mirror of
https://github.com/Tria-plc/edr-platform.git
synced 2026-08-27 00:52:50 +00:00
Gates the previously open support-agent, procurement, compliance, facilities, list-users and trade-access controllers, separates customer from staff routes across bookings, contracts, companies, billing, warehouses, files and train scheduling, and moves billing, overview, reports and the settings controllers onto their own keys instead of the blanket admin key. Drops the demo-permissions module and the untested notification test route.
73 lines
2.5 KiB
TypeScript
73 lines
2.5 KiB
TypeScript
import {
|
|
Body,
|
|
Controller,
|
|
Get,
|
|
Param,
|
|
ParseUUIDPipe,
|
|
Post,
|
|
Query,
|
|
Put,
|
|
} from "@nestjs/common";
|
|
import { ApiOperation, ApiTags } from "@nestjs/swagger";
|
|
|
|
import { BookingStaff } from "../../common/booking-guards";
|
|
import { FREIGHT_PERMS } from "../../seed/freight-permissions.registry";
|
|
import { BackofficeService } from "./backoffice.service";
|
|
import { CreateOrganizationUserDto } from "./dto/create-organization-user.dto";
|
|
import { UpdateEmployeeUserRolesDto } from "./dto/update-employee-user-roles.dto";
|
|
|
|
@ApiTags("backoffice")
|
|
@Controller("backoffice")
|
|
export class BackofficeController {
|
|
constructor(private readonly backofficeService: BackofficeService) {}
|
|
|
|
@Post("organizations/:orgId/users")
|
|
@BookingStaff([FREIGHT_PERMS.staff.employeeRegistration.create, FREIGHT_PERMS.admin])
|
|
@ApiOperation({ summary: "Create an organization user without assigning positions" })
|
|
createOrganizationUser(
|
|
@Param("orgId", ParseUUIDPipe) organizationId: string,
|
|
@Body() dto: CreateOrganizationUserDto,
|
|
) {
|
|
return this.backofficeService.createOrganizationUser(organizationId, dto);
|
|
}
|
|
|
|
@Get("organizations/:orgId/employees")
|
|
@BookingStaff([FREIGHT_PERMS.staff.roleAssignment.view, FREIGHT_PERMS.admin])
|
|
@ApiOperation({ summary: "Get deduplicated organization employees for backoffice" })
|
|
getOrganizationEmployees(
|
|
@Param("orgId", ParseUUIDPipe) organizationId: string,
|
|
@Query("skip") skip?: string,
|
|
@Query("take") take?: string,
|
|
) {
|
|
return this.backofficeService.getOrganizationEmployees(organizationId, {
|
|
skip,
|
|
take,
|
|
});
|
|
}
|
|
|
|
@Get("organizations/:orgId/employee-users/:userId/roles")
|
|
@BookingStaff([FREIGHT_PERMS.staff.roleAssignment.view, FREIGHT_PERMS.admin])
|
|
@ApiOperation({ summary: "Get org-scoped roles assigned to an employee user" })
|
|
getEmployeeUserRoles(
|
|
@Param("orgId", ParseUUIDPipe) organizationId: string,
|
|
@Param("userId", ParseUUIDPipe) userId: string,
|
|
) {
|
|
return this.backofficeService.getEmployeeUserRoles(organizationId, userId);
|
|
}
|
|
|
|
@Put("organizations/:orgId/employee-users/:userId/roles")
|
|
@BookingStaff([FREIGHT_PERMS.staff.roleAssignment.replace, FREIGHT_PERMS.admin])
|
|
@ApiOperation({ summary: "Replace org-scoped roles assigned to an employee user" })
|
|
replaceEmployeeUserRoles(
|
|
@Param("orgId", ParseUUIDPipe) organizationId: string,
|
|
@Param("userId", ParseUUIDPipe) userId: string,
|
|
@Body() dto: UpdateEmployeeUserRolesDto,
|
|
) {
|
|
return this.backofficeService.replaceEmployeeUserRoles(
|
|
organizationId,
|
|
userId,
|
|
dto.roleIds,
|
|
);
|
|
}
|
|
}
|