# DigiDala backend — v0.3.0-alpha

## Purpose

First persistent server layer for DigiDala.

The Mini App remains a separate frontend. This release introduces a server-side source
of truth for users, mandalas and cells.

## Stack

- Node.js HTTP server
- Node `node:sqlite` / `DatabaseSync`
- SQLite file under `/opt/pixdala/data/pixdala.db`
- SQL migrations
- repository layer
- Telegram Mini App `initData` validation

Node's v24 documentation marks `node:sqlite` as Release Candidate; it provides
`DatabaseSync`, prepared statements and transaction support. citeturn650868search0

## API

### Health

`GET /health`

### Mandala

`GET /api/v1/mandalas/:number`

`GET /api/v1/mandalas/:number/cells`

### Occupy cell

`POST /api/v1/mandalas/:number/cells/:position/occupy`

Headers:

`X-Telegram-Init-Data: <initData>`

JSON:

```json
{
  "displayName": "Имя",
  "message": "Послание"
}
```

The server derives the user identity from Telegram `initData` instead of trusting a
client-supplied Telegram user id. Telegram documents the Mini App initialization data
and its validation mechanisms in the Mini Apps documentation. citeturn669868search0

### Complaints

`POST /api/v1/complaints`

JSON:

```json
{
  "targetType": "message",
  "targetId": 123,
  "reason": "Оскорбление",
  "comment": "Пояснение"
}
```

`GET /api/v1/admin/complaints` is intentionally localhost-bound in this alpha.
Full server-side moderator role enforcement is the next moderation substep.

## Concurrency rule

Cell occupation runs inside `BEGIN IMMEDIATE` and checks that the target cell is still
free before committing.

The application must never trust the browser as the owner of a cell.

## Moderation foundation

The schema already includes:

- moderation items;
- complaints;
- user restrictions;
- moderator/admin roles;
- audit events.

This release stores the foundation; the full admin UI and hardened admin auth follow
after the core API is stable.

## Data boundary

The following are not part of this release:

- Stars;
- Credits;
- Pix;
- payment providers;
- public mandala creation;
- production webhook.
