUT | /payment/unarchive-order | Admin, SuperAdmin, Staff |
Staff: only assigned order IDs (via AssignOrders + idnew). Admin: all tenant orders.
Implementation: Backend/service/orderArchive.service.js.
Legacy aliases: /payment/staffarchive-order, /payment/staffunarchive-order.
CRM remarks (/note) and order notes (/ordernote) — M12
| Area | Canonical | Staff rule |
|---|---|---|
| POST create | POST /note, POST /ordernote | Tenant from JWT; order notes require assignment |
| List by tenant | GET /note/all | Same handler as admin |
| List by order | GET /ordernote/all/:orderId | Staff must be assigned to order |
| CRM filter | GET /note/crmnotes | Staff allowed (property_id = tenant) |
Legacy aliases: POST /note/staff, GET /note/staff/all, POST /ordernote/staff, GET /ordernote/staff/all/:id, etc.
Route order fix: GET /note/all registered before GET /note/:id so all is not treated as an id.
CRM enquiry create (M13)
| Method | Path | Roles |
|---|---|---|
| POST | /leads/admin | Admin, SuperAdmin, Staff |
Staff submissions auto-create AssignLeads (self-assign). Admin submissions log AdminActivity.
Legacy alias: POST /leads/staff → same createWorkspaceEnquiry handler.
Canonical task workspace API (M21)
Shared service: Backend/service/taskWorkspace.service.js (tenantIdFromJwt, staffCanViewTask / staffCanMutateTask).
| Method | Path | Roles |
|---|---|---|
| GET | /task/all | Admin, SuperAdmin, Staff (staff = visible assigned/watched tasks) |
| PUT | /task/:id | Admin, SuperAdmin, Staff (staff = assignee mutate) |
| PUT | /task/change/:id | Admin, SuperAdmin, Staff |
| PATCH | /task/update/:id | Admin, SuperAdmin, Staff |
| DELETE | /task/:id | Admin, SuperAdmin, Staff (staff = assignee-owned) |
| POST | /task/reorder | Admin, SuperAdmin, Staff |
Staff create (self/complaint): POST /task/create-task (Staff only). Admin create: POST /task.
Legacy aliases (deprecated, same handlers): GET /task/stafftask, PUT /task/stafftask/:id, PUT /task/changetask/:id, PATCH /task/updatetask/:id, DELETE /task/stafftask/:id, POST /task/reorder-staff.
Still separate
| Area | Path | Why |
|---|---|---|
| CRM create | Legacy POST /leads/staff alias | Use POST /leads/admin |
| Notes / remarks | Legacy /note/staff*, /ordernote/staff* aliases | Canonical paths in M12 section |
Frontend
- Canonical client:
Admin/src/shared/tasks/api/taskListApi.js,taskApi.js, and path maptaskApiPaths.js(history uses/task-historyfor all roles). - Legacy clients: may still call deprecated staff URL aliases; canonical paths above are preferred.