- Add role-based restrictions to POST /api/auth/register endpoint - Only admins can create admin accounts if any admin already exists - First user automatically gets admin role regardless of request - Regular users can only create user accounts, not admin accounts - Unauthenticated users can only create first admin, not subsequent admins - Reorganize Bruno collection into logical subfolders (auth/, admin/, profile/) - Update documentation to reflect new registration restrictions and security rules BREAKING CHANGES: - /api/auth/register now enforces role-based creation restrictions - Bruno collection reorganized with subfolder structure
48 lines
714 B
Plaintext
48 lines
714 B
Plaintext
meta {
|
|
name: Update Profile
|
|
type: http
|
|
seq: 4
|
|
}
|
|
|
|
put {
|
|
url: {{base_url}}/api/auth/profile
|
|
body: json
|
|
auth: inherit
|
|
}
|
|
|
|
body:json {
|
|
{
|
|
"first_name": "Updated",
|
|
"last_name": "Name"
|
|
}
|
|
}
|
|
|
|
settings {
|
|
encodeUrl: true
|
|
timeout: 0
|
|
}
|
|
|
|
docs {
|
|
## Update User Profile
|
|
|
|
Updates the authenticated user's profile information.
|
|
|
|
**Method:** PUT
|
|
|
|
**Endpoint:** /api/auth/profile
|
|
|
|
**Authentication:** Required (Bearer token)
|
|
|
|
**Request Body:**
|
|
- `first_name` (string, optional): First name
|
|
- `last_name` (string, optional): Last name
|
|
|
|
**Response:**
|
|
- `message` (string): Success message
|
|
|
|
**Status Codes:**
|
|
- 200: Success
|
|
- 400: Invalid request
|
|
- 401: Unauthorized
|
|
}
|