4.3 KiB
Assessment Results Backend
Purpose
assessment_results is the per-organization join between an assessment and a student, holding
that student's score, letter grade, and remarks for the assessment. It is a generic-CRUD slice
assembled from the shared factories; the backend is the source of truth for these records.
Slice Files (by layer)
- Route:
src/routes/assessment_results.ts—createCrudRouter(controller, { permission: 'assessment_results' }). - Controller:
src/api/controllers/assessment_results.controller.ts—createCrudController(service, { csvFields }). - Service (BLL):
src/services/assessment_results.ts—createCrudService(DbApi, { notFoundCode: 'assessment_resultsNotFound' }). - Repository (DAL):
src/db/api/assessment_results.ts(Assessment_resultsDBApi) — entity-specificcreate/bulkImport/update/findBy/findAll;remove/deleteByIds/findAllAutocompletedelegate todb/api/shared/repository.ts. - Model:
src/db/models/assessment_results.ts. - Shared used: CRUD factories (
services/shared/crud-service.ts,api/controllers/shared/crud-controller.ts,api/http/crud-router.ts), repository helpers (db/api/shared/repository.ts),shared/constants/pagination.ts(resolvePagination).
API
The standard generic-CRUD surface (all under /api/assessment_results, JWT +
${METHOD}_ASSESSMENT_RESULTS permission, all 200) — see backend-architecture.md for the
shared contract:
POST /— body{ data }, returnstrue.POST /bulk-import— multipart CSV file, returnstrue.PUT /:id— body{ data, id }(the service reads the id from the body), returnstrue.DELETE /:id— returnstrue.POST /deleteByIds— body{ data: string[] }, returnstrue.GET /— query filters, returns{ rows, count };?filetype=csvstreams a CSV ofcsvFields.GET /count— returns{ rows: [], count }.GET /autocomplete—?query&limit&offset, returns[{ id, label }]wherelabelisgrade_letter.GET /:id— returns the record with eager associations (see Data Contract).
csvFields: id, remarks, score.
Access Rules
- JWT required; the whole router is guarded by
checkCrudPermissions('assessment_results'), derivingREAD_ASSESSMENT_RESULTS/CREATE_ASSESSMENT_RESULTS/UPDATE_ASSESSMENT_RESULTS/DELETE_ASSESSMENT_RESULTSper HTTP method. - Access is granted by role permission or per-user
custom_permissions(seepermissions.md).
Tenant Scope
findAllscopeswhere.organizationIdtocurrentUser.organizationId; aglobalAccessrole clears the org filter (sees all tenants).createassigns the organization fromcurrentUser.organizationId;updateonly reassigns organization forglobalAccessusers (otherwise it stays the caller's org).
Data Contract
Model columns (paranoid, soft-delete via deletedAt):
id(UUID PK),remarks(TEXT, nullable).score— DECIMAL (nullable).grade_letter— ENUMA|B|C|D|E|F|P|N.importHash(unique),organizationId,assessmentId,studentId,createdById,updatedById, timestamps.
Associations: belongsTo organization, assessment (assessments),
createdBy/updatedBy (users). findBy/GET /:id eager-load organization and assessment in a single Promise.all.
List filters (AssessmentResultsFilter): id, remarks, scoreRange, active,
grade_letter, assessment (id or assessment name, |-separated, applied as an include
where-clause), student (id or student_number, |-separated, applied as an include
where-clause), organization (|-separated ids), createdAtRange, plus field/sort
ordering and limit/page pagination.
Behavior / Notes
create/updateset theassessment,student, andorganizationassociations from the ids in the request body.bulkImportoffsetscreatedAtper row byBULK_IMPORT_TIMESTAMP_STEP_MSto preserve order.- List pagination uses the shared
resolvePaginationdefaults (page size 10, capped at 100). - Note:
AssessmentResultsFilteraccepts anactiveflag the model has no column for; it is currently inert (kept for source accuracy).
Tests
None yet.
Related
- Generic-CRUD contract:
backend-architecture.md; related slices:assessments,organizations,permissions.md.