# UML Sequence Diagram: Authentication

Package flow: `api.views.admin.login`, `api.views.admin.logout`, `api.views.admin.base`, `api.models.user`, `api.models.access_token`.

## Flow Description

1. The frontend posts email and encrypted password to `/api/admin/login`.
2. `Login` bypasses token authentication, validates email/password, decrypts the password, and calls Django `authenticate()`.
3. A successful admin login removes any token for the same user, app type, and device, then creates a new `AccessToken`.
4. Protected calls send `Authorization: Token <token>`.
5. `TokenAuthentication` loads the token and user, rejects expired tokens, and returns `(user, token)` to DRF.
6. Logout deletes the token found in the authorization header.

```mermaid
sequenceDiagram
autonumber
participant FE as Frontend
participant Login as Login view
participant Validator as BaseValidator
participant Crypto as AES helper
participant DjangoAuth as Django authenticate
participant User as User
participant Token as AccessToken
participant API as Protected AdminApiBase view
participant Logout as Logout view

FE->>Login: POST /api/admin/login email, encrypted password
Login->>Validator: validate required email/password
Login->>Crypto: decrypt_aes_128_cbc(password)
Login->>DjangoAuth: authenticate(email, password)
DjangoAuth->>User: load custom user by email
User-->>DjangoAuth: admin user
Login->>Token: delete existing token for user/type/device
Login->>Token: create token expiring in 2 hours
Login-->>FE: user profile and token
FE->>API: POST protected endpoint with Authorization: Token value
API->>Token: TokenAuthentication loads AccessToken
Token-->>API: user and token if not expired
API-->>FE: normalized response
FE->>Logout: POST /api/admin/logout with Authorization header
Logout->>Token: delete token
Logout-->>FE: empty success data
```

