Accounts — serializers¶
Responsibilities¶
The accounts serializers define the API contract for:
- authentication and password flows
- workforce profile and personal settings
- work schedule read/write payloads
- device/session data returned to clients
- invite creation, preview, acceptance, and management
- skills and user-skill assignment operations
- the aggregated
mepayload
They are responsible for:
- validating incoming request data
- normalizing user input
- shaping response payloads for frontend clients
- exposing derived/read-only fields where useful
- keeping view logic thin
They are not responsible for business workflows that have been moved into services, such as invite lifecycle handling or auth session mutation.
Main serializers¶
LoginSerializer¶
Validates login requests for username-or-email authentication plus device context.
- Fields
identifierusernamepassworddevice_idplatformdevice_nameapp_versionpush_token- Validation
- Requires either
identifierorusername - Normalizes both into
identifier - Strips whitespace
- Normalizes
platform - Used by
LoginView
This serializer exists partly for backward compatibility: older clients can still send username, while newer clients can send identifier.
LogoutSerializer¶
Validates logout requests.
- Fields
refresh- Validation
- Requires a non-empty refresh token
- Used by
LogoutView
ChangePasswordSerializer¶
Validates authenticated password change requests.
- Fields
current_passwordnew_passwordnew_password_confirm- Validation
- Confirms current password is correct
- Confirms new password and confirmation match
- Runs Django password validators
- Used by
ChangePasswordView
This serializer enforces password-change rules before the auth service updates the stored password.
ForgotPasswordSerializer¶
Validates password reset request initiation.
- Fields
email- Validation
- Lowercases and strips email
- Used by
ForgotPasswordView
This serializer intentionally stays simple because the endpoint always returns a generic response to avoid account enumeration.
ResetPasswordSerializer¶
Validates password reset completion.
- Fields
uidtokennew_passwordnew_password_confirm- Validation
- Confirms password match
- Decodes the user id from
uid - Validates the reset token
- Runs Django password validators
- Injects resolved
userintovalidated_data - Used by
ResetPasswordView
This serializer is the bridge between the password reset link payload and the actual user account.
DeviceSessionSummarySerializer¶
Read-only summary serializer for active device sessions.
- Fields
idcreated_atrevoked_atipuser_agent- Used by
- nested device responses
This serializer is intentionally limited and does not expose refresh_jti.
DeviceSerializer¶
Read serializer for registered devices.
- Fields
iddevice_idnameplatformapp_versionpush_providerpush_tokennotifications_enabledtimezonelast_seen_atcreated_atactive_sessions- Derived fields
active_sessionsfrom non-revokedDeviceSessionrows- Used by
MyDevicesView- device upsert responses
This serializer gives the frontend enough information to render device/session management screens.
DeviceUpsertSerializer¶
Validates device registration/update payloads.
- Fields
device_idplatformdevice_nameapp_versionpush_providerpush_tokennotifications_enabledtimezone- Validation
- Requires non-empty
device_id - Validates allowed platform choice
- Normalizes
platformandpush_provider - Used by
UpsertDeviceView
DeviceSessionSerializer¶
Full read-only session serializer.
- Fields
iddevicerefresh_jticreated_atrevoked_atipuser_agent
This is useful internally, though most frontend-facing APIs should prefer the summary serializer.
UserProfileSerializer¶
Primary serializer for workforce profile read/write operations.
- Fields
- Basic identity/display
display_namephonejob_titleavatarpreferred_namepronouns
- Localization
timezonelocaleweek_start
- General profile
biodepartmentlocationemployee_idstart_date
- Workforce fields
employment_typeemployment_statusmanagermanager_namemanager_usernamehome_baseprimary_regiontravel_radius_kmhas_company_vehicledriver_license_typecan_travel_internationallyavailability_statusis_dispatchableon_callassignment_notesemergency_contact_nameemergency_contact_phoneemergency_contact_relation
- Workload
minimum_weekly_hourseffective_minimum_weekly_hours
- Validation
- Strips string fields
- Prevents negative numeric values where not allowed
- Prevents a user from being their own manager
- Derived fields
manager_namemanager_usernameeffective_minimum_weekly_hours- Used by
UpdateProfileView- nested inside
MeSerializer
This is the main operational serializer for workforce identity.
UserSettingsSerializer¶
Read/write serializer for user UI and preference settings.
- Fields
languagethemegradientcard_stylecard_colorfont_familyfont_scaleaccentdensityreduce_motionpreferences- Validation
- Strips language value
- Validates theme against allowed set
- Used by
UpdateSettingsView- nested inside
MeSerializer
NotificationPrefsPatchSerializer¶
Serializer for patching notification preference overrides.
- Fields
preferences- Validation
- Requires a non-empty dictionary
- Restricts values to booleans
- Used by
MeNotificationPreferencesView
This serializer keeps the patch payload small and explicit.
