267e80e2ec
- Refactor server initialization to separate concerns and improve error handling. - Implement centralized environment validation using Zod. - Introduce database, Redis, and queue lifecycle management. - Add health check endpoints for liveness and readiness. - Enhance error handling middleware for better response structure. - Implement rate limiting for API endpoints. - Add request ID middleware for traceability. - Create Sequelize CLI configuration and baseline migration for schema management. - Establish CI workflow with Gitea for testing and syntax checks. - Document foundational changes and migration strategy in PHASE_0_FOUNDATION_STABILIZATION.md. - Add Docker Compose configuration for local development and testing. - Implement unit and integration tests for critical functionality.
50 lines
1.4 KiB
JavaScript
50 lines
1.4 KiB
JavaScript
/**
|
|
* Copyright (c) 2026 Niolla
|
|
* All rights reserved.
|
|
*
|
|
* This source code is proprietary and confidential.
|
|
* Unauthorized copying, modification, distribution, or use
|
|
* of this file, via any medium, is strictly prohibited.
|
|
*/
|
|
|
|
// app/routes/profile.routes.js
|
|
|
|
const express = require("express");
|
|
const router = express.Router();
|
|
const profileController = require("../controllers/profile.controller.js");
|
|
const { authenticate } = require("../middleware/auth.middleware");
|
|
|
|
const {
|
|
authorizedAccountType,
|
|
checkPermission,
|
|
} = require("../middleware/permission.middleware");
|
|
const PERMISSIONS = require("../constants/permissions");
|
|
const { sensitiveLimiter } = require("../middleware/rateLimit.middleware");
|
|
|
|
router.post("/req-reset-password", sensitiveLimiter, profileController.requestPasswordReset);
|
|
|
|
router.post("/reset-password", sensitiveLimiter, profileController.resetPassword);
|
|
|
|
router.post(
|
|
"/change-password",
|
|
authenticate,
|
|
authorizedAccountType(["admin", "management", "team_head", "user"]),
|
|
profileController.changePassword,
|
|
);
|
|
|
|
router.get(
|
|
"/avatar/:userId",
|
|
authenticate,
|
|
authorizedAccountType(["admin", "management", "team_head", "user"]),
|
|
profileController.getProfileAvatar,
|
|
);
|
|
|
|
router.get(
|
|
"/background/:userId",
|
|
authenticate,
|
|
authorizedAccountType(["admin", "management", "team_head", "user"]),
|
|
profileController.getProfileBackgroundImage,
|
|
);
|
|
|
|
module.exports = router;
|