01 — The Problem
Four applications wanted the same record
Patients, doctors, administrators and a mobile client each needed the clinical record, and each needed a different part of it. Written per surface, that is four codebases drifting apart — and four places for a permission to be wrong.
- One record, four readings of it — patient, prescriber, administrator, mobile.
- Permissions that differ by role, not by endpoint.
- Dashboards that summarise the same data the surfaces are writing.
02 — What I Built
One API, with the permissions in front of it
A single Express service organised by module rather than by client. Validation, pagination and permission checks all run before any controller does, so a route is only the part that is genuinely different.
- 406 endpoints across 53 Mongoose models, grouped by domain module.
- JWT sessions, with role and permission resolution in middleware.
- Aggregation pipelines for the dashboard figures, compound indexes behind them.
- Socket.IO for appointment changes, so the four surfaces stay in agreement.
03 — What Changed
One place to fix it
A permission rule is written once and applies to every surface that touches the route. A new screen consumes the contract that already exists instead of asking for an endpoint of its own.
- A new surface is a consumer of the API, not a fork of it.
- Dashboard figures come back from one pipeline instead of several round trips.
- An appointment change reaches every screen that is watching it.