Backend API¶
The backend lives under iqvflex/backend/: Node.js 22 + Express (ESM),
no TypeScript.
Endpoints¶
| Method | Path | Description |
|---|---|---|
GET |
/health |
Service status (returns 200 even if MongoDB is unreachable) |
POST |
/erp-mapping |
Node-RED equivalent. Saves a format_template or a work order (JSON/XML) |
GET |
/erp-mapping/format-template |
Reads a saved template |
POST |
/api/v1/erp/auth/login |
ERP user login, { identifier, password } body |
GET |
/api/v1/erp/auth/me |
Protected — requires a valid token |
POST |
/api/v1/auth/token |
OAuth 2.0 client_credentials (credentials only in backend .env) |
POST |
/api/v1/inbound/work-orders/test |
Forwarded to the Go API (test) |
POST |
/api/v1/inbound/work-orders |
Forwarded to the Go API |
GET |
/api/v1/machine-events |
Forwarded to the Go API, query params unmodified |
GET |
/api/v1/production-performance |
Forwarded to the Go API, query params unmodified |
API documentation (Swagger)¶
The backend also exposes its endpoints in a browsable form (added without
changing any API code — see src/config/swagger.js, app.js):
| Path | Content |
|---|---|
/api-docs |
Swagger UI (browsable OpenAPI interface) |
/openapi.json |
Raw OpenAPI 3.0 document (JSON) |
Go API authentication¶
If GO_API_CLIENT_ID and GO_API_CLIENT_SECRET are empty, no
Authorization header is sent — this matches the legacy Node-RED
behavior. If they are set, the backend runs the client_credentials flow
against POST {GO_API_BASE_URL}/api/v1/auth/token, caches
data.access_token, and adds Authorization: Bearer <token> to requests.
If the client sends its own Authorization header, that header is
forwarded unchanged.
client_secret and access_token are never returned to the frontend.
Response contract¶
Successful MongoDB write (201 for a new record, 200 for an update):
{
"success": true,
"message": "Alan eslestirme sablonu olusturuldu.",
"id": null,
"data": {
"database": "iqvizyon",
"collection": "erp_mapping",
"record_type": "format_template",
"upserted_id": null,
"matched_count": 0,
"modified_count": 0,
"upserted_count": 0
}
}
Error (400):
{ "success": false, "message": "Istek govdesi islenemedi.", "error": "…" }
Go API errors are not converted to 500; the Go HTTP status code,
message and errors fields are forwarded to the frontend as-is (JSON as
JSON, XML as raw XML).
Environment variables¶
All settings live in iqvflex/backend/.env; template: .env.example.
| Variable | Default | Description |
|---|---|---|
PORT |
3001 |
HTTP port |
CORS_ORIGIN |
http://localhost:5173 |
Comma-separated origin list |
MONGODB_URI |
(required) | MongoDB connection string |
MONGODB_DATABASE |
iqvizyon |
Existing production value — do not change |
ERP_AUTH_SECRET |
(required) | JWT/HS256 signing key |
ERP_AUTH_TOKEN_TTL_SECONDS |
28800 |
Token lifetime (8 hours) |
GO_API_BASE_URL |
(required) | Address of the external Go service |
GO_API_CLIENT_ID / _SECRET |
(empty) | If empty, no Authorization is sent |
Commands¶
cd iqvflex/backend
npm install
npm start # server.js
npm run dev # node --watch
npm test # unit tests + smoke checks (node:test)