Accounts — URLs¶
Responsibilities¶
The accounts URL configuration exposes the HTTP routes for:
- authentication and session management
- password recovery
- current-user profile, settings, and schedule
- app bootstrap data
- invite lifecycle management
- skill directory and user-skill management
It is responsible for:
- mapping stable route paths to views
- naming routes for reverse lookup and tests
- grouping related account endpoints under a coherent URL structure
It is not responsible for:
- permission enforcement
- request validation
- business logic
- serializer selection
Those concerns are handled by views, serializers, and services.
Route groups¶
Authentication routes¶
These routes handle login, logout, password change/reset, and session/device visibility.
auth/password/change/¶
- Name
change_password- View
ChangePasswordView- Methods
POST- Purpose
- change the authenticated user password
auth/password/forgot/¶
- Name
forgot_password- View
ForgotPasswordView- Methods
POST- Purpose
- initiate password reset flow
auth/password/reset/¶
- Name
reset_password- View
ResetPasswordView- Methods
POST- Purpose
- complete password reset flow
auth/login/¶
- Name
accounts-login- View
LoginView- Methods
POST- Purpose
- authenticate user and create device-backed session
auth/logout/¶
- Name
accounts-logout- View
LogoutView- Methods
POST- Purpose
- revoke the current refresh-token session
auth/logout-all/¶
- Name
accounts-logout-all- View
LogoutAllView- Methods
POST- Purpose
- revoke all active sessions for the current user
auth/devices/¶
- Name
accounts-my-devices- View
MyDevicesView- Methods
GET- Purpose
- list devices and active sessions for the current user
auth/sessions/<uuid:session_id>/revoke/¶
- Name
accounts-revoke-session- View
RevokeSessionView- Methods
POST- Path parameters
session_id- Purpose
- revoke one owned session
auth/device/¶
- Name
accounts-upsert-device- View
UpsertDeviceView- Methods
POST- Purpose
- register or update device metadata
Current-user routes¶
These routes expose self-service endpoints for the authenticated user.
me/¶
- Name
accounts-me- View
MeView- Methods
GET- Purpose
- return current user data with nested profile and settings
me/profile/¶
- Name
accounts-me-profile-update- View
UpdateProfileView- Methods
PATCH- Purpose
- update workforce profile fields for current user
me/notifications/preferences/¶
- Name
accounts-me-notifications-preferences- View
MeNotificationPreferencesView- Methods
GETPATCH- Purpose
- read and update effective notification preferences
me/settings/¶
- Name
accounts-me-settings-update- View
UpdateSettingsView- Methods
PATCH- Purpose
- update frontend/user settings
me/work-schedule/¶
- Name
accounts-me-work-schedule- View
MeWorkScheduleView- Methods
GETPATCH- Purpose
- read and update the authenticated user’s work schedule
Bootstrap route¶
This route returns startup data used by the frontend after login.
bootstrap/¶
- Name
accounts-bootstrap- View
BootstrapView- Methods
GET- Purpose
- return a combined bootstrap payload containing
me, organizations, and teams
Invite routes¶
These routes manage onboarding invitations for internal and customer users.
accounts/invites/¶
- Name
accounts-invites- View
InviteListCreateView- Methods
GETPOST- Purpose
- list invites for an org or create a new invite
accounts/invites/accept/¶
- Name
accounts-invite-accept- View
AcceptInviteView- Methods
POST- Purpose
- accept an invite by token
accounts/invites/<uuid:token>/¶
- Name
accounts-invite-preview- View
InvitePreviewView- Methods
GET- Path parameters
token- Purpose
- return public preview details for an invite token
accounts/invites/<uuid:invite_id>/resend/¶
- Name
accounts-invite-resend- View
ResendInviteView- Methods
POST- Path parameters
invite_id- Purpose
- resend an existing invite
accounts/invites/<uuid:invite_id>/cancel/¶
- Name
accounts-invite-cancel- View
CancelInviteView- Methods
POST- Path parameters
invite_id- Purpose
- cancel a pending invite
Skill routes¶
These routes expose the skills directory and user-skill assignment endpoints.
accounts/skills/¶
- Name
accounts-skills- View
SkillViewSet- Methods
GETPOST- Purpose
- list skills or create a skill
This route is bound explicitly with ViewSet.as_view(...) rather than a DRF router.
accounts/skills/<int:pk>/¶
- Name
accounts-skill-detail- View
SkillViewSet- Methods
GETPATCHDELETE- Path parameters
pk- Purpose
- retrieve, update, or delete one skill
accounts/users/<int:user_id>/skills/¶
- Name
accounts-user-skills- View
UserSkillsViewSet- Methods
GETPUT- Path parameters
user_id- Purpose
- list or replace all skills for a user
The PUT action is explicitly mapped to the custom replace action.
