API Dashboard added
24
api-dashboard/.gitignore
vendored
Normal file
@@ -0,0 +1,24 @@
|
||||
# Logs
|
||||
logs
|
||||
*.log
|
||||
npm-debug.log*
|
||||
yarn-debug.log*
|
||||
yarn-error.log*
|
||||
pnpm-debug.log*
|
||||
lerna-debug.log*
|
||||
|
||||
node_modules
|
||||
dist
|
||||
dist-ssr
|
||||
*.local
|
||||
|
||||
# Editor directories and files
|
||||
.vscode/*
|
||||
!.vscode/extensions.json
|
||||
.idea
|
||||
.DS_Store
|
||||
*.suo
|
||||
*.ntvs*
|
||||
*.njsproj
|
||||
*.sln
|
||||
*.sw?
|
||||
49
api-dashboard/README.md
Normal file
@@ -0,0 +1,49 @@
|
||||
# Tillo Developer Console (API Dashboard)
|
||||
|
||||
Welcome to the **Tillo Developer Console**, a premium management dashboard and integration interface for creating, managing, and testing developer API Keys for external system widgets and program modules.
|
||||
|
||||
## 🏗️ Architecture & Security Model
|
||||
|
||||
To protect sensitive canteen financials and limit key usage footprint, this module operates under a robust security architecture:
|
||||
|
||||
1. **Usage Quota Limits**: Each system administrator or customer user is strictly limited to obtaining a maximum of **3 active API keys**.
|
||||
2. **Access Control Scopes**: API Keys obtain a specialized **Read-Only** access scope. Write operations, wallet top-ups, session creations, or master configurations are rejected with a HTTP `401 Unauthorized` or `403 Forbidden` response.
|
||||
3. **Financial Exclusion Guard**: All developer API key requests are barred from viewing financial statistics (e.g. daily store revenue, hourly billing graphs, transaction tables, master ledgers, and vendor settlement logs). General non-sensitive counters like active product pricing lists, public store stalls, and order statuses are open for querying.
|
||||
4. **Wallet Safeguard**:
|
||||
- **Customer API Keys** can query the active wallet balance of the owner user account.
|
||||
- **System API Keys** can query general system token circulation statistics, but cannot access individual customer transaction lines or private ledger balances.
|
||||
|
||||
---
|
||||
|
||||
## 🚀 Getting Started
|
||||
|
||||
### 1. Run the Dev Server
|
||||
Navigate to this directory and boot Vite:
|
||||
```bash
|
||||
npm run dev
|
||||
```
|
||||
|
||||
### 2. Authentication
|
||||
Log in with either:
|
||||
- **System Admin / Staff Credentials**: email/password credentials.
|
||||
- **Customer Mobile Credentials**: 10-digit mobile number and 4-digit PIN.
|
||||
|
||||
*Credentials matches your core Tillo application database.*
|
||||
|
||||
---
|
||||
|
||||
## 📡 API Reference Directory
|
||||
|
||||
Include the custom header `X-Developer-Key: DEV-XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX` in all requests to query:
|
||||
|
||||
| Method | Path | Description | Access Level |
|
||||
| :--- | :--- | :--- | :--- |
|
||||
| `GET` | `/api/developer/v1/validate` | Verify API key health and view owner details. | Key validated |
|
||||
| `GET` | `/api/developer/v1/stalls` | Fetch catalog listings of active canteen stalls. | Key validated |
|
||||
| `GET` | `/api/developer/v1/products` | Retrieve catalog list of products and current stock. | Key validated |
|
||||
| `GET` | `/api/developer/v1/wallet` | Fetch wallet balance (owner only) or total circulation volume. | Owner scope |
|
||||
| `GET` | `/api/developer/v1/orders` | Retrieve list of active orders (owner only) or order statuses. | Owner scope |
|
||||
|
||||
---
|
||||
|
||||
*Developed by the Canteen Automation Team.*
|
||||
22
api-dashboard/eslint.config.js
Normal file
@@ -0,0 +1,22 @@
|
||||
import js from '@eslint/js'
|
||||
import globals from 'globals'
|
||||
import reactHooks from 'eslint-plugin-react-hooks'
|
||||
import reactRefresh from 'eslint-plugin-react-refresh'
|
||||
import tseslint from 'typescript-eslint'
|
||||
import { defineConfig, globalIgnores } from 'eslint/config'
|
||||
|
||||
export default defineConfig([
|
||||
globalIgnores(['dist']),
|
||||
{
|
||||
files: ['**/*.{ts,tsx}'],
|
||||
extends: [
|
||||
js.configs.recommended,
|
||||
tseslint.configs.recommended,
|
||||
reactHooks.configs.flat.recommended,
|
||||
reactRefresh.configs.vite,
|
||||
],
|
||||
languageOptions: {
|
||||
globals: globals.browser,
|
||||
},
|
||||
},
|
||||
])
|
||||
13
api-dashboard/index.html
Normal file
@@ -0,0 +1,13 @@
|
||||
<!doctype html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8" />
|
||||
<link rel="icon" type="image/svg+xml" href="/favicon.svg" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||
<title>api-dashboard</title>
|
||||
</head>
|
||||
<body>
|
||||
<div id="root"></div>
|
||||
<script type="module" src="/src/main.tsx"></script>
|
||||
</body>
|
||||
</html>
|
||||
2771
api-dashboard/package-lock.json
generated
Normal file
30
api-dashboard/package.json
Normal file
@@ -0,0 +1,30 @@
|
||||
{
|
||||
"name": "api-dashboard",
|
||||
"private": true,
|
||||
"version": "0.0.0",
|
||||
"type": "module",
|
||||
"scripts": {
|
||||
"dev": "vite",
|
||||
"build": "tsc -b && vite build",
|
||||
"lint": "eslint .",
|
||||
"preview": "vite preview"
|
||||
},
|
||||
"dependencies": {
|
||||
"react": "^19.2.7",
|
||||
"react-dom": "^19.2.7"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@eslint/js": "^10.0.1",
|
||||
"@types/node": "^24.13.2",
|
||||
"@types/react": "^19.2.17",
|
||||
"@types/react-dom": "^19.2.3",
|
||||
"@vitejs/plugin-react": "^6.0.3",
|
||||
"eslint": "^10.6.0",
|
||||
"eslint-plugin-react-hooks": "^7.1.1",
|
||||
"eslint-plugin-react-refresh": "^0.5.3",
|
||||
"globals": "^17.7.0",
|
||||
"typescript": "~6.0.2",
|
||||
"typescript-eslint": "^8.62.0",
|
||||
"vite": "^8.1.1"
|
||||
}
|
||||
}
|
||||
1
api-dashboard/public/favicon.svg
Normal file
|
After Width: | Height: | Size: 9.3 KiB |
