Skip to content

Create a new partners access point to flood affected villages - #280

Draft
wadhwamatic wants to merge 1 commit into
mainfrom
feature-flood-affected-villages-api
Draft

wadhwamatic wants to merge 1 commit into
mainfrom
feature-flood-affected-villages-api

Conversation

@wadhwamatic

@wadhwamatic wadhwamatic commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

Summary

Adds a new partner-facing API endpoint that exposes approved flood-affected village data to external partners (starting with IDPoor), without giving them direct access to Kobo.

Closes #278

What's included

  • GET /partners/flood-affected-villages?startDate=&endDate= — returns one row per affected village for approved flood submissions in the given disaster-event date range
  • API key auth (x-api-key header) via PARTNER_API_KEYS, separate from staff login
  • Dedicated Kobo credential (KOBO_PUBLIC_API_TOKEN), isolated from the validation-workflow token
  • Village-level gazetteerCode resolution from the flood form's g2/village select-multiple field, backed by a generated villageToCommune lookup table (packages/interfaces/src/kobo/villages.ts)
  • Basic request logging (partner, date range, timestamp) for audit purposes
  • PARTNER_SKIP_APPROVAL_FILTER local-dev-only escape hatch for testing before any submissions are approved
  • Unit tests for PartnersService (query filtering, village expansion, unknown-code handling, pagination)

Design notes

  • Approved-only filtering is enforced by the DMP backend's Kobo query, not by Kobo permissions — Kobo's "View submissions" grant doesn't distinguish validation status
  • Village → commune mapping can't be derived arithmetically (fails on ~2% of real codes), so it's sourced from an explicit lookup table generated from the live Kobo XLSForm
  • No wrapper/gateway beyond this thin module — not justified at current partner scale

Testing

  • All existing backend tests pass unaffected
  • New PartnersService tests cover the approval filter, village expansion, and pagination
  • Manually verified against real Kobo data locally

Follow-ups (tracked separately, not blocking this PR)

  • Provision the dedicated Kobo service account to replace personal tokens
  • Issue IDPoor a real API key
  • Confirm response contract with WebEssentials
  • Decide on per-partner geographic scoping if/when partners beyond IDPoor are added

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

Build succeeded and deployed:

(hash 52cf790 deployed at 2026-09-09T02:39:25)

Surge is deprecated and will be removed once backend CORS changes are deployed to staging. Use GitHub Pages for preview; Surge remains available until then.

@wadhwamatic
wadhwamatic marked this pull request as draft September 9, 2026 04:10

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Partner data-sharing API: expose approved flood-affected village data to IDPoor

1 participant