profilev0.01This module provides utilities relating to the user profile, including the following:
email_token field of the users table, and expire after 30 minutesusers tablerequires_2fa field in the users table/core/authEncryptedSharedPreferencesusers table as source of truthuser_id acts as primary and foreign key where neededdb_generic for all operationsNot yet implemented in the Rust code
Rate limiting on sensitive endpoints such as:
/api/password/request-reset/api/password/reset/api/profile/delete/api/profile/updateRate limiting is handled via package_name
users table specific to Google sign in| Field | Type | Purpose |
|---|---|---|
google_id |
Option<String> |
Stores Google user ID |
provider |
Option<String> |
e.g., "google" vs "native" |
profile_image |
Option<String> |
User’s Google profile picture URL |
locale |
Option<String> |
Locale/language from Google account |
password_hash |
Option<String> |
Optional, since Google users may not have passwords |
users table specific to Two-Factor Authentication| Field | Type | Purpose |
|---|---|---|
requires_2fa |
bool |
Whether or not the user has 2fa enabled |
| Method | Path | Description |
|---|---|---|
| GET | /api/profile/me |
Get current user's profile |
| PUT | /api/profile/update |
Update name and email |
| DELETE | /api/profile/delete |
Delete account (with password) |
| POST | /api/password/change |
Change password while logged in |
| GET | /api/profile/:id |
Public/admin view of a profile |
| GET | /api/password/request-reset |
Request password reset token |
| GET | /api/password/reset |
Reset password with token |
users| Field | Type | Description |
|---|---|---|
| id | UUID | Primary key |
| String | Unique email address | |
| password_hash | String (option) | Secure hash of password, optional for Google users |
| email_verified | bool | Is the email verified? |
| email_token | String (option) | Token of the email, optional for Google users |
| requires_2fa | bool (option) | Does the user require two factor authentication? Optional for Google users |
| created_at | timestamp | Timestamp of creation |
| updated_at | timestamp | Last update time |
| role | String | Role of the user |
| google_id | String (option) | Google OAuth ID (optional for regular users) |
| provider | String (option) | Google OAuth provider (optional for regular users) |
| profile_image | String (option) | Google OAuth profile picture (optional for regular users) |
| locale | String (option) | Google OAuth locale (optional for regular users) |