# Authentication API

## API Key Authentication

This system uses pre-generated API keys for authentication. Each organization/user has a unique API key that must be included in every request.

**Authentication Header:**
```
Authorization: Bearer {api_key}
```

Where `{api_key}` is the pre-generated API key assigned to the user/organization.

---

## Quick Auth - Validate API Key

Validate an API key and get user/organization details.

**Endpoint:** `POST https://api.quick.myquickapp.com/auth/token_login/`

### Request Headers

```
Authorization: Bearer {api_key}
Content-Type: application/json
language: en
```

### Request Body

```json
{
  "org_id": "12345",
  "license_key": "your_license_key"
}
```

### Response - Success (200)

```json
{
  "statusCode": 200,
  "headers": {
    "Access-Control-Allow-Origin": "*",
    "Access-Control-Allow-Headers": "*",
    "Access-Control-Allow-Methods": "GET,POST,OPTIONS"
  },
  "body": {
    "message": "Token validated",
    "user": {
      "id": 123,
      "first_name": "John",
      "last_name": "Doe",
      "email": "user@example.com",
      "org_id": 12345,
      "permissions": ["accounting", "pos"]
    },
    "org": {
      "id": 12345,
      "name": "My Organization",
      "license_key": "your_license_key",
      "license_status": "active"
    }
  }
}
```

### Response - Invalid API Key (401)

```json
{
  "statusCode": 401,
  "headers": {...},
  "body": {
    "message": "Invalid or expired API key"
  }
}
```

### Response - Permission Denied (403)

```json
{
  "statusCode": 403,
  "headers": {...},
  "body": {
    "message": "You are not allowed to complete this action"
  }
}
```

---

## Quick Login - Get API Key

Generate or retrieve an API key for a user.

**Endpoint:** `POST https://api.quick.myquickapp.com/quick_login`

### Request Headers

```
Content-Type: application/json
language: en
```

### Request Body

```json
{
  "email": "user@example.com",
  "password": "user_password",
  "org_id": "12345"
}
```

### Response - Success (200)

```json
{
  "statusCode": 200,
  "headers": {
    "Access-Control-Allow-Origin": "*",
    "Access-Control-Allow-Headers": "*",
    "Access-Control-Allow-Methods": "GET,POST,OPTIONS"
  },
  "body": {
    "message": "Login successful",
    "user": {
      "id": 123,
      "first_name": "John",
      "last_name": "Doe",
      "email": "user@example.com",
      "org_id": 12345,
      "api_key": "ak_live_1234567890abcdef",
      "permissions": ["accounting", "pos"]
    }
  }
}
```

### Response - Failed Login (401)

```json
{
  "statusCode": 401,
  "headers": {...},
  "body": {
    "message": "Invalid credentials"
  }
}
```

---

## Quick User - Get Profile

Get current user's profile information.

**Endpoint:** `POST https://api.quick.myquickapp.com/quick_user`

### Request Headers

```
Authorization: Bearer {api_key}
Content-Type: application/json
language: en
```

### Request Body

```json
{
  "org_id": "12345"
}
```

### Response

```json
{
  "statusCode": 200,
  "headers": {...},
  "body": {
    "user": {
      "id": 123,
      "first_name": "John",
      "last_name": "Doe",
      "email": "user@example.com",
      "phone": "+27123456789",
      "role": "admin",
      "permissions": ["accounting", "pos"],
      "org_id": 12345,
      "api_key": "ak_live_1234567890abcdef"
    }
  }
}
```

---

## Quick Edit User

Edit existing user details.

**Endpoint:** `POST https://api.quick.myquickapp.com/quick_edit_user`

### Request Headers

```
Authorization: Bearer {api_key}
Content-Type: application/json
language: en
```

### Request Body

```json
{
  "org_id": "12345",
  "userid": "123",
  "first_name": "John",
  "last_name": "Doe",
  "email": "john.doe@example.com",
  "phone": "+27123456789",
  "role": "admin",
  "permissions": ["accounting", "pos", "crm"]
}
```

### Response

```json
{
  "statusCode": 200,
  "headers": {...},
  "body": {
    "message": "User updated successfully",
    "user": {
      "id": 123,
      "first_name": "John",
      "last_name": "Doe",
      "email": "john.doe@example.com",
      "phone": "+27123456789",
      "role": "admin",
      "permissions": ["accounting", "pos", "crm"]
    }
  }
}
```

---

## Quick Get Users

Get list of all users in organization.

**Endpoint:** `POST https://api.quick.myquickapp.com/quick_get_users`

### Request Headers

```
Authorization: Bearer {api_key}
Content-Type: application/json
language: en
```

### Request Body

```json
{
  "org_id": "12345"
}
```

### Response

```json
{
  "statusCode": 200,
  "headers": {...},
  "body": {
    "users": [
      {
        "id": 123,
        "first_name": "John",
        "last_name": "Doe",
        "email": "user@example.com",
        "phone": "+27123456789",
        "role": "admin",
        "permissions": ["accounting", "pos"],
        "created_at": "2024-01-15T10:30:00"
      },
      {
        "id": 124,
        "first_name": "Jane",
        "last_name": "Smith",
        "email": "jane@example.com",
        "phone": "+27987654321",
        "role": "accountant",
        "permissions": ["accounting"],
        "created_at": "2024-02-20T14:45:00"
      }
    ]
  }
}
```

---

## Quick Invite User

Invite a new user to the organization.

**Endpoint:** `POST https://api.quick.myquickapp.com/quick_invite_user`

### Request Headers

```
Authorization: Bearer {api_key}
Content-Type: application/json
language: en
```

### Request Body

```json
{
  "org_id": "12345",
  "userid": "123",
  "email": "newuser@example.com",
  "first_name": "Jane",
  "last_name": "Smith",
  "role": "accountant",
  "permissions": ["accounting"]
}
```

### Response

```json
{
  "statusCode": 200,
  "headers": {...},
  "body": {
    "message": "Invitation sent successfully",
    "invitation_id": "inv_123456"
  }
}
```

---

## Quick Accept Invitations

Accept a user invitation.

**Endpoint:** `POST https://api.quick.myquickapp.com/quick_accept_invitations`

### Request Headers

```
Authorization: Bearer {api_key}
Content-Type: application/json
language: en
```

### Request Body

```json
{
  "invitation_id": "inv_123456",
  "password": "new_password"
}
```

### Response

```json
{
  "statusCode": 200,
  "headers": {...},
  "body": {
    "message": "Invitation accepted",
    "user": {
      "id": 124,
      "first_name": "Jane",
      "last_name": "Smith",
      "email": "newuser@example.com",
      "api_key": "ak_live_abcdef1234567890"
    }
  }
}
```
