export default defineEventHandler(async (event) => { if (!passwordAuthEnabled()) { throw createError({ statusCode: 404, statusMessage: 'Password login is not enabled' }) } const user = getSessionUser(event) if (!user) throw createError({ statusCode: 401, statusMessage: 'Authentication required' }) const body = await readBody<{ username?: string; password?: string; currentPassword?: string }>(event) const current = String(body?.currentPassword || '') const nextUser = String(body?.username || '').trim() const nextPass = String(body?.password || '') if (!current) throw createError({ statusCode: 400, statusMessage: 'Current password is required' }) const matched = await verifyLocalLogin(publicUsername() || user.name || '', current) if (!matched) throw createError({ statusCode: 401, statusMessage: 'Current password is incorrect' }) const updated = await updateCredentials(nextUser || matched, nextPass || current) setSessionUser(event, { sub: user.sub, name: updated.username }) return { ok: true, username: updated.username } })