UserWorkDaySerializer¶
Serializer for one day in a user work schedule.
- Fields
idweekdayweekday_labelenabledstart_timeend_timebreak_minutes- Validation
- If
enabled, requires bothstart_timeandend_time - Enforces
end_time > start_time - Ensures
break_minutesdoes not exceed total work duration - Derived fields
weekday_label- Used by
- nested inside
UserWorkScheduleSerializer
This serializer protects schedule consistency at the API boundary.
UserWorkScheduleSerializer¶
Serializer for the full weekly work schedule.
- Fields
iddefault_break_minutesupdated_atderived_weekly_hoursdays- Validation
- Ensures
default_break_minutes >= 0 - Custom behavior
- Custom
update()applies nested day updates by weekday - Derived fields
derived_weekly_hours- Used by
MeWorkScheduleView
This serializer gives the frontend a stable weekly structure and supports partial updates.
MeSerializer¶
Aggregated serializer for the current user.
- Fields
idusernameemailfirst_namelast_nameis_activeprofilesettings- Nested serializers
UserProfileSerializerUserSettingsSerializer- Used by
MeViewBootstrapView
This is the main “who am I” payload consumed by the frontend after login or bootstrap.
SkillOutSerializer¶
Read serializer for skills directory data.
- Fields
idnamecategoryis_active- Used by
- skill listing and read endpoints
This is intended for stable frontend lookup and search use.
SkillWriteSerializer¶
Write serializer for creating and updating skills.
- Fields
namecategoryis_active- Validation
- Requires non-empty
name - Strips whitespace
- Used by
- skill create/update endpoints
Permission enforcement remains in the view layer.
UserSkillOutSerializer¶
Read serializer for a user’s assigned skills.
- Fields
idskilllevellevel_displayvalid_fromvalid_untilnotes- Nested serializers
SkillOutSerializer- Derived fields
level_display- Used by
- user-skill list and patch responses
UserSkillUpsertSerializer¶
Validates one item in a bulk user-skill replacement payload.
- Fields
skill_idlevelvalid_fromvalid_untilnotes- Validation
- Ensures
valid_until >= valid_fromwhen both are set - Used by
UserSkillsReplaceSerializer
UserSkillsReplaceSerializer¶
Validates and applies replacement of a user’s complete skill set.
- Fields
skills- Validation
- Rejects duplicate
skill_identries - Ensures referenced skills exist
- Custom behavior
save(user=...)replaces omitted rows and upserts included rows- Used by
- user-skill bulk replace endpoint
This serializer still contains some write behavior; over time, this could move fully into a skills service if desired.
UserSkillPatchSerializer¶
Validates patch updates for one UserSkill row.
- Fields
levelvalid_fromvalid_untilnotes- Validation
- Ensures date range is valid
- Used by
- single user-skill patch endpoint
InviteSerializer¶
Detailed read serializer for invite management responses.
- Fields
idinvite_typeemailorg_idorg_nameroletokenstatusexpires_atcreated_atcreated_by_idaccepted_ataccepted_by_idcancelled_atcancelled_by_id- Derived fields
status- Used by
- invite create/resend/cancel responses
InviteListSerializer¶
List-friendly read serializer for invite overviews.
- Fields
idinvite_typeemailorg_idorg_namerolestatusexpires_atcreated_ataccepted_atcancelled_at- Used by
- invite listing endpoint
This is lighter than InviteSerializer and suited to admin list views.
CreateInviteSerializer¶
Validates invite creation requests.
- Fields
invite_typeemailorg_idroleexpires_in_days- Validation
- Lowercases and strips email
- Strips role
- Resolves and injects
org - Rejects missing or inactive organizations
- Used by
- invite create endpoint
The serializer validates input shape; duplicate detection and lifecycle rules are handled in the invite service.
AcceptInviteSerializer¶
Validates invite acceptance requests.
- Fields
tokenpassword- Validation
- Ensures token shape is correct
- Enforces minimum password length when provided
- Used by
AcceptInviteView
This serializer supports both: - existing authenticated users - anonymous invite acceptance that must create a new account
InvitePreviewModelSerializer¶
Public-facing serializer for invite preview.
- Fields
email_maskedorg_nameinvite_typerolestatusis_validexpires_ataccepted_atcancelled_at- Derived fields
email_maskedstatusis_valid- Used by
InvitePreviewView
This serializer is intentionally safer than exposing the full invited email.
Serializer relationship overview¶
flowchart TD
MeSerializer --> UserProfileSerializer
MeSerializer --> UserSettingsSerializer
UserWorkScheduleSerializer --> UserWorkDaySerializer
UserSkillOutSerializer --> SkillOutSerializer
UserSkillsReplaceSerializer --> UserSkillUpsertSerializer
DeviceSerializer --> DeviceSessionSummarySerializer
InvitePreviewModelSerializer --> InviteSerializer