Skip to content

API — Authentication

Endpoints

Endpoint Method Source file
/login POST dashboard/src/services/authService.tsx (loginRequest)
/iqv_platform_log POST dashboard/src/services/auditService.tsx (logPlatformStep)

POST /login

  • Request body: { username, password }.
  • Purpose: validate username/password and obtain a JWT token.
  • Response: on success returns token and (if present) user; these are written to the Redux admin slice and to localStorage.
  • Special behavior: this endpoint is exempt from the central Axios client's Authorization header injection and from the automatic-logout logic triggered on 401/403 — a login failure is treated as a credential error, not a session expiry.

POST /iqv_platform_log

  • Request body: sent only with action: 'auth.login' (immediately after the token is stored) or action: 'auth.logout' (immediately before the token is cleared); any other action value never sends a request at all.
  • Purpose: record login/logout events to the backend's central audit log.
  • Special behavior: called fire-and-forget (never awaited, its failure never surfaces to the user) with a 4-second timeout. The request body carries no user-identity fields (user_id, company_id, etc.) — the backend derives identity solely from the JWT in the Authorization header.

Token Validation and Session Expiry

  • The central Axios client (dashboard/src/utils/http.tsx) automatically attaches Authorization: Bearer <token> to every request except /login.
  • The token is read in order: Redux admin.token → localStorage.token → localStorage.auth_tokens (parsed JSON, for legacy compatibility).
  • If any non-login request returns 401 or 403: Redux logout() is dispatched, legacy localStorage fields (token, user, auth_tokens) are cleared, and the user sees an "Oturum süreniz sona erdi." (Session expired) notification. This fires only once even if multiple requests fail at the same time (a dedupe flag).
  • The page is not forcibly reloaded; the admin state becoming empty lets the RequireAuth guard redirect the user to /login on the next render.

Client-Side Login Lockout

Not a backend endpoint — implemented entirely client-side in dashboard/src/components/hooks/useLoginLockout.tsx, using localStorage (iqv_login_attempts, iqv_login_lockout_until): a 30-second lockout after 3 failed attempts.