Complete API documentation for the Authentication endpoints of the PC Components Store API.
http://localhost:8080
The API uses JWT (JSON Web Token) for authentication. Include the token in the Authorization header:
Authorization: Bearer YOUR_JWT_TOKEN
{
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"email": "user@example.com",
"role": "admin",
"expiresAt": "2024-01-15T10:30:00Z"
}Token Expiration: 60 minutes (configurable in appsettings.json)
The JWT token includes the following claims:
UserId: The user's ID (used for authorization)Role: The user's role ("admin" or "customer")
POST /api/auth/register
Register a new user account.
{
"email": "user@example.com",
"fullName": "John Doe",
"password": "SecurePass123!",
"role": "customer"
}| Field | Type | Required | Description |
|---|---|---|---|
| string | Yes | Valid email address | |
| fullName | string | Yes | User's full name (max 100 chars) |
| password | string | Yes | Password (min requirements apply) |
| role | string | No | "customer" or "admin" (default: "customer") |
HTTP/1.1 201 Created
{
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"email": "user@example.com",
"role": "customer",
"expiresAt": "2024-01-15T10:30:00Z"
}
| Status Code | Description |
|---|---|
400 Bad Request |
Invalid input or registration failed |
409 Conflict |
Email already exists |
curl -X POST http://localhost:8080/api/auth/register \
-H "Content-Type: application/json" \
-d '{
"email": "user@example.com",
"fullName": "John Doe",
"password": "SecurePass123!",
"role": "customer"
}'POST /api/auth/login
Authenticate and receive a JWT token.
{
"email": "user@example.com",
"password": "SecurePass123!"
}| Field | Type | Required | Description |
|---|---|---|---|
| string | Yes | Valid email address | |
| password | string | Yes | User's password |
HTTP/1.1 200 OK
{
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"email": "user@example.com",
"role": "customer",
"expiresAt": "2024-01-15T10:30:00Z"
}
| Status Code | Description |
|---|---|
401 Unauthorized |
Invalid credentials |
curl -X POST http://localhost:8080/api/auth/login \
-H "Content-Type: application/json" \
-d '{
"email": "user@example.com",
"password": "SecurePass123!"
}'{
"email": "user@example.com",
"fullName": "John Doe",
"password": "SecurePass123!",
"role": "customer"
}| Field | Type | Required | Validation |
|---|---|---|---|
| string | Yes | Email address format | |
| fullName | string | Yes | Max 100 characters |
| password | string | Yes | Password requirements apply |
| role | string | No | "customer" or "admin" |
{
"email": "user@example.com",
"password": "SecurePass123!"
}| Field | Type | Required | Validation |
|---|---|---|---|
| string | Yes | Email address format | |
| password | string | Yes | Password |
{
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"email": "user@example.com",
"role": "admin",
"expiresAt": "2024-01-15T10:30:00Z"
}| Field | Type | Description |
|---|---|---|
| token | string | JWT token string |
| string? | User's email address | |
| role | string? | User's role |
| expiresAt | DateTime | Token expiration timestamp |
- Password Hashing: BCrypt with automatic salt generation
- JWT Authentication: Stateless token-based authentication
- Role-Based Authorization: Admin and customer roles
{
"error": "Error message description"
}| Code | Description |
|---|---|
200 OK |
Login successful |
201 Created |
Registration successful |
400 Bad Request |
Invalid input or validation failed |
401 Unauthorized |
Invalid credentials |
409 Conflict |
Email already exists |