POST /api/v1/profile/password # Session
Change your own password.
Session-only. current_password is required — the caller already holds
a session, so without it an unlocked browser would be enough to lock the
real owner out. This is what separates it from the admin reset on
PATCH /admin/users/{id}.
On success every existing session for the user is dropped and a new
cookie is issued to the caller, so other browsers are logged out but the
tab making the request is not.
Request body required
application/json
object
current_password string required
new_password string required
Responses
200 Updated; a fresh session cookie is set. status is updated.
application/json
object
An acknowledgement with nothing else to report.
status names what happened — ok, updated, deleted, cleared,
started and so on; the operation says which it sends. A client needs only
the HTTP status to know it worked.
400 Malformed or rejected input.
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.
401 No valid session cookie or token. Also returned when a token is
presented to a session-only endpoint — the endpoint does not accept
tokens at all, so the scope is irrelevant.
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.
{
"code": 401,
"error": "Authentication required. Log in to access this endpoint."
}
403 The current password is wrong.
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.
POST /api/v1/profile/avatar # Session
Upload a profile picture.
Session-only, multipart/form-data, 4 MB maximum. The extension comes
from the declared content type, never from the client's filename. The
picture it replaces is deleted.
Request body required
multipart/form-data
object
A multipart/form-data upload of one file.
The server takes the first file part whatever its field name; file is the
name to use. Its declared Content-Type decides how the file is stored — a
filename from the client never reaches a path on disk.
file string · binary required
Responses
application/json
object
Where the stored picture is served from.
avatar string required
Always /api/v1/profile/avatar.
400 Malformed or rejected input.
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.
401 No valid session cookie or token. Also returned when a token is
presented to a session-only endpoint — the endpoint does not accept
tokens at all, so the scope is irrelevant.
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.
{
"code": 401,
"error": "Authentication required. Log in to access this endpoint."
}
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.
415 Not an image type we store.
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.