24
api-dashboard/public/icons.svg
Normal file
@@ -0,0 +1,24 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg">
|
||||
<symbol id="bluesky-icon" viewBox="0 0 16 17">
|
||||
<g clip-path="url(#bluesky-clip)"><path fill="#08060d" d="M7.75 7.735c-.693-1.348-2.58-3.86-4.334-5.097-1.68-1.187-2.32-.981-2.74-.79C.188 2.065.1 2.812.1 3.251s.241 3.602.398 4.13c.52 1.744 2.367 2.333 4.07 2.145-2.495.37-4.71 1.278-1.805 4.512 3.196 3.309 4.38-.71 4.987-2.746.608 2.036 1.307 5.91 4.93 2.746 2.72-2.746.747-4.143-1.747-4.512 1.702.189 3.55-.4 4.07-2.145.156-.528.397-3.691.397-4.13s-.088-1.186-.575-1.406c-.42-.19-1.06-.395-2.741.79-1.755 1.24-3.64 3.752-4.334 5.099"/></g>
|
||||
<defs><clipPath id="bluesky-clip"><path fill="#fff" d="M.1.85h15.3v15.3H.1z"/></clipPath></defs>
|
||||
</symbol>
|
||||
<symbol id="discord-icon" viewBox="0 0 20 19">
|
||||
<path fill="#08060d" d="M16.224 3.768a14.5 14.5 0 0 0-3.67-1.153c-.158.286-.343.67-.47.976a13.5 13.5 0 0 0-4.067 0c-.128-.306-.317-.69-.476-.976A14.4 14.4 0 0 0 3.868 3.77C1.546 7.28.916 10.703 1.231 14.077a14.7 14.7 0 0 0 4.5 2.306q.545-.748.965-1.587a9.5 9.5 0 0 1-1.518-.74q.191-.14.372-.293c2.927 1.369 6.107 1.369 8.999 0q.183.152.372.294-.723.437-1.52.74.418.838.963 1.588a14.6 14.6 0 0 0 4.504-2.308c.37-3.911-.63-7.302-2.644-10.309m-9.13 8.234c-.878 0-1.599-.82-1.599-1.82 0-.998.705-1.82 1.6-1.82.894 0 1.614.82 1.599 1.82.001 1-.705 1.82-1.6 1.82m5.91 0c-.878 0-1.599-.82-1.599-1.82 0-.998.705-1.82 1.6-1.82.893 0 1.614.82 1.599 1.82 0 1-.706 1.82-1.6 1.82"/>
|
||||
</symbol>
|
||||
<symbol id="documentation-icon" viewBox="0 0 21 20">
|
||||
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="m15.5 13.333 1.533 1.322c.645.555.967.833.967 1.178s-.322.623-.967 1.179L15.5 18.333m-3.333-5-1.534 1.322c-.644.555-.966.833-.966 1.178s.322.623.966 1.179l1.534 1.321"/>
|
||||
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M17.167 10.836v-4.32c0-1.41 0-2.117-.224-2.68-.359-.906-1.118-1.621-2.08-1.96-.599-.21-1.349-.21-2.848-.21-2.623 0-3.935 0-4.983.369-1.684.591-3.013 1.842-3.641 3.428C3 6.449 3 7.684 3 10.154v2.122c0 2.558 0 3.838.706 4.726q.306.383.713.671c.76.536 1.79.64 3.581.66"/>
|
||||
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M3 10a2.78 2.78 0 0 1 2.778-2.778c.555 0 1.209.097 1.748-.047.48-.129.854-.503.982-.982.145-.54.048-1.194.048-1.749a2.78 2.78 0 0 1 2.777-2.777"/>
|
||||
</symbol>
|
||||
<symbol id="github-icon" viewBox="0 0 19 19">
|
||||
<path fill="#08060d" fill-rule="evenodd" d="M9.356 1.85C5.05 1.85 1.57 5.356 1.57 9.694a7.84 7.84 0 0 0 5.324 7.44c.387.079.528-.168.528-.376 0-.182-.013-.805-.013-1.454-2.165.467-2.616-.935-2.616-.935-.349-.91-.864-1.143-.864-1.143-.71-.48.051-.48.051-.48.787.051 1.2.805 1.2.805.695 1.194 1.817.857 2.268.649.064-.507.27-.857.49-1.052-1.728-.182-3.545-.857-3.545-3.87 0-.857.31-1.558.8-2.104-.078-.195-.349-1 .077-2.078 0 0 .657-.208 2.14.805a7.5 7.5 0 0 1 1.946-.26c.657 0 1.328.092 1.946.26 1.483-1.013 2.14-.805 2.14-.805.426 1.078.155 1.883.078 2.078.502.546.799 1.247.799 2.104 0 3.013-1.818 3.675-3.558 3.87.284.247.528.714.528 1.454 0 1.052-.012 1.896-.012 2.156 0 .208.142.455.528.377a7.84 7.84 0 0 0 5.324-7.441c.013-4.338-3.48-7.844-7.773-7.844" clip-rule="evenodd"/>
|
||||
</symbol>
|
||||
<symbol id="social-icon" viewBox="0 0 20 20">
|
||||
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M12.5 6.667a4.167 4.167 0 1 0-8.334 0 4.167 4.167 0 0 0 8.334 0"/>
|
||||
<path fill="none" stroke="#aa3bff" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.35" d="M2.5 16.667a5.833 5.833 0 0 1 8.75-5.053m3.837.474.513 1.035c.07.144.257.282.414.309l.93.155c.596.1.736.536.307.965l-.723.73a.64.64 0 0 0-.152.531l.207.903c.164.715-.213.991-.84.618l-.872-.52a.63.63 0 0 0-.577 0l-.872.52c-.624.373-1.003.094-.84-.618l.207-.903a.64.64 0 0 0-.152-.532l-.723-.729c-.426-.43-.289-.864.306-.964l.93-.156a.64.64 0 0 0 .412-.31l.513-1.034c.28-.562.735-.562 1.012 0"/>
|
||||
</symbol>
|
||||
<symbol id="x-icon" viewBox="0 0 19 19">
|
||||
<path fill="#08060d" fill-rule="evenodd" d="M1.893 1.98c.052.072 1.245 1.769 2.653 3.77l2.892 4.114c.183.261.333.48.333.486s-.068.089-.152.183l-.522.593-.765.867-3.597 4.087c-.375.426-.734.834-.798.905a1 1 0 0 0-.118.148c0 .01.236.017.664.017h.663l.729-.83c.4-.457.796-.906.879-.999a692 692 0 0 0 1.794-2.038c.034-.037.301-.34.594-.675l.551-.624.345-.392a7 7 0 0 1 .34-.374c.006 0 .93 1.306 2.052 2.903l2.084 2.965.045.063h2.275c1.87 0 2.273-.003 2.266-.021-.008-.02-1.098-1.572-3.894-5.547-2.013-2.862-2.28-3.246-2.273-3.266.008-.019.282-.332 2.085-2.38l2-2.274 1.567-1.782c.022-.028-.016-.03-.65-.03h-.674l-.3.342a871 871 0 0 1-1.782 2.025c-.067.075-.405.458-.75.852a100 100 0 0 1-.803.91c-.148.172-.299.344-.99 1.127-.304.343-.32.358-.345.327-.015-.019-.904-1.282-1.976-2.808L6.365 1.85H1.8zm1.782.91 8.078 11.294c.772 1.08 1.413 1.973 1.425 1.984.016.017.241.02 1.05.017l1.03-.004-2.694-3.766L7.796 5.75 5.722 2.852l-1.039-.004-1.039-.004z" clip-rule="evenodd"/>
|
||||
</symbol>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 4.9 KiB |
1240
api-dashboard/src/App.css
Normal file
1266
api-dashboard/src/App.tsx
Normal file
BIN
api-dashboard/src/assets/Tillo.png
Normal file
|
After Width: | Height: | Size: 17 KiB |
BIN
api-dashboard/src/assets/hero.png
Normal file
|
After Width: | Height: | Size: 13 KiB |
BIN
api-dashboard/src/assets/logo.png
Normal file
|
After Width: | Height: | Size: 18 KiB |
1
api-dashboard/src/assets/react.svg
Normal file
