backend phase 3: identity profiles, patients & nurse bank accounts Add the role-attached identity layer on top of the b2 auth spine: nurse seller profiles (guarded is_verified, read-only aggregates), thin customer payer profiles, first-class patients (tenancy-scoped), and nurse payout bank accounts hardened with an iban_hash uniqueness guard and an automated استعلام شبا IBAN-ownership inquiry. - Four usr tables via one migration (1:1 uniques, UNIQUE(iban_hash), filtered UNIQUE(nurse_id) WHERE is_primary=1, guarded is_verified, encrypted PII, soft-delete on nurse_profiles) - 15 CQRS slices + 4 role-scoped controllers; reads projected + paginated, IBAN masked (last-4); ownership-inquiry endpoints rate-limited - New IBankAccountOwnershipVerifier seam (mock deterministic شبا match) + per-domain repositories on IUnitOfWork + encrypted-PII value converters - Activate FluentValidation repo-wide (validators were never registered) - Handler unit tests + WebApplicationFactory integration tests (76 pass); contract identity-profiles.md + swagger snapshot; docs, handoff & report Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> @
OpenAPI snapshots
The server already generates OpenAPI via NSwag (Swagger UI at /swagger, documents v1, v1.1).
This folder holds the published swagger.json snapshot(s) so the frontend can generate/verify types
without running the backend.
Backend: publish on every API-shipping phase
After adding/changing endpoints and confirming the build, export the OpenAPI document and commit it here
as swagger.v1.json (overwrite — git history is the version trail). Typical options:
- Run the API and save
GET /swagger/v1/swagger.jsontodev/contracts/openapi/swagger.v1.json, or - Use the NSwag CLI / build target the server already wires to emit the document.
Record in your handoff that the snapshot was refreshed. Keep it in sync with ../domains/*.md — the
markdown is the human contract, this JSON is the machine contract; they must agree.
Frontend: consume
Generate types from swagger.v1.json (e.g. an openapi-typescript-style step) or hand-write
src/services/{domain}/types.ts to match it. Either way, the wire shapes come from here — not from
guessing. Casing/format questions are resolved by this file.
Until the first API-shipping backend phase runs, this folder is empty by design.