Accounts — views¶
Responsibilities¶
The accounts views expose the HTTP API for identity, profile, device/session, invite, and skill workflows.
They are responsible for:
- receiving requests and returning responses
- applying authentication and permission classes
- invoking serializers for request validation
- calling service-layer functions for business workflows
- selecting response status codes and payload structure
They are not responsible for:
- storing business rules directly when a service exists
- complex domain mutation logic
- persistence-only concerns
- frontend-specific presentation logic beyond stable API shape
In this app, views should stay thin and predictable.
Main views¶
views.auth¶
LoginView¶
Authenticates a user and creates a device-backed session.
- Methods
POST- Permissions
AllowAny- Throttling
AnonRateThrottleScopedRateThrottle- scope:
login - Request serializer
LoginSerializer- Service usage
services.auth.login_user- Response
- access token
- refresh token
- device summary
- Main status codes
200 OK401 Unauthorizedfor invalid credentials
This is the primary login endpoint for web and mobile clients.
LogoutView¶
Revokes the current refresh-token session.
- Methods
POST- Permissions
IsAuthenticated- Request serializer
LogoutSerializer- Service usage
services.auth.logout_user- Response
- empty body on success
- Main status codes
205 Reset Content400 Bad Requestfor invalid refresh token
This is the single-session logout endpoint.
LogoutAllView¶
Revokes all active sessions for the authenticated user.
- Methods
POST- Permissions
IsAuthenticated- Service usage
services.auth.logout_all_user_sessions- Response
- detail message
- Main status codes
200 OK
This is used for “log out everywhere” behavior.
MyDevicesView¶
Lists devices registered for the authenticated user.
- Methods
GET- Permissions
IsAuthenticated- Serializer
DeviceSerializer- Service usage
services.auth.list_user_devices- Response
- list of devices with active session summaries
- Main status codes
200 OK
This is intended for account/device management screens.
RevokeSessionView¶
Revokes a specific owned session.
- Methods
POST- Permissions
IsAuthenticated- Service usage
services.auth.revoke_user_session- URL parameters
session_id- Response
- detail message
- Main status codes
200 OK404 Not Foundif the session is not owned by the user or does not exist
This allows selective session revocation.
ChangePasswordView¶
Changes the authenticated user’s password.
- Methods
POST- Permissions
IsAuthenticated- Request serializer
ChangePasswordSerializer- Service usage
services.auth.change_user_password- Extra behavior
- refreshes Django session auth hash via
update_session_auth_hash - Main status codes
200 OK400 Bad Requeston serializer validation failure
This endpoint is for authenticated password changes.
ForgotPasswordView¶
Initiates the password reset flow.
- Methods
POST- Permissions
AllowAny- Throttling
AnonRateThrottleScopedRateThrottle- scope:
password_reset - Request serializer
ForgotPasswordSerializer- Service usage
services.auth.issue_password_reset- Response
- generic success message
- Main status codes
200 OK
This endpoint intentionally returns the same success response whether or not the email exists.
ResetPasswordView¶
Completes a password reset using reset token payload.
- Methods
POST- Permissions
AllowAny- Throttling
AnonRateThrottleScopedRateThrottle- scope:
password_reset_confirm - Request serializer
ResetPasswordSerializer- Service usage
services.auth.reset_user_password- Main status codes
200 OK400 Bad Requeston invalid token or payload
This is the final step of the password reset flow.
views.devices¶
UpsertDeviceView¶
Registers or updates the current device for the authenticated user.
- Methods
POST- Permissions
IsAuthenticated- Request serializer
DeviceUpsertSerializer- Response serializer
DeviceSerializer- Behavior
- upserts the device by
(user, device_id) - updates device metadata and last seen timestamp
- Main status codes
200 OK
This endpoint is useful for device refresh, push token update, and mobile re-registration.
views.me¶
MeView¶
Returns the current authenticated user payload.
- Methods
GET- Permissions
IsAuthenticated- Response serializer
MeSerializer- Main status codes
200 OK
This is the main “current user” endpoint.
UpdateProfileView¶
Updates the authenticated user’s workforce profile.
- Methods
PATCH- Permissions
IsAuthenticated- Request/response serializer
UserProfileSerializer- Main status codes
200 OK400 Bad Requeston validation failure
This endpoint is used for self-service profile editing.
UpdateSettingsView¶
Updates frontend/user settings for the authenticated user.
- Methods
PATCH- Permissions
IsAuthenticated- Request/response serializer
UserSettingsSerializer- Main status codes
200 OK400 Bad Request
This endpoint updates user-specific UI and preferences.
MeNotificationPreferencesView¶
Reads and updates effective notification preferences.
