about summary refs log tree commit diff stats
path: root/crates/rocie-server/src/api/get/auth
diff options
context:
space:
mode:
Diffstat (limited to 'crates/rocie-server/src/api/get/auth')
-rw-r--r--crates/rocie-server/src/api/get/auth/inventory.rs53
-rw-r--r--crates/rocie-server/src/api/get/auth/mod.rs32
-rw-r--r--crates/rocie-server/src/api/get/auth/product.rs362
-rw-r--r--crates/rocie-server/src/api/get/auth/product_parent.rs111
-rw-r--r--crates/rocie-server/src/api/get/auth/recipe.rs76
-rw-r--r--crates/rocie-server/src/api/get/auth/unit.rs120
-rw-r--r--crates/rocie-server/src/api/get/auth/unit_property.rs79
-rw-r--r--crates/rocie-server/src/api/get/auth/user.rs85
8 files changed, 918 insertions, 0 deletions
diff --git a/crates/rocie-server/src/api/get/auth/inventory.rs b/crates/rocie-server/src/api/get/auth/inventory.rs
new file mode 100644
index 0000000..24a8e3d
--- /dev/null
+++ b/crates/rocie-server/src/api/get/auth/inventory.rs
@@ -0,0 +1,53 @@
+use actix_identity::Identity;
+use actix_web::{HttpResponse, Responder, Result, get, web};
+
+use crate::{
+    app::App,
+    storage::sql::{
+        product::{ProductId, ProductIdStub},
+        product_amount::ProductAmount,
+    },
+};
+
+/// Get the amount of an product
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "Product found in database and amount fetched",
+            body = ProductAmount
+        ),
+        (
+            status = NOT_FOUND,
+            description = "Product not found in database"
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "id" = ProductId,
+            description = "Product id"
+        ),
+    )
+)]
+#[get("/inventory/{id}")]
+pub(crate) async fn amount_by_id(
+    app: web::Data<App>,
+    id: web::Path<ProductIdStub>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let id = id.into_inner();
+
+    match ProductAmount::from_id(&app, id.into()).await? {
+        Some(product) => Ok(HttpResponse::Ok().json(product)),
+        None => Ok(HttpResponse::NotFound().finish()),
+    }
+}
diff --git a/crates/rocie-server/src/api/get/auth/mod.rs b/crates/rocie-server/src/api/get/auth/mod.rs
new file mode 100644
index 0000000..c51f6a7
--- /dev/null
+++ b/crates/rocie-server/src/api/get/auth/mod.rs
@@ -0,0 +1,32 @@
+use actix_web::web;
+
+pub(crate) mod inventory;
+pub(crate) mod product;
+pub(crate) mod product_parent;
+pub(crate) mod recipe;
+pub(crate) mod unit;
+pub(crate) mod unit_property;
+pub(crate) mod user;
+
+pub(crate) fn register_paths(cfg: &mut web::ServiceConfig) {
+    cfg.service(inventory::amount_by_id)
+        .service(product::product_by_id)
+        .service(product::product_by_name)
+        .service(product::product_suggestion_by_name)
+        .service(product::products_by_product_parent_id_direct)
+        .service(product::products_by_product_parent_id_indirect)
+        .service(product::products_in_storage)
+        .service(product::products_registered)
+        .service(product_parent::product_parents)
+        .service(product_parent::product_parents_toplevel)
+        .service(product_parent::product_parents_under)
+        .service(recipe::recipe_by_id)
+        .service(recipe::recipes)
+        .service(unit::unit_by_id)
+        .service(unit::units)
+        .service(unit::units_by_property_id)
+        .service(unit_property::unit_properties)
+        .service(unit_property::unit_property_by_id)
+        .service(user::users)
+        .service(user::user_by_id);
+}
diff --git a/crates/rocie-server/src/api/get/auth/product.rs b/crates/rocie-server/src/api/get/auth/product.rs
new file mode 100644
index 0000000..1a1e31d
--- /dev/null
+++ b/crates/rocie-server/src/api/get/auth/product.rs
@@ -0,0 +1,362 @@
+use actix_identity::Identity;
+use actix_web::{HttpRequest, HttpResponse, Responder, Result, get, web};
+use log::info;
+use percent_encoding::percent_decode_str;
+
+use crate::{
+    app::App,
+    storage::sql::{
+        product::{Product, ProductId, ProductIdStub},
+        product_amount::ProductAmount,
+        product_parent::{ProductParent, ProductParentId, ProductParentIdStub},
+    },
+};
+
+/// A String, that is not url-decoded on parse.
