Document the self-service password change

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KGcjxF1cNLcuwc3DAPcnfj
This commit is contained in:
2026-09-29 15:31:21 +05:30
parent 6068b2c3c7
commit e0bd764e44
2 changed files with 70 additions and 0 deletions

29
API.md
View File

@@ -43,6 +43,7 @@ user; the tenant is always taken from the session and never from the request.
|---|---|
| `POST /api/auth/login` `refresh` · `GET /api/auth/invitation` · `POST /api/auth/register` | **no auth** |
| `POST /api/auth/logout` · `GET /api/auth/me` · `/api/auth/sessions*` | authed |
| `POST /api/auth/password` — change your OWN | authed (platform admins too) |
| `GET /api/visits` · `GET /api/visits/stream` | authed |
| `GET /api/visitors` · `GET /api/visitors/{id}/history` · `GET /api/visitors/{id}/image` · `GET /api/faces/{id}` | authed |
| `PUT /api/visitors/{id}/profile` · `POST /api/purchases` | staff |
@@ -477,6 +478,34 @@ deactivate them (§4); that revokes every session they hold.
---
### `POST /api/auth/password` — any signed-in account
Change your own password. Works for **every** account including a platform
admin, who has no company and therefore cannot be reached by the team routes.
```json
{ "current_password": "...", "new_password": "..." }
```
```json
{ "changed": true, "sessions_revoked": 3 }
```
- **The current password is required.** An access token lives twelve hours and
travels on shop-floor PCs and staff phones; without this a stolen one would
own the account permanently rather than until it expires. Wrong current
password is **403 `wrong_password`** and changes nothing.
- **Every other session is revoked; the caller's is kept.** Somebody changing
their password because they think it is known must not wonder whether the
device that already had it is still signed in — and must not be signed out of
the one in their hand while dealing with it.
- A new password under the floor is **400**, and so is reusing the current one.
This is the route to use rather than asking an administrator. `POST
/api/team/{id}/password` remains what a manager uses on somebody *else*.
---
## 4. The team
### `GET /api/team` — anyone in the company