feat(quick-260630-gbh-01): avatar storage endpoints + enriched /auth/me

- Add avatarPath String? column to User model (migration: add_user_avatar)
- POST /users/me/avatar: 2MB limit, image/png/jpeg/webp allowlist, writes to user-files/avatars/{userId}.{ext}
- GET /users/me/avatar: streams avatar with Cache-Control: no-store
- AuthService.getMe(): returns isLocalUser + hasAvatar without leaking passwordHash/ldapDn
- AuthController GET /auth/me: now returns enriched profile via getMe()
This commit is contained in:
2026-06-30 11:57:33 +02:00
parent dcba4b9977
commit 0fba45d2c2
5 changed files with 159 additions and 3 deletions
@@ -0,0 +1,2 @@
-- AlterTable
ALTER TABLE "User" ADD COLUMN "avatarPath" TEXT;
+1
View File
@@ -39,6 +39,7 @@ model User {
createdAt DateTime @default(now())
updatedAt DateTime @updatedAt
lastLoginAt DateTime?
avatarPath String?
passwordResetTokens PasswordResetToken[]
@@index([tenantId])