+struct UrlEncodedString(String);
+
+impl UrlEncodedString {
+    /// Percent de-encode a given string
+    fn percent_decode(&self) -> Result<String, std::str::Utf8Error> {
+        percent_decode_str(self.0.replace('+', "%20").as_str())
+            .decode_utf8()
+            .map(|s| s.to_string())
+            .inspect(|s| info!("Decoded `{}` as `{s}`", self.0))
+    }
+
+    fn from_str(inner: &str) -> Self {
+        Self(inner.to_owned())
+    }
+}
+
+/// Get Product by id
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "Product found from database",
+            body = Product
+        ),
+        (
+            status = NOT_FOUND,
+            description = "Product not found in database"
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "id" = ProductId,
+            description = "Product id"
+        ),
+    )
+)]
+#[get("/product/by-id/{id}")]
+pub(crate) async fn product_by_id(
+    app: web::Data<App>,
+    id: web::Path<ProductIdStub>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let id = id.into_inner();
+
+    match Product::from_id(&app, id.into()).await? {
+        Some(product) => Ok(HttpResponse::Ok().json(product)),
+
+        None => Ok(HttpResponse::NotFound().finish()),
+    }
+}
+
+/// Get Product by name
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "Product found from database",
+            body = Product
+        ),
+        (
+            status = NOT_FOUND,
+            description = "Product not found in database"
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "name" = String,
+            description = "Name of the product"
+        ),
+    )
+)]
+#[get("/product/by-name/{name}")]
+pub(crate) async fn product_by_name(
+    app: web::Data<App>,
+    req: HttpRequest,
+    name: web::Path<String>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    drop(name);
+
+    let name = UrlEncodedString::from_str(
+        req.path()
+            .strip_prefix("/product/by-name/")
+            .expect("Will always exists"),
+    );
+    let name = name.percent_decode()?;
+
+    match Product::from_name(&app, name).await? {
+        Some(product) => Ok(HttpResponse::Ok().json(product)),
+
+        None => Ok(HttpResponse::NotFound().finish()),
+    }
+}
+
+/// Get Product suggestion by name
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "Product suggestions found from database",
+            body = Vec<Product>
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "name" = String,
+            description = "Partial name of a product"
+        ),
+    )
+)]
+#[get("/product/by-part-name/{name}")]
+pub(crate) async fn product_suggestion_by_name(
+    app: web::Data<App>,
+    req: HttpRequest,
+    name: web::Path<String>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    drop(name);
+
+    let name = UrlEncodedString::from_str(
+        req.path()
+            .strip_prefix("/product/by-part-name/")
+            .expect("Will always exists"),
+    );
+    let name = &name.percent_decode()?;
+
+    let all = Product::get_all(&app).await?;
+
+    let matching = all
+        .into_iter()
+        .filter(|product| product.name.starts_with(name.as_str()))
+        .collect::<Vec<_>>();
+
+    Ok(HttpResponse::Ok().json(matching))
+}
+
+/// Return all registered products
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "All products found",
+            body = Vec<Product>
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+)]
+#[get("/products_registered/")]
+pub(crate) async fn products_registered(
+    app: web::Data<App>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let all = Product::get_all(&app).await?;
+
+    Ok(HttpResponse::Ok().json(all))
+}
+
+/// Return all products, which non-null amount in storage
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "All products found",
+            body = Vec<Product>
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+)]
+#[get("/products_in_storage/")]
+pub(crate) async fn products_in_storage(
+    app: web::Data<App>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let all = Product::get_all(&app).await?;
+
+    let mut output_products = Vec::with_capacity(all.len());
+    for product in all {
+        let amount = ProductAmount::from_id(&app, product.id).await?;
+
+        if amount.is_some_and(|amount| amount.amount.value > 0) {
+            output_products.push(product);
+        }
+    }
+
+    Ok(HttpResponse::Ok().json(output_products))
+}
+
+/// Get Products by it's product parent id
+///
+/// This will also return all products below this product parent id
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "Products found from database",
+            body = Vec<Product>
+        ),
+        (
+            status = NOT_FOUND,
+            description = "Product parent id not found in database"
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "id" = ProductParentId,
+            description = "Product parent id"
+        ),
+    )
+)]
+#[get("/product/by-product-parent-id-indirect/{id}")]
+pub(crate) async fn products_by_product_parent_id_indirect(
+    app: web::Data<App>,
+    id: web::Path<ProductParentIdStub>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let id = id.into_inner();
+
+    if let Some(parent) = ProductParent::from_id(&app, id.into()).await? {
+        async fn collect_products(app: &App, parent: ProductParent) -> Result<Vec<Product>> {
+            let mut all = Product::get_all(app)
+                .await?
