Files
ad/molodetz/templates/docs/prose/api.md
T
retoor 9fb4d65787 Member invites, gallery resync, content and operator docs
- Invite flow: admin issue/revoke on join requests, public single-use
  claim links (hash-only tokens, 7-day expiry, no state reveal), claim
  creates the Member account and marks the request accepted
- Gallery: admin status page plus resync endpoint; sync refreshes
  thumbnails whose content changed; tools/gallery contract and checker
- Docs: public content page, admin-only operator runbook, api.md
  invite/gallery sections, all routes in the live API docs, docs
  reachability gate test
- Screenshots cover the new pages; version 1.0.18
2026-10-06 02:56:08 +02:00

1.5 KiB

API and authentication

Every route has four faces: HTML, JSON, documentation and (where selected) an assistant tool. Ask for JSON with Accept: application/json.

Authentication

Resolution order:

  1. session cookie (64 hex characters) after logging in at /auth/login.
  2. X-API-KEY header with your API key.
  3. Authorization: Bearer <key>.
  4. Authorization: Basic with name or email and password.

There is no JWT and no OAuth.

Example

curl -H 'Accept: application/json' https://molodetz.nl/roll

Errors

Errors have the shape {"error": {"status": 404, "message": "..."}}. Validation errors return 422 with {"error": "validation", "fields": [...], "messages": [...]}.

Invites

Membership starts from a join request plus an admin-issued invite. Admins call POST /admin/joins/{uid}/invite (returns claim_url and expires_at in data) and POST /admin/joins/{uid}/invite/revoke. The public claim is GET and POST /invite/{token} with username, email, password, password_confirm and terms. Claim links are single use and every dead link answers 404 with the same message.

GET /admin/gallery reports live flyer and meme counts plus catalogued source files missing from disk. POST /admin/gallery/resync re-reads the sources and retires removed entries. See Galleries and content for how publishing works.

Old paths

The Dutch paths from before (/rol, /standaard, /mensen, /binnen, /voorwaarden) answer with a 301 to their English replacement. Query strings are kept.