feat: improve learning and platform operations
This commit is contained in:
16
BACKEND.md
16
BACKEND.md
@@ -16,19 +16,33 @@ The API health endpoint is available at `http://localhost:3001/api/v1/health` an
|
||||
|
||||
- `GET /api/v1/courses` returns published courses.
|
||||
- `GET /api/v1/courses/:courseId` returns one published course.
|
||||
- `GET /api/v1/courses/me/learning` returns the authenticated learner's started courses, ordered by their last activity, with completion percentage.
|
||||
- `GET /api/v1/courses/:courseId/progress` and `PUT /api/v1/lessons/:lessonId/progress` persist completion and watch position.
|
||||
- `GET /api/v1/admin/audit-log` exposes the last 50 administrative actions to superadmins.
|
||||
|
||||
## Accounts and instructor access
|
||||
|
||||
- `POST /api/v1/auth/register` creates student accounts only.
|
||||
- `POST /api/v1/auth/login` creates a seven-day signed session.
|
||||
- `GET /api/v1/auth/me` restores an existing session.
|
||||
- Public authentication endpoints are rate-limited per source IP. Configure `AUTH_RATE_LIMIT_MAX` and `AUTH_RATE_LIMIT_WINDOW_SECONDS` if the defaults (10 attempts / 15 minutes) do not fit your environment.
|
||||
- `GET`, `POST`, `PATCH`, and `DELETE` under `/api/v1/manage/courses` require an instructor or administrator session. Instructors can manage only their own courses.
|
||||
|
||||
Courses can be saved as a draft or published. Drafts are visible only in the managing instructor's dashboard and are never exposed by public course endpoints. Existing lessons keep their IDs when a course is edited, preserving learner progress and comment history; a lesson with progress or comments cannot be removed.
|
||||
|
||||
To create the first local administrator, set `SUPERADMIN_EMAIL`, `SUPERADMIN_PASSWORD`, and optionally `SUPERADMIN_NAME`, then run `npm run db:bootstrap-admin`. In Docker/Portainer, the API runs this command automatically after migrations.
|
||||
|
||||
For local demos, `npm run db:seed-demo-content` imports the original frontend catalogue into PostgreSQL. It requires the bootstrap administrator to exist and skips courses already present.
|
||||
|
||||
Public course endpoints return only public lessons and public assets. Enrolment checks, learner progress, and comments will be added in the next milestone.
|
||||
Anonymous visitors can browse course and lesson information, but media and download links are removed from their response. A signed-in account is required to play lessons, download materials, track progress, or participate in discussion.
|
||||
|
||||
## Provider boundaries
|
||||
|
||||
Videos remain provider-neutral through `lesson_media.provider` and `lesson_media.external_id`. The platform does not yet create signed playback URLs because that requires the chosen provider's credentials and API. Do not add a provider secret until Panda Video, Vimeo, or another provider has been selected. Invitations and password resets currently generate secure, expiring links for the superadmin to copy; email delivery will be connected once an email service is chosen.
|
||||
|
||||
## Administrative operations
|
||||
|
||||
The superadmin page supports user activation/role changes, invitations, password reset links, user learning details, CSV export, platform metrics, and an immutable-style activity log. Audit records cover invitations, reset links, user updates, course publishing/drafts/archive, and instructor comment moderation.
|
||||
|
||||
## CI/CD status
|
||||
|
||||
|
||||
Reference in New Issue
Block a user