+                .into_iter()
+                .filter(|prod| prod.parent.is_some_and(|val| val == parent.id))
+                .collect::<Vec<_>>();
+
+            if let Some(child) = ProductParent::get_all(app)
+                .await?
+                .into_iter()
+                .find(|pp| pp.parent.is_some_and(|id| id == parent.id))
+            {
+                all.extend(Box::pin(collect_products(app, child)).await?);
+            }
+
+            Ok(all)
+        }
+
+        let all = collect_products(&app, parent).await?;
+
+        Ok(HttpResponse::Ok().json(all))
+    } else {
+        Ok(HttpResponse::NotFound().finish())
+    }
+}
+
+/// Get Products by it's product parent id
+///
+/// This will only return products directly associated with this product parent id
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "Products found from database",
+            body = Vec<Product>
+        ),
+        (
+            status = NOT_FOUND,
+            description = "Product parent id not found in database"
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "id" = ProductParentId,
+            description = "Product parent id"
+        ),
+    )
+)]
+#[get("/product/by-product-parent-id-direct/{id}")]
+pub(crate) async fn products_by_product_parent_id_direct(
+    app: web::Data<App>,
+    id: web::Path<ProductParentIdStub>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let id = id.into_inner();
+
+    if let Some(parent) = ProductParent::from_id(&app, id.into()).await? {
+        let all = Product::get_all(&app)
+            .await?
+            .into_iter()
+            .filter(|prod| prod.parent.is_some_and(|val| val == parent.id))
+            .collect::<Vec<_>>();
+
+        Ok(HttpResponse::Ok().json(all))
+    } else {
+        Ok(HttpResponse::NotFound().finish())
+    }
+}
diff --git a/crates/rocie-server/src/api/get/auth/product_parent.rs b/crates/rocie-server/src/api/get/auth/product_parent.rs
new file mode 100644
index 0000000..6c3351d
--- /dev/null
+++ b/crates/rocie-server/src/api/get/auth/product_parent.rs
@@ -0,0 +1,111 @@
+use actix_identity::Identity;
+use actix_web::{HttpResponse, Responder, error::Result, get, web};
+
+use crate::{
+    app::App,
+    storage::sql::product_parent::{ProductParent, ProductParentId, ProductParentIdStub},
+};
+
+/// Return all registered product parents
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "All parents found",
+            body = Vec<ProductParent>
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+)]
+#[get("/product_parents/")]
+pub(crate) async fn product_parents(
+    app: web::Data<App>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let all: Vec<ProductParent> = ProductParent::get_all(&app).await?;
+
+    Ok(HttpResponse::Ok().json(all))
+}
+
+/// Return all registered product parents, that have no parents themselves
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "All parents found",
+            body = Vec<ProductParent>
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+)]
+#[get("/product_parents_toplevel/")]
+pub(crate) async fn product_parents_toplevel(
+    app: web::Data<App>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let all: Vec<ProductParent> = ProductParent::get_all(&app)
+        .await?
+        .into_iter()
+        .filter(|parent| parent.parent.is_none())
+        .collect();
+
+    Ok(HttpResponse::Ok().json(all))
+}
+
+/// Return all parents, that have this parent as parent
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "All parents found",
+            body = Vec<ProductParent>
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "id" = ProductParentId,
+            description = "Product parent id"
+        ),
+    ),
+)]
+#[get("/product_parents_under/{id}")]
+pub(crate) async fn product_parents_under(
+    app: web::Data<App>,
+    id: web::Path<ProductParentIdStub>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let id = id.into_inner().into();
+
+    let all: Vec<_> = ProductParent::get_all(&app)
+        .await?
