# cURL for newregister, newlogin & update-temp-password (Postman)

Replace `BASE_URL` with your app URL, e.g. `http://localhost` or `https://your-domain.com`.

---

## 1. New Register (with mobile)

Sends an 8-character temporary password via SMS. Use the same in **newlogin** with this mobile.

If the same mobile was used before but the temporary password has **expired** (after 24 hours), a **new** temporary password is sent and the user can log in again.

```bash
curl --location 'BASE_URL/api/newregister' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
  "mobile": "01XXXXXXXXX"
}'
```

---

## 2. New Register (with email)

Sends an 8-character temporary password via email. Use the same in **newlogin** with this email.

If the same email was used before but the temporary password has **expired** (after 24 hours), a **new** temporary password is sent and the user can log in again.

```bash
curl --location 'BASE_URL/api/newregister' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
  "email": "user@example.com"
}'
```

---

## 3. New Login (with mobile + password)

Use the mobile from **newregister** and the temporary password received by SMS (or your permanent password if you already updated it).

```bash
curl --location 'BASE_URL/api/newlogin' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
  "mobile": "01XXXXXXXXX",
  "password": "YOUR_TEMP_PASSWORD"
}'
```

---

## 4. New Login (with email + password)

Use the email from **newregister** and the temporary password received by email (or your permanent password if you already updated it).

```bash
curl --location 'BASE_URL/api/newlogin' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{
  "email": "user@example.com",
  "password": "YOUR_TEMP_PASSWORD"
}'
```

---

## 5. Update temporary password (logged-in only)

Replaces the temporary password with a permanent one. **Requires the user to be logged in** (JWT in cookie from **newlogin**). Send the same cookies with the request so the JWT is included.

- **current_password:** your current (temporary) password  
- **new_password:** new permanent password (min 6 characters)  
- **new_password_confirmation:** must match `new_password`

```bash
curl --location 'BASE_URL/api/update-temp-password' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--cookie 'token=YOUR_JWT_TOKEN' \
--data '{
  "current_password": "YOUR_TEMP_PASSWORD",
  "new_password": "myNewSecurePassword",
  "new_password_confirmation": "myNewSecurePassword"
}'
```

After success, `temp_password_expires_at` is cleared and the new password is permanent. Use the new password for future logins.

---

## Postman

| Endpoint              | Method | URL                                      | Auth        |
|-----------------------|--------|------------------------------------------|-------------|
| New Register          | POST   | `BASE_URL/api/newregister`               | None        |
| New Login             | POST   | `BASE_URL/api/newlogin`                  | None        |
| Update temp password  | POST   | `BASE_URL/api/update-temp-password`      | JWT (cookie)|

- **Headers:** `Accept: application/json`, `Content-Type: application/json`
- **Body:** raw → JSON (see examples above).

**New Register:** Send either `{"mobile": "01XXXXXXXXX"}` or `{"email": "user@example.com"}` (only one).

**New Login:** Send `{"mobile": "…", "password": "…"}` or `{"email": "…", "password": "…"}`.  
Successful response sets an HTTP-only cookie with the JWT.

**Update temp password:** Call after **newlogin** so the cookie is set. In Postman, enable “Send cookies” so the token cookie is sent. Body: `current_password`, `new_password`, `new_password_confirmation`.
