Auth Management
Get Current User
GET /api/v1/auth/me
Returns the authenticated user's profile.
Response: 200 OK
{
"user": {
"id": "uuid",
"username": "admin",
"display_name": "",
"role": "admin",
"is_active": true,
"created_at": "2024-01-01T00:00:00Z",
"updated_at": "2024-01-01T00:00:00Z"
},
"default_password_warning": false
}
Change Password
PUT /api/v1/auth/password
Rate limit: 3 requests per minute per IP.
Changes the authenticated user's password. Users of any role can change their own password.
Request body:
{
"current_password": "old-password",
"new_password": "new-password-min-8-chars"
}
Validation: New password must be 8-72 characters.
Response: 200 OK
{"message": "password updated successfully"}
Error responses:
400 Bad Request — Missing fields, password too short/long
401 Unauthorized — Current password incorrect
429 Too Many Requests — Rate limit exceeded
Logout
POST /api/v1/auth/logout
Revokes the refresh token family and clears authentication cookies.
Response: 200 OK