Auth Management

Get Current User

GET /api/v1/auth/me

Returns the authenticated user's profile.

Response: 200 OK

{
  "user": {
    "id": "uuid",
    "username": "admin",
    "display_name": "",
    "role": "admin",
    "is_active": true,
    "created_at": "2024-01-01T00:00:00Z",
    "updated_at": "2024-01-01T00:00:00Z"
  },
  "default_password_warning": false
}

Change Password

PUT /api/v1/auth/password

Rate limit: 3 requests per minute per IP.

Changes the authenticated user's password. Users of any role can change their own password.

Request body:

{
  "current_password": "old-password",
  "new_password": "new-password-min-8-chars"
}

Validation: New password must be 8-72 characters.

Response: 200 OK

{"message": "password updated successfully"}

Error responses:

Logout

POST /api/v1/auth/logout

Revokes the refresh token family and clears authentication cookies.

Response: 200 OK