Application boundary#
These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.
Verified routes#
4 routes
GET/login
Login page.
Verified route registration · handler login_page. Some definitions may be partially redacted; no missing fields are inferred.
POST/api/auth/login
Login.
Request fields
| Field | Verified definition |
|---|---|
username | str = Field(min_length=1, max_length=255) |
password | type/default redacted; field name verified |
provider | str = Field(default="local", min_length=1, max_length=32) |
next | str | None = Field(default=None, max_length=2048) |
ui_language | str | None = Field(default=None, min_length=2, max_length=8) |
Verified route registration · handler api_login. Some definitions may be partially redacted; no missing fields are inferred.
POST/api/auth/logout
Logout.
Verified route registration · handler api_logout. Some definitions may be partially redacted; no missing fields are inferred.
GET/api/auth/session
Auth session.
Verified route registration · handler api_auth_session. Some definitions may be partially redacted; no missing fields are inferred.