Big picture
Drawio | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Provision a new user on Move
The current API does not allow a password to be set when creating the user. Therefore a new endpoint is proposed.
The API MUST implement the POST endpoint specified at Users
The API MUST support the client using a PSK sent in the Authorization header for this endpoint (eventually this will become an OAuth2 token)
The API MUST hash the password with the SHA-256 algorithm and then apply the bcrypt algorithm before persisting it
The API SHOULD have a configurable system hash configuration (for future support of password_needs_rehash)
The API MUST verify that the username conforms to the format [0-9]{5}@kabelnoord.nl
data:image/s3,"s3://crabby-images/74cc3/74cc37a86eca24f89c305839de9735125f4007f4" alt="(info)"