feat: API d administration JSON sous /admin/api (CRUD, PUT, DELETE) #151

Merged
Corentin merged 1 commit from feat/admin-json-api into dev 2026-09-26 05:45:04 +02:00
Owner
No description provided.
feat: JSON admin API under /admin/api with full CRUD, PUT and DELETE
All checks were successful
CI / secret-scan (pull_request) Successful in 30s
CI / php-lint (pull_request) Successful in 27s
CI / static-tests (pull_request) Successful in 2m39s
CI / js-tests (pull_request) Successful in 44s
CI / secret-scan (push) Successful in 25s
CI / php-lint (push) Successful in 26s
CI / static-tests (push) Successful in 2m21s
CI / js-tests (push) Successful in 44s
f404ab30e7
Adds a JSON administration API next to the server-rendered back-office
(ADR-0017), covering categories, products, menus, ingredients and stock,
users, roles, orders and stats. Controllers extend their HTML
counterparts to reuse validation and repositories; JsonApiTrait holds
the session, permission, X-CSRF-Token and typed body guards; PinGate
factors the PIN re-authorisation with throttle and audit in the same
transaction. Routes live under /admin/api, outside the kiosk /api relay.

GET /admin/me now returns csrf_token. Stock quantity parsing is shared
with the HTML forms through NumericInput (behaviour unchanged).

docs/api/conventions.md is brought back in line with the registered
routes (v0.3), with a Postman collection, environment and guide.
Tests: RouteMatrixTest checks CSRF and exact permission on all 50 routes.
Corentin scheduled this pull request to auto merge when all checks succeed 2026-09-26 05:40:35 +02:00
Sign in to join this conversation.
No reviewers
No labels
auto-merge
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
AcadeNice/corentin_wakdo!151
No description provided.