Skip to content

Users API ​

Implementation: front/src/services/api/userService.ts. Request type declarations are in front/src/types/common.ts. All operations use shared Axios JSON requests.

GET /users ​

  • Called from: User Management initial load/search; Create/Edit Permission pages use user-list methods.
  • Query: page, limit, optional search; service defaults to page 1 and limit 1000.
  • Response expected: PaginatedResponse<User> (success, data[], pagination); User Management transforms API users before rendering.
  • Failure: logged and thrown; caller handles load error.
  • Example: GET {VITE_API_BASE_URL}/users?page=1&limit=1000

GET /users/:userId ​

  • Called from: Edit User load and permission flow.
  • Path: userId string.
  • Response expected: success, data: User, optional message.
  • Failure: logged and thrown.
  • Example: GET {VITE_API_BASE_URL}/users/{userId}

POST /users ​

  • Called from: Create User form submission.
  • Body type: UserCreateData — name, email, password; optional role, department, entityName, jobTitle, phone.
  • Response expected: success/data User/message.
  • Failure: logged and thrown.
  • Example: use UserCreateData; do not treat the type as proof of backend requiredness.

PUT /users/:userId ​

  • Called from: Edit User submit and User Management status toggle.
  • Path: userId string.
  • Body type: UserUpdateData — optional name, email, role, department, entityName, jobTitle, phone, status.
  • Response expected: success/data User/message.
  • Failure: logged and thrown.
  • Example: PUT {VITE_API_BASE_URL}/users/{userId} with a partial UserUpdateData JSON object.

DELETE /users/:userId ​

  • Called from: User Management delete action.
  • Path: userId string.
  • Response expected: success and optional message; service returns normalized success/message.
  • Failure: logged and thrown.
  • Example: DELETE {VITE_API_BASE_URL}/users/{userId}

PUT /users/:userId/permissions ​

  • Called from: User Permissions save.
  • Path: userId string.
  • Body: permissions argument typed any; exact request fields cannot be documented safely from this service signature.
  • Response expected: success/data/message.
  • Failure: logged and thrown.
  • Contract note: Not available from frontend source code. Backend/API contract verification required.

GET /users/search?q=... ​

  • Called from: searchUsers; page call site not confirmed in reviewed page sources.
  • Query: q, URL-encoded.
  • Response expected: success/data as User array (or a single value normalized to array), optional message.
  • Failure: logged and thrown.
  • Example: GET {VITE_API_BASE_URL}/users/search?q={encoded-query}

For all endpoints, the exact server-side validation, authorization and error body are not available from frontend source. The shared client handles HTTP 401 as described in API overview.