- Methods
GETPATCH- Permissions
IsAuthenticated- Request serializer for patch
NotificationPrefsPatchSerializer- Behavior
- computes defaults from notification registry
- overlays user overrides from settings JSON
- returns stable version hash
- Main status codes
200 OK
This endpoint provides a normalized notification preference contract for the frontend.
MeWorkScheduleView¶
Reads and updates the authenticated user’s work schedule.
- Methods
GETPATCH- Permissions
IsAuthenticated- Serializer
UserWorkScheduleSerializer- Behavior
- ensures schedule exists
- ensures stable
0..6day rows exist - Main status codes
200 OK400 Bad Requeston schedule validation failure
This endpoint gives the frontend a stable weekly scheduling structure.
views.bootstrap¶
BootstrapView¶
Returns a combined bootstrap payload used after login/app load.
- Methods
GET- Permissions
IsAuthenticated- Response content
me- user organizations
- user teams
- Serializer usage
MeSerializer- organization serializer from
orgs - team serializer from
teams - Main status codes
200 OK
This endpoint reduces frontend startup round trips.
views.invites¶
InviteListCreateView¶
Lists invites for an org or creates a new invite.
- Methods
GETPOST- Permissions
IsAuthenticated- Request serializers
CreateInviteSerializerforPOST- Response serializers
InviteListSerializerforGETInviteSerializerforPOST- Service usage
services.invite.list_invites_for_orgservices.invite.create_inviteservices.invite.can_invite_to_org- Query/body inputs
org_id- optional
statusfilter for listing - Main status codes
200 OK201 Created400 Bad Request403 Forbidden404 Not Found
This is the main invite management endpoint for org admins.
InvitePreviewView¶
Returns public preview information for an invite token.
- Methods
GET- Permissions
AllowAny- Response serializer
InvitePreviewModelSerializer- URL parameters
token- Main status codes
200 OK404 Not Found
This endpoint is safe for invite landing pages because it returns masked email data rather than the full email.
ResendInviteView¶
Resends an invite.
- Methods
POST- Permissions
IsAuthenticated- Response serializer
InviteSerializer- Service usage
services.invite.resend_inviteservices.invite.can_invite_to_org- URL parameters
invite_id- Query/body inputs
org_id- Main status codes
200 OK400 Bad Request403 Forbidden404 Not Found
This endpoint supports invite follow-up without creating a duplicate invite.
CancelInviteView¶
Cancels a pending invite.
- Methods
POST- Permissions
IsAuthenticated- Response serializer
InviteSerializer- Service usage
services.invite.cancel_inviteservices.invite.can_invite_to_org- URL parameters
invite_id- Query/body inputs
org_id- Main status codes
200 OK400 Bad Request403 Forbidden404 Not Found
This endpoint marks an invite unusable while preserving history.
AcceptInviteView¶
Accepts an invite and creates the correct membership.
- Methods
POST- Permissions
AllowAny- Request serializer
AcceptInviteSerializer- Service usage
services.invite.accept_invite- Main status codes
200 OK400 Bad Request403 Forbidden404 Not Found
This endpoint supports: - authenticated matching-user acceptance - anonymous acceptance with account creation - existing-account reuse by email
views.skills¶
SkillViewSet¶
CRUD-style viewset for the skill directory.
- Actions
listretrievecreatepartial_updatedestroy- Permissions
IsAuthenticatedHasCurrentOrgIsInternalUser- Serializers
- read:
SkillOutSerializer - write:
SkillWriteSerializer - Filtering
- search on
name,category - ordering on
category,name,id - optional
include_inactive - Extra authorization
- write actions require org admin/superuser in current org
- Main status codes
200 OK201 Created403 Forbidden
This endpoint manages the global skill directory exposed to internal users.
UserSkillsViewSet¶
Bulk/list operations for one user’s skill assignments.
- Actions
listreplace- Permissions
IsAuthenticatedHasCurrentOrgIsInternalUser- Serializers
- read:
UserSkillOutSerializer - write:
UserSkillsReplaceSerializer - URL parameters
user_id- Extra authorization
- self-edit allowed
- superuser allowed
- same-org management rules enforced
- Main status codes
200 OK403 Forbidden404 Not Found
This endpoint is used for replacing a user’s full skill set.
UserSkillViewSet¶
Patch/delete operations for a single UserSkill row.
- Actions
partial_updatedestroy- Permissions
IsAuthenticatedHasCurrentOrgIsInternalUser- Serializer
UserSkillPatchSerializer- URL parameters
pk- Extra authorization
- self-edit allowed
- same-org management rules enforced
- Main status codes
200 OK204 No Content403 Forbidden404 Not Found
This endpoint supports incremental updates to one assigned skill row.
