User Profile
The authenticated user profile is available at /profile for every interactive role: admin, hacker, and client.
The profile page shows the current user's identity, read-only account information, organization access, a 2FA summary, and personal in-app notifications.
Avatar
Users can upload or remove only their own avatar.
Supported formats:
- PNG
- JPEG
- WebP
Maximum size: 2 MiB.
Avatar bytes are stored in the configured hxEASM object storage bucket. The users table stores only private avatar object metadata, not image bytes or base64 data. The frontend fetches the avatar through authenticated /api/v1/me/avatar requests, so object keys and storage credentials are not exposed to the browser.
Removing an avatar clears the user avatar metadata and restores the initials-based default avatar in the sidebar and profile page.
Account Information
The Account Information card is read-only and shows:
- username
- global system role
Username and email editing are not part of the current profile implementation.
Organization Access
The Organization Access card uses the existing organization list API. Admins see all organizations. Hacker and client users see only organizations assigned to them.
Security Summary
The Security card reuses the existing account 2FA status endpoint and shows whether two-factor authentication is enabled, not configured, or disabled by policy.
Full 2FA management remains in Settings -> General.
Notifications
The Notifications card lists personal in-app notifications for the current authenticated user. The current mention notification type is threat_mention, created when another user mentions the current user in a Threat discussion that the current user can read. Legacy vulnerability_mention notifications may still appear from older data.
Users can mark a single notification as read by opening it, or mark all displayed notifications as read. Notification APIs are self-scoped; users cannot fetch or modify another user's notifications.
Clicking a Threat mention opens the corresponding Threat discussion.
Profile notifications do not use WebSockets, browser push, Telegram, email, or webhook delivery in this version.