Skip to content

Latest commit

 

History

History
85 lines (72 loc) · 4.83 KB

File metadata and controls

85 lines (72 loc) · 4.83 KB

Documentation map

Every document here describes the current release unless stated otherwise. Planned work appears only in the Roadmap; release history is in the changelog. Start with the repository README for an overview.

Using the API

Document Covers
HTTP API Endpoint, transport, request flow, and the Universal JSON Contract
Action reference Every public data action with examples
JSON request reference Exact accepted fields and shapes
Response reference Success and write envelopes, per-action messages
Errors and validation Error envelope, every error code, failure handling
Frontend integration Turning UI state into requests
Capability matrix What each mode supports, side by side
Limitations Intentional boundaries and known gaps

Query modes

Document Covers
JSON Query Mode Client-composed SELECT, joins, CTEs, windows, set operations
Query functions The complete function allowlist
Filtering, sorting, and pagination Operators, sort rules, and paging across modes
Query examples Worked requests
Metadata and routines Metadata actions and routine calls
SQL Resource Mode Executing server-owned SQL files by ID
SQL Resource authoring Adding and reviewing SQL Resource files
Write API INSERT, UPDATE, DELETE, and UPSERT on any user table
SQL Parser Converting SQL into request JSON

Operating the backend

Document Covers
Architecture Components, request flow, and process model
Local development Launchers, bundled runtimes, local troubleshooting
Production security and deployment Production hosting for IIS and Nginx, permissions, secrets, operator checklists
Windows Server IIS deployment Step-by-step Windows installation
Database configuration The database registry, encryption, ODBC, key rotation
Upgrading to V3 V2 → V3 migration, compatibility changes, verification, rollback
Admin Console Pages, availability controls, every Admin API action
Authentication and authorization Modes, sessions, API keys, roles, user management
Runtime and performance controls Timeouts, rate limits, sessions, request and page limits
Monitoring and health Liveness, readiness, detailed health
Logging Operational and audit logs
Backup and recovery Application configuration backups and restore

Security

Document Covers
Security model Current trust boundaries, controls, and accepted risks
Security verification Verification history, findings register, deferred work
Penetration-test preparation Handoff for the outstanding external penetration test

Maintaining the repository

Document Covers
AI development guide Repository boundaries and invariants for maintainers and coding agents
Testing Running the suite, coverage, static checks, deployment validation
Contributing Change expectations and pull requests
Roadmap Current, upcoming, and deferred work

Terminology

  • Universal JSON Contract: the shared request dispatch (action) and response envelope.
  • JSON Query Mode: the backend builds a validated SELECT from client-supplied structure.
  • SQL Resource Mode: the client runs a server-owned, read-only SQL file by ID, optionally with validated execution metadata.
  • Execution metadata: the request's declaration of approved SQL Resource output columns, filter mappings, and default sort; never arbitrary SQL.
  • Write API: single-object INSERT, UPDATE, DELETE, or UPSERT on a table named in the request.
  • Principal: the authenticated caller (session user, API key, legacy key, or anonymous), whose role permissions decide every authorization.
  • Runtime configuration directory: the directory named by GENERIC_RUNTIME_CONFIG_DIR holding users, roles, API keys, Admin settings, and availability state.