- Module:
profile
- Version:
v0.01
- Ownership default: If unclear, profile owns until reassigned.
- Provides: profile management features, including CRUD, password resets, OAuth integration, and 2FA settings.
- Includes: fetching, updating, and deleting profiles; changing and resetting passwords; Google OAuth handling; 2FA enable/disable.
- Excludes: core authentication (handled in
auth), payment or billing profile details, or vendor-specific attributes.
¶ 1. Roles and Views
[MOBILE] KMM Android/iOS app dev
[FE] Web frontend dev
[BE-RUST] Axum service dev
[BE-DB] PostgreSQL/Redis ops
-
Fetch Current Profile
- Authenticated users fetch their profile.
-
Fetch Another User’s Profile
- Public/admin view of another profile.
-
Update Profile
- Authenticated, verified users can update email/name.
-
Delete Account
- Authenticated, verified users can delete with password confirmation.
-
Password Reset Flow
- Request reset → email token issued (expires 30m).
- Reset password with token → token invalidated.
-
Change Password
- Authenticated users change password with old-password check.
-
Google OAuth
- Passwordless login/updates.
- Stores Google metadata in
users table.
-
Apple OAuth
- Passwordless login/updates.
- Stores Apple metadata in
users table.
-
Two-Factor Authentication
- Enable/disable 2FA (email/SMS).
- Updates
requires_2fa field.
| Method |
Path |
Description |
Auth |
| GET |
/api/profile/me |
Get current user’s profile |
JWT |
| GET |
/api/profile/:id |
Public/admin view of profile |
JWT/Role |
| PUT |
/api/profile/update |
Update name/email |
JWT |
| DELETE |
/api/profile/delete |
Delete account (requires password) |
JWT |
| POST |
/api/password/change |
Change password (old → new) |
JWT |
| POST |
/api/password/request-reset |
Request password reset token |
none |
| POST |
/api/password/reset |
Reset password with token |
none |
{ "error": { "code":"STRING", "http":INT, "message":"STRING", "trace_id":"UUIDv4" } }
- Debounce form submits; block duplicate requests in-flight.
- Validate email format and password policy locally.
- Securely store updated tokens after password changes.
- Display backend error messages verbatim where safe.
- Respect
429 rate limits (backoff + jitter).
| Key |
Required |
Example |
Notes |
BCRYPT_COST |
yes |
12 |
Cost factor for password hash |
JWT_SECRET |
yes |
base64 |
Token signing key |
PASSWORD_RESET_TTL |
yes |
1800 |
Reset token lifetime (sec) |
GOOGLE_CLIENT_ID |
no |
client.apps.google.com |
OAuth integration |
-
Android: Compose, secure storage via EncryptedSharedPreferences.
-
iOS: Swift UI, secure storage via Keychain.
-
Must support:
- Profile fetch/update flows.
- Password reset via email token.
- 2FA prompts where required.
- Google OAuth sign-in (native SDKs).
-
Acceptance:
- Profile update reflected < 1s.
- Password reset flows complete successfully.
-
React + Tailwind profile screen.
-
Hooks for profile fetch/update/delete.
-
UI for change/reset password, delete account.
-
Support Google OAuth login.
-
2FA enable/disable toggle in profile.
-
Acceptance:
- Lighthouse a11y ≥ 90.
- Error states handled clearly.
- Axum route handlers.
- SeaORM queries for
users table.
- Passwords hashed (bcrypt/argon2).
- JWT auth required for update/delete/change.
- Password reset tokens stored and expired.
- Google OAuth token verified.
- 2FA codes validated before sensitive operations.
- Rate limiting applied to password reset endpoints.
- CSRF protection for HTML endpoints.
| Field |
Type |
Description |
| id |
UUID |
Primary key |
| email |
String |
Unique |
| password_hash |
Option |
bcrypt/argon2 hash or null (Google) |
| email_verified |
bool |
Email verified flag |
| email_token |
Option |
Verification/reset token |
| requires_2fa |
Option |
2FA enabled |
| created_at |
Timestamp |
Creation time |
| updated_at |
Timestamp |
Last update time |
| role |
String |
Role (user/admin) |
| google_id |
Option |
Google OAuth ID |
| provider |
Option |
“google” vs “native” |
| profile_image |
Option |
Google profile picture |
| locale |
Option |
Google locale/language |
- Index:
user_id, email.
- Tokens expire after 30m.
- JWT/session-based auth.
- Passwords hashed with bcrypt/argon2.
- CSRF protection on HTML.
- PII redacted in logs.
- 2FA enforced where enabled.
- Password reset tokens: single-use, 30m expiry.
- Latency: p95 ≤ 250 ms/profile operation.
- Availability: 99.9% for profile endpoints.
- Scalability: ≥ 1000 concurrent profile fetches/sec.
- Accessibility: WCAG 2.1 AA for FE/mobile.
- Password hash/verify.
- Token expiry logic.
- Google OAuth validation.
- Register → verify → fetch/update → delete.
- Reset token creation + expiry.
- 2FA enforcement.
- Profile update.
- Password reset loop.
- Google login.
- Profile UI update.
- Delete account confirmation.
- 2FA toggle works.
- KMM client: getProfile, updateProfile, deleteProfile, requestReset, resetPassword, changePassword.
- Token store wrapper with Google OAuth + 2FA support.
- Profile UI: view/update/delete, reset/change password.
- Hooks for API integration.
- Route handlers:
/me, /update, /delete, /password/*.
- Middleware: auth, rate limit, CSRF.
- Migration for
users table (fields above).
- Indexes + constraints.
- Authenticated users can fetch/update/delete their profile.
- Password change and reset flows work.
- Google OAuth integrated.
- 2FA enforced if enabled.
- CSRF + rate limiting active.
- API versioning for breaking changes.
- Deprecation ≥ 2 release cycles.
- New profile fields require migration + docs.