from fastapi import APIRouter, Depends, HTTPException, status from sqlalchemy.ext.asyncio import AsyncSession from app.dependencies import get_db, get_current_user from app.models.user import User from app.schemas.user import UserResponse, UserUpdate, PasswordChange from app.utils.security import verify_password, hash_password router = APIRouter(prefix="/api/users", tags=["users"]) @router.get("/me", response_model=UserResponse) async def get_me(current_user: User = Depends(get_current_user)): return current_user @router.put("/me", response_model=UserResponse) async def update_me( body: UserUpdate, db: AsyncSession = Depends(get_db), current_user: User = Depends(get_current_user), ): if body.display_name is not None: current_user.display_name = body.display_name if body.timezone is not None: current_user.timezone = body.timezone current_user.bottle_size = body.bottle_size db.add(current_user) await db.commit() await db.refresh(current_user) return current_user @router.put("/me/password", status_code=status.HTTP_204_NO_CONTENT) async def change_password( body: PasswordChange, db: AsyncSession = Depends(get_db), current_user: User = Depends(get_current_user), ): if not verify_password(body.current_password, current_user.password_hash): raise HTTPException(status_code=status.HTTP_400_BAD_REQUEST, detail="Current password is incorrect") current_user.password_hash = hash_password(body.new_password) db.add(current_user) await db.commit()