@@ -0,0 +1 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" class="iconify iconify--logos" width="35.93" height="32" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 228"><path fill="#00D8FF" d="M210.483 73.824a171.49 171.49 0 0 0-8.24-2.597c.465-1.9.893-3.777 1.273-5.621c6.238-30.281 2.16-54.676-11.769-62.708c-13.355-7.7-35.196.329-57.254 19.526a171.23 171.23 0 0 0-6.375 5.848a155.866 155.866 0 0 0-4.241-3.917C100.759 3.829 77.587-4.822 63.673 3.233C50.33 10.957 46.379 33.89 51.995 62.588a170.974 170.974 0 0 0 1.892 8.48c-3.28.932-6.445 1.924-9.474 2.98C17.309 83.498 0 98.307 0 113.668c0 15.865 18.582 31.778 46.812 41.427a145.52 145.52 0 0 0 6.921 2.165a167.467 167.467 0 0 0-2.01 9.138c-5.354 28.2-1.173 50.591 12.134 58.266c13.744 7.926 36.812-.22 59.273-19.855a145.567 145.567 0 0 0 5.342-4.923a168.064 168.064 0 0 0 6.92 6.314c21.758 18.722 43.246 26.282 56.54 18.586c13.731-7.949 18.194-32.003 12.4-61.268a145.016 145.016 0 0 0-1.535-6.842c1.62-.48 3.21-.974 4.76-1.488c29.348-9.723 48.443-25.443 48.443-41.52c0-15.417-17.868-30.326-45.517-39.844Zm-6.365 70.984c-1.4.463-2.836.91-4.3 1.345c-3.24-10.257-7.612-21.163-12.963-32.432c5.106-11 9.31-21.767 12.459-31.957c2.619.758 5.16 1.557 7.61 2.4c23.69 8.156 38.14 20.213 38.14 29.504c0 9.896-15.606 22.743-40.946 31.14Zm-10.514 20.834c2.562 12.94 2.927 24.64 1.23 33.787c-1.524 8.219-4.59 13.698-8.382 15.893c-8.067 4.67-25.32-1.4-43.927-17.412a156.726 156.726 0 0 1-6.437-5.87c7.214-7.889 14.423-17.06 21.459-27.246c12.376-1.098 24.068-2.894 34.671-5.345a134.17 134.17 0 0 1 1.386 6.193ZM87.276 214.515c-7.882 2.783-14.16 2.863-17.955.675c-8.075-4.657-11.432-22.636-6.853-46.752a156.923 156.923 0 0 1 1.869-8.499c10.486 2.32 22.093 3.988 34.498 4.994c7.084 9.967 14.501 19.128 21.976 27.15a134.668 134.668 0 0 1-4.877 4.492c-9.933 8.682-19.886 14.842-28.658 17.94ZM50.35 144.747c-12.483-4.267-22.792-9.812-29.858-15.863c-6.35-5.437-9.555-10.836-9.555-15.216c0-9.322 13.897-21.212 37.076-29.293c2.813-.98 5.757-1.905 8.812-2.773c3.204 10.42 7.406 21.315 12.477 32.332c-5.137 11.18-9.399 22.249-12.634 32.792a134.718 134.718 0 0 1-6.318-1.979Zm12.378-84.26c-4.811-24.587-1.616-43.134 6.425-47.789c8.564-4.958 27.502 2.111 47.463 19.835a144.318 144.318 0 0 1 3.841 3.545c-7.438 7.987-14.787 17.08-21.808 26.988c-12.04 1.116-23.565 2.908-34.161 5.309a160.342 160.342 0 0 1-1.76-7.887Zm110.427 27.268a347.8 347.8 0 0 0-7.785-12.803c8.168 1.033 15.994 2.404 23.343 4.08c-2.206 7.072-4.956 14.465-8.193 22.045a381.151 381.151 0 0 0-7.365-13.322Zm-45.032-43.861c5.044 5.465 10.096 11.566 15.065 18.186a322.04 322.04 0 0 0-30.257-.006c4.974-6.559 10.069-12.652 15.192-18.18ZM82.802 87.83a323.167 323.167 0 0 0-7.227 13.238c-3.184-7.553-5.909-14.98-8.134-22.152c7.304-1.634 15.093-2.97 23.209-3.984a321.524 321.524 0 0 0-7.848 12.897Zm8.081 65.352c-8.385-.936-16.291-2.203-23.593-3.793c2.26-7.3 5.045-14.885 8.298-22.6a321.187 321.187 0 0 0 7.257 13.246c2.594 4.48 5.28 8.868 8.038 13.147Zm37.542 31.03c-5.184-5.592-10.354-11.779-15.403-18.433c4.902.192 9.899.29 14.978.29c5.218 0 10.376-.117 15.453-.343c-4.985 6.774-10.018 12.97-15.028 18.486Zm52.198-57.817c3.422 7.8 6.306 15.345 8.596 22.52c-7.422 1.694-15.436 3.058-23.88 4.071a382.417 382.417 0 0 0 7.859-13.026a347.403 347.403 0 0 0 7.425-13.565Zm-16.898 8.101a358.557 358.557 0 0 1-12.281 19.815a329.4 329.4 0 0 1-23.444.823c-7.967 0-15.716-.248-23.178-.732a310.202 310.202 0 0 1-12.513-19.846h.001a307.41 307.41 0 0 1-10.923-20.627a310.278 310.278 0 0 1 10.89-20.637l-.001.001a307.318 307.318 0 0 1 12.413-19.761c7.613-.576 15.42-.876 23.31-.876H128c7.926 0 15.743.303 23.354.883a329.357 329.357 0 0 1 12.335 19.695a358.489 358.489 0 0 1 11.036 20.54a329.472 329.472 0 0 1-11 20.722Zm22.56-122.124c8.572 4.944 11.906 24.881 6.52 51.026c-.344 1.668-.73 3.367-1.15 5.09c-10.622-2.452-22.155-4.275-34.23-5.408c-7.034-10.017-14.323-19.124-21.64-27.008a160.789 160.789 0 0 1 5.888-5.4c18.9-16.447 36.564-22.941 44.612-18.3ZM128 90.808c12.625 0 22.86 10.235 22.86 22.86s-10.235 22.86-22.86 22.86s-22.86-10.235-22.86-22.86s10.235-22.86 22.86-22.86Z"></path></svg>
|
||||
|
After Width: | Height: | Size: 4.0 KiB |
1
api-dashboard/src/assets/vite.svg
Normal file
|
After Width: | Height: | Size: 8.5 KiB |
73
api-dashboard/src/index.css
Normal file
@@ -0,0 +1,73 @@
|
||||
@import url('https://fonts.googleapis.com/css2?family=Inter:wght@300;400;500;600;700;800;900&display=swap');
|
||||
|
||||
:root {
|
||||
--font-sans: "Inter", "system-ui", "-apple-system", "sans-serif";
|
||||
--color-primary: #08a850;
|
||||
--color-primary-light: #0cb859;
|
||||
--color-primary-dark: #068d42;
|
||||
--color-primary-glow: rgba(8, 168, 80, 0.06);
|
||||
--color-bg-main: #f4fbf7;
|
||||
--color-bg-sidebar: #ffffff;
|
||||
--color-text-dark: #001828;
|
||||
--color-text-primary: #0f172a;
|
||||
--color-text-secondary: #475569;
|
||||
--color-text-muted: #94a3b8;
|
||||
--color-border: rgba(0, 24, 40, 0.08);
|
||||
--color-border-light: rgba(0, 24, 40, 0.04);
|
||||
--color-danger: #ef4444;
|
||||
--color-danger-glow: rgba(239, 68, 68, 0.08);
|
||||
--color-warning: #ea580c;
|
||||
--color-warning-glow: rgba(234, 88, 12, 0.08);
|
||||
--color-card-bg: #ffffff;
|
||||
--shadow-sm: 0 1px 2px 0 rgba(0, 0, 0, 0.05);
|
||||
--shadow-md: 0 4px 6px -1px rgba(0, 0, 0, 0.05), 0 2px 4px -1px rgba(0, 0, 0, 0.03);
|
||||
--shadow-lg: 0 10px 15px -3px rgba(0, 0, 0, 0.05), 0 4px 6px -2px rgba(0, 0, 0, 0.03);
|
||||
--shadow-xl: 0 20px 25px -5px rgba(8, 168, 80, 0.04), 0 10px 10px -5px rgba(8, 168, 80, 0.02);
|
||||
}
|
||||
|
||||
* {
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
box-sizing: border-box;
|
||||
border-color: var(--color-border);
|
||||
}
|
||||
|
||||
body {
|
||||
font-family: var(--font-sans);
|
||||
background-color: var(--color-bg-main);
|
||||
color: var(--color-text-primary);
|
||||
min-height: 100vh;
|
||||
line-height: 1.5;
|
||||
-webkit-font-smoothing: antialiased;
|
||||
-moz-osx-font-smoothing: grayscale;
|
||||
}
|
||||
|
||||
#root {
|
||||
min-height: 100vh;
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
}
|
||||
|
||||
/* Custom Scrollbars */
|
||||
* {
|
||||
scrollbar-width: thin;
