Rezepte
ReferenceAuth

Auth

Signing in, signing out and reading the current session.

Confirm an address through the link mailed to it

Public. Confirms only while the address is still the account's; never signs in.

Log in with username and password

End the current session

Return the current user

Change the current user's password

Verifies the current password, stores the new one and ends every other session of the user; the session making the call stays valid. An account without a password sets one without currentPassword.

Remove the own picture

Set the own picture (JPEG, PNG or WebP, at most 10 MiB)

The square to keep, as x,y,size: x and y place its top-left corner as fractions of the upright image's width and height, size is its side as a fraction of the shorter side. Absent keeps the centered square.

List the color palette and how many accounts hold each color

Counts, not names: the picker only needs to mark a color as taken. It sits under /auth/me because it describes what the caller may choose for themselves; /people names every account without counting colors, and everything under /users is admin-only.

Mail a new confirmation link for the current user's address

At most once a minute; the minute starts before the send, so a failed send also waits a minute. 409 when there is no address, it is confirmed, or mail is not configured.

Tell whether the current account is connected to the identity provider

Disconnect the current account from the identity provider

Ends every other session of the account; the session making the call stays valid. Refused with 409 while the account has no password: it would have no way left to sign in.

Change the current user's display name, color and interface language

Its own path rather than PATCH /api/v1/auth/me, which is the password change and demands the current password - a rename has nothing to do with it.

Tell whether sign-in through an identity provider is offered

Public: the login page asks before anyone is signed in. The flow itself runs through POST /api/v1/auth/oidc/start, a form post the browser follows to the provider.

Finish signing in through the identity provider

The redirect URI the provider sends the browser back to with code and state. Answers 303 into the SPA: signed in, connected, or with ?oidc=unlinked|taken|linked|failed.

Start signing in through the identity provider

A form post (application/x-www-form-urlencoded) the browser follows: intent is login, link (connect the signed-in account) or setup (finish an account through its setup link, passed as setup); next is the SPA path to return to. Answers 303 to the provider, or back to the SPA with ?oidc=failed.

Tell whether a forgotten password can be reset by mail

Public, like GET /api/v1/auth/oidc: the login page asks before anyone is signed in.

Mail a password reset link

Public. Always 204, whether or not an account matches, and the mail goes out in the background, so neither the answer nor its timing tells whether an account exists. A login with @ is an address and reaches every account whose confirmed address it is; otherwise it is a username with a confirmed address. An account without a password that signs in through the identity provider gets a hint instead. The owner is never reset by mail; at most one mail per account per 5 minutes.

Look up the account a setup link belongs to, without using it

Set a password through a setup link and sign in