Skip to content

Backend API

The backend lives under iqvflex/backend/: Node.js 22 + Express (ESM), no TypeScript.

Endpoints

Method Path Description
GET /health Service status (returns 200 even if MongoDB is unreachable)
POST /erp-mapping Node-RED equivalent. Saves a format_template or a work order (JSON/XML)
GET /erp-mapping/format-template Reads a saved template
POST /api/v1/erp/auth/login ERP user login, { identifier, password } body
GET /api/v1/erp/auth/me Protected — requires a valid token
POST /api/v1/auth/token OAuth 2.0 client_credentials (credentials only in backend .env)
POST /api/v1/inbound/work-orders/test Forwarded to the Go API (test)
POST /api/v1/inbound/work-orders Forwarded to the Go API
GET /api/v1/machine-events Forwarded to the Go API, query params unmodified
GET /api/v1/production-performance Forwarded to the Go API, query params unmodified

API documentation (Swagger)

The backend also exposes its endpoints in a browsable form (added without changing any API code — see src/config/swagger.js, app.js):

Path Content
/api-docs Swagger UI (browsable OpenAPI interface)
/openapi.json Raw OpenAPI 3.0 document (JSON)

Go API authentication

If GO_API_CLIENT_ID and GO_API_CLIENT_SECRET are empty, no Authorization header is sent — this matches the legacy Node-RED behavior. If they are set, the backend runs the client_credentials flow against POST {GO_API_BASE_URL}/api/v1/auth/token, caches data.access_token, and adds Authorization: Bearer <token> to requests. If the client sends its own Authorization header, that header is forwarded unchanged.

client_secret and access_token are never returned to the frontend.

Response contract

Successful MongoDB write (201 for a new record, 200 for an update):

{
  "success": true,
  "message": "Alan eslestirme sablonu olusturuldu.",
  "id": null,
  "data": {
    "database": "iqvizyon",
    "collection": "erp_mapping",
    "record_type": "format_template",
    "upserted_id": null,
    "matched_count": 0,
    "modified_count": 0,
    "upserted_count": 0
  }
}

Error (400):

{ "success": false, "message": "Istek govdesi islenemedi.", "error": "…" }

Go API errors are not converted to 500; the Go HTTP status code, message and errors fields are forwarded to the frontend as-is (JSON as JSON, XML as raw XML).

Environment variables

All settings live in iqvflex/backend/.env; template: .env.example.

Variable Default Description
PORT 3001 HTTP port
CORS_ORIGIN http://localhost:5173 Comma-separated origin list
MONGODB_URI (required) MongoDB connection string
MONGODB_DATABASE iqvizyon Existing production value — do not change
ERP_AUTH_SECRET (required) JWT/HS256 signing key
ERP_AUTH_TOKEN_TTL_SECONDS 28800 Token lifetime (8 hours)
GO_API_BASE_URL (required) Address of the external Go service
GO_API_CLIENT_ID / _SECRET (empty) If empty, no Authorization is sent

Commands

cd iqvflex/backend
npm install
npm start     # server.js
npm run dev   # node --watch
npm test      # unit tests + smoke checks (node:test)