|
@@ -1,59 +1,36 @@
|
|
|
import { NextResponse } from "next/server";
|
|
import { NextResponse } from "next/server";
|
|
|
import { db } from "@/lib/db";
|
|
import { db } from "@/lib/db";
|
|
|
|
|
+import { withDesktopAuth } from "@/lib/with-desktop-auth";
|
|
|
import { rateLimit } from "@/lib/rate-limit";
|
|
import { rateLimit } from "@/lib/rate-limit";
|
|
|
|
|
|
|
|
export async function GET(request: Request) {
|
|
export async function GET(request: Request) {
|
|
|
- const limited = rateLimit(request);
|
|
|
|
|
- if (limited) return limited;
|
|
|
|
|
-
|
|
|
|
|
- const authHeader = request.headers.get("Authorization");
|
|
|
|
|
- if (!authHeader?.startsWith("Bearer ")) {
|
|
|
|
|
- return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
|
|
|
|
- }
|
|
|
|
|
- const token = authHeader.slice(7);
|
|
|
|
|
-
|
|
|
|
|
- const session = await db.session.findFirst({
|
|
|
|
|
- where: { token, expiresAt: { gt: new Date() } },
|
|
|
|
|
- select: { userId: true },
|
|
|
|
|
- });
|
|
|
|
|
-
|
|
|
|
|
- if (!session) {
|
|
|
|
|
- return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
|
|
|
|
- }
|
|
|
|
|
-
|
|
|
|
|
- const user = await db.user.findUnique({
|
|
|
|
|
- where: { id: session.userId },
|
|
|
|
|
- select: { id: true, name: true, email: true },
|
|
|
|
|
- });
|
|
|
|
|
|
|
+ return withDesktopAuth(request, async ({ userId, organizationId }) => {
|
|
|
|
|
+ const user = await db.user.findUnique({
|
|
|
|
|
+ where: { id: userId },
|
|
|
|
|
+ select: { id: true, name: true, email: true },
|
|
|
|
|
+ });
|
|
|
|
|
|
|
|
- if (!user) {
|
|
|
|
|
- return NextResponse.json({ error: "User not found" }, { status: 401 });
|
|
|
|
|
- }
|
|
|
|
|
|
|
+ if (!user) {
|
|
|
|
|
+ return NextResponse.json({ error: "User not found" }, { status: 401 });
|
|
|
|
|
+ }
|
|
|
|
|
|
|
|
- // Get active organization
|
|
|
|
|
- const membership = await db.organizationMember.findFirst({
|
|
|
|
|
- where: { userId: session.userId },
|
|
|
|
|
- select: {
|
|
|
|
|
- organizationId: true,
|
|
|
|
|
- organization: { select: { id: true, name: true } },
|
|
|
|
|
- },
|
|
|
|
|
- });
|
|
|
|
|
|
|
+ const org = await db.organization.findUnique({
|
|
|
|
|
+ where: { id: organizationId },
|
|
|
|
|
+ select: { id: true, name: true },
|
|
|
|
|
+ });
|
|
|
|
|
|
|
|
- // Get company logo
|
|
|
|
|
- let companyLogo: string | null = null;
|
|
|
|
|
- if (membership?.organizationId) {
|
|
|
|
|
|
|
+ // Get company logo
|
|
|
|
|
+ let companyLogo: string | null = null;
|
|
|
const logoSetting = await db.appSetting.findFirst({
|
|
const logoSetting = await db.appSetting.findFirst({
|
|
|
- where: { organizationId: membership.organizationId, key: "workshop.logo" },
|
|
|
|
|
|
|
+ where: { organizationId, key: "workshop.logo" },
|
|
|
select: { value: true },
|
|
select: { value: true },
|
|
|
});
|
|
});
|
|
|
companyLogo = logoSetting?.value || null;
|
|
companyLogo = logoSetting?.value || null;
|
|
|
- }
|
|
|
|
|
|
|
|
|
|
- return NextResponse.json({
|
|
|
|
|
- user,
|
|
|
|
|
- organization: membership?.organization
|
|
|
|
|
- ? { ...membership.organization, logo: companyLogo }
|
|
|
|
|
- : null,
|
|
|
|
|
|
|
+ return NextResponse.json({
|
|
|
|
|
+ user,
|
|
|
|
|
+ organization: org ? { ...org, logo: companyLogo } : null,
|
|
|
|
|
+ });
|
|
|
});
|
|
});
|
|
|
}
|
|
}
|
|
|
|
|
|
|
@@ -67,7 +44,21 @@ export async function DELETE(request: Request) {
|
|
|
}
|
|
}
|
|
|
const token = authHeader.slice(7);
|
|
const token = authHeader.slice(7);
|
|
|
|
|
|
|
|
- await db.session.deleteMany({ where: { token } });
|
|
|
|
|
|
|
+ if (!token || token.length > 256) {
|
|
|
|
|
+ return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
|
|
|
|
+ }
|
|
|
|
|
+
|
|
|
|
|
+ // Only delete if the session is valid and belongs to a real user
|
|
|
|
|
+ const session = await db.session.findFirst({
|
|
|
|
|
+ where: { token, expiresAt: { gt: new Date() } },
|
|
|
|
|
+ select: { id: true },
|
|
|
|
|
+ });
|
|
|
|
|
+
|
|
|
|
|
+ if (!session) {
|
|
|
|
|
+ return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
|
|
|
|
+ }
|
|
|
|
|
+
|
|
|
|
|
+ await db.session.delete({ where: { id: session.id } });
|
|
|
|
|
|
|
|
return new NextResponse(null, { status: 204 });
|
|
return new NextResponse(null, { status: 204 });
|
|
|
}
|
|
}
|