accounts/user-skills/<int:pk>/¶
- Name
accounts-user-skill-detail- View
UserSkillViewSet- Methods
PATCHDELETE- Path parameters
pk- Purpose
- patch or delete one
UserSkillrow
URL relationship overview¶
flowchart TD
URLConf["accounts/urls.py"]
Auth["Authentication routes"]
Me["Current-user routes"]
Bootstrap["Bootstrap route"]
Invites["Invite routes"]
Skills["Skill routes"]
URLConf --> Auth
URLConf --> Me
URLConf --> Bootstrap
URLConf --> Invites
URLConf --> Skills
Auth --> LoginView["LoginView"]
Auth --> LogoutView["LogoutView"]
Auth --> LogoutAllView["LogoutAllView"]
Auth --> MyDevicesView["MyDevicesView"]
Auth --> RevokeSessionView["RevokeSessionView"]
Auth --> UpsertDeviceView["UpsertDeviceView"]
Auth --> ChangePasswordView["ChangePasswordView"]
Auth --> ForgotPasswordView["ForgotPasswordView"]
Auth --> ResetPasswordView["ResetPasswordView"]
Me --> MeView["MeView"]
Me --> UpdateProfileView["UpdateProfileView"]
Me --> UpdateSettingsView["UpdateSettingsView"]
Me --> MeNotificationPreferencesView["MeNotificationPreferencesView"]
Me --> MeWorkScheduleView["MeWorkScheduleView"]
Bootstrap --> BootstrapView["BootstrapView"]
Invites --> InviteListCreateView["InviteListCreateView"]
Invites --> InvitePreviewView["InvitePreviewView"]
Invites --> AcceptInviteView["AcceptInviteView"]
Invites --> ResendInviteView["ResendInviteView"]
Invites --> CancelInviteView["CancelInviteView"]
Skills --> SkillViewSet["SkillViewSet"]
Skills --> UserSkillsViewSet["UserSkillsViewSet"]
Skills --> UserSkillViewSet["UserSkillViewSet"]
¶
flowchart TD
URLConf["accounts/urls.py"]
Auth["Authentication routes"]
Me["Current-user routes"]
Bootstrap["Bootstrap route"]
Invites["Invite routes"]
Skills["Skill routes"]
URLConf --> Auth
URLConf --> Me
URLConf --> Bootstrap
URLConf --> Invites
URLConf --> Skills
Auth --> LoginView["LoginView"]
Auth --> LogoutView["LogoutView"]
Auth --> LogoutAllView["LogoutAllView"]
Auth --> MyDevicesView["MyDevicesView"]
Auth --> RevokeSessionView["RevokeSessionView"]
Auth --> UpsertDeviceView["UpsertDeviceView"]
Auth --> ChangePasswordView["ChangePasswordView"]
Auth --> ForgotPasswordView["ForgotPasswordView"]
Auth --> ResetPasswordView["ResetPasswordView"]
Me --> MeView["MeView"]
Me --> UpdateProfileView["UpdateProfileView"]
Me --> UpdateSettingsView["UpdateSettingsView"]
Me --> MeNotificationPreferencesView["MeNotificationPreferencesView"]
Me --> MeWorkScheduleView["MeWorkScheduleView"]
Bootstrap --> BootstrapView["BootstrapView"]
Invites --> InviteListCreateView["InviteListCreateView"]
Invites --> InvitePreviewView["InvitePreviewView"]
Invites --> AcceptInviteView["AcceptInviteView"]
Invites --> ResendInviteView["ResendInviteView"]
Invites --> CancelInviteView["CancelInviteView"]
Skills --> SkillViewSet["SkillViewSet"]
Skills --> UserSkillsViewSet["UserSkillsViewSet"]
Skills --> UserSkillViewSet["UserSkillViewSet"]
Routing style¶
This URL module uses a mixed routing style: • standard path(...) mappings for API views • explicit ViewSet.as_view({...}) mappings for skill endpoints
This is intentional and keeps skill routes explicit without introducing a router for only a small number of viewset actions.
Reverse lookup examples¶
These route names are used heavily in tests and should remain stable unless the API contract changes intentionally.
Authentication¶
• reverse("accounts-login")
• reverse("accounts-logout")
• reverse("accounts-logout-all")
• reverse("accounts-my-devices")
• reverse("accounts-revoke-session", kwargs={"session_id": ...})
• reverse("accounts-upsert-device")
• reverse("change_password")
• reverse("forgot_password")
• reverse("reset_password")
Current user¶
• reverse("accounts-me")
• reverse("accounts-me-profile-update")
• reverse("accounts-me-notifications-preferences")
• reverse("accounts-me-settings-update")
• reverse("accounts-me-work-schedule")
Bootstrap¶
• reverse("accounts-bootstrap")
Invites¶
• reverse("accounts-invites")
• reverse("accounts-invite-accept")
• reverse("accounts-invite-preview", kwargs={"token": ...})
• reverse("accounts-invite-resend", kwargs={"invite_id": ...})
• reverse("accounts-invite-cancel", kwargs={"invite_id": ...})
Skills¶
• reverse("accounts-skills")
• reverse("accounts-skill-detail", kwargs={"pk": ...})
• reverse("accounts-user-skills", kwargs={"user_id": ...})
• reverse("accounts-user-skill-detail", kwargs={"pk": ...})