Auth & Identity
| Controllers | 5 |
| Endpoints | 22 |
| Tables | 5 |
| Screens | 4 |
| API reference | /api/ — group auth-and-identity |
| OpenAPI spec | /openapi/auth-and-identity.json |
URL prefixes
Endpoints belong to this module by URL, exactly as the OpenAPI group defines it in backend/src/main/java/com/motorph/payroll/config/OpenApiConfiguration.java.
/api/auth/**/api/users/**/api/roles/**/api/permissions/**/api/audit-logs/**
Controllers
| Controller | Base path | Endpoints | GET | POST | PUT | PATCH | DELETE |
|---|---|---|---|---|---|---|---|
| AuditLogController | /api/audit-logs | 1 | 1 | — | — | — | — |
| AuthController | /api/auth | 5 | 1 | 4 | — | — | — |
| PermissionController | /api/permissions | 5 | 2 | 1 | 1 | — | 1 |
| RoleController | /api/roles | 6 | 2 | 1 | 2 | — | 1 |
| UserController | /api/users | 5 | 2 | 1 | 1 | — | 1 |
Across the module: 8 GET, 7 POST, 4 PUT, 3 DELETE.
Tables
Everything this module's controllers can reach through a repository, including through a shared service — so this is the upper bound of what the module touches, not the set of tables it owns. A table appearing under two modules means two modules can read it.
| Entity | Table | Columns | Tenant-scoped |
|---|---|---|---|
| Employee | employee | 24 | Yes |
| Permission | permission | 4 | — |
| Role | role | 6 | — |
| User | users | 11 | — |
| UserLog | user_log | 5 | — |
Screens
Frontend routes gated by a permission this module's endpoints also require — the link between a page and its API is the permission string, not the URL.
| Route | Component | Requires |
|---|---|---|
/audit-logs | AuditLogs | system.admin.logs.view |
/permissions | Permissions | system.admin.permissions.view |
/roles | Roles | system.admin.roles.view |
/users | Users | system.admin.users.view |
Unauthenticated endpoints
3 endpoint(s) in this module are permitted without a token by PUBLIC_ENDPOINTS in backend/src/main/java/com/motorph/payroll/config/SecurityConfiguration.java.
| Method | Path |
|---|---|
POST | /api/auth/login |
POST | /api/auth/refresh |
POST | /api/auth/logout |
This page is rebuilt from the source on every docs build by docs-site/scripts/gen-code-wiki.mjs. Editing it has no effect — change the code, or, if what you want to say is prose, write it in docs/.