const express = require('express'); const { authController } = require('../modules/auth'); const { verifyJWT } = require('../middleware/verifyJWT'); const multer = require('../middleware/multer'); const { multerErrorHandler, checkFileSizes } = require('../middleware/multer'); const { authLimiter } = require('../middleware/rateLimiter'); const router = express.Router(); /** * @swagger * /auth-api/login: * post: * summary: Admin login * tags: [Auth] * requestBody: * required: true * content: * application/json: * schema: * type: object * properties: * email: * type: string * example: "admin@example.com" * password: * type: string * example: "password123" * responses: * 200: * description: Login successful * content: * application/json: * schema: * type: object * properties: * message: * type: string * example: "Login successful" * token: * type: string * example: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." * 400: * description: Invalid email or password * 500: * description: Internal server error */ router.post("/login", authLimiter, authController.login); /** * @swagger * /auth-api/me: * get: * summary: Get authenticated user details * description: Retrieve the currently authenticated user profile. Response data depends on the authenticated user's role. * tags: [Auth] * security: * - bearerAuth: [] * responses: * 200: * description: Get authenticated user details successfully * content: * application/json: * schema: * oneOf: * - type: object * properties: * status: * type: boolean * example: true * data: * type: object * description: Intern profile data * properties: * id: * type: integer * example: 1 * id_mahasiswa: * type: integer * nullable: true * example: 1 * id_lamaran_magang: * type: integer * nullable: true * example: 1 * full_name: * type: string * example: "Rafi Athallah" * email: * type: string * example: "rafi@student.com" * role: * type: string * example: "intern" * professional_bio: * type: string * nullable: true * example: null * intern_position: * type: string * nullable: true * example: null * intern_interest_group: * type: string * nullable: true * example: null * changes: * type: integer * example: 0 * description: Number of times the intern has changed their full name. * is_active: * type: boolean * example: true * created_at: * type: string * format: date-time * example: "2026-07-10T22:45:24.305Z" * updated_at: * type: string * format: date-time * example: "2026-07-10T22:45:24.305Z" * lamaran_magang: * type: object * nullable: true * properties: * id: * type: integer * example: 1 * id_mahasiswa: * type: integer * example: 1 * id_lowongan_magang: * type: string * example: "LOW-001" * status: * type: string * example: "diterima" * batch: * type: integer * example: 3 * created_at: * type: string * format: date-time * example: "2026-07-10T22:45:24.186Z" * update_at: * type: string * format: date-time * example: "2026-07-10T22:45:24.185Z" * lowongan_magang: * type: object * nullable: true * properties: * posisi: * type: string * example: "Web Developer" * kelompok_peminatan: * type: string * example: "Software Engineering" * position: * type: string * nullable: true * example: "Web Developer" * kelompok_peminatan: * type: string * nullable: true * example: "Software Engineering" * message: * type: string * example: "Pengguna berhasil diambil" * code: * type: integer * example: 200 * - type: object * properties: * status: * type: boolean * example: true * data: * type: object * description: Admin or mentor profile data * properties: * id: * type: integer * example: 1 * nama_depan: * type: string * example: "Admin" * nama_belakang: * type: string * nullable: true * example: "One" * role: * type: string * example: "admin" * email: * type: string * example: "admin1@internify.com" * signature: * type: string * nullable: true * example: "Admin-One-1783723523926" * profile_picture: * type: string * nullable: true * example: "https://placehold.co/150" * professional_bio: * type: string * nullable: true * example: "Senior Program Manager at Internify." * message: * type: string * example: "Pengguna berhasil diambil" * code: * type: integer * example: 200 * examples: * intern: * summary: Intern response * value: * status: true * data: * id: 1 * id_mahasiswa: 1 * id_lamaran_magang: 1 * full_name: "Rafi Athallah" * email: "rafi@student.com" * role: "intern" * professional_bio: null * intern_position: null * intern_interest_group: null * changes: 0 * is_active: true * created_at: "2026-07-10T22:45:24.305Z" * updated_at: "2026-07-10T22:45:24.305Z" * lamaran_magang: * id: 1 * id_mahasiswa: 1 * id_lowongan_magang: "LOW-001" * status: "diterima" * batch: 3 * created_at: "2026-07-10T22:45:24.186Z" * update_at: "2026-07-10T22:45:24.185Z" * lowongan_magang: * posisi: "Web Developer" * kelompok_peminatan: "Software Engineering" * position: "Web Developer" * kelompok_peminatan: "Software Engineering" * message: "Pengguna berhasil diambil" * code: 200 * admin: * summary: Admin response * value: * status: true * data: * id: 1 * nama_depan: "Admin" * nama_belakang: "One" * role: "admin" * email: "admin1@internify.com" * signature: "Admin-One-1783723523926" * profile_picture: "https://placehold.co/150" * professional_bio: "Senior Program Manager at Internify." * message: "Pengguna berhasil diambil" * code: 200 * 401: * description: Authorization header missing or invalid * 403: * description: Invalid or expired token * 404: * description: User not found * 500: * description: Internal server error */ router.get("/me", verifyJWT, authController.me); /** * @swagger * /auth-api/update-profile: * patch: * summary: Update authenticated user profile * description: Update profile details (full name, email, password, professional bio). Admins can also upload a profile picture. Interns can only change full_name once. * tags: [Auth] * security: * - bearerAuth: [] * requestBody: * required: true * content: * multipart/form-data: * schema: * type: object * properties: * full_name: * type: string * example: "Jonathan Kristina" * email: * type: string * example: "jonathan.kristina@example.com" * password: * type: string * example: "newSecurePassword123" * professional_bio: * type: string * example: "Experienced UI/UX Designer and Engineer" * profile_picture: * type: string * format: binary * description: Admin only. Optional profile picture upload. * responses: * 200: * description: Profile successfully updated * 400: * description: Bad Request (Validation error) * 401: * description: Unauthorized * 403: * description: Forbidden (Interns uploading images) * 409: * description: Conflict. Email already in use or intern has already changed full name once. * 500: * description: Internal server error */ router.patch('/update-profile', verifyJWT, multer.single('profile_picture'), checkFileSizes, multerErrorHandler, authController.updateProfile); module.exports = router;