|
||||
scrollbar-color: var(--color-border) transparent;
|
||||
}
|
||||
|
||||
::-webkit-scrollbar {
|
||||
width: 6px;
|
||||
height: 6px;
|
||||
}
|
||||
|
||||
::-webkit-scrollbar-track {
|
||||
background: transparent;
|
||||
}
|
||||
|
||||
::-webkit-scrollbar-thumb {
|
||||
background-color: var(--color-border);
|
||||
border-radius: 10px;
|
||||
}
|
||||
|
||||
::-webkit-scrollbar-thumb:hover {
|
||||
background-color: var(--color-text-muted);
|
||||
}
|
||||
10
api-dashboard/src/main.tsx
Normal file
@@ -0,0 +1,10 @@
|
||||
import { StrictMode } from 'react'
|
||||
import { createRoot } from 'react-dom/client'
|
||||
import './index.css'
|
||||
import App from './App.tsx'
|
||||
|
||||
createRoot(document.getElementById('root')!).render(
|
||||
<StrictMode>
|
||||
<App />
|
||||
</StrictMode>,
|
||||
)
|
||||
26
api-dashboard/tsconfig.app.json
Normal file
@@ -0,0 +1,26 @@
|
||||
{
|
||||
"compilerOptions": {
|
||||
"tsBuildInfoFile": "./node_modules/.tmp/tsconfig.app.tsbuildinfo",
|
||||
"target": "es2023",
|
||||
"lib": ["ES2023", "DOM"],
|
||||
"module": "esnext",
|
||||
"types": ["vite/client"],
|
||||
"allowArbitraryExtensions": true,
|
||||
"skipLibCheck": true,
|
||||
|
||||
/* Bundler mode */
|
||||
"moduleResolution": "bundler",
|
||||
"allowImportingTsExtensions": true,
|
||||
"verbatimModuleSyntax": true,
|
||||
"moduleDetection": "force",
|
||||
"noEmit": true,
|
||||
"jsx": "react-jsx",
|
||||
|
||||
/* Linting */
|
||||
"noUnusedLocals": true,
|
||||
"noUnusedParameters": true,
|
||||
"erasableSyntaxOnly": true,
|
||||
"noFallthroughCasesInSwitch": true
|
||||
},
|
||||
"include": ["src"]
|
||||
}
|
||||
7
api-dashboard/tsconfig.json
Normal file
@@ -0,0 +1,7 @@
|
||||
{
|
||||
"files": [],
|
||||
"references": [
|
||||
{ "path": "./tsconfig.app.json" },
|
||||
{ "path": "./tsconfig.node.json" }
|
||||
]
|
||||
}
|
||||
23
api-dashboard/tsconfig.node.json
Normal file
@@ -0,0 +1,23 @@
|
||||
{
|
||||
"compilerOptions": {
|
||||
"tsBuildInfoFile": "./node_modules/.tmp/tsconfig.node.tsbuildinfo",
|
||||
"target": "es2023",
|
||||
"lib": ["ES2023"],
|
||||
"types": ["node"],
|
||||
"skipLibCheck": true,
|
||||
|
||||
/* Bundler mode */
|
||||
"module": "nodenext",
|
||||
"allowImportingTsExtensions": true,
|
||||
"verbatimModuleSyntax": true,
|
||||
"moduleDetection": "force",
|
||||
"noEmit": true,
|
||||
|
||||
/* Linting */
|
||||
"noUnusedLocals": true,
|
||||
"noUnusedParameters": true,
|
||||
"erasableSyntaxOnly": true,
|
||||
"noFallthroughCasesInSwitch": true
|
||||
},
|
||||
"include": ["vite.config.ts"]
|
||||
}
|
||||
7
api-dashboard/vite.config.ts
Normal file
@@ -0,0 +1,7 @@
|
||||
import { defineConfig } from 'vite'
|
||||
import react from '@vitejs/plugin-react'
|
||||
|
||||
// https://vite.dev/config/
|
||||
export default defineConfig({
|
||||
plugins: [react()],
|
||||
})
|
||||
@@ -82,6 +82,8 @@ public class SecurityConfig {
|
||||
.requestMatchers(HttpMethod.PUT, "/api/auth/users/*").authenticated()
|
||||
.requestMatchers(HttpMethod.PUT, "/api/orders/*").authenticated()
|
||||
.requestMatchers(HttpMethod.POST, "/api/orders/*/cancel").authenticated()
|
||||
.requestMatchers("/api/developer-keys/**").authenticated()
|
||||
.requestMatchers("/api/developer/v1/**").permitAll()
|
||||
.requestMatchers("/api/counter/**").hasAnyRole("MASTER", "MANAGER", "STAFF")
|
||||
|
||||
// ── STAFF/MANAGER/MASTER: All other management APIs ──
|
||||
|
||||
@@ -0,0 +1,515 @@
|
||||
package com.rit.canteen.sales.controller;
|
||||
|
||||
import com.rit.canteen.sales.model.*;
|
||||
import com.rit.canteen.sales.repository.*;
|
||||
import com.rit.canteen.sales.service.DeveloperApiKeyService;
|
||||
import com.rit.canteen.sales.service.TokenService;
|
||||
import com.rit.canteen.sales.service.SystemNotificationService;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
import org.springframework.transaction.annotation.Transactional;
|
||||
|
||||
import java.math.BigDecimal;
|
||||
import java.time.LocalDateTime;
|
||||
import java.util.*;
|
||||
import java.util.stream.Collectors;
|
||||
|
||||
@RestController
|
||||
@RequestMapping("/api/developer/v1")
|
||||
public class DeveloperApiController {
|
||||
|
||||
@Autowired
|
||||
private DeveloperApiKeyService keyService;
|
||||
|
||||
@Autowired
|
||||
private StallRepository stallRepository;
|
||||
|
||||
@Autowired
|
||||
private ProductRepository productRepository;
|
||||
|
||||
@Autowired
|
||||
private UserRepository userRepository;
|
||||
|
||||
@Autowired
|
||||
private OrderRepository orderRepository;
|
||||
|
||||
@Autowired
|
||||
private TokenTransactionRepository transactionRepository;
|
||||
|
||||
@Autowired
|
||||
private TokenService tokenService;
|
||||
|
||||
@Autowired
|
||||
private SystemNotificationService notificationService;
|
||||
|
||||
@Autowired
|
||||
private StockUpdateController stockUpdateController;
|
||||
|
||||
// ── Helper to authenticate key ─────────────────────────────────────────
|
||||
private DeveloperApiKey authenticate(String headerKey) {
|
||||
if (headerKey == null || headerKey.trim().isEmpty()) {
|
||||
return null;
|
||||
}
|
||||
return keyService.validateAndUseKey(headerKey).orElse(null);
|
||||
}
|
||||
|
||||
private boolean checkPermission(DeveloperApiKey key, String requiredScope) {
|
||||
if (key == null) return false;
|
||||
|
||||
// If the operation requires write access but the key doesn't have it, block immediately.
|
||||
if (requiredScope.startsWith("WRITE_") && !key.isWriteAccess()) {
|
||||
return false;
|
||||
}
|
||||
|
||||
// If it's a customer key, they only get default read-only scopes.
|
||||
if (!"SYSTEM".equalsIgnoreCase(key.getUserType())) {
|
||||
return requiredScope.startsWith("READ_");
|
||||
}
|
||||
|
||||
// System users get custom scopes.