+        .into_iter()
+        .filter(|parent| parent.parent.is_some_and(|found| found == id))
+        .collect();
+
+    Ok(HttpResponse::Ok().json(all))
+}
diff --git a/crates/rocie-server/src/api/get/auth/recipe.rs b/crates/rocie-server/src/api/get/auth/recipe.rs
new file mode 100644
index 0000000..cb80597
--- /dev/null
+++ b/crates/rocie-server/src/api/get/auth/recipe.rs
@@ -0,0 +1,76 @@
+use actix_identity::Identity;
+use actix_web::{HttpResponse, Responder, error::Result, get, web};
+
+use crate::{
+    app::App,
+    storage::sql::recipe::{Recipe, RecipeId, RecipeIdStub},
+};
+
+/// Get an recipe by it's id.
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "Recipe found in database and fetched",
+            body = Recipe,
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = NOT_FOUND,
+            description = "Recipe not found in database"
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "id" = RecipeId,
+            description = "Recipe id"
+        ),
+    )
+)]
+#[get("/recipe/by-id/{id}")]
+pub(crate) async fn recipe_by_id(
+    app: web::Data<App>,
+    id: web::Path<RecipeIdStub>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let id = id.into_inner();
+
+    match Recipe::from_id(&app, id.into()).await? {
+        Some(recipe) => Ok(HttpResponse::Ok().json(recipe)),
+        None => Ok(HttpResponse::NotFound().finish()),
+    }
+}
+
+/// Get all added recipes
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "All recipes found in database and fetched",
+            body = Recipe,
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+)]
+#[get("/recipe/all")]
+pub(crate) async fn recipes(app: web::Data<App>, _user: Identity) -> Result<impl Responder> {
+    let all = Recipe::get_all(&app).await?;
+
+    Ok(HttpResponse::Ok().json(all))
+}
diff --git a/crates/rocie-server/src/api/get/auth/unit.rs b/crates/rocie-server/src/api/get/auth/unit.rs
new file mode 100644
index 0000000..980d9c7
--- /dev/null
+++ b/crates/rocie-server/src/api/get/auth/unit.rs
@@ -0,0 +1,120 @@
+use actix_identity::Identity;
+use actix_web::{HttpResponse, Responder, Result, get, web};
+
+use crate::{
+    app::App,
+    storage::sql::{
+        unit::{Unit, UnitId, UnitIdStub},
+        unit_property::{UnitPropertyId, UnitPropertyIdStub},
+    },
+};
+
+/// Return all registered units
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "All units founds",
+            body = Vec<Unit>
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+)]
+#[get("/units/")]
+pub(crate) async fn units(app: web::Data<App>, _user: Identity) -> Result<impl Responder> {
+    let all = Unit::get_all(&app).await?;
+
+    Ok(HttpResponse::Ok().json(all))
+}
+
+/// Return all registered units for a specific unit property
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "All units founds",
+            body = Vec<Unit>
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "id" = UnitPropertyId,
+            description = "Unit property id"
+        ),
+    )
+)]
+#[get("/units-by-property/{id}")]
+pub(crate) async fn units_by_property_id(
+    app: web::Data<App>,
+    id: web::Path<UnitPropertyIdStub>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let id = id.into_inner();
+    let all = Unit::get_all(&app)
+        .await?
