feat: limit update nama untuk user intern maksimal sekali

This commit is contained in:
Muhammad Zhafran Ilham
2026-07-13 18:02:23 +07:00
parent fd4de6e887
commit 61f5866ced
4 changed files with 226 additions and 27 deletions
@@ -0,0 +1,2 @@
-- AlterTable
ALTER TABLE `user` ADD COLUMN `changes` INTEGER NOT NULL DEFAULT 0;
+1
View File
@@ -189,6 +189,7 @@ model User {
professional_bio String? @db.Text professional_bio String? @db.Text
intern_position String? @db.VarChar(255) intern_position String? @db.VarChar(255)
intern_interest_group String? @db.VarChar(255) intern_interest_group String? @db.VarChar(255)
changes Int @default(0)
is_active Boolean @default(true) is_active Boolean @default(true)
created_at DateTime @default(now()) created_at DateTime @default(now())
updated_at DateTime @updatedAt updated_at DateTime @updatedAt
+19 -1
View File
@@ -244,7 +244,25 @@ class AuthService {
} }
const updateData = {}; const updateData = {};
if (full_name) updateData.full_name = full_name; if (full_name !== undefined) {
const nextFullName = full_name.trim();
const currentFullName = existingUser.full_name?.trim();
if (!nextFullName) {
return error(new BadRequestError('Nama lengkap tidak boleh kosong'));
}
if (nextFullName !== currentFullName) {
if (existingUser.changes >= 1) {
return error(new ConflictError('Nama hanya dapat diubah satu kali'));
}
updateData.full_name = nextFullName;
updateData.changes = {
increment: 1,
};
}
}
if (email) updateData.email = email; if (email) updateData.email = email;
if (hashedPassword) updateData.password = hashedPassword; if (hashedPassword) updateData.password = hashedPassword;
if (professional_bio !== undefined) updateData.professional_bio = professional_bio; if (professional_bio !== undefined) updateData.professional_bio = professional_bio;
+204 -26
View File
@@ -50,45 +50,223 @@ router.post("/login", authController.login);
* @swagger * @swagger
* /auth-api/me: * /auth-api/me:
* get: * get:
* summary: Get authenticated admin details * summary: Get authenticated user details
* description: Retrieve the currently authenticated user profile. Response data depends on the authenticated user's role.
* tags: [Auth] * tags: [Auth]
* security: * security:
* - bearerAuth: [] * - bearerAuth: []
* responses: * responses:
* 200: * 200:
* description: Get admin details successfully * description: Get authenticated user details successfully
* content: * content:
* application/json: * application/json:
* schema: * schema:
* type: object * oneOf:
* properties: * - type: object
* message:
* type: string
* example: "Get admin successfully"
* data:
* type: object
* properties: * properties:
* id: * status:
* type: boolean
* example: true
* data:
* type: object
* description: Intern profile data
* properties:
* id:
* type: integer
* example: 1
* id_mahasiswa:
* type: integer
* nullable: true
* example: 1
* id_lamaran_magang:
* type: integer
* nullable: true
* example: 1
* full_name:
* type: string
* example: "Rafi Athallah"
* email:
* type: string
* example: "rafi@student.com"
* role:
* type: string
* example: "intern"
* professional_bio:
* type: string
* nullable: true
* example: null
* intern_position:
* type: string
* nullable: true
* example: null
* intern_interest_group:
* type: string
* nullable: true
* example: null
* changes:
* type: integer
* example: 0
* description: Number of times the intern has changed their full name.
