Authentication API
Implementation: front/src/services/api/authService.ts, front/src/services/api/passwordResetService.ts, front/src/services/api/client.ts. Shared headers and 401 behavior are described in API overview.
For each request below, the service passes JSON unless noted. The shared request interceptor adds a bearer token only if one is already stored. Frontend usage suggests login and password-reset operations are usable without an authenticated session; whether the backend enforces this cannot be determined from frontend source code.
POST /auth/login
- Endpoint:
POST {VITE_API_BASE_URL}/auth/login - Called from:
LoginForm; on form submission. - Request body:
LoginCredentials—{ email: string, password: string }. - Request example:
{"email":"user@example.com","password":"<password>"} - Frontend success expectation: outer
successanddata;dataisAuthResponsewithuser,token, optionalrefreshToken. Tokens are saved; token values are never included in docs. - Response fields consumed:
user.id,user.email,user.name,user.role, optionaluser.permissions,token, optionalrefreshToken. - Failure behavior: thrown error is logged and rendered by the login form. Exact error response/status contract is unavailable.
- Related page: Login.
POST /auth/logout
- Endpoint:
POST {VITE_API_BASE_URL}/auth/logout - Called from:
authService.logout; invoked through app navigation controls where wired. - Request body:
{ token: string }, read from local storage. - Success expectation: not inspected beyond request; service returns
trueand clears local auth values on success or failure. - Failure behavior: logs error and still clears local token/user values. Exact response schema unavailable.
- Implementation:
authService.ts.
POST /auth/refresh
- Endpoint:
POST {VITE_API_BASE_URL}/auth/refresh - Called from: API client's 401 refresh flow via registered auth callback; auth service also exposes
refreshToken(). - Request body:
{ refreshToken: string }. - Success expectation: response
success,data.token, and optionaldata.refreshToken; tokens are stored. - Frontend behavior: successful refresh retries queued/original request; failed refresh clears auth and redirects to
/login. - Failure statuses: HTTP 401 from refresh is explicitly logged as invalid/expired token; exact response shape unavailable.
- Implementation:
authService.ts,client.ts.
GET /auth/me
- Endpoint:
GET {VITE_API_BASE_URL}/auth/me - Called from: profile load and
authService.getCurrentUser(); only when an access token is present. - Request body: none.
- Success expectation:
ApiResponse<User>withsuccessanddata; data is stored and returned. - Failure behavior: logs error and returns
null. Exact backend error contract unavailable. - Related page: Profile.
PUT /auth/me
- Endpoint:
PUT {VITE_API_BASE_URL}/auth/me - Called from: profile form submission.
- Request body type:
Pick-like object declared inline: optionalname,email,department,jobTitle,phone. - Success expectation:
ApiResponse<User>; response user is stored and consumed by Profile. - Failure behavior: logs and rethrows; Profile renders an error.
- Related page: Profile.
POST /auth/change-password
- Endpoint:
POST {VITE_API_BASE_URL}/auth/change-password - Called from: change-password form submission.
- Request body:
{ oldPassword: string, newPassword: string }. - Success expectation:
ApiResponse<{ success: boolean }>; page checks outersuccess. - Failure behavior: logs/rethrows; UI uses API error text or fallback. Client validates confirmation and minimum six characters before calling API.
- Related page: Change password.
POST /password-reset/forgot-password
- Endpoint:
POST {VITE_API_BASE_URL}/password-reset/forgot-password - Called from: forgot-password form on Login;
authService.forgotPassword(). - Request body:
{ email: string }. - Success expectation: auth service returns true when outer
successanddata.success === true. - Failure behavior: logs and returns false; Login displays failure message. Exact server response unavailable.
- Related page: Login.
POST /password-reset/reset-password
- Endpoint:
POST {VITE_API_BASE_URL}/password-reset/reset-password - Called from: reset-password page through
authService.resetPassword(); password reset service also exposes the same operation. - Request body:
{ token: string, newPassword: string }. - Success expectation: auth service checks outer success and
data.success; password-reset service typesdataas{ success, message }. - Failure behavior: auth service logs and returns false; password reset service logs and rethrows. Exact backend response unavailable.
- Related page: Reset password.
GET /password-reset/validate-token/:token
- Endpoint:
GET {VITE_API_BASE_URL}/password-reset/validate-token/{token} - Called from: method exposed by
passwordResetService; no page call confirmed in reviewed page sources. - Path parameter:
tokenstring. - Success expectation:
ApiResponse<{ isValid: boolean; message: string }>according to service type. - Failure behavior: logs and rethrows.
- Backend availability and route access: Not available from frontend source code. Backend/API contract verification required.
POST /password-reset/cleanup-tokens
- Endpoint:
POST {VITE_API_BASE_URL}/password-reset/cleanup-tokens - Called from: method exposed by
passwordResetService; no page call confirmed in reviewed page sources. - Request body: none supplied.
- Success expectation:
ApiResponse<{ deletedCount: number; message: string }>according to service type. - Failure behavior: logs and rethrows.
- Backend availability and route access: Not available from frontend source code. Backend/API contract verification required.