Files
Zumri-Backend/Documentation/Profile-API.md
T
Isuru Bimsara 81d0e65686 first commit
2026-08-14 22:46:02 +05:30

4.9 KiB

Profile API

Get Profile Avatar

Endpoint

GET: http://localhost:3070/api/profile/avatar/:userId

Path Parameters

Parameter Type Required Description
userId string Yes The user ID

Headers

Authorization: Bearer <token>

Response

{
  "success": true,
  "data": {
    "userId": "usr_763107d9-b56f-4b81-9d86-1889f98a6e6c",
    "profilePictureUrl": "https://signed-s3-url.com/profile-picture.jpg"
  }
}

Error Responses

{
  "success": false,
  "message": "Profile not found",
  "error": "Profile not found"
}
{
  "success": false,
  "message": "Internal server error",
  "error": "error message"
}

Get Profile Background Image

Endpoint

GET: http://localhost:3070/api/profile/background/:userId

Path Parameters

Parameter Type Required Description
userId string Yes The user ID

Headers

Authorization: Bearer <token>

Response

{
  "success": true,
  "data": {
    "userId": "usr_763107d9-b56f-4b81-9d86-1889f98a6e6c",
    "backgroundImageUrl": "https://signed-s3-url.com/background-image.jpg"
  }
}

Error Responses

{
  "success": false,
  "message": "Profile not found",
  "error": "Profile not found"
}
{
  "success": false,
  "message": "Internal server error",
  "error": "error message"
}

Profile Object Structure

The Profile object contains the following fields:

Field Type Description
profile_id string Unique profile identifier
user_id string Associated user ID
theme string User theme preference (light/dark)
notificationsEnabled boolean Notification settings
profilePicture_id string Upload ID for profile picture
backgroundImage_id string Upload ID for background image
dob date Date of birth
phone_number string Phone number
createdAt datetime Profile creation timestamp
updatedAt datetime Profile last update timestamp

Request Password Reset

Endpoint

POST: http://localhost:3070/api/profile/req-reset-password

Request Body

{
  "email": "sathira.nirmal@gmail.com"
}

Response

{
  "success": true,
  "message": "If an account exists with this email address, a password reset email has been sent."
}

Description

This endpoint generates a password reset token and sends a reset link to the user's email. The reset link will be sent in email format:

http://localhost:3000/reset-password?token=TOKEN_HERE&email=EMAIL_HERE

Example reset link:

http://localhost:3000/reset-password?token=aa27def4222adedcf72a417dfc40b69cd01f8bdb07f37b324a8501f3bdb37e44&email=sathira.nirmal%40gmail.com

Notes

  • This endpoint does not require authentication
  • No error is returned if email doesn't exist (for security reasons)
  • Token expires after the time specified in PASSWORD_RESET_EXPIRY_TIME environment variable (default: 10 minutes)

Reset Password

Endpoint

POST: http://localhost:3070/api/profile/reset-password

Request Body

{
  "email": "sathira.nirmal@gmail.com",
  "token": "168e5d9d4dfb124571f412c5521874e8440a0f9e4c151fa24518ae57ca1c4f8f",
  "newPassword": "niolla"
}

Response

{
  "success": true,
  "message": "Password reset successfully."
}

Error Responses

{
  "success": false,
  "message": "Invalid email address."
}
{
  "success": false,
  "message": "Invalid or expired token."
}

Description

This endpoint resets the user's password using a valid reset token. The token must be obtained from the password reset email.

Notes

  • This endpoint does not require authentication
  • Token must be valid and not expired
  • New password will replace the old password immediately


Authentication

All endpoints require authentication token unless otherwise noted. Include the Bearer token in the Authorization header:

Authorization: Bearer <your_jwt_token>

Authentication Required:

  • GET /avatar/:userId
  • GET /background/:userId
  • POST /change-password

No Authentication Required:

  • POST /req-reset-password
  • POST /reset-password

Authorization

Access levels for profile endpoints:

  • GET /avatar/:userId - Accessible by: admin, management, team_head, user
  • GET /background/:userId - Accessible by: admin, management, team_head, user
  • POST /change-password - Accessible by: admin, management, team_head, user (authenticated users)