|
||||
String scopes = key.getPermissions();
|
||||
if (scopes == null || scopes.trim().isEmpty()) {
|
||||
return false;
|
||||
}
|
||||
|
||||
return Arrays.stream(scopes.split(","))
|
||||
.map(String::trim)
|
||||
.anyMatch(scope -> scope.equalsIgnoreCase(requiredScope));
|
||||
}
|
||||
|
||||
// ── 1. Validate API Key ────────────────────────────────────────────────
|
||||
@GetMapping("/validate")
|
||||
public ResponseEntity<?> validateKey(@RequestHeader(value = "X-Developer-Key", required = false) String headerKey) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
return ResponseEntity.ok(Map.of(
|
||||
"status", "VALID",
|
||||
"name", key.getName(),
|
||||
"ownerType", key.getUserType(),
|
||||
"createdAt", key.getCreatedAt(),
|
||||
"readOnly", !key.isWriteAccess(),
|
||||
"permissions", key.getPermissions() != null ? Arrays.asList(key.getPermissions().split(",")) : Collections.emptyList()
|
||||
));
|
||||
}
|
||||
|
||||
// ── 2. Get Stalls (Read-only, non-financial) ───────────────────────────
|
||||
@GetMapping("/stalls")
|
||||
public ResponseEntity<?> getStalls(@RequestHeader(value = "X-Developer-Key", required = false) String headerKey) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "READ_STALLS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: READ_STALLS permission required"));
|
||||
}
|
||||
|
||||
List<Stall> stalls = stallRepository.findAll();
|
||||
// Map to DTO to avoid circular references and hide sensitive fields
|
||||
List<Map<String, Object>> result = stalls.stream().map(s -> {
|
||||
Map<String, Object> map = new HashMap<>();
|
||||
map.put("id", s.getId());
|
||||
map.put("name", s.getName());
|
||||
map.put("description", s.getDescription());
|
||||
map.put("active", s.isActive());
|
||||
map.put("temporarilyClosed", s.isTemporarilyClosed());
|
||||
return map;
|
||||
}).collect(Collectors.toList());
|
||||
|
||||
return ResponseEntity.ok(result);
|
||||
}
|
||||
|
||||
// ── 3. Get Products (Read-only, non-financial) ─────────────────────────
|
||||
@GetMapping("/products")
|
||||
public ResponseEntity<?> getProducts(@RequestHeader(value = "X-Developer-Key", required = false) String headerKey) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "READ_PRODUCTS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: READ_PRODUCTS permission required"));
|
||||
}
|
||||
|
||||
List<Product> products = productRepository.findAll();
|
||||
List<Map<String, Object>> result = products.stream().map(p -> {
|
||||
Map<String, Object> map = new HashMap<>();
|
||||
map.put("id", p.getId());
|
||||
map.put("productId", p.getProductId());
|
||||
map.put("name", p.getName());
|
||||
map.put("category", p.getCategory());
|
||||
map.put("price", p.getPrice()); // List price is fine for catalog, not a financial report
|
||||
map.put("stock", p.getStock());
|
||||
map.put("active", p.isActive());
|
||||
map.put("isDraft", p.isDraft());
|
||||
return map;
|
||||
}).collect(Collectors.toList());
|
||||
|
||||
return ResponseEntity.ok(result);
|
||||
}
|
||||
|
||||
@GetMapping("/wallet")
|
||||
public ResponseEntity<?> getWallet(
|
||||
@RequestHeader(value = "X-Developer-Key", required = false) String headerKey,
|
||||
@RequestParam(required = false) String mobileNumber,
|
||||
@RequestParam(required = false) Long userId) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "READ_WALLETS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: READ_WALLETS permission required"));
|
||||
}
|
||||
|
||||
// ── Check if checking balance for another user by mobileNumber or userId ──
|
||||
if (mobileNumber != null || userId != null) {
|
||||
Optional<User> targetUserOpt = Optional.empty();
|
||||
if (userId != null) {
|
||||
targetUserOpt = userRepository.findById(userId);
|
||||
} else {
|
||||
targetUserOpt = userRepository.findByMobileNumber(mobileNumber);
|
||||
}
|
||||
|
||||
if (targetUserOpt.isPresent()) {
|
||||
User user = targetUserOpt.get();
|
||||
return ResponseEntity.ok(Map.of(
|
||||
"userMobile", user.getMobileNumber(),
|
||||
"userName", user.getName() != null ? user.getName() : "Customer",
|
||||
"ritzTokenBalance", user.getRitzTokenBalance(),
|
||||
"currency", "Ritz Token",
|
||||
"queryScope", "SPECIFIC_USER"
|
||||
));
|
||||
} else {
|
||||
return ResponseEntity.status(404).body(Map.of("error", "Target user not found"));
|
||||
}
|
||||
}
|
||||
|
||||
if ("CUSTOMER".equals(key.getUserType())) {
|
||||
// Customer key: return their specific wallet balance
|
||||
Optional<User> userOpt = userRepository.findById(key.getUserId());
|
||||
if (userOpt.isPresent()) {
|
||||
User user = userOpt.get();
|
||||
return ResponseEntity.ok(Map.of(
|
||||
"userMobile", user.getMobileNumber(),
|
||||
"userName", user.getName() != null ? user.getName() : "Customer",
|
||||
"ritzTokenBalance", user.getRitzTokenBalance(),
|
||||
"currency", "Ritz Token",
|
||||
"queryScope", "OWNER"
|
||||
));
|
||||
}
|
||||
return ResponseEntity.status(404).body(Map.of("error", "Owner user not found"));
|
||||
} else {
|
||||
// System key: return overall token circulation stats, but NO individual user accounts or detailed ledgers
|
||||
List<User> allUsers = userRepository.findAll();
|
||||
BigDecimal totalCirculation = allUsers.stream()
|
||||
.map(User::getRitzTokenBalance)
|
||||
.reduce(BigDecimal.ZERO, BigDecimal::add);
|
||||
|
||||
return ResponseEntity.ok(Map.of(
|
||||
"scope", "SYSTEM_CIRCULATION",
|
||||
"activeWalletsCount", allUsers.size(),
|
||||
"totalCirculationBalance", totalCirculation,
|
||||
"currency", "Ritz Token",
|
||||
"queryScope", "SYSTEM"
|
||||
));
|
||||
}
|
||||
}
|
||||
|
||||
// ── 5. Get Orders (requires READ_ORDERS) ────────────────────────────────
|
||||
@GetMapping("/orders")
|
||||
public ResponseEntity<?> getOrders(@RequestHeader(value = "X-Developer-Key", required = false) String headerKey) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "READ_ORDERS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: READ_ORDERS permission required"));
|
||||
}
|
||||
|
||||
List<Order> orders;
|
||||
if ("CUSTOMER".equals(key.getUserType())) {
|
||||
orders = orderRepository.findByUserIdOrderByCreatedAtDesc(key.getUserId());
|
||||
} else {
|
||||
orders = orderRepository.findAll();
|
||||
}
|
||||
|
||||
// Map to DTO. Financial details (totalAmount, paymentMethod, item prices) are only exposed for staff/SYSTEM keys.
