API Dashboard added
This commit is contained in:
49
api-dashboard/README.md
Normal file
49
api-dashboard/README.md
Normal file
@@ -0,0 +1,49 @@
|
||||
# Tillo Developer Console (API Dashboard)
|
||||
|
||||
Welcome to the **Tillo Developer Console**, a premium management dashboard and integration interface for creating, managing, and testing developer API Keys for external system widgets and program modules.
|
||||
|
||||
## 🏗️ Architecture & Security Model
|
||||
|
||||
To protect sensitive canteen financials and limit key usage footprint, this module operates under a robust security architecture:
|
||||
|
||||
1. **Usage Quota Limits**: Each system administrator or customer user is strictly limited to obtaining a maximum of **3 active API keys**.
|
||||
2. **Access Control Scopes**: API Keys obtain a specialized **Read-Only** access scope. Write operations, wallet top-ups, session creations, or master configurations are rejected with a HTTP `401 Unauthorized` or `403 Forbidden` response.
|
||||
3. **Financial Exclusion Guard**: All developer API key requests are barred from viewing financial statistics (e.g. daily store revenue, hourly billing graphs, transaction tables, master ledgers, and vendor settlement logs). General non-sensitive counters like active product pricing lists, public store stalls, and order statuses are open for querying.
|
||||
4. **Wallet Safeguard**:
|
||||
- **Customer API Keys** can query the active wallet balance of the owner user account.
|
||||
- **System API Keys** can query general system token circulation statistics, but cannot access individual customer transaction lines or private ledger balances.
|
||||
|
||||
---
|
||||
|
||||
## 🚀 Getting Started
|
||||
|
||||
### 1. Run the Dev Server
|
||||
Navigate to this directory and boot Vite:
|
||||
```bash
|
||||
npm run dev
|
||||
```
|
||||
|
||||
### 2. Authentication
|
||||
Log in with either:
|
||||
- **System Admin / Staff Credentials**: email/password credentials.
|
||||
- **Customer Mobile Credentials**: 10-digit mobile number and 4-digit PIN.
|
||||
|
||||
*Credentials matches your core Tillo application database.*
|
||||
|
||||
---
|
||||
|
||||
## 📡 API Reference Directory
|
||||
|
||||
Include the custom header `X-Developer-Key: DEV-XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX` in all requests to query:
|
||||
|
||||
| Method | Path | Description | Access Level |
|
||||
| :--- | :--- | :--- | :--- |
|
||||
| `GET` | `/api/developer/v1/validate` | Verify API key health and view owner details. | Key validated |
|
||||
| `GET` | `/api/developer/v1/stalls` | Fetch catalog listings of active canteen stalls. | Key validated |
|
||||
| `GET` | `/api/developer/v1/products` | Retrieve catalog list of products and current stock. | Key validated |
|
||||
| `GET` | `/api/developer/v1/wallet` | Fetch wallet balance (owner only) or total circulation volume. | Owner scope |
|
||||
| `GET` | `/api/developer/v1/orders` | Retrieve list of active orders (owner only) or order statuses. | Owner scope |
|
||||
|
||||
---
|
||||
|
||||
*Developed by the Canteen Automation Team.*
|
||||
Reference in New Issue
Block a user