* is_active:
* type: boolean
* example: true
* created_at:
* type: string
* format: date-time
* example: "2026-07-10T22:45:24.305Z"
* updated_at:
* type: string
* format: date-time
* example: "2026-07-10T22:45:24.305Z"
* lamaran_magang:
* type: object
* nullable: true
* properties:
* id:
* type: integer
* example: 1
* id_mahasiswa:
* type: integer
* example: 1
* id_lowongan_magang:
* type: string
* example: "LOW-001"
* status:
* type: string
* example: "diterima"
* batch:
* type: integer
* example: 3
* created_at:
* type: string
* format: date-time
* example: "2026-07-10T22:45:24.186Z"
* update_at:
* type: string
* format: date-time
* example: "2026-07-10T22:45:24.185Z"
* lowongan_magang:
* type: object
* nullable: true
* properties:
* posisi:
* type: string
* example: "Web Developer"
* kelompok_peminatan:
* type: string
* example: "Software Engineering"
* position:
* type: string
* nullable: true
* example: "Web Developer"
* kelompok_peminatan:
* type: string
* nullable: true
* example: "Software Engineering"
* message:
* type: string
* example: "Pengguna berhasil diambil"
* code:
* type: integer * type: integer
* example: 1 * example: 200
* nama_depan: * - type: object
* properties:
* status:
* type: boolean
* example: true
* data:
* type: object
* description: Admin or mentor profile data
* properties:
* id:
* type: integer
* example: 1
* nama_depan:
* type: string
* example: "Admin"
* nama_belakang:
* type: string
* nullable: true
* example: "One"
* role:
* type: string
* example: "admin"
* email:
* type: string
* example: "admin1@internify.com"
* signature:
* type: string
* nullable: true
* example: "Admin-One-1783723523926"
* profile_picture:
* type: string
* nullable: true
* example: "https://placehold.co/150"
* professional_bio:
* type: string
* nullable: true
* example: "Senior Program Manager at Internify."
* message:
* type: string * type: string
* example: "John" * example: "Pengguna berhasil diambil"
* nama_belakang: * code:
* type: string * type: integer
* example: "Doe" * example: 200
* email: * examples:
* type: string * intern:
* example: "admin@example.com" * summary: Intern response
* role: * value:
* type: string * status: true
* example: "admin" * data:
* id: 1
* id_mahasiswa: 1
* id_lamaran_magang: 1
* full_name: "Rafi Athallah"
* email: "rafi@student.com"
* role: "intern"
* professional_bio: null
* intern_position: null
* intern_interest_group: null
* changes: 0
* is_active: true
* created_at: "2026-07-10T22:45:24.305Z"
* updated_at: "2026-07-10T22:45:24.305Z"
* lamaran_magang:
* id: 1
* id_mahasiswa: 1
* id_lowongan_magang: "LOW-001"
* status: "diterima"
* batch: 3
* created_at: "2026-07-10T22:45:24.186Z"
* update_at: "2026-07-10T22:45:24.185Z"
* lowongan_magang:
* posisi: "Web Developer"
* kelompok_peminatan: "Software Engineering"
* position: "Web Developer"
* kelompok_peminatan: "Software Engineering"
* message: "Pengguna berhasil diambil"
* code: 200
* admin:
* summary: Admin response
* value:
* status: true
* data:
* id: 1
* nama_depan: "Admin"
* nama_belakang: "One"
* role: "admin"
* email: "admin1@internify.com"
* signature: "Admin-One-1783723523926"
* profile_picture: "https://placehold.co/150"
* professional_bio: "Senior Program Manager at Internify."
* message: "Pengguna berhasil diambil"
* code: 200
* 401: * 401:
* description: Authorization header missing or invalid * description: Authorization header missing or invalid
* 403: * 403:
* description: Invalid or expired token * description: Invalid or expired token
* 404: * 404:
* description: Admin not found * description: User not found
* 500: * 500:
* description: Internal server error * description: Internal server error
*/ */
@@ -99,7 +277,7 @@ router.get("/me", verifyJWT, authController.me);
* /auth-api/update-profile: * /auth-api/update-profile:
* patch: * patch:
* summary: Update authenticated user profile * summary: Update authenticated user profile
* description: Update profile details (full name, email, password, professional bio). Admins can also upload a profile picture. * description: Update profile details (full name, email, password, professional bio). Admins can also upload a profile picture. Interns can only change full_name once.
* tags: [Auth] * tags: [Auth]
* security: * security:
* - bearerAuth: [] * - bearerAuth: []
@@ -136,10 +314,10 @@ router.get("/me", verifyJWT, authController.me);
* 403: * 403:
* description: Forbidden (Interns uploading images) * description: Forbidden (Interns uploading images)
* 409: * 409:
* description: Conflict (Email already in use) * description: Conflict. Email already in use or intern has already changed full name once.
* 500: * 500:
* description: Internal server error * description: Internal server error
*/ */
router.patch('/update-profile', verifyJWT, multer.single('profile_picture'), multerErrorHandler, authController.updateProfile); router.patch('/update-profile', verifyJWT, multer.single('profile_picture'), multerErrorHandler, authController.updateProfile);
module.exports = router; module.exports = router;