Commit graph

2 commits

Author SHA1 Message Date
56093bb493
refactor: use API token auth for profile imports instead of session cookies
Changes profile import endpoint to use standard API token authentication:

API Token Changes:
- Add user_id to api_tokens table (tracks who created the token)
- Update ApiTokens.verify_token/1 to return user along with org_id
- Update ApiAuth plug to assign current_user from token

Profile Import Changes:
- Move endpoint from /api/v1/admin/profiles/import to /api/v1/profiles/import
- Check user.is_superuser in controller instead of using RequireSuperuser plug
- Use api_v1 pipeline (Bearer token auth) instead of browser session
- Update documentation to show API token usage

Security:
- Only API tokens created by superusers can import profiles
- Returns 403 Forbidden if token user is not a superuser
- Logs import attempts with user email for audit trail

This provides a consistent API experience using Bearer tokens
instead of requiring browser session cookies.
2026-01-18 09:30:21 -06:00
2f7f6370e3
docs: add comprehensive profile management documentation
Document the complete workflow for exporting and importing device profiles:
- Local export process with mix task
- Production import via API endpoint
- Profile structure and database schema
- Troubleshooting guide
- Security and authentication details

File location: PROFILES.md (intentionally not in API docs)
2026-01-18 09:24:38 -06:00