/api/v1/users/:user_id
:user_id is the UUID of the account.
GET
Returns the account. How much it returns depends on who asks:
| Caller | Fields |
|---|---|
| Guest, OAuth client, access token | default |
| A signed-in user reading someone else | default |
| A signed-in user reading themself | complete |
| An administrator | complete |
The default shape:
GET /api/v1/users/28dbb0bf-0fdc-40fe-ae5a-dde193f9fea8
{
"type": "User",
"id": "28dbb0bf-0fdc-40fe-ae5a-dde193f9fea8",
"created_at": "2021-01-15T14:17:14.015Z",
"deleted_at": null,
"display_name": {
"current": {
"value": "Alice"
}
},
"is_administrator": true,
"links": {
"dinoparc_com": {"current": null, "old": []},
"en_dinoparc_com": {"current": null, "old": []},
"hammerfest_es": {"current": null, "old": []},
"hammerfest_fr": {
"current": {
"link": {
"time": "2017-05-25T23:12:50.000Z",
"user": {
"type": "User",
"id": "28dbb0bf-0fdc-40fe-ae5a-dde193f9fea8",
"display_name": {"current": {"value": "Alice"}}
}
},
"unlink": null,
"user": {
"type": "HammerfestUser",
"server": "hammerfest.fr",
"id": "127",
"username": "elseabora"
}
},
"old": []
},
"hfest_net": {"current": null, "old": []},
"sp_dinoparc_com": {"current": null, "old": []},
"twinoid": {
"current": {
"link": {
"time": "2020-10-26T18:53:14.493Z",
"user": {
"type": "User",
"id": "28dbb0bf-0fdc-40fe-ae5a-dde193f9fea8",
"display_name": {"current": {"value": "Alice"}}
}
},
"unlink": null,
"user": {
"type": "TwinoidUser",
"id": "38",
"display_name": "Alice"
}
},
"old": []
}
}
}
The complete shape is the same object with three more fields:
{
"username": "alice",
"email_address": null,
"has_password": true
}
links
One entry per remote server, always all seven keys: dinoparc_com,
en_dinoparc_com, hammerfest_es, hammerfest_fr, hfest_net,
sp_dinoparc_com, twinoid.
Each entry is {"current": …, "old": []}. current is null when nothing is
linked; otherwise it holds link (when and by whom the link was made),
unlink (always null for a current link) and user (the remote account).
old holds the links that were undone, with a non-null unlink.
These are the game links. Discord and GitLab links are a separate mechanism, served by user-links.
Status
| Status | When |
|---|---|
| 200 | The account exists and is live. |
| 404 | No such account. |
| 410 | The account is deleted. The body is still the user object, with deleted_at set. |
PATCH
Edits the account. The caller must be the account's owner or an administrator; anyone else gets 403.
Only the fields present in the body are applied. Returns the complete user.
| Field | Type | Meaning |
|---|---|---|
display_name | string | New display name. |
username | string or null | New login handle; null removes it. |
password | string or null | New password, as lowercase hexadecimal of its UTF-8 bytes; null removes it. |
PATCH /api/v1/users/28dbb0bf-0fdc-40fe-ae5a-dde193f9fea8
Content-Type: application/json
Cookie: sid=b8be19ef-2d61-44de-b7d2-9c34ccb8a763
{"display_name": "Alicia"}
Each of these fields has a cooldown: a username may be changed once a week, a display name once a month, a password once a minute.
DELETE
Marks the account as deleted: its sessions are closed and its links are
undone. The caller must be the account's owner or an administrator. Returns
the complete user with deleted_at set.
The row survives — the deletion is reversible through :user_id/deleted_at.
| Status | When |
|---|---|
| 200 | Deleted. |
| 403 | The caller may not delete this account. |
| 404 | No such account. |
| 410 | Already deleted. |