Files
clinicpro/docs/api
hamedandClaude Opus 5 fb1cb20c11 feat(representation): let registering reps edit their doctors and clinics
A representative could create a doctor or clinic but not finish its profile:
PATCH /api/v1/doctor/{uuid} accepted only the doctor or an admin, and the
clinic gate ran through ClinicDoctorPermissionChecker, which asks about clinic
membership — a representative is not a member. Onboarding stopped at an empty
public record.

Grant is permanent while representation_id points at the rep, and limited to
content: RepresentationEditPolicy holds ownership plus the field whitelist.
Sending a key outside it aborts the whole request with 403 and names the field,
rather than filtering the payload silently, so a rep never believes a change
saved when it did not. medical_system_code, `active` and clinic `doctors` stay
out — credential, and membership, belong to the record's owner. `active` already
has a dedicated rep endpoint.

ClinicDoctorPermissionChecker is untouched on purpose; folding a second concept
into it would give it two reasons to change.

Doctor/clinic detail responses now carry can_edit, computed by the same policy
the PATCH gate uses, so the panel reads authorization instead of re-deriving it
and drifting. Both endpoints stay public: no token means can_edit false and an
otherwise unchanged payload, which is what nobat724_front consumes.

Address endpoints follow the same policy. createAddress now resolves its target
from an explicit doctor_uuid instead of findByUser first — a representative who
also has a doctor profile was silently writing the address onto their own.

Every rep edit writes one app_log row (channel representation_edit) recording
who, what, and which field names — never values. Owner and admin edits write
nothing, keeping /admin/logs readable.

Docs corrected where they already disagreed with the code: 403/404 error codes
on both PATCH routes, a non-existent "cannot delete the last clinic address"
409, and the missing gallery-size 422.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-08 15:50:17 +03:30
..

ClinicPro — API Documentation Index

Base URL: https://clinic-pro.ddev.site
API Prefix: /api/v1
Swagger UI: https://clinic-pro.ddev.site/api/doc — user: admin / pass: clinic123


Authentication

All protected endpoints require:

Authorization: Bearer <JWT_TOKEN>
Role Description
PUBLIC No token required
AUTH Any valid JWT
ROLE_ADMIN Admin user
ROLE_DOCTOR Doctor user
ROLE_CLINIC Clinic owner
ROLE_SECRETARY Secretary

Standard Response Envelope

// Success
{ "success": true, "data": { ... } }

// Paginated
{ "success": true, "data": [...], "meta": { "totalRecords": 100, "totalPages": 5, "currentPage": 1, "limit": 20 } }

// Error
{ "success": false, "data": null, "errors": [{ "code": "ERR_XXX_000", "message": "..." }] }

meta.limit اندازهٔ صفحهٔ واقعاً اعمال‌شده است. ریپازیتوری‌ها limit درخواستی را به سقف خودشان کاهش می‌دهند (مثلاً لیست پزشکان: سقف ۵۰)، پس برای پیمایش کامل به meta.totalPages تکیه کن — نه به این فرض که «تعداد آیتم کمتر از limit درخواستی یعنی صفحهٔ آخر».


Persian digit normalization (global)

Persian (۰) and Arabic (٠) digits sent in numeric request fields are translated to Latin server-side, before the controller runssrc/Shared/EventSubscriber/NumericFieldNormalizerSubscriber.php. Every client benefits: the React admin panel, nobat724_front, and clinic-pro-tauri.

Applies to POST / PUT / PATCH requests under /api/v1/ with a JSON body, recursively through nested arrays.

Normalized keys:

mobile, mobile_number, telephone, phone, notification_mobile,
national_code, postal_code,
card_number, account_number, sheba, shaba, iban,
price_rials, amount_rials, amount, free_visit_price_rials,
insurance_price_rials, patient_share_rials, visit_price_rials,
duration_minutes, duration, commission_percent, coverage,
coverage_percent, franchise, ceiling, tax_percent,
base_insurance_discount_percent, supplementary_discount_percent

Only digits are translated — no characters are stripped, so IR in a sheba and - in a landline survive. Non-string values (int, bool, null) and keys outside the list are untouched, so a name like منشی شماره ۲ keeps its Persian digit.

// request
{ "mobile_number": "۰۹۱۲۳۴۵۶۷۸۹", "national_code": "۰۰۱۲۳۴۵۶۷۸", "name": "منشی شماره ۲" }

// what the controller sees
{ "mobile_number": "09123456789", "national_code": "0012345678", "name": "منشی شماره ۲" }

Adding a new numeric field to any endpoint? Add its key to NUMERIC_KEYS in the subscriber, otherwise Persian digits reach the database.


Modules

File Domain Endpoints
auth.md Authentication — OTP, Login, JWT 8
doctor.md Doctor profile & addresses 11
clinic.md Clinics 7
practice-domain.md Practice domains — a clinic's field of practice 3
treatment.md Treatment protocols — multi-session courses on a service 3
clinic-invitation.md Doctor invitations to clinics 8
resource.md Resources, types, skills, pools 16
resource-calendar.md Resource calendars, exceptions, national holidays 9
appointment-plan.md Appointment segments and plan preview 3
appointment-availability.md Multi-resource availability search 2
appointment-booking.md Holds, confirmation and multi-resource occupancy 4
pricing.md Date-ranged price lists and appointment invoices 8
appointment.md Appointments & slot booking 6
appointment-settings.md Weekly schedule, date overrides, holidays 14
payment.md Payments (Mellat / Sep) 5
settlement.md Wallet & settlement requests 7
rating.md Ratings, comments, likes 9
secretary.md Doctor secretaries 5
permission.md Permission catalog — single registry of permissionable resources 1
representation.md Representations (agents) 6
sms.md SMS send & templates 10
blog.md Blog posts 6
specialty.md Medical specialties 5
insurance.md Insurances & doctor-insurance links 10
doctor-service.md Doctor services 5
tag.md Blog tags 5
location.md Provinces & cities 10
user-profile.md User medical profile 4
admin.md Admin dashboard & management 25+

Error Code Reference

Code Message (FA) HTTP
ERR_AUTH_001 توکن JWT منقضی یا نامعتبر 401
ERR_AUTH_002 کد OTP نامعتبر 401
ERR_AUTH_003 کد OTP منقضی شده 401
ERR_AUTH_004 تعداد تلاش‌های OTP به حد مجاز رسیده 429
ERR_AUTH_005 نام کاربری یا رمز عبور اشتباه 401
ERR_AUTH_006 دسترسی ممنوع 403
ERR_VALIDATION_001 ورودی نامعتبر 422
ERR_VALIDATION_002 فیلد الزامی وارد نشده 422
ERR_NOT_FOUND_001 منبع درخواستی یافت نشد 404
ERR_CONFLICT_001 تداخل: منبع در حال استفاده 409
ERR_FORBIDDEN_001 دسترسی به این منبع مجاز نیست 403
ERR_PAYMENT_001 درگاه پرداخت در دسترس نیست 503
ERR_PAYMENT_002 مبلغ پرداخت نامعتبر 422
ERR_PAYMENT_003 وضعیت نوبت برای پرداخت مناسب نیست 422
ERR_FILE_001 فرمت فایل مجاز نیست 422
ERR_SMS_003 تمپلیت قبلاً ارسال شده 422
ERR_SECRETARY_001 پلن فعلی اجازه منشی بیشتر نمی‌دهد 422
ERR_RATE_LIMIT_001 درخواست‌های زیاد، بعداً تلاش کنید 429