// Mirrors the frontend's stricter check in lib/validation.ts — a plain
// minLength let obviously-invalid values through when hit directly via the
// API, bypassing the UI's real validation. Email format is also enforced
// here now, matching client.schema.ts (this previously accepted any string).
const employeeProperties = {
  name: { type: 'string', minLength: 1 },
  mobile: { type: 'string', pattern: '^[6-9][0-9]{9}$' },
  email: { type: 'string', format: 'email', nullable: true },
  role_id: { type: 'string', minLength: 1 },
  auth_enabled: { type: 'boolean', default: false },
  user_id: { type: 'string', nullable: true },
  password: {
    type: 'string',
    nullable: true,
    minLength: 8,
    pattern: '^(?=.*[A-Za-z])(?=.*[0-9]).+$',
  },
  permission_overrides: {
    type: 'array',
    nullable: true,
    items: {
      type: 'object',
      required: ['permission', 'effect'],
      properties: {
        permission: { type: 'string', minLength: 1 },
        effect: { type: 'string', enum: ['grant', 'deny'] },
      },
    },
  },
  stage_transitions: {
    type: 'array',
    nullable: true,
    items: {
      type: 'object',
      required: ['fromStageId', 'toStageId'],
      properties: {
        fromStageId: { type: 'string', minLength: 1 },
        toStageId: { type: 'string', minLength: 1 },
      },
    },
  },
};

export const createEmployeeSchema = {
  body: {
    type: 'object',
    required: ['name', 'mobile', 'role_id'],
    properties: employeeProperties,
  },
};

export const updateEmployeeSchema = {
  body: {
    type: 'object',
    properties: {
      ...employeeProperties,
      role_id: { type: 'string' },
    },
  },
};