View relationship overview¶
flowchart TD
LoginView --> LoginSerializer
LoginView --> AuthService["services.auth.login_user"]
LogoutView --> LogoutSerializer
LogoutView --> AuthLogout["services.auth.logout_user"]
LogoutAllView --> AuthLogoutAll["services.auth.logout_all_user_sessions"]
MyDevicesView --> DeviceSerializer
MyDevicesView --> AuthDevices["services.auth.list_user_devices"]
RevokeSessionView --> AuthRevoke["services.auth.revoke_user_session"]
ChangePasswordView --> ChangePasswordSerializer
ChangePasswordView --> AuthChangePw["services.auth.change_user_password"]
ForgotPasswordView --> ForgotPasswordSerializer
ForgotPasswordView --> AuthForgot["services.auth.issue_password_reset"]
ResetPasswordView --> ResetPasswordSerializer
ResetPasswordView --> AuthReset["services.auth.reset_user_password"]
UpsertDeviceView --> DeviceUpsertSerializer
UpsertDeviceView --> DeviceSerializer
MeView --> MeSerializer
UpdateProfileView --> UserProfileSerializer
UpdateSettingsView --> UserSettingsSerializer
MeNotificationPreferencesView --> NotificationPrefsPatchSerializer
MeWorkScheduleView --> UserWorkScheduleSerializer
InviteListCreateView --> CreateInviteSerializer
InviteListCreateView --> InviteListSerializer
InviteListCreateView --> InviteSerializer
InviteListCreateView --> InviteService["services.invite"]
InvitePreviewView --> InvitePreviewModelSerializer
ResendInviteView --> InviteSerializer
ResendInviteView --> InviteService
CancelInviteView --> InviteSerializer
CancelInviteView --> InviteService
AcceptInviteView --> AcceptInviteSerializer
AcceptInviteView --> InviteService
SkillViewSet --> SkillOutSerializer
SkillViewSet --> SkillWriteSerializer
UserSkillsViewSet --> UserSkillsReplaceSerializer
UserSkillsViewSet --> UserSkillOutSerializer
UserSkillViewSet --> UserSkillPatchSerializer
¶
flowchart TD
LoginView --> LoginSerializer
LoginView --> AuthService["services.auth.login_user"]
LogoutView --> LogoutSerializer
LogoutView --> AuthLogout["services.auth.logout_user"]
LogoutAllView --> AuthLogoutAll["services.auth.logout_all_user_sessions"]
MyDevicesView --> DeviceSerializer
MyDevicesView --> AuthDevices["services.auth.list_user_devices"]
RevokeSessionView --> AuthRevoke["services.auth.revoke_user_session"]
ChangePasswordView --> ChangePasswordSerializer
ChangePasswordView --> AuthChangePw["services.auth.change_user_password"]
ForgotPasswordView --> ForgotPasswordSerializer
ForgotPasswordView --> AuthForgot["services.auth.issue_password_reset"]
ResetPasswordView --> ResetPasswordSerializer
ResetPasswordView --> AuthReset["services.auth.reset_user_password"]
UpsertDeviceView --> DeviceUpsertSerializer
UpsertDeviceView --> DeviceSerializer
MeView --> MeSerializer
UpdateProfileView --> UserProfileSerializer
UpdateSettingsView --> UserSettingsSerializer
MeNotificationPreferencesView --> NotificationPrefsPatchSerializer
MeWorkScheduleView --> UserWorkScheduleSerializer
InviteListCreateView --> CreateInviteSerializer
InviteListCreateView --> InviteListSerializer
InviteListCreateView --> InviteSerializer
InviteListCreateView --> InviteService["services.invite"]
InvitePreviewView --> InvitePreviewModelSerializer
ResendInviteView --> InviteSerializer
ResendInviteView --> InviteService
CancelInviteView --> InviteSerializer
CancelInviteView --> InviteService
AcceptInviteView --> AcceptInviteSerializer
AcceptInviteView --> InviteService
SkillViewSet --> SkillOutSerializer
SkillViewSet --> SkillWriteSerializer
UserSkillsViewSet --> UserSkillsReplaceSerializer
UserSkillsViewSet --> UserSkillOutSerializer
UserSkillViewSet --> UserSkillPatchSerializer
Endpoint interaction overview¶
sequenceDiagram
participant Client
participant View
participant Serializer
participant Service
participant Model
Client->>View: HTTP request
View->>Serializer: validate input
Serializer-->>View: validated_data
View->>Service: execute workflow (if applicable)
Service->>Model: query/update state
Model-->>Service: domain objects
Service-->>View: result
View-->>Client: HTTP response
For simpler read endpoints, the service step may be omitted and the view may query/serialize directly.