# 1. Personal Information Management

User Type: **Student**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 1. Personal Information Management

### 1.1 View and Edit Personal Information
**What it does:** Lets the Student view and update their personal information (full name, date of birth, gender, profile photo, phone number, email address, city, province, and school name). Changes are validated, saved, and reflected across the platform (dashboard greeting, reports, certificates). Sensitive changes (email, phone) trigger re-verification.

**Sub-features:**
- Profile view: all personal information displayed in a read-only summary
- Edit full name with length and character validation
- Edit date of birth with date validation (must be a real, past date)
- Edit gender (optional field)
- Upload and replace profile photo (format and size validation, cropping)
- Edit phone number with format validation; triggers re-verification
- Edit email address with format validation; triggers re-verification
- Edit city, province, and school name (optional fields)
- Save with a single "Save changes" action and a success confirmation
- Change history: a record of what was changed and when
- Audit logging of the personal information changes

**Student User Journey:**
1. Student opens Profile → "Personal information" and sees a read-only summary of their details (name, date of birth, phone, email, city, province, school).
2. Student clicks "Edit" and updates their city from Johannesburg to Pretoria, then clicks "Save changes".
3. The system validates the change, saves it, and shows "Your profile has been updated."
4. The dashboard greeting and any reports now reflect the updated city.
5. Student clicks "Edit" again and changes their email address; the system saves the new email and sends a verification email to it.
6. Until the new email is verified, the old email remains the active contact and a banner shows "Verify your new email address".
7. Student opens Profile → "Change history" and sees each change (field, old value, new value, timestamp).

**Rules & Edge Cases:**
- Date of birth must be a real, past date; future or invalid dates are rejected.
- Changing the email or phone triggers re-verification; the old value stays active until the new one is verified.
- The profile photo must meet the format and size limits; oversized or unsupported files are rejected with a clear message.
- Required fields (name, date of birth) cannot be left blank.
- Every change is recorded in the change history with the field, old value, new value, and timestamp.
- The personal information changes are audit-logged with the account, the fields changed, and the timestamp.

### 1.2 Profile Photo Management
**What it does:** Lets the Student upload, replace, and remove their profile photo. The photo is validated for format and size, cropped to a standard aspect ratio, and displayed across the platform (dashboard, social learning, live sessions). The Student can remove the photo to revert to an initial-based avatar.

**Sub-features:**
- Upload a profile photo (accepted formats: JPG, PNG; size limit)
- Client-side cropping to a square aspect ratio before upload
- Replace the existing photo at any time
- Remove the photo to revert to an initial-based avatar
- Photo displayed across the platform (dashboard, social learning, live sessions)
- Format and size validation with clear error messages
- Photo storage and delivery optimized for display (compressed thumbnails)
- Photo change event logging
- Audit logging of the profile photo management

**Student User Journey:**
1. Student opens Profile → "Personal information" and clicks "Change photo".
2. Student selects an image from their device; the platform shows a cropping interface to frame the photo as a square.
3. Student adjusts the crop and clicks "Apply". The photo is uploaded and validated.
4. The new photo appears on the dashboard and in the profile.
5. Later, Student clicks "Change photo" again and selects a new image, replacing the previous one.
6. Student clicks "Remove photo"; the platform confirms and reverts to an initial-based avatar.
7. Student opens Profile → "Change history" and confirms the photo changes are recorded with timestamps.

**Rules & Edge Cases:**
- Only JPG and PNG are accepted; other formats are rejected with a clear message.
- The photo must be within the size limit; oversized files are rejected before upload.
- The photo is cropped to a square aspect ratio; the original aspect is not preserved.
- Removing the photo reverts to an initial-based avatar; it does not delete the account.
- Photo changes (upload, replace, remove) are logged with timestamp.
- The profile photo management is audit-logged with the account, the action, and the timestamp.

### 1.3 Contact Information Verification
**What it does:** Keeps the Student's contact information (email and phone) verified and current. When the Student changes their email or phone, the platform sends a verification to the new value and keeps the old value active until the new one is confirmed. The Student can also re-verify their current contact details on demand.

**Sub-features:**
- Re-verify current email on demand (sends a fresh verification link)
- Re-verify current phone on demand (sends a fresh OTP)
- New email verification flow (link, single-use, time-limited)
- New phone verification flow (OTP, single-use, time-limited)
- Old contact value remains active until the new one is verified
- Verification status indicator (verified, pending verification)
- Resend verification with rate limiting
- Expired-verification handling with a reissue option
- Verification event logging (sent, verified, expired, failed)
- Audit logging of the contact information verification

**Student User Journey:**
1. Student opens Profile → "Contact information" and sees the email and phone, each with a "Verified" badge.
2. Student clicks "Re-verify" next to the phone; the platform sends a fresh OTP to the registered number.
3. Student enters the OTP; the phone is re-verified and the badge updates.
4. Student changes their email address; the platform sends a verification link to the new email and shows a "Pending verification" badge on it.
5. Until Student clicks the link, the old email remains the active contact.
6. Student clicks the link; the new email is verified and becomes the active contact, and the old email is removed.
7. Student opens Profile → "Change history" and confirms the verification events are recorded with timestamps.

**Rules & Edge Cases:**
- The old contact value remains active until the new one is verified; there is never a gap in a verified contact.
- Verification links and OTPs are single-use and time-limited; expiry produces a reissue path.
- Resends are rate-limited to prevent abuse.
- A "Pending verification" badge is shown on any contact value that is not yet verified.
- Verification events (sent, verified, expired, failed) are logged with timestamp and channel.
- The contact information verification is audit-logged with the account, the channel, and the timestamp.