|
||||
List<Map<String, Object>> result = orders.stream().map(o -> {
|
||||
Map<String, Object> map = new HashMap<>();
|
||||
map.put("id", o.getId());
|
||||
map.put("orderNumber", o.getOrderNumber());
|
||||
map.put("displayOrderId", o.getDisplayOrderId());
|
||||
map.put("status", o.getStatus());
|
||||
map.put("createdAt", o.getCreatedAt());
|
||||
map.put("orderType", o.getOrderType());
|
||||
|
||||
if ("SYSTEM".equalsIgnoreCase(key.getUserType())) {
|
||||
map.put("totalAmount", o.getTotalAmount());
|
||||
map.put("paymentMethod", o.getPaymentMethod());
|
||||
}
|
||||
|
||||
List<Map<String, Object>> itemsList = o.getItems().stream().map(item -> {
|
||||
Map<String, Object> itemMap = new HashMap<>();
|
||||
itemMap.put("productName", item.getProductName());
|
||||
itemMap.put("quantity", item.getQuantity());
|
||||
itemMap.put("stallName", item.getStallName());
|
||||
if ("SYSTEM".equalsIgnoreCase(key.getUserType())) {
|
||||
itemMap.put("price", item.getPrice());
|
||||
}
|
||||
return itemMap;
|
||||
}).collect(Collectors.toList());
|
||||
|
||||
map.put("items", itemsList);
|
||||
return map;
|
||||
}).collect(Collectors.toList());
|
||||
|
||||
return ResponseEntity.ok(result);
|
||||
}
|
||||
|
||||
// ── 5a. Get Wallet Transactions (requires READ_WALLETS & SYSTEM key) ─────
|
||||
@GetMapping("/wallet/transactions")
|
||||
public ResponseEntity<?> getWalletTransactions(@RequestHeader(value = "X-Developer-Key", required = false) String headerKey) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!"SYSTEM".equalsIgnoreCase(key.getUserType())) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: Only staff keys can view general transaction records"));
|
||||
}
|
||||
if (!checkPermission(key, "READ_WALLETS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: READ_WALLETS permission required"));
|
||||
}
|
||||
return ResponseEntity.ok(tokenService.getAllTransactions());
|
||||
}
|
||||
|
||||
// ── 5b. Get Wallet Circulation Stats (requires READ_WALLETS & SYSTEM key) ──
|
||||
@GetMapping("/wallet/stats")
|
||||
public ResponseEntity<?> getWalletStats(@RequestHeader(value = "X-Developer-Key", required = false) String headerKey) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!"SYSTEM".equalsIgnoreCase(key.getUserType())) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: Only staff keys can view wallet statistics"));
|
||||
}
|
||||
if (!checkPermission(key, "READ_WALLETS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: READ_WALLETS permission required"));
|
||||
}
|
||||
return ResponseEntity.ok(tokenService.getGlobalStats());
|
||||
}
|
||||
|
||||
// ── 6. Create Stall (requires WRITE_STALLS) ───────────────────────────
|
||||
@PostMapping("/stalls")
|
||||
public ResponseEntity<?> createStall(
|
||||
@RequestHeader(value = "X-Developer-Key", required = false) String headerKey,
|
||||
@RequestBody Stall stall) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "WRITE_STALLS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: WRITE_STALLS permission required"));
|
||||
}
|
||||
Stall saved = stallRepository.save(stall);
|
||||
return ResponseEntity.status(201).body(saved);
|
||||
}
|
||||
|
||||
// ── 7. Update Stall (requires WRITE_STALLS) ───────────────────────────
|
||||
@PutMapping("/stalls/{id}")
|
||||
@Transactional
|
||||
public ResponseEntity<?> updateStall(
|
||||
@RequestHeader(value = "X-Developer-Key", required = false) String headerKey,
|
||||
@PathVariable Long id,
|
||||
@RequestBody Stall updatedStall) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "WRITE_STALLS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: WRITE_STALLS permission required"));
|
||||
}
|
||||
return stallRepository.findById(id).map(stall -> {
|
||||
stall.setName(updatedStall.getName());
|
||||
stall.setDescription(updatedStall.getDescription());
|
||||
stall.setActive(updatedStall.isActive());
|
||||
stall.setTemporarilyClosed(updatedStall.isTemporarilyClosed());
|
||||
stall.setSessionOptional(updatedStall.isSessionOptional());
|
||||
return ResponseEntity.ok(stallRepository.save(stall));
|
||||
}).orElse(ResponseEntity.notFound().build());
|
||||
}
|
||||
|
||||
// ── 8. Delete Stall (requires WRITE_STALLS) ───────────────────────────
|
||||
@DeleteMapping("/stalls/{id}")
|
||||
public ResponseEntity<?> deleteStall(
|
||||
@RequestHeader(value = "X-Developer-Key", required = false) String headerKey,
|
||||
@PathVariable Long id) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "WRITE_STALLS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: WRITE_STALLS permission required"));
|
||||
}
|
||||
return stallRepository.findById(id).map(stall -> {
|
||||
stallRepository.delete(stall);
|
||||
return ResponseEntity.ok(Map.of("success", true, "message", "Stall deleted successfully"));
|
||||
}).orElse(ResponseEntity.notFound().build());
|
||||
}
|
||||
|
||||
// ── 9. Create Product (requires WRITE_PRODUCTS) ───────────────────────
|
||||
@PostMapping("/products")
|
||||
@Transactional
|
||||
public ResponseEntity<?> createProduct(
|
||||
@RequestHeader(value = "X-Developer-Key", required = false) String headerKey,
|
||||
@RequestBody Product product) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "WRITE_PRODUCTS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: WRITE_PRODUCTS permission required"));
|
||||
}
|
||||
Product saved = productRepository.save(product);
|
||||
if (saved.isDraft()) {
|
||||
notificationService.createNotification(
|
||||
"Draft Product Created via API",
|
||||
"A product draft '" + saved.getName() + "' was created via developer API key.",
|
||||
"PRODUCT",
|
||||
"/inventory/products"
|
||||
);
|
||||
}
|
||||
return ResponseEntity.status(201).body(saved);
|
||||
}
|
||||
|
||||
// ── 10. Update Product (requires WRITE_PRODUCTS) ───────────────────────
|
||||
@PutMapping("/products/{id}")
|
||||
@Transactional
|
||||
public ResponseEntity<?> updateProduct(
|
||||
@RequestHeader(value = "X-Developer-Key", required = false) String headerKey,
|
||||
@PathVariable Long id,
|
||||
@RequestBody Product details) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "WRITE_PRODUCTS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: WRITE_PRODUCTS permission required"));
|
||||
}
|
||||
return productRepository.findById(id).map(p -> {
|
||||
p.setProductId(details.getProductId());
|
||||
p.setName(details.getName());
|
||||
p.setCategory(details.getCategory());
|
||||
p.setDescription(details.getDescription());
|
||||
p.setPrice(details.getPrice());
|
||||
p.setStock(details.getStock());
|
||||
p.setActive(details.isActive());
|
||||
p.setVeg(details.isVeg());
|
||||
|
||||
Product updated = productRepository.save(p);
|
||||
stockUpdateController.broadcastStockUpdate(updated.getId(), updated.getStock());
|
||||
return ResponseEntity.ok(updated);
|
||||
}).orElse(ResponseEntity.notFound().build());
|
||||
}
|
||||
|
||||
// ── 11. Delete Product (requires WRITE_PRODUCTS) ──────────────────────
|
||||
@DeleteMapping("/products/{id}")
|
||||
public ResponseEntity<?> deleteProduct(
|
||||
@RequestHeader(value = "X-Developer-Key", required = false) String headerKey,
|
||||
@PathVariable Long id) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "WRITE_PRODUCTS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: WRITE_PRODUCTS permission required"));
|
||||
}
|
||||
return productRepository.findById(id).map(p -> {
|
||||
productRepository.delete(p);
|
||||
return ResponseEntity.ok(Map.of("success", true, "message", "Product deleted successfully"));
|
||||
}).orElse(ResponseEntity.notFound().build());
