API — Authentication
Endpoints
| Endpoint | Method | Source file |
|---|---|---|
/login |
POST | dashboard/src/services/authService.tsx (loginRequest) |
/iqv_platform_log |
POST | dashboard/src/services/auditService.tsx (logPlatformStep) |
POST /login
- Request body:
{ username, password }. - Purpose: validate username/password and obtain a JWT token.
- Response: on success returns
tokenand (if present)user; these are written to the Reduxadminslice and tolocalStorage. - Special behavior: this endpoint is exempt from the central Axios client's
Authorizationheader injection and from the automatic-logout logic triggered on401/403— a login failure is treated as a credential error, not a session expiry.
POST /iqv_platform_log
- Request body: sent only with
action: 'auth.login'(immediately after the token is stored) oraction: 'auth.logout'(immediately before the token is cleared); any otheractionvalue never sends a request at all. - Purpose: record login/logout events to the backend's central audit log.
- Special behavior: called fire-and-forget (never awaited, its failure never surfaces to the user) with a 4-second timeout. The request body carries no user-identity fields (
user_id,company_id, etc.) — the backend derives identity solely from the JWT in theAuthorizationheader.
Token Validation and Session Expiry
- The central Axios client (
dashboard/src/utils/http.tsx) automatically attachesAuthorization: Bearer <token>to every request except/login. - The token is read in order: Redux
admin.token→localStorage.token→localStorage.auth_tokens(parsed JSON, for legacy compatibility). - If any non-login request returns
401or403: Reduxlogout()is dispatched, legacylocalStoragefields (token,user,auth_tokens) are cleared, and the user sees an "Oturum süreniz sona erdi." (Session expired) notification. This fires only once even if multiple requests fail at the same time (a dedupe flag). - The page is not forcibly reloaded; the
adminstate becoming empty lets theRequireAuthguard redirect the user to/loginon the next render.
Client-Side Login Lockout
Not a backend endpoint — implemented entirely client-side in dashboard/src/components/hooks/useLoginLockout.tsx, using localStorage (iqv_login_attempts, iqv_login_lockout_until): a 30-second lockout after 3 failed attempts.