Auth & profile architecture
Session tokens, route guards, profile persistence, and theme application.
Authentication spans the public /login page, the dashboard AuthGuard, the central api.auth client methods, and the backend AuthModule. Profile settings reuse the same user record for identity, password updates, theme, and accent color.
Runtime flow
Register, login, refresh, forgot-password (emails a one-time reset link), reset-password, profile update, and logout are exposed by /api/auth. The frontend stores access and refresh tokens in localAuth, applies theme values immediately, and verifies dashboard access with GET /auth/me.
Implementation map
Frontend
/login, /profile, AuthGuard, Sidebar theme toggle, localAuth, and api.auth.
Backend
AuthController, AuthService, TokenService, password helpers, Public decorator, and global AuthGuard.
Data
User stores email, passwordHash, refreshTokenHash, name, initials, title, company, phone, theme, and accentColor.
Security
Access tokens are short-lived, refresh tokens are hashed on the user document, and logout invalidates the stored refresh token hash.