Skip to main content

Auth & Identity

Controllers5
Endpoints22
Tables5
Screens4
API reference/api/ — group auth-and-identity
OpenAPI spec/openapi/auth-and-identity.json

URL prefixes​

Endpoints belong to this module by URL, exactly as the OpenAPI group defines it in backend/src/main/java/com/motorph/payroll/config/OpenApiConfiguration.java.

  • /api/auth/**
  • /api/users/**
  • /api/roles/**
  • /api/permissions/**
  • /api/audit-logs/**

Controllers​

ControllerBase pathEndpointsGETPOSTPUTPATCHDELETE
AuditLogController/api/audit-logs11————
AuthController/api/auth514———
PermissionController/api/permissions5211—1
RoleController/api/roles6212—1
UserController/api/users5211—1

Across the module: 8 GET, 7 POST, 4 PUT, 3 DELETE.

Tables​

Everything this module's controllers can reach through a repository, including through a shared service — so this is the upper bound of what the module touches, not the set of tables it owns. A table appearing under two modules means two modules can read it.

EntityTableColumnsTenant-scoped
Employeeemployee24Yes
Permissionpermission4—
Rolerole6—
Userusers11—
UserLoguser_log5—

Screens​

Frontend routes gated by a permission this module's endpoints also require — the link between a page and its API is the permission string, not the URL.

RouteComponentRequires
/audit-logsAuditLogssystem.admin.logs.view
/permissionsPermissionssystem.admin.permissions.view
/rolesRolessystem.admin.roles.view
/usersUserssystem.admin.users.view

Unauthenticated endpoints​

3 endpoint(s) in this module are permitted without a token by PUBLIC_ENDPOINTS in backend/src/main/java/com/motorph/payroll/config/SecurityConfiguration.java.

MethodPath
POST/api/auth/login
POST/api/auth/refresh
POST/api/auth/logout

Generated page

This page is rebuilt from the source on every docs build by docs-site/scripts/gen-code-wiki.mjs. Editing it has no effect — change the code, or, if what you want to say is prose, write it in docs/.