Skip to content

Authentication API ​

Implementation: front/src/services/api/authService.ts, front/src/services/api/passwordResetService.ts, front/src/services/api/client.ts. Shared headers and 401 behavior are described in API overview.

For each request below, the service passes JSON unless noted. The shared request interceptor adds a bearer token only if one is already stored. Frontend usage suggests login and password-reset operations are usable without an authenticated session; whether the backend enforces this cannot be determined from frontend source code.

POST /auth/login ​

  • Endpoint: POST {VITE_API_BASE_URL}/auth/login
  • Called from: LoginForm; on form submission.
  • Request body: LoginCredentials — { email: string, password: string }.
  • Request example: {"email":"user@example.com","password":"<password>"}
  • Frontend success expectation: outer success and data; data is AuthResponse with user, token, optional refreshToken. Tokens are saved; token values are never included in docs.
  • Response fields consumed: user.id, user.email, user.name, user.role, optional user.permissions, token, optional refreshToken.
  • Failure behavior: thrown error is logged and rendered by the login form. Exact error response/status contract is unavailable.
  • Related page: Login.

POST /auth/logout ​

  • Endpoint: POST {VITE_API_BASE_URL}/auth/logout
  • Called from: authService.logout; invoked through app navigation controls where wired.
  • Request body: { token: string }, read from local storage.
  • Success expectation: not inspected beyond request; service returns true and clears local auth values on success or failure.
  • Failure behavior: logs error and still clears local token/user values. Exact response schema unavailable.
  • Implementation: authService.ts.

POST /auth/refresh ​

  • Endpoint: POST {VITE_API_BASE_URL}/auth/refresh
  • Called from: API client's 401 refresh flow via registered auth callback; auth service also exposes refreshToken().
  • Request body: { refreshToken: string }.
  • Success expectation: response success, data.token, and optional data.refreshToken; tokens are stored.
  • Frontend behavior: successful refresh retries queued/original request; failed refresh clears auth and redirects to /login.
  • Failure statuses: HTTP 401 from refresh is explicitly logged as invalid/expired token; exact response shape unavailable.
  • Implementation: authService.ts, client.ts.

GET /auth/me ​

  • Endpoint: GET {VITE_API_BASE_URL}/auth/me
  • Called from: profile load and authService.getCurrentUser(); only when an access token is present.
  • Request body: none.
  • Success expectation: ApiResponse<User> with success and data; data is stored and returned.
  • Failure behavior: logs error and returns null. Exact backend error contract unavailable.
  • Related page: Profile.

PUT /auth/me ​

  • Endpoint: PUT {VITE_API_BASE_URL}/auth/me
  • Called from: profile form submission.
  • Request body type: Pick-like object declared inline: optional name, email, department, jobTitle, phone.
  • Success expectation: ApiResponse<User>; response user is stored and consumed by Profile.
  • Failure behavior: logs and rethrows; Profile renders an error.
  • Related page: Profile.

POST /auth/change-password ​

  • Endpoint: POST {VITE_API_BASE_URL}/auth/change-password
  • Called from: change-password form submission.
  • Request body: { oldPassword: string, newPassword: string }.
  • Success expectation: ApiResponse<{ success: boolean }>; page checks outer success.
  • Failure behavior: logs/rethrows; UI uses API error text or fallback. Client validates confirmation and minimum six characters before calling API.
  • Related page: Change password.

POST /password-reset/forgot-password ​

  • Endpoint: POST {VITE_API_BASE_URL}/password-reset/forgot-password
  • Called from: forgot-password form on Login; authService.forgotPassword().
  • Request body: { email: string }.
  • Success expectation: auth service returns true when outer success and data.success === true.
  • Failure behavior: logs and returns false; Login displays failure message. Exact server response unavailable.
  • Related page: Login.

POST /password-reset/reset-password ​

  • Endpoint: POST {VITE_API_BASE_URL}/password-reset/reset-password
  • Called from: reset-password page through authService.resetPassword(); password reset service also exposes the same operation.
  • Request body: { token: string, newPassword: string }.
  • Success expectation: auth service checks outer success and data.success; password-reset service types data as { success, message }.
  • Failure behavior: auth service logs and returns false; password reset service logs and rethrows. Exact backend response unavailable.
  • Related page: Reset password.

GET /password-reset/validate-token/:token ​

  • Endpoint: GET {VITE_API_BASE_URL}/password-reset/validate-token/{token}
  • Called from: method exposed by passwordResetService; no page call confirmed in reviewed page sources.
  • Path parameter: token string.
  • Success expectation: ApiResponse<{ isValid: boolean; message: string }> according to service type.
  • Failure behavior: logs and rethrows.
  • Backend availability and route access: Not available from frontend source code. Backend/API contract verification required.

POST /password-reset/cleanup-tokens ​

  • Endpoint: POST {VITE_API_BASE_URL}/password-reset/cleanup-tokens
  • Called from: method exposed by passwordResetService; no page call confirmed in reviewed page sources.
  • Request body: none supplied.
  • Success expectation: ApiResponse<{ deletedCount: number; message: string }> according to service type.
  • Failure behavior: logs and rethrows.
  • Backend availability and route access: Not available from frontend source code. Backend/API contract verification required.