# Tag API — Curl / Postman

**Controller:** `TagController`  
**Middleware:** `jwt.auth`, `check.token`, `dynamic.permission`  
(assign these routes to the back-office user’s role in route-API permissions first)

Base URL (XAMPP local):

```text
http://localhost/fintraBackend/fi_adm/public/api
```

Replace `YOUR_JWT_TOKEN` with the `access_token` from login.

---

## 0. Login (get JWT)

```bash
curl --location --request POST "http://localhost/fintraBackend/fi_adm/public/api/auth/login" \
  --header "Accept: application/json" \
  --header "Content-Type: application/json" \
  --data-raw "{
    \"email\": \"your.backoffice@email.com\",
    \"password\": \"your_password\"
  }"
```

---

## 1. List tags (index)

```bash
curl --location --request GET "http://localhost/fintraBackend/fi_adm/public/api/tag/tag-index" \
  --header "Accept: application/json" \
  --header "Authorization: Bearer YOUR_JWT_TOKEN"
```

Optional pagination:

```bash
curl --location --request GET "http://localhost/fintraBackend/fi_adm/public/api/tag/tag-index?per_page=20" \
  --header "Accept: application/json" \
  --header "Authorization: Bearer YOUR_JWT_TOKEN"
```

---

## 2. Show tag by ID

```bash
curl --location --request GET "http://localhost/fintraBackend/fi_adm/public/api/tag/tag-show/1" \
  --header "Accept: application/json" \
  --header "Authorization: Bearer YOUR_JWT_TOKEN"
```

---

## 3. Create tag (store)

```bash
curl --location --request POST "http://localhost/fintraBackend/fi_adm/public/api/tag/tag-store" \
  --header "Accept: application/json" \
  --header "Authorization: Bearer YOUR_JWT_TOKEN" \
  --header "Content-Type: application/json" \
  --data-raw "{
    \"name\": \"equity\"
  }"
```

---

## 4. Update tag (POST, not PUT)

```bash
curl --location --request POST "http://localhost/fintraBackend/fi_adm/public/api/tag/tag-update/1" \
  --header "Accept: application/json" \
  --header "Authorization: Bearer YOUR_JWT_TOKEN" \
  --header "Content-Type: application/json" \
  --data-raw "{
    \"name\": \"equity-updated\"
  }"
```

---

## 5. Delete tag

```bash
curl --location --request DELETE "http://localhost/fintraBackend/fi_adm/public/api/tag/tag-delete/1" \
  --header "Accept: application/json" \
  --header "Authorization: Bearer YOUR_JWT_TOKEN"
```

Returns **409** if the tag is still attached to research reports.

---

## Routes summary

| Method | URL | Route name |
|---|---|---|
| GET | `/api/tag/tag-index` | `tag-index` |
| GET | `/api/tag/tag-show/{id}` | `tag-show/{id}` |
| POST | `/api/tag/tag-store` | `tag-store` |
| POST | `/api/tag/tag-update/{id}` | `tag-update/{id}` |
| DELETE | `/api/tag/tag-delete/{id}` | `tag-delete/{id}` |

---

## Postman quick setup

1. Collection variable `base_url` = `http://localhost/fintraBackend/fi_adm/public/api`
2. Collection Authorization: **Bearer Token** = `{{token}}`
3. Header: `Accept: application/json`
4. Store/Update body: **raw JSON**

---

## Expected success shapes

**Create (201)**

```json
{
  "status": true,
  "message": "Tag created successfully",
  "data": {
    "id": 1,
    "name": "equity",
    "created_at": "...",
    "updated_at": "..."
  }
}
```

**List (200)**

```json
{
  "status": true,
  "data": [ ... ],
  "pagination": {
    "current_page": 1,
    "last_page": 1,
    "per_page": 10,
    "total": 1
  }
}
```

---

## `route_apis` insert

```sql
INSERT INTO `route_apis` (`api_id`, `name`, `url`, `controller`, `function`, `prefix`, `method`, `details`, `api_activity_flag`, `created_by`, `create_date`, `create_time`, `update_by`, `update_date`, `update_time`, `created_at`, `updated_at`) VALUES
(NULL, 'tag-index', 'tag-index', 'TagController', 'index', 'tag', 'GET', 'tag-index API', 'R', '5', '2026-09-23', '22:25:00', NULL, NULL, NULL, '2026-09-23 22:25:00', '2026-09-23 22:25:00'),
(NULL, 'tag-show/{id}', 'tag-show/{id}', 'TagController', 'show', 'tag', 'GET', 'tag-show/{id} API', 'R', '5', '2026-09-23', '22:25:00', NULL, NULL, NULL, '2026-09-23 22:25:00', '2026-09-23 22:25:00'),
(NULL, 'tag-store', 'tag-store', 'TagController', 'store', 'tag', 'POST', 'tag-store API', 'R', '5', '2026-09-23', '22:25:00', NULL, NULL, NULL, '2026-09-23 22:25:00', '2026-09-23 22:25:00'),
(NULL, 'tag-update/{id}', 'tag-update/{id}', 'TagController', 'update', 'tag', 'POST', 'tag-update/{id} API', 'R', '5', '2026-09-23', '22:25:00', NULL, NULL, NULL, '2026-09-23 22:25:00', '2026-09-23 22:25:00'),
(NULL, 'tag-delete/{id}', 'tag-delete/{id}', 'TagController', 'destroy', 'tag', 'DELETE', 'tag-delete/{id} API', 'R', '5', '2026-09-23', '22:25:00', NULL, NULL, NULL, '2026-09-23 22:25:00', '2026-09-23 22:25:00');
```
