project-conversation¶
Account-manager messaging, hosted by the Bricks CRM (brickssas/CRM-PDP) and surfaced in BO Projets through an iframe. The API stores nothing: it returns a ready-to-use embed URL built by the CrmApi provider (src/__new/lib/providers/crm/crm.api.ts), which owns the CRM base URL, embed paths and api key (env crm.url, crm.embedApiKey — Doppler CRM_URL, CRM_EMBED_API_KEY).
Endpoint¶
GET /administration/project-conversation/all-conversations/embed (AdminAuthGuard) → { url }.
url={CRM_URL}/embed/conversations-all?userExternalId={admin.id}&apiKey=…. The CRM keys its users on our admin id (better_auth_user.id); an admin the CRM does not know yet sees the CRM's own error screen inside the iframe (BRI-1764 creates the remaining admins CRM-side).- The api key travels in the query string on purpose for the beta (internal BO, gated) — to harden before GA with a short-lived server-to-server token (BRI-1762).
- Missing env →
ApiExceptioncrm.config-missing(500), thrown by the provider.
Prerequisite CRM-side¶
The CRM must serve Content-Security-Policy: frame-ancestors 'self' https://bo-projet.bricks.co https://bo-projet.dev.bricks.co http://localhost:3000, otherwise the browser refuses the frame regardless of what BO Projets does. No postMessage is emitted by this embed: nothing to listen to.
Outbound calls¶
The same CrmApi provider also pushes dossiers and their account manager to the CRM — createPerson,
createProject, addAccountManager, over crm.axios.ts (env crm.url, crm.externalApiJwt —
Doppler CRM_URL, CRM_EXTERNAL_API_JWT), behind the ENABLE_CRM_PDP_SYNC feature flag. Those
writes belong to the project-financing-request-account-manager module; this module stays
read-only.