- Module:
settings
- Version:
v0.01
- Ownership default: If unclear, settings owns until reassigned.
- Provides: user-facing preferences and configuration management.
- Includes: fetching and updating settings (theme, notifications, future preferences).
- Excludes: business profile management, payment settings, or system-wide configuration.
¶ 1. Roles and Views
[MOBILE] KMM Android/iOS app dev
[FE] Web frontend dev
[BE-RUST] Axum service dev
[BE-DB] PostgreSQL/Redis ops
-
Fetch Settings
- Return current preferences (theme, notifications).
- Authenticated-only.
-
Update Settings
- Upsert logic: insert if first-time, update otherwise.
- Authenticated-only.
-
Future Expansion
- Additional preferences (security, accessibility, integrations).
- Rate limiting on update endpoints.
| Method |
Path |
Purpose |
Auth |
| GET |
/api/settings/get |
Fetch user settings |
JWT |
| POST |
/api/settings/update |
Update or create user settings |
JWT |
| GET |
/api/settings |
Render HTML settings panel |
JWT |
Same as Core/Auth:
{ "error": { "code":"STRING", "http":INT, "message":"STRING", "trace_id":"UUIDv4" } }
- Debounce submits to avoid duplicate updates.
- Input validation (theme values restricted to supported options).
- Secure session persistence; all requests authenticated.
- Respect
429; exponential backoff with jitter.
- Show backend error messages where safe.
| Key |
Required |
Example |
Notes |
RATE_RPS |
no |
5 |
Global default req/sec/IP |
CORS_ORIGINS |
yes |
https://app.example.com |
CSV for web origin whitelist |
TLS_MIN |
no |
1.3 |
Enforce TLS 1.3 if terminated |
-
Android: Jetpack Compose/XML UI, store settings in EncryptedSharedPreferences.
-
iOS: Swift UI derived from shared KMM, secure storage via Keychain.
-
Preferences synced with backend via API.
-
Acceptance:
- Update visible in UI within 1s after save.
- Persisted across app restarts.
- React + Tailwind settings panel.
- API-driven persistence.
- CSRF protection on HTML form submission.
- Accessibility: WCAG 2.1 AA.
- Axum routes:
/get, /update.
- Authenticated middleware required (
AuthenticatedUser).
- SeaORM integration with
user_settings.
- Auto-create row if missing on first update.
- Rate limiting optional but recommended on
/update.
- CORS + CSRF layers applied.
| Field |
Type |
Description |
| id |
UUID |
Primary key |
| user_id |
UUID |
FK → users.id |
| theme |
String |
Theme (dark, light) |
| notifications |
bool |
Whether notifications enabled |
| created_at |
DateTimeUtc |
Creation timestamp |
| updated_at |
DateTimeUtc |
Last updated timestamp |
- Foreign key enforced.
- Index on
user_id for fast lookup.
- Auth required for all routes.
- CSRF tokens required on web POST.
- No sensitive data stored in settings for v0.01.
- If future security preferences added, must require 2FA.
- Latency: p95 ≤ 250 ms per request.
- Availability: 99.9% uptime.
- Scalability: ≥ 500 concurrent settings updates/sec sustained.
- Accessibility: WCAG 2.1 AA compliance on FE/mobile.
- Upsert logic correctness.
- Error mapping.
- New user creates row automatically.
- Existing user updates row.
- DB rollback safe on error.
- Update persists across restart.
- Rate limiting respected.
- CSRF token validated.
- A11y check passes ≥ 90 Lighthouse.
- KMM client methods:
getSettings(), updateSettings().
- UI for settings panel.
- React UI components.
- Form submission with CSRF token.
- Handlers for
/get, /update.
- Middleware enforcing auth.
- Migration for
user_settings.
- Index creation and FK enforcement.
- Authenticated user can fetch/update settings.
- Row auto-created on first update.
- Data persists and is consistent across clients.
- CSRF and CORS protections enabled.
- New preferences must be backward-compatible.
- DB migration required for schema changes.
- API versioning if breaking changes.