seahaven-ap/packages/api/openapi/paths/invoices-id.yaml
Adam Moussa 864531b51e
feat(api): portal contract, cookie auth, and domain stubs (AP-51) (#64)
* feat(api): serve portal-shaped health and error envelope

Move liveness to GET /api/health { stage, sha } with a Node 24 image on 8080 so ALB probes and deploy verify do not need auth or a database ping.

* feat(api): switch live auth to host cookie BFF

Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.

* feat(web): add unused cookie SPA API client

Land a credentials-include fetch helper and hand-synced health/me types without wiring pages or domain hooks, so mocks stay the default data path.

* feat(api): add master-data OpenAPI and Hono stubs

* feat(api): add invoice, line, and document stubs

* feat(api): add approval policy, inbox, and activity stubs

* test(web): fix SPA client fetch mock types

* test(web): cast fetch mock call args for tsc

* fix(api): do not default DEV_AUTH_BYPASS outside local migrate

* fix(api): replace invoice lines in a single transaction

* fix(api): create invoices and lines in one transaction

* fix(api): inline GIT_SHA from the image build arg

* fix(api): stop PATCH from skipping the approval workflow

* fix(api): address review feedback

* fix(ci): format upsert-user test

* fix(api): document only the auth statuses the routes return

* fix(api): drop health 400 responses the routes never return
2026-09-25 22:43:44 +00:00

107 lines
2.9 KiB
YAML

parameters:
- name: id
in: path
required: true
description: Invoice primary key.
schema:
type: string
format: uuid
example: 88888888-8888-4888-8888-888888888888
get:
tags: [Invoices]
summary: Get an invoice
description: Returns one invoice and its coding lines.
operationId: get-api-invoices-id
responses:
"200":
description: Invoice.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Invoice
"400":
description: Invalid id.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
"401":
description: Missing session.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
"404":
description: Invoice not found.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
patch:
tags: [Invoices]
summary: Update an invoice
description: Patch header fields. Duplicate active vendor plus invoice number is a conflict.
operationId: patch-api-invoices-id
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
vendorId:
type: string
format: uuid
example: 55555555-5555-4555-8555-555555555555
invoiceNumber:
type: string
example: INV-1001
amount:
type: string
example: "1250.00"
dueDate:
type: string
example: "2026-09-01"
status:
type: string
enum: [void]
description: The only status PATCH may set. Approval and payment statuses go through decision routes.
example: void
paymentMethod:
type: string
enum: [check, ach]
example: ach
memo:
type: string
example: Updated memo
responses:
"200":
description: Updated invoice.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Invoice
"400":
description: Validation failed.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
"403":
description: Caller lacks write:invoices.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
"404":
description: Invoice not found.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
"409":
description: Active vendor and invoice number already exist.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error