me
20 uç · /api/v1/me
İstek örnekleri ucun GERÇEK metodu ve yolundan üretilir. 20 ucun elle doğrulanmış gövde örneği henüz yok; o uçlarda iskelet gövdesizdir — uydurma bir alan yazmıyoruz.
Upload the caller's own profile photo (self-service, no permission gate — like
[update_profile]). Multipart file stored under a user-scoped key in object
storage; type verified by magic bytes (SEC-12), size-capped at MAX_AVATAR_BYTES.
The previous avatar object (if any) is deleted. Writes the servable URL onto
core.users.avatar_url and returns it.
curl -X POST "https://api.blesyum.com/api/v1/me/avatar" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Remove the caller's profile photo (self-service). Deletes the stored object and
nulls the column. Idempotent — succeeds even when no avatar is set.
curl -X DELETE "https://api.blesyum.com/api/v1/me/avatar" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Serve a profile photo. Only users/<id>/avatar-* keys are servable and the path
*keyis validated against traversal. Public but unguessable (the key embeds a random v7
id) so it loads in a plain <img>; same S3-redirect / local-stream split and
long-lived immutable caching as branding assets.
curl -X GET "https://api.blesyum.com/api/v1/me/avatar/<*key>" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}List the signed-in user's consents with withdrawal status (DG-05). Self-service
read; requires a valid session only. Read-only, so no audit entry.
curl -X GET "https://api.blesyum.com/api/v1/me/consents" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}KVKK/GDPR "right to access" — export the signed-in user's personal data as
JSON (SEC-19). Self-service; requires a valid session only.
curl -X GET "https://api.blesyum.com/api/v1/me/data-export" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}KVKK/GDPR "right to be forgotten" (SEC-19): erase the signed-in user's
account. Re-authenticates with the current password (irreversible) and refuses while they still own an active workspace.
curl -X POST "https://api.blesyum.com/api/v1/me/delete-account" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}POST /api/v1/me/deletion-requests → 202 Talep · 409 (+ bekleyen talep datada).
curl -X POST "https://api.blesyum.com/api/v1/me/deletion-requests" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}POST /api/v1/me/deletion-requests/{id}/cancel
idcurl -X POST "https://api.blesyum.com/api/v1/me/deletion-requests/<id>/cancel" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Signed-in help center (SUP-12 ext): the public articles plus any the caller's
role unlocks. The panel reads this instead of /api/v1/kb so an approved
developer sees the developer guides in the list and on the article page.
curl -X GET "https://api.blesyum.com/api/v1/me/kb" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Signed-in help center (SUP-12 ext): one published article by slug, gated by
slugaudience. A caller without the role gets 404 — not 403 — so the existence of a developer-only guide is not disclosed.
curl -X GET "https://api.blesyum.com/api/v1/me/kb/<slug>" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}**Kullanıcı kendi isteğiyle çalışma alanından ayrılır** (2026-08-18).
# Neden var
Kullanıcı vakası: *"eklenen kişi kendi isteğiyle çıkabilmeli; bu sorun Meta
Business'ta, Play Console'da var — adam bana 5 yıl önce yetki verdi, çıkamıyorum,
illa onun silmesi lazım."* Doğru bir şikayet: üyelik iki taraflı bir ilişkidir ve
bir tarafın onu bitirebilmesi için diğerinin iznine ihtiyacı olmamalı. Kişi ayrıca
o çalışma alanının verisini GÖRMEYE devam ettiği için bu bir gizlilik sorunudur.
# Kısıtlar
* **Onay kodu ZORUNLU** — leave-tenant/challenge ile e-postaya gider (gerekçe orada).
* **SAHİP ayrılamaz** (409). Önce sahipliği devretmeli; aksi hâlde sahipsiz bir
çalışma alanı kalır ve faturalama/KYC kararlarını kimse veremez.
* Ayrılan kişinin bekleyen davetleri de iptal edilir — yoksa eski bir davet
bağlantısı onu geri alabilirdi.
* Oturumun aktif kiracısı buysa, oturum kalan bir üyeliğe taşınır (yoksa kiracısız
kalır). Aksi hâlde kişi ayrıldığı kiracının oturumuyla 403 duvarına çarpardı.
İzin İSTEMEZ: bu kişinin kendi üyeliğidir. (core.users.manage istemek, tam da
şikayet edilen "sahibinin insafına kalma" durumunu üretirdi.)
curl -X POST "https://api.blesyum.com/api/v1/me/leave-tenant" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}**Ayrılma onay kodu iste** (2026-08-18, kullanıcı kararı: *"ayrılmadan önce maile kod
gidecek, onay alacak, çalışma alanının adını yazacak, ağır güvenlik önlemleri"*). # Neden üç kapı Ayrılmak geri alınamaz: kişi kendi erişimini kapatır ve geri dönmek için bir yöneticinin onu YENİDEN davet etmesi gerekir. Üç kapının her biri FARKLI bir vakayı karşılıyor; biri diğerinin yerine geçmez: | Kapı | Neyi engeller | |---|---| | **Parola** | Çalınmış/açık bırakılmış oturumla kurbanı kendi alanından atmayı | | **Çalışma alanı adını yazma** | Yanlış tıklamayı ve YANLIŞ ALANDAN çıkmayı (çok üyelikli kullanıcı) | | **E-postaya giden kod** | Parolayı bilen ama posta kutusuna erişemeyen saldırganı | # Kod NEDEN parola+addan SONRA gönderiliyor Sırayı ters kurmak (önce kod, sonra parola) bu ucu ücretsiz bir posta bombası yapardı: saldırgan kurbanın kutusuna istediği kadar "ayrılma kodu" yağdırırdı. Bu sırada e-posta ancak parolayı ve alan adını doğru bilen birine gider. Yanlış parola **422** döner, 401 değil — 401 dönseydi merkezî oturum kapısı kullanıcıyı panelden atardı (kök AGENTS.md: "yeniden-kimlik ucu 422 döner").
curl -X POST "https://api.blesyum.com/api/v1/me/leave-tenant/challenge" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Self-service profile rectification (SEC-19 / KVKK): update own
name / phone / timezone / country.
curl -X POST "https://api.blesyum.com/api/v1/me/profile" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}