+        .into_iter()
+        .filter(|unit| unit.unit_property == id.into())
+        .collect::<Vec<_>>();
+
+    Ok(HttpResponse::Ok().json(all))
+}
+
+/// Get Unit by id
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "Unit found from database",
+            body = Unit
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = NOT_FOUND,
+            description = "Unit not found in database"
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "id" = UnitId,
+            description = "Unit id"
+        ),
+    )
+)]
+#[get("/unit/{id}")]
+pub(crate) async fn unit_by_id(
+    app: web::Data<App>,
+    id: web::Path<UnitIdStub>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let id = id.into_inner();
+
+    match Unit::from_id(&app, id.into()).await? {
+        Some(unit) => Ok(HttpResponse::Ok().json(unit)),
+        None => Ok(HttpResponse::NotFound().finish()),
+    }
+}
diff --git a/crates/rocie-server/src/api/get/auth/unit_property.rs b/crates/rocie-server/src/api/get/auth/unit_property.rs
new file mode 100644
index 0000000..f5b070a
--- /dev/null
+++ b/crates/rocie-server/src/api/get/auth/unit_property.rs
@@ -0,0 +1,79 @@
+use actix_identity::Identity;
+use actix_web::{HttpResponse, Responder, Result, get, web};
+
+use crate::{
+    app::App,
+    storage::sql::unit_property::{UnitProperty, UnitPropertyId, UnitPropertyIdStub},
+};
+
+/// Return all registered unit properties
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "All unit properties founds",
+            body = Vec<UnitProperty>
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+)]
+#[get("/unit-properties/")]
+pub(crate) async fn unit_properties(
+    app: web::Data<App>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let all = UnitProperty::get_all(&app).await?;
+
+    Ok(HttpResponse::Ok().json(all))
+}
+
+/// Get Unit property by id
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "Unit property found from database",
+            body = UnitProperty
+        ),
+        (
+            status = NOT_FOUND,
+            description = "Unit Property not found in database"
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "id" = UnitPropertyId,
+            description = "Unit Property id"
+        ),
+    )
+)]
+#[get("/unit-property/{id}")]
+pub(crate) async fn unit_property_by_id(
+    app: web::Data<App>,
+    id: web::Path<UnitPropertyIdStub>,
+    _user: Identity,
+) -> Result<impl Responder> {
+    let id = id.into_inner();
+
+    match UnitProperty::from_id(&app, id.into()).await? {
+        Some(unit_property) => Ok(HttpResponse::Ok().json(unit_property)),
+        None => Ok(HttpResponse::NotFound().finish()),
+    }
+}
diff --git a/crates/rocie-server/src/api/get/auth/user.rs b/crates/rocie-server/src/api/get/auth/user.rs
new file mode 100644
index 0000000..e4a5046
--- /dev/null
+++ b/crates/rocie-server/src/api/get/auth/user.rs
@@ -0,0 +1,85 @@
+use actix_identity::Identity;
+use actix_web::{HttpResponse, Responder, Result, get, web};
+
+use crate::{
+    app::App,
+    storage::sql::user::{User, UserId, UserIdStub},
+};
+
+/// Get all registered users.
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "Users found in database and fetched",
+            body = Vec<User>,
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+)]
+#[get("/users")]
+async fn users(app: web::Data<App>, _user: Identity) -> Result<impl Responder> {
+    let output = User::get_all(&app).await?;
+
+    Ok(HttpResponse::Ok().json(output))
+}
+
+/// Get an specific user by id.
+#[utoipa::path(
+    responses(
+        (
+            status = OK,
+            description = "User found in database and fetched",
+            body = User,
+        ),
+        (
+            status = NOT_FOUND,
+            description = "User not found in database"
+        ),
+        (
+            status = UNAUTHORIZED,
+            description = "You did not login before calling this endpoint",
+        ),
+        (
+            status = FORBIDDEN,
+            description = "The current logged in user is not allowed to access this end-point."
+        ),
+        (
+            status = INTERNAL_SERVER_ERROR,
+            description = "Server encountered error",
+            body = String
+        )
+    ),
+    params(
+        (
+            "id" = UserId,
+            description = "User id"
+        ),
+    )
+)]
+#[get("/user/{id}")]
+async fn user_by_id(
+    id: web::Path<UserIdStub>,
+    app: web::Data<App>,
+    user: Identity,
+) -> Result<impl Responder> {
+    let id: UserId = id.into_inner().into();
+
+    if user.id().expect("to have one") != id.to_string() {
+        return Ok(HttpResponse::Forbidden()
+            .body("You must be logged-in as the same user, you request the info for."));
+    }
+
+    match User::from_id(&app, id).await? {
+        Some(user) => Ok(HttpResponse::Ok().json(user)),
+        None => Ok(HttpResponse::NotFound().finish()),
+    }
+}