feat(quick-260630-gbh-01): avatar storage endpoints + enriched /auth/me
- Add avatarPath String? column to User model (migration: add_user_avatar)
- POST /users/me/avatar: 2MB limit, image/png/jpeg/webp allowlist, writes to user-files/avatars/{userId}.{ext}
- GET /users/me/avatar: streams avatar with Cache-Control: no-store
- AuthService.getMe(): returns isLocalUser + hasAvatar without leaking passwordHash/ldapDn
- AuthController GET /auth/me: now returns enriched profile via getMe()
This commit is contained in:
@@ -53,11 +53,12 @@ export class AuthController {
|
||||
|
||||
/**
|
||||
* GET /auth/me
|
||||
* Returns the current user from JWT (session check).
|
||||
* Returns enriched user profile: public fields + isLocalUser + hasAvatar.
|
||||
* T-gbh-03: passwordHash and ldapDn are never serialised in the response.
|
||||
*/
|
||||
@Get('me')
|
||||
me(@CurrentUser() user: any) {
|
||||
return user;
|
||||
async me(@CurrentUser() user: any) {
|
||||
return this.authService.getMe(user.id);
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user