Skip to main content
PUT
Update User Profile

Overview

This endpoint allows authenticated users to update their profile information. Users can only update their own profile. Supports partial updates and avatar image uploads.

Authentication

This endpoint requires authentication. Include a valid JWT access token in the Authorization header:

Authorization

Users can only update their own profile. The authenticated user must match the user ID in the URL path, otherwise a 403 Forbidden error is returned.

Request

Endpoint

Path Parameters

Headers

Request Body

Supports partial updates. All fields are optional:

Avatar Upload

To upload an avatar, use multipart/form-data encoding and include the avatar file field:

Request Fields

Response

Success Response (200 OK)

Returns the updated user profile data:

Response Fields

Error Responses

400 Bad Request

Returned when the request data is invalid:

401 Unauthorized

Returned when the authentication token is missing or invalid:

403 Forbidden

Returned when the authenticated user tries to update another user’s profile:

404 Not Found

Returned when the user ID doesn’t exist:

500 Internal Server Error

Returned when an unexpected error occurs:

Example Requests

Update Basic Information (JSON)

Update with Avatar Upload (Multipart)

Partial Update (Single Field)

Example Response

Implementation Details

This endpoint is implemented in /apps/users/views.py:97 as the update_profile function view:
  • Decorated with @permission_classes([IsAuthenticated]) to require authentication
  • Verifies that request.user matches the user being updated (authorization check)
  • Supports MultiPartParser and FormParser for file uploads
  • Handles avatar file uploads separately before serializer validation
  • Uses UsersSerializer with partial=True to allow partial updates
  • Returns updated user data on success

Notes

  • Partial updates are supported - you only need to include fields you want to change
  • Avatar images are uploaded to the media/avatars/ directory
  • Email and username must remain unique across all users
  • The endpoint uses PUT method but supports partial updates (PATCH-like behavior)