|
||||
}
|
||||
|
||||
// ── 12. Update Order Status (requires WRITE_ORDERS) ───────────────────
|
||||
@PatchMapping("/orders/{id}/status")
|
||||
@Transactional
|
||||
public ResponseEntity<?> updateOrderStatus(
|
||||
@RequestHeader(value = "X-Developer-Key", required = false) String headerKey,
|
||||
@PathVariable Long id,
|
||||
@RequestBody Map<String, String> body) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "WRITE_ORDERS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: WRITE_ORDERS permission required"));
|
||||
}
|
||||
String newStatus = body.get("status");
|
||||
if (newStatus == null || newStatus.isEmpty()) {
|
||||
return ResponseEntity.badRequest().body(Map.of("error", "Status field is required"));
|
||||
}
|
||||
return orderRepository.findById(id).map(order -> {
|
||||
String oldStatus = order.getStatus();
|
||||
String nextStatus = newStatus.toUpperCase();
|
||||
if ("CANCELLED".equals(nextStatus) && !"CANCELLED".equals(oldStatus)) {
|
||||
if ("RITZ_TOKEN".equals(order.getPaymentMethod())) {
|
||||
tokenService.refund(order.getUserId(), "ORD-" + order.getDisplayOrderId(),
|
||||
order.getTotalAmount(), "Status changed to CANCELLED via API");
|
||||
}
|
||||
}
|
||||
order.setStatus(nextStatus);
|
||||
orderRepository.save(order);
|
||||
return ResponseEntity.ok(Map.of("success", true, "message", "Order status updated to " + nextStatus));
|
||||
}).orElse(ResponseEntity.notFound().build());
|
||||
}
|
||||
|
||||
// ── 13. Wallet Topup (requires WRITE_WALLETS) ──────────────────────────
|
||||
@PostMapping("/wallet/topup")
|
||||
@Transactional
|
||||
public ResponseEntity<?> walletTopup(
|
||||
@RequestHeader(value = "X-Developer-Key", required = false) String headerKey,
|
||||
@RequestBody Map<String, Object> body) {
|
||||
DeveloperApiKey key = authenticate(headerKey);
|
||||
if (key == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Invalid or missing X-Developer-Key header"));
|
||||
}
|
||||
if (!checkPermission(key, "WRITE_WALLETS")) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", "Access Denied: WRITE_WALLETS permission required"));
|
||||
}
|
||||
|
||||
try {
|
||||
Long targetUserId = null;
|
||||
if (body.containsKey("userId") && body.get("userId") != null) {
|
||||
targetUserId = Long.valueOf(body.get("userId").toString());
|
||||
} else if (body.containsKey("mobileNumber") && body.get("mobileNumber") != null) {
|
||||
String mobile = body.get("mobileNumber").toString();
|
||||
User targetUser = userRepository.findByMobileNumber(mobile).orElse(null);
|
||||
if (targetUser != null) {
|
||||
targetUserId = targetUser.getId();
|
||||
} else {
|
||||
return ResponseEntity.status(404).body(Map.of("error", "User with mobile number " + mobile + " not found"));
|
||||
}
|
||||
} else {
|
||||
return ResponseEntity.badRequest().body(Map.of("error", "userId or mobileNumber is required"));
|
||||
}
|
||||
|
||||
BigDecimal amount = new BigDecimal(body.get("amount").toString());
|
||||
if (amount.compareTo(new BigDecimal("50")) < 0) {
|
||||
return ResponseEntity.badRequest().body(Map.of("error", "Minimum top up amount is 50 tokens"));
|
||||
}
|
||||
if (amount.compareTo(new BigDecimal("5000")) > 0) {
|
||||
return ResponseEntity.badRequest().body(Map.of("error", "Single transaction limit exceeded (Max: 5000 tokens)"));
|
||||
}
|
||||
|
||||
String ref = body.getOrDefault("referenceId", "API-TOPUP-" + System.currentTimeMillis()).toString();
|
||||
User updatedUser = tokenService.topUp(targetUserId, amount, ref);
|
||||
return ResponseEntity.ok(Map.of(
|
||||
"success", true,
|
||||
"newBalance", updatedUser.getRitzTokenBalance(),
|
||||
"message", "Successfully added " + amount + " Ritz Tokens via API Key"
|
||||
));
|
||||
} catch (Exception e) {
|
||||
return ResponseEntity.status(500).body(Map.of("error", e.getMessage()));
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,120 @@
|
||||
package com.rit.canteen.sales.controller;
|
||||
|
||||
import com.rit.canteen.sales.model.DeveloperApiKey;
|
||||
import com.rit.canteen.sales.service.DeveloperApiKeyService;
|
||||
import io.jsonwebtoken.Claims;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.security.core.Authentication;
|
||||
import org.springframework.security.core.context.SecurityContextHolder;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
import java.util.List;
|
||||
import java.util.Map;
|
||||
|
||||
@RestController
|
||||
@RequestMapping("/api/developer-keys")
|
||||
public class DeveloperApiKeyController {
|
||||
|
||||
@Autowired
|
||||
private DeveloperApiKeyService keyService;
|
||||
|
||||
@GetMapping
|
||||
public ResponseEntity<?> listKeys() {
|
||||
UserContext context = getUserContext();
|
||||
if (context == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Unauthorized"));
|
||||
}
|
||||
List<DeveloperApiKey> keys = keyService.getKeysForUser(context.userId, context.userType);
|
||||
return ResponseEntity.ok(keys);
|
||||
}
|
||||
|
||||
@PostMapping
|
||||
public ResponseEntity<?> createKey(@RequestBody Map<String, Object> body) {
|
||||
UserContext context = getUserContext();
|
||||
if (context == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Unauthorized"));
|
||||
}
|
||||
String name = body.containsKey("name") && body.get("name") != null
|
||||
? body.get("name").toString()
|
||||
: "My API Key";
|
||||
|
||||
boolean writeAccess = false;
|
||||
String permissions = "";
|
||||
|
||||
if ("SYSTEM".equalsIgnoreCase(context.userType)) {
|
||||
Object writeVal = body.get("writeAccess");
|
||||
if (writeVal instanceof Boolean) {
|
||||
writeAccess = (Boolean) writeVal;
|
||||
} else if (writeVal != null) {
|
||||
writeAccess = Boolean.parseBoolean(writeVal.toString());
|
||||
}
|
||||
permissions = body.containsKey("permissions") && body.get("permissions") != null
|
||||
? body.get("permissions").toString()
|
||||
: "";
|
||||
} else {
|
||||
permissions = "READ_PRODUCTS,READ_STALLS,READ_ORDERS,READ_WALLETS";
|
||||
}
|
||||
|
||||
try {
|
||||
DeveloperApiKey newKey = keyService.createKey(context.userId, context.userType, context.identifier, name, writeAccess, permissions);
|
||||
return ResponseEntity.status(201).body(newKey);
|
||||
} catch (IllegalStateException e) {
|
||||
return ResponseEntity.badRequest().body(Map.of("error", e.getMessage()));
|
||||
}
|
||||
}
|
||||
|
||||
@DeleteMapping("/{id}")
|
||||
public ResponseEntity<?> deleteKey(@PathVariable Long id) {
|
||||
UserContext context = getUserContext();
|
||||
if (context == null) {
|
||||
return ResponseEntity.status(401).body(Map.of("error", "Unauthorized"));
|
||||
}
|
||||
try {
|
||||
keyService.deleteKey(id, context.userId, context.userType);
|
||||
return ResponseEntity.ok(Map.of("success", true, "message", "API Key revoked successfully"));
|
||||
} catch (SecurityException e) {
|
||||
return ResponseEntity.status(403).body(Map.of("error", e.getMessage()));
|
||||
}
|
||||
}
|
||||
|
||||
// ── Helper UserContext parser ──────────────────────────────────────────
|
||||
|
||||
private UserContext getUserContext() {
|
||||
Authentication auth = SecurityContextHolder.getContext().getAuthentication();
|
||||
if (auth == null || !auth.isAuthenticated()) return null;
|
||||
|
||||
if (auth.getDetails() instanceof Claims claims) {
|
||||
Long userId;
|
||||
Object uid = claims.get("userId");
|
||||
if (uid instanceof Integer) {
|
||||
userId = ((Integer) uid).longValue();
|
||||
} else if (uid instanceof Long) {
|
||||
userId = (Long) uid;
|
||||
} else if (uid != null) {
|
||||
userId = Long.valueOf(uid.toString());
|
||||
