Implement user registration and email verification features

This commit is contained in:
Isuru Bimsara
2026-08-17 16:52:44 +05:30
parent ef8db0988b
commit c3d9f899a1
11 changed files with 781 additions and 53 deletions
+87 -16
View File
@@ -1,10 +1,20 @@
# User API
#### Create New User
#### Create New Customer Account
Creates a new customer account and sends an email verification link.
The account is initially created with:
```text
accountType = customer
accountStatus = PENDING_VERIFICATION
emailVerifiedAt = null
```
**Endpoint**
```
```text
POST: http://localhost:3070/api/user
```
@@ -12,33 +22,94 @@ POST: http://localhost:3070/api/user
```json
{
"firstName": "Jhon",
"lastName": "Doe",
"email": "kalanajayasekara@niolla.lk",
"role": "System Developer",
"accountType": "admin",
"department": "IT Department"
"firstName": "Isuru",
"lastName": "Bimsara",
"email": "ibimsara00@gmail.com",
"password": "Hello@12346"
}
```
**Respond**
**Response**
```json
{
"success": true,
"message": "User Created Successfully",
"data": {
"id": "usr_763107d9-b56f-4b81-9d86-1889f98a6e6c",
"firstName": "Jhon",
"lastName": "Doe",
"email": "kalanajayasekara@niolla.lk",
"accountType": "admin",
"role": "System Developer",
"department": "IT Department"
"id": "usr_ei6i4n49",
"firstName": "Isuru",
"lastName": "Bimsara",
"email": "ibimsara00@gmail.com",
"accountType": "customer"
}
}
```
After registration, the user receives an email containing a verification link.
```
#### Verify Email
Verifies the customer's email using the raw verification token received by email.
The backend hashes the received token and compares the resulting hash with the `tokenHash` stored in the `email_verifications` table.
The token must:
```text
Exist in the database
Not have been used
Not have expired
```
**Endpoint**
```text
POST: http://localhost:3070/api/user/verify-email
```
**Request Body**
```json
{
"token": "RAW_VERIFICATION_TOKEN_FROM_EMAIL"
}
```
**Successful Response**
```json
{
"success": true,
"message": "Email verified successfully. Your account is now active."
}
```
After successful verification, the user record changes from:
```text
accountStatus = PENDING_VERIFICATION
emailVerifiedAt = NULL
```
to:
```text
accountStatus = ACTIVE
emailVerifiedAt = <current date and time>
```
The verification record is also updated:
```text
usedAt = <current date and time>
```
This prevents the same verification token from being successfully used again.
---
#### Get All Users
**Endpoint**