Auth & profile architecture

Session tokens, route guards, profile persistence, and theme application.

Authentication spans the public /login page, the dashboard AuthGuard, the central api.auth client methods, and the backend AuthModule. Profile settings reuse the same user record for identity, password updates, theme, and accent color.

Runtime flow

Register, login, refresh, forgot-password (emails a one-time reset link), reset-password, profile update, and logout are exposed by /api/auth. The frontend stores access and refresh tokens in localAuth, applies theme values immediately, and verifies dashboard access with GET /auth/me.

Auth, token, profile, and theme flow
Rendering architecture diagram...

Implementation map

Frontend

/login, /profile, AuthGuard, Sidebar theme toggle, localAuth, and api.auth.

Backend

AuthController, AuthService, TokenService, password helpers, Public decorator, and global AuthGuard.

Data

User stores email, passwordHash, refreshTokenHash, name, initials, title, company, phone, theme, and accentColor.

Security

Access tokens are short-lived, refresh tokens are hashed on the user document, and logout invalidates the stored refresh token hash.