/** * Copyright (c) 2026 Niolla * All rights reserved. * * This source code is proprietary and confidential. * Unauthorized copying, modification, distribution, or use * of this file, via any medium, is strictly prohibited. */ // app/routes/profile.routes.js const express = require("express"); const router = express.Router(); const profileController = require("../controllers/profile.controller.js"); const authController = require("../controllers/auth.controller.js"); const { authenticate } = require("../middleware/auth.middleware"); const { authorizedAccountType, checkPermission, } = require("../middleware/permission.middleware"); const PERMISSIONS = require("../constants/permissions"); const { sensitiveLimiter } = require("../middleware/rateLimit.middleware"); const validate = require("../middleware/validate.middleware"); const schemas = require("../validation/auth.schemas"); const { requireOwnership } = require("../middleware/permission.middleware"); router.post("/req-reset-password", sensitiveLimiter, validate(schemas.forgot), authController.forgotPassword); router.post("/reset-password", sensitiveLimiter, validate(schemas.reset), authController.resetPassword); router.post( "/change-password", authenticate, validate(schemas.change), authController.changePassword, ); router.get( "/me/avatar", authenticate, profileController.getProfileAvatar, ); router.get( "/me/background", authenticate, profileController.getProfileBackgroundImage, ); router.get( "/avatar/:userId", authenticate, requireOwnership("userId"), profileController.getProfileAvatar, ); router.get( "/background/:userId", authenticate, requireOwnership("userId"), profileController.getProfileBackgroundImage, ); module.exports = router;