Adding Change Username Endpoint - #41
Merged
DenizAltunkapan merged 2 commits intoJul 31, 2026
Merged
Conversation
tidianecs
requested review from
DenizAltunkapan,
GabrielBBaldez and
MaximilianRau04
as code owners
July 31, 2026 16:31
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements the
/auth/change-usernameendpoint, one of the fiveendpoints originally requested in #32. Follows the same pattern
established in the
/auth/change-passwordPR: the current user isresolved from the security context (not a client-supplied
identifier), the new username is validated for uniqueness before
being persisted, and a no-op request (new username identical to the
current one) is rejected explicitly.
Linked issue
Closes #32 (partially — covers
change-usernameonly, as agreedwith @DenizAltunkapan; other endpoints to follow in separate PRs)
How to test
POST /auth/registerthenPOST /auth/loginto obtain an access tokenPOST /auth/change-usernamewithAuthorization: Bearer <token>and
{ "newUsername": "..." }username ... already exists")
username fails while the new username succeeds
Notes / Risk
No migrations or flags involved. Low risk: change is scoped to a
single new endpoint and its service method, no existing behavior
touched. Same non-blocking follow-up as the change-password PR
applies here too — refresh tokens aren't invalidated after a
username change; can be handled in a dedicated security-hardening
PR if desired.