# Profile API #### Get Profile Avatar **Endpoint** ``` GET: http://localhost:3070/api/profile/avatar/:userId ``` **Path Parameters** | Parameter | Type | Required | Description | |-----------|--------|----------|-----------------| | userId | string | Yes | The user ID | **Headers** ``` Authorization: Bearer ``` **Response** ```json { "success": true, "data": { "userId": "usr_763107d9-b56f-4b81-9d86-1889f98a6e6c", "profilePictureUrl": "https://signed-s3-url.com/profile-picture.jpg" } } ``` **Error Responses** ```json { "success": false, "message": "Profile not found", "error": "Profile not found" } ``` ```json { "success": false, "message": "Internal server error", "error": "error message" } ``` --- #### Get Profile Background Image **Endpoint** ``` GET: http://localhost:3070/api/profile/background/:userId ``` **Path Parameters** | Parameter | Type | Required | Description | |-----------|--------|----------|-----------------| | userId | string | Yes | The user ID | **Headers** ``` Authorization: Bearer ``` **Response** ```json { "success": true, "data": { "userId": "usr_763107d9-b56f-4b81-9d86-1889f98a6e6c", "backgroundImageUrl": "https://signed-s3-url.com/background-image.jpg" } } ``` **Error Responses** ```json { "success": false, "message": "Profile not found", "error": "Profile not found" } ``` ```json { "success": false, "message": "Internal server error", "error": "error message" } ``` --- #### Profile Object Structure The Profile object contains the following fields: | Field | Type | Description | |--------------------|---------|----------------------------------| | profile_id | string | Unique profile identifier | | user_id | string | Associated user ID | | theme | string | User theme preference (light/dark) | | notificationsEnabled | boolean | Notification settings | | profilePicture_id | string | Upload ID for profile picture | | backgroundImage_id | string | Upload ID for background image | | dob | date | Date of birth | | phone_number | string | Phone number | | createdAt | datetime| Profile creation timestamp | | updatedAt | datetime| Profile last update timestamp | --- #### Request Password Reset **Endpoint** ``` POST: http://localhost:3070/api/profile/req-reset-password ``` **Request Body** ```json { "email": "sathira.nirmal@gmail.com" } ``` **Response** ```json { "success": true, "message": "If an account exists with this email address, a password reset email has been sent." } ``` **Description** This endpoint generates a password reset token and sends a reset link to the user's email. The reset link will be sent in email format: ``` http://localhost:3000/reset-password?token=TOKEN_HERE&email=EMAIL_HERE ``` Example reset link: ``` http://localhost:3000/reset-password?token=aa27def4222adedcf72a417dfc40b69cd01f8bdb07f37b324a8501f3bdb37e44&email=sathira.nirmal%40gmail.com ``` **Notes** - This endpoint does not require authentication - No error is returned if email doesn't exist (for security reasons) - Token expires after the time specified in `PASSWORD_RESET_EXPIRY_TIME` environment variable (default: 10 minutes) --- #### Reset Password **Endpoint** ``` POST: http://localhost:3070/api/profile/reset-password ``` **Request Body** ```json { "email": "sathira.nirmal@gmail.com", "token": "168e5d9d4dfb124571f412c5521874e8440a0f9e4c151fa24518ae57ca1c4f8f", "newPassword": "niolla" } ``` **Response** ```json { "success": true, "message": "Password reset successfully." } ``` **Error Responses** ```json { "success": false, "message": "Invalid email address." } ``` ```json { "success": false, "message": "Invalid or expired token." } ``` **Description** This endpoint resets the user's password using a valid reset token. The token must be obtained from the password reset email. **Notes** - This endpoint does not require authentication - Token must be valid and not expired - New password will replace the old password immediately --- --- #### Authentication All endpoints require authentication token unless otherwise noted. Include the Bearer token in the Authorization header: ``` Authorization: Bearer ``` **Authentication Required:** - GET /avatar/:userId - GET /background/:userId - POST /change-password **No Authentication Required:** - POST /req-reset-password - POST /reset-password #### Authorization Access levels for profile endpoints: - **GET /avatar/:userId** - Accessible by: admin, management, team_head, user - **GET /background/:userId** - Accessible by: admin, management, team_head, user - **POST /change-password** - Accessible by: admin, management, team_head, user (authenticated users)