Aller au contenu

project-conversation

Account-manager messaging, hosted by the Bricks CRM (brickssas/CRM-PDP) and surfaced in BO Projets through an iframe. The API stores nothing: it returns a ready-to-use embed URL built by the CrmApi provider (src/__new/lib/providers/crm/crm.api.ts), which owns the CRM base URL, embed paths and api key (env crm.url, crm.embedApiKey — Doppler CRM_URL, CRM_EMBED_API_KEY).

Endpoint

GET /administration/project-conversation/all-conversations/embed (AdminAuthGuard) → { url }.

  • url = {CRM_URL}/embed/conversations-all?userExternalId={admin.id}&apiKey=…. The CRM keys its users on our admin id (better_auth_user.id); an admin the CRM does not know yet sees the CRM's own error screen inside the iframe (BRI-1764 creates the remaining admins CRM-side).
  • The api key travels in the query string on purpose for the beta (internal BO, gated) — to harden before GA with a short-lived server-to-server token (BRI-1762).
  • Missing env → ApiException crm.config-missing (500), thrown by the provider.

Prerequisite CRM-side

The CRM must serve Content-Security-Policy: frame-ancestors 'self' https://bo-projet.bricks.co https://bo-projet.dev.bricks.co http://localhost:3000, otherwise the browser refuses the frame regardless of what BO Projets does. No postMessage is emitted by this embed: nothing to listen to.

Outbound calls

The same CrmApi provider also pushes dossiers and their account manager to the CRM — createPerson, createProject, addAccountManager, over crm.axios.ts (env crm.url, crm.externalApiJwt — Doppler CRM_URL, CRM_EXTERNAL_API_JWT), behind the ENABLE_CRM_PDP_SYNC feature flag. Those writes belong to the project-financing-request-account-manager module; this module stays read-only.