- 📦 Module:
settings
- 🔢 Version:
v0.01
This module allows authenticated users to manage personal application settings. It includes:
-
Fetching user settings
- Returns current preferences (e.g., theme, notification settings)
- Only accessible by authenticated users
-
Updating user settings
- Allows users to change preferences like UI theme and notification opt-in
- Supports create-or-update logic (upsert)
- Only accessible by authenticated users
Design
Requirements
Tests
- RESTful API endpoints
- Upsert (update-insert) logic for first-time vs returning users
- Secure access via token-based middleware
- Platform parity (mobile, web)
- React components using TailwindCSS
- Uses settings API to persist preferences
- Authenticated-only settings panel
- CSRF protection applied
- Kotlin-derived UI
- Secure storage in Keychain
- Platform-appropriate UX
¶ Android Specific
- Kotlin UI via Compose/XML
- EncryptedSharedPreferences
- Push notifications as needed
- Axum-based route handlers
- DB integration via SeaORM
- CSRF & CORS middleware enabled
- Modular route structure:
/api/settings/get
/api/settings/update
user_settings table stores user preferences
- Related to the
users table via user_id (foreign key)
- Auto-creates a new row on first update if missing
- Timestamps managed automatically via ORM
- All routes behind
AuthenticatedUser middleware
- Only users with valid auth tokens may update/view settings
- CSRF middleware active for all HTML views
- Theme preferences are non-sensitive, but security settings (planned) will require 2FA
Not yet implemented in the Rust code
- Rate limiting could be added to:
| Method |
Path |
Description |
| GET |
/api/settings/get |
Retrieve current user settings |
| POST |
/api/settings/update |
Update or create user settings |
| GET |
/api/settings |
Render HTML settings page (web) |
- Comes from
/profile/entity
| Field |
Type |
Description |
| id |
UUID |
Primary key |
| user_id |
UUID |
Foreign key to users table |
| theme |
String |
UI theme (e.g., "dark", "light") |
| notifications |
bool |
Whether user enables notifications |
| updated_at |
DateTimeUTC |
Last updated timestamp |
| created_at |
DateTimeUTC |
Created timestamp |
Mermaid Diagram
- Implement rate limiting on sensitive endpoints
- Adding more settings other than just theme and notificatins