docs: update comprehensive API documentation and project guides
This commit updates all documentation files throughout the project: - Updated IMPLEMENTATION_PLAN.md with new implementation details - Updated PROJECT_GUIDELINES.md with coding standards and practices - Updated README.md with current project information - Updated SCREENSHOT_AUTOMATION.md with new automation details - Added TEST_DATA.md with test fixtures data - Updated cover_image_serving_plan.md with static URL patterns Documentation API updates: - Updated API reference documentation for all endpoints including: - Authentication (login, logout, register, refresh_token) - Book matching (auto_link, bulk_link, link_book, search) - Collections (CRUD operations, shelf mappings, auto-assign rules) - Conflicts (bulk operations, resolve/dismiss) - Devices (registration, approval, shelf management) - Highlights (create, update, delete, get) - Kobo sync (bookmark, markup, initialization, sync) - KOReader sync (library, metadata, bookmarks, progress) - Libraries (CRUD, folders, media items, stats) - Media items (bulk operations, CRUD) - Notes (CRUD operations) - OPDS (acquisition, feeds, publication) - Progress (reading progress tracking) - Queue (device queue management) - Ratings (star ratings) - Scanner (watch mode, scan operations) - Sync protocols (Kobo, KOReader) - Users (profile, password, admin operations) - WebSocket protocols - Updated user guides (admin, dashboard, settings, sync) - Updated device setup guides (Kobo, KOReader) - Updated developer guides (testing, contributing, operations) - Updated scripts/README.md
This commit is contained in:
@@ -42,6 +42,7 @@ When a user registers or logs in:
|
||||
4. Server returns JSON response with both tokens and user profile
|
||||
|
||||
**Request**:
|
||||
|
||||
```json
|
||||
POST /api/auth/login
|
||||
{
|
||||
@@ -51,6 +52,7 @@ POST /api/auth/login
|
||||
```
|
||||
|
||||
**Response**:
|
||||
|
||||
```json
|
||||
{
|
||||
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
|
||||
@@ -67,6 +69,7 @@ POST /api/auth/login
|
||||
```
|
||||
|
||||
**Set-Cookie Header**:
|
||||
|
||||
```
|
||||
Set-Cookie: token=eyJhbG...; Max-Age=604800; Path=/; HttpOnly
|
||||
```
|
||||
@@ -94,6 +97,7 @@ POST /api/auth/refresh
|
||||
```
|
||||
|
||||
**Response**:
|
||||
|
||||
```json
|
||||
{
|
||||
"access_token": "new-jwt-token",
|
||||
@@ -135,6 +139,7 @@ When an API call receives a 401 Unauthorized response:
|
||||
```
|
||||
|
||||
The frontend toast.js interceptor:
|
||||
|
||||
1. Clears invalid tokens from localStorage
|
||||
2. Shows an error toast notification
|
||||
3. Allows user to re-authenticate
|
||||
@@ -149,10 +154,12 @@ The frontend toast.js interceptor:
|
||||
## Token Storage Recommendations
|
||||
|
||||
### Browser Applications
|
||||
|
||||
- **Backend**: Automatically manages HTTP-only cookie
|
||||
- **Frontend**: Store tokens in localStorage for API calls
|
||||
|
||||
### Mobile Applications
|
||||
|
||||
- Store access token in secure storage (Keychain/Keystore)
|
||||
- Store refresh token in secure storage
|
||||
- Handle 401 responses by prompting user to re-authenticate
|
||||
@@ -160,6 +167,7 @@ The frontend toast.js interceptor:
|
||||
## Constants Reference
|
||||
|
||||
All session durations use constants defined in:
|
||||
|
||||
- `internal/handlers/auth.go` - SessionDuration, SessionDurationSec
|
||||
- `internal/handlers/refresh_token.go` - SessionDurationSec (mirrored)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user