} else {
|
||||
return null;
|
||||
}
|
||||
|
||||
String type = (String) claims.get("type");
|
||||
String userType = "customer".equals(type) ? "CUSTOMER" : "SYSTEM";
|
||||
String identifier = claims.getSubject();
|
||||
|
||||
return new UserContext(userId, userType, identifier);
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
private static class UserContext {
|
||||
final Long userId;
|
||||
final String userType;
|
||||
final String identifier;
|
||||
|
||||
UserContext(Long userId, String userType, String identifier) {
|
||||
this.userId = userId;
|
||||
this.userType = userType;
|
||||
this.identifier = identifier;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,137 @@
|
||||
package com.rit.canteen.sales.model;
|
||||
|
||||
import jakarta.persistence.*;
|
||||
import java.time.LocalDateTime;
|
||||
|
||||
@Entity
|
||||
@Table(name = "developer_api_keys")
|
||||
public class DeveloperApiKey {
|
||||
|
||||
@Id
|
||||
@GeneratedValue(strategy = GenerationType.IDENTITY)
|
||||
private Long id;
|
||||
|
||||
@Column(unique = true, nullable = false)
|
||||
private String apiKey;
|
||||
|
||||
@Column(nullable = false)
|
||||
private String name;
|
||||
|
||||
@Column(nullable = false)
|
||||
private Long userId;
|
||||
|
||||
@Column(nullable = false)
|
||||
private String userType; // "SYSTEM" or "CUSTOMER"
|
||||
|
||||
@Column(nullable = false)
|
||||
private String ownerIdentifier; // Email or Mobile Number
|
||||
|
||||
@Column(nullable = false)
|
||||
private boolean active = true;
|
||||
|
||||
@Column(nullable = false, columnDefinition = "boolean default false")
|
||||
private boolean writeAccess = false;
|
||||
|
||||
@Column(nullable = true, length = 1000)
|
||||
private String permissions; // comma-separated scopes (e.g. READ_PRODUCTS,WRITE_PRODUCTS)
|
||||
|
||||
@Column(nullable = false)
|
||||
private LocalDateTime createdAt;
|
||||
|
||||
private LocalDateTime lastUsedAt;
|
||||
|
||||
public DeveloperApiKey() {}
|
||||
|
||||
@PrePersist
|
||||
protected void onCreate() {
|
||||
createdAt = LocalDateTime.now();
|
||||
}
|
||||
|
||||
public Long getId() {
|
||||
return id;
|
||||
}
|
||||
|
||||
public void setId(Long id) {
|
||||
this.id = id;
|
||||
}
|
||||
|
||||
public String getApiKey() {
|
||||
return apiKey;
|
||||
}
|
||||
|
||||
public void setApiKey(String apiKey) {
|
||||
this.apiKey = apiKey;
|
||||
}
|
||||
|
||||
public String getName() {
|
||||
return name;
|
||||
}
|
||||
|
||||
public void setName(String name) {
|
||||
this.name = name;
|
||||
}
|
||||
|
||||
public Long getUserId() {
|
||||
return userId;
|
||||
}
|
||||
|
||||
public void setUserId(Long userId) {
|
||||
this.userId = userId;
|
||||
}
|
||||
|
||||
public String getUserType() {
|
||||
return userType;
|
||||
}
|
||||
|
||||
public void setUserType(String userType) {
|
||||
this.userType = userType;
|
||||
}
|
||||
|
||||
public String getOwnerIdentifier() {
|
||||
return ownerIdentifier;
|
||||
}
|
||||
|
||||
public void setOwnerIdentifier(String ownerIdentifier) {
|
||||
this.ownerIdentifier = ownerIdentifier;
|
||||
}
|
||||
|
||||
public boolean isActive() {
|
||||
return active;
|
||||
}
|
||||
|
||||
public void setActive(boolean active) {
|
||||
this.active = active;
|
||||
}
|
||||
|
||||
public LocalDateTime getCreatedAt() {
|
||||
return createdAt;
|
||||
}
|
||||
|
||||
public void setCreatedAt(LocalDateTime createdAt) {
|
||||
this.createdAt = createdAt;
|
||||
}
|
||||
|
||||
public LocalDateTime getLastUsedAt() {
|
||||
return lastUsedAt;
|
||||
}
|
||||
|
||||
public void setLastUsedAt(LocalDateTime lastUsedAt) {
|
||||
this.lastUsedAt = lastUsedAt;
|
||||
}
|
||||
|
||||
public boolean isWriteAccess() {
|
||||
return writeAccess;
|
||||
}
|
||||
|
||||
public void setWriteAccess(boolean writeAccess) {
|
||||
this.writeAccess = writeAccess;
|
||||
}
|
||||
|
||||
public String getPermissions() {
|
||||
return permissions;
|
||||
}
|
||||
|
||||
public void setPermissions(String permissions) {
|
||||
this.permissions = permissions;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
package com.rit.canteen.sales.repository;
|
||||
|
||||
import com.rit.canteen.sales.model.DeveloperApiKey;
|
||||
import org.springframework.data.jpa.repository.JpaRepository;
|
||||
import java.util.List;
|
||||
import java.util.Optional;
|
||||
|
||||
public interface DeveloperApiKeyRepository extends JpaRepository<DeveloperApiKey, Long> {
|
||||
Optional<DeveloperApiKey> findByApiKey(String apiKey);
|
||||
List<DeveloperApiKey> findByUserIdAndUserType(Long userId, String userType);
|
||||
long countByUserIdAndUserType(Long userId, String userType);
|
||||
}
|
||||
@@ -0,0 +1,74 @@
|
||||
package com.rit.canteen.sales.service;
|
||||
|
||||
import com.rit.canteen.sales.model.DeveloperApiKey;
|
||||
import com.rit.canteen.sales.repository.DeveloperApiKeyRepository;
|
||||
import org.springframework.beans.factory.annotation.Autowired;
|
||||
import org.springframework.stereotype.Service;
|
||||
import org.springframework.transaction.annotation.Transactional;
|
||||
|
||||
import java.time.LocalDateTime;
|
||||
import java.util.List;
|
||||
import java.util.Optional;
|
||||
import java.util.UUID;
|
||||
|
||||
@Service
|
||||
public class DeveloperApiKeyService {
|
||||
|
||||
@Autowired
|
||||
private DeveloperApiKeyRepository repository;
|
||||
|
||||
@Transactional(readOnly = true)
|
||||
public List<DeveloperApiKey> getKeysForUser(Long userId, String userType) {
|
||||
return repository.findByUserIdAndUserType(userId, userType);
|
||||
}
|
||||
|
||||
@Transactional
|
||||
public DeveloperApiKey createKey(Long userId, String userType, String ownerIdentifier, String name, boolean writeAccess, String permissions) {
|
||||
// Enforce the 3 key limit only for regular CUSTOMER users. SYSTEM users (admin/managers) get unlimited keys.
|
||||
if (!"SYSTEM".equalsIgnoreCase(userType)) {
|
||||
long count = repository.countByUserIdAndUserType(userId, userType);
|
||||
if (count >= 3) {
|
||||
throw new IllegalStateException("Maximum limit of 3 API keys reached");
|
||||
}
|
||||
}
|
||||
|
||||
DeveloperApiKey key = new DeveloperApiKey();
|
||||
key.setUserId(userId);
|
||||
key.setUserType(userType);
|
||||
key.setOwnerIdentifier(ownerIdentifier);
|
||||
key.setName(name);
|
||||
key.setWriteAccess(writeAccess);
|
||||
key.setPermissions(permissions);
|
||||
|
||||
// Generate a secure API key
|
||||
String prefix = writeAccess ? "DEV-W-" : "DEV-";
|
||||
String rawKey = prefix + UUID.randomUUID().toString().replace("-", "").toUpperCase();
|
||||
key.setApiKey(rawKey);
|
||||
|
||||
return repository.save(key);
|
||||
}
|
||||
|
||||
@Transactional
|
||||
public void deleteKey(Long keyId, Long userId, String userType) {
|
||||
Optional<DeveloperApiKey> keyOpt = repository.findById(keyId);
|
||||
if (keyOpt.isPresent()) {
|
||||
DeveloperApiKey key = keyOpt.get();
|
||||
if (key.getUserId().equals(userId) && key.getUserType().equals(userType)) {
|
||||
repository.delete(key);
|
||||
} else {
|
||||
throw new SecurityException("Unauthorized to delete this API key");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@Transactional
|
||||
public Optional<DeveloperApiKey> validateAndUseKey(String apiKey) {
|
||||
Optional<DeveloperApiKey> keyOpt = repository.findByApiKey(apiKey);
|
||||
if (keyOpt.isPresent() && keyOpt.get().isActive()) {
|
||||
DeveloperApiKey key = keyOpt.get();
|
||||
key.setLastUsedAt(LocalDateTime.now());
|
||||
return Optional.of(repository.save(key));
|
||||
}
|
||||
return Optional.empty();
|
||||
}
|
||||
}
|
||||