profile ModuleThe Profile Module is used for managing user data and related profile operations including:
Viewing user profiles
Updating profile information
Deleting accounts
Resetting or changing passwords
This module uses token-based authentication and middleware protection for all sensitive routes.
src/
├── profile/
│ ├── api/
│ │ ├── profile.rs # Profile management (view, update, delete)
│ │ └── password.rs # Password reset & change
│ ├── entity/
│ │ ├── users.rs # Users table definition
│ │ ├── author.rs # Optional: author info
│ │ └── user_settings.rs # Optional: user preferences
│ ├── constants.rs # Route and path constants
│ └── web/ # Web endpoints
| Method | Path | Description |
|---|---|---|
| GET | /api/profile/me |
Get current user's profile |
| PUT | /api/profile/update |
Update name and email |
| DELETE | /api/profile/delete |
Delete account (with password) |
| POST | /api/password/change |
Change password while logged in |
| GET | /api/profile/:id |
Public/admin view of a profile |
| GET | /api/password/request-reset |
Request password reset token |
| GET | /api/password/reset |
Reset password with token |
/entity/user_settings.rs pub id: Uuid,
pub user_id: Uuid,
pub theme: String, // e.g. "dark"
pub notifications: bool, // Enable/disable email/push
pub created_at: DateTimeUtc,
pub updated_at: DateTimeUtc,
}
/entity/users.rspub struct Model {
pub id: Uuid,
pub email: String,
pub password_hash: Option<String>,
pub email_verified: bool,
pub email_token: Option<String>,
pub requires_2fa: Option<bool>,
pub created_at: DateTimeUtc,
pub updated_at: DateTimeUtc,
pub role: String,
pub google_id: Option<String>,
pub provider: Option<String>,
pub profile_image: Option<String>,
pub locale: Option<String>,
}
/entity/author.rspub struct Model {
pub id: Uuid,
pub user_id: Uuid,
pub pen_name: Option<String>,
pub biography: Option<String>,
}
DeleteAccountRequest:
pub struct DeleteAccountRequest {
pub email: String,
pub password: String,
}
delete_account_handlerUpdateProfileRequest
pub struct UpdateProfileRequest {
pub name: String,
pub email: String,
}
update_profile_handlerRequestReset
pub struct RequestReset {
pub email: String,
}
request_reset_handlerResetPassword
pub struct ResetPassword {
pub token: String,
pub new_password: String,
}
reset_passowrd_handlerChangePasswordRequest
pub struct ChangePasswordRequest {
pub current_password: String,
pub new_password: String,
}
change_password_handlerUpdateProfileResponse
pub struct UpdateProfileResponse {
pub success: bool,
pub verified: bool,
pub error: Option<String>,
}
update_profile_handlersuccess: Whether or not the update was successfulverified: Whether or not the user is verifiederror: Handles the error message if there is oneProfileResponse
pub struct ProfileResponse {
pub id: Uuid,
pub email: String,
pub created_at: chrono::DateTime<chrono::Utc>,
pub role: String,
}
get_profileMeResponse
pub struct MeResponse {
pub id: Uuid,
pub email: String,
pub role: String,
}
me_handlerme_handler
get_profile
update_profile_handler
Updates the user's email/name.
Uses SeaORM ActiveModel::update()
delete_account_handler
request_reset_handler
reset_password_handler
change_password_handler
Add support for enforcing 2FA on sensitive endpoints.
Extend user_settings with full privacy controls (i.e. profile visibility toggles).
Email service integration for password resets and verification.
Add audit logging for profile updates and deletions.