User Endpoints (Djoser)
Registration, activation, password management via djoser REST endpoints.
All djoser endpoints are mounted under /auth/. The configuration is in config/settings/base.py under DJOSER.
Registration
Create User
POST /auth/users/{
"email": "user@example.com",
"password": "secure-password-123",
"re_password": "secure-password-123"
}Returns 201 Created and sends an activation email (SEND_ACTIVATION_EMAIL). The account can't sign in until it's activated.
Activate Account
POST /auth/users/activation/{
"uid": "MQ",
"token": "c3g3vj-abc123..."
}The uid and token come from the activation email's link, which opens the frontend at user-activation/{uid}/{token}.
Resend Activation Email
POST /auth/users/resend_activation/{
"email": "user@example.com"
}Current User
Get Profile
GET /auth/users/me/Returns the signed-in user's id, name and email, and their workspaces: each with its id, name, slug, status, the user's role, created_at and updated_at.
Update Profile
PUT /auth/users/me/
PATCH /auth/users/me/Changes name. The email is read-only here; see Email Management.
Delete Account
DELETE /auth/users/me/{
"current_password": "your-password"
}Deleting an account deletes the workspaces it owns, so it's refused (400, with the reasons) until:
- the account's subscriptions are cancelled, and
- every workspace it owns that has other members is transferred to someone else, or has no other members left.
Password Management
Change Password
POST /auth/users/set_password/{
"new_password": "new-secure-password",
"re_new_password": "new-secure-password",
"current_password": "old-password"
}Request Password Reset
POST /auth/users/reset_password/{
"email": "user@example.com"
}Sends a password reset email whose link opens the frontend at confirm-password-reset/{uid}/{token}. The response is the same whether or not the address has an account.
Confirm Password Reset
POST /auth/users/reset_password_confirm/{
"uid": "MQ",
"token": "c3g3vj-abc123...",
"new_password": "new-secure-password",
"re_new_password": "new-secure-password"
}Email Management
Changing an account's email takes three steps, so the change only happens once both addresses are proven.
1. Request a Change
POST /auth/users/reset_email/{
"email": "current@example.com"
}Emails the current address a link to confirm-username-reset/{uid}/{token}.
2. Choose the New Address
POST /auth/users/reset_email_confirm/{
"uid": "MQ",
"token": "c3g3vj-abc123...",
"new_email": "new@example.com",
"re_new_email": "new@example.com"
}Nothing changes yet. A confirmation link is sent to the new address, opening the frontend at confirm-email-change/{token}. It's valid for 3 days.
3. Confirm at the New Address
POST /auth/users/confirm_email_change/{
"token": "eyJ1c2VyIjoxLCJmcm9tIjoi..."
}Switches the account to the new address and tells the old one. No sign-in needed: the token is the proof.
POST /auth/users/set_email/, which changes the email directly, is restricted to staff.
Djoser Configuration
DJOSER = {
"USER_CREATE_PASSWORD_RETYPE": True,
"SEND_ACTIVATION_EMAIL": True,
"SEND_CONFIRMATION_EMAIL": True,
"PASSWORD_CHANGED_EMAIL_CONFIRMATION": True,
"USERNAME_CHANGED_EMAIL_CONFIRMATION": True,
"ACTIVATION_URL": "user-activation/{uid}/{token}",
"PASSWORD_RESET_CONFIRM_URL": "confirm-password-reset/{uid}/{token}",
"USERNAME_RESET_CONFIRM_URL": "confirm-username-reset/{uid}/{token}",
# Answer the same whether or not the email is registered.
"PASSWORD_RESET_SHOW_EMAIL_NOT_FOUND": False,
"USERNAME_RESET_SHOW_EMAIL_NOT_FOUND": False,
"PERMISSIONS": {
"set_username": ["rest_framework.permissions.IsAdminUser"],
},
"SERIALIZERS": {
"user": "backend.users.api.serializers.UserSerializer",
"current_user": "backend.users.api.serializers.UserSerializer",
"user_delete": "backend.users.api.serializers.UserDeleteSerializer",
},
}The /auth/users/ routes are served by AccountViewSet (users/api/account_views.py), a subclass of djoser's view that adds the confirmed email change.