Bug #42 (journeys): PatientJourneyStageInstanceViewSet.get_queryset()
called select_related('physician', 'survey_instance') but neither field
exists on the model. Changed 'physician' -> 'staff' (the actual FK)
and removed 'survey_instance' (no such relation). Endpoint now returns 200.
Bug #43 (standards): StandardAttachmentViewSet.get_queryset() filtered on
'departments__hospital' but StandardAttachment has no 'departments' field.
Fixed to traverse compliance__department__hospital. Also fixed invalid
ordering field 'uploaded_at' -> 'created_at'. Endpoint now returns 200.
API endpoint sweep: 73 DRF endpoints across all 21 apps tested, 0 errors.
Full URL sweep: 427 URL patterns tested, 0 server errors.
Pre-production security fixes to prevent cross-hospital data leaks:
- Standards API: add get_queryset() filtering by department__hospital
- Reports service: add user param with hospital filtering to all querysets
- RCA views: replace is_superuser with tenant_hospital pattern, add access
checks to all 11 mutation views
- Notifications views: replace is_superuser patterns with _get_notification_hospital
helper across all 5 settings functions
- Appreciation API: add tenant_hospital fallback to AppreciationViewSet,
AppreciationStatsViewSet, and LeaderboardView
- AI Analytics: add tenant_hospital fallback in ExecutiveSummaryGenerator and
ActionRecommendationEngine
- SourceUserRestrictionMiddleware: remove None from ALLOWED_URL_NAMES
- Complaint export: fix nullable patient/due_at/description crashes in CSV
and Excel export, fix invalid get_category_display/get_source_display calls
E2E test updates:
- Update isolation gap tests to actively assert hospital filtering
- Fix CSV export test to use API context for download handling
- Switch clinical-staff tests to serial mode to prevent race conditions