Files
bookhoard/docs/developer/api/users/change_password.md
T
john-okeefe 4d321528b2 docs: update comprehensive API documentation and project guides
This commit updates all documentation files throughout the project:

- Updated IMPLEMENTATION_PLAN.md with new implementation details
- Updated PROJECT_GUIDELINES.md with coding standards and practices
- Updated README.md with current project information
- Updated SCREENSHOT_AUTOMATION.md with new automation details
- Added TEST_DATA.md with test fixtures data
- Updated cover_image_serving_plan.md with static URL patterns

Documentation API updates:
- Updated API reference documentation for all endpoints including:
  - Authentication (login, logout, register, refresh_token)
  - Book matching (auto_link, bulk_link, link_book, search)
  - Collections (CRUD operations, shelf mappings, auto-assign rules)
  - Conflicts (bulk operations, resolve/dismiss)
  - Devices (registration, approval, shelf management)
  - Highlights (create, update, delete, get)
  - Kobo sync (bookmark, markup, initialization, sync)
  - KOReader sync (library, metadata, bookmarks, progress)
  - Libraries (CRUD, folders, media items, stats)
  - Media items (bulk operations, CRUD)
  - Notes (CRUD operations)
  - OPDS (acquisition, feeds, publication)
  - Progress (reading progress tracking)
  - Queue (device queue management)
  - Ratings (star ratings)
  - Scanner (watch mode, scan operations)
  - Sync protocols (Kobo, KOReader)
  - Users (profile, password, admin operations)
  - WebSocket protocols

- Updated user guides (admin, dashboard, settings, sync)
- Updated device setup guides (Kobo, KOReader)
- Updated developer guides (testing, contributing, operations)
- Updated scripts/README.md
2026-02-27 17:06:22 -05:00

73 lines
2.1 KiB
Markdown

# Change Password
Change user password. Supports both self-service and admin modes.
**Endpoints**:
- Self-service: `PUT /api/auth/password`
- Admin reset: `PUT /api/auth/password/:id`
**Auth**: Required
**Content-Type**: `application/json`
## Self-Service Mode
Users can change their own password by providing current password verification.
### Request Body
| Field | Type | Required | Description |
| ---------------- | ------ | -------- | ----------------------------------------------- |
| current_password | string | Yes | Current password for verification |
| new_password | string | Yes | New password (min 8 chars, complexity required) |
| confirm_password | string | Yes | Must match new_password |
### Example Request
```json
{
"current_password": "OldPassword123!",
"new_password": "NewSecureP@ss123!",
"confirm_password": "NewSecureP@ss123!"
}
```
## Admin Mode
Admins can reset any user's password without knowing the current password.
**URL Parameter**: `:id` - Target user's UUID
### Request Body (Admin Mode)
| Field | Type | Required | Description |
| ---------------- | ------ | -------- | ----------------------------------------------- |
| new_password | string | Yes | New password (min 8 chars, complexity required) |
| confirm_password | string | Yes | Must match new_password |
### Example Admin Request
```json
{
"new_password": "NewSecureP@ss123!",
"confirm_password": "NewSecureP@ss123!"
}
```
## Response (200 OK)
```json
{
"message": "password updated"
}
```
## Error Responses
| Code | Description |
| ---- | ------------------------------------------------------ |
| 400 | Invalid input, weak password, or passwords don't match |
| 401 | Current password is incorrect (self-service mode) |
| 403 | Admin access required (admin mode only) |
| 404 | User not found (admin mode only) |