3.8 KiB
Subjects Backend
Purpose
subjects is the per-organization catalog of teaching subjects (name, code, description). It is
a generic-CRUD slice assembled from the shared factories; the backend is the source of truth for
subject records.
Slice Files (by layer)
- Route:
src/routes/subjects.ts—createCrudRouter(controller, { permission: 'subjects' }). - Controller:
src/api/controllers/subjects.controller.ts—createCrudController(service, { csvFields }). - Service (BLL):
src/services/subjects.ts—createCrudService(DbApi, { notFoundCode: 'subjectsNotFound' }). - Repository (DAL):
src/db/api/subjects.ts(SubjectsDBApi) — entity-specificcreate/bulkImport/update/findBy/findAll;remove/deleteByIds/findAllAutocompletedelegate todb/api/shared/repository.ts. - Model:
src/db/models/subjects.ts. - Shared used: CRUD factories (
services/shared/crud-service.ts,api/controllers/shared/crud-controller.ts,api/http/crud-router.ts), repository helpers (db/api/shared/repository.ts),shared/constants/pagination.ts(resolvePagination),shared/constants/database.ts(BULK_IMPORT_TIMESTAMP_STEP_MS),db/utils.ts(Utils).
API
The standard generic-CRUD surface (all under /api/subjects, JWT + ${METHOD}_SUBJECTS
permission, all 200) — see backend-architecture.md for the shared contract:
POST /— body{ data }, returnstrue.POST /bulk-import— multipart CSV file, returnstrue.PUT /:id— body{ data, id }(the service reads the id from the body), returnstrue.DELETE /:id— returnstrue.POST /deleteByIds— body{ data: string[] }, returnstrue.GET /— query filters, returns{ rows, count };?filetype=csvstreams a CSV ofcsvFields.GET /count— returns{ rows: [], count }.GET /autocomplete—?query&limit&offset, returns[{ id, label }]wherelabelisname.GET /:id— returns the record with eager associations (see Data Contract).
csvFields: id, name, code, description.
Access Rules
- JWT required; the whole router is guarded by
checkCrudPermissions('subjects'), derivingREAD_SUBJECTS/CREATE_SUBJECTS/UPDATE_SUBJECTS/DELETE_SUBJECTSper HTTP method. - Access is granted by role permission or per-user
custom_permissions(seepermissions.md).
Tenant Scope
findAllscopeswhere.organizationIdtocurrentUser.organizationId; aglobalAccessrole clears the org filter (sees all tenants).createassigns the organization fromcurrentUser.organizationId;updateonly reassigns organization forglobalAccessusers (otherwise it stays the caller's org).
Data Contract
Model columns (paranoid, soft-delete via deletedAt):
id(UUID PK).name,code,description— TEXT, nullable.importHash(unique),organizationId,createdById,updatedById, timestamps.
Associations: belongsTo organization, createdBy/updatedBy (users); hasMany
class_subjects_subject. findBy/GET /:id eager-load class_subjects_subject and organization
in a single Promise.all.
List filters (SubjectsFilter): id, name (ilike), code (ilike), description (ilike),
organization, createdAtRange, plus field/sort ordering and limit/page pagination.
Behavior / Notes
create/updatewire the organization relation via thesetOrganizationassociation mixin.bulkImportoffsetscreatedAtper row byBULK_IMPORT_TIMESTAMP_STEP_MSto preserve order.- List pagination uses the shared
resolvePaginationdefaults (page size 10, capped at 100). - Note:
SubjectsFilteraccepts anactiveflag the model has no column for; it is currently inert (kept for source accuracy).
Tests
None yet.
Related
- Generic-CRUD contract:
backend-architecture.md; related slices:class_subjects,classes,permissions.md.