fixed a bit

This commit is contained in:
bobbert committed 2025-03-11 21:22:34 +00:00
1 parent e9d831c0a2
commit 9326f2845e
8 files changed
+990 -584

No files matched your search

+33 -26
View File
@@ -1,31 +1,38 @@
import { queryOne } from '../../../../lib/db';
import { getServerSession } from 'next-auth/next';
import { authOptions } from '../../auth/[...nextauth]/route';
import { queryOne } from "../../../../lib/db";
import { getServerSession } from "next-auth/next";
import { authOptions } from "../../auth/[...nextauth]/route";
export async function GET(request, { params }) {
const session = await getServerSession(authOptions);
const session = await getServerSession(authOptions);
if (!session) {
return Response.json({ error: 'Unauthorised' }, { status: 401 });
if (!session) {
return Response.json({ error: "Unauthorised" }, { status: 401 });
}
try {
const { teamId } = params;
// Single query to get team data with authorization check
const team = await queryOne(
`SELECT t.* FROM teams t
LEFT JOIN users u ON u.id = ?
WHERE t.id = ? AND (u.team_id = t.id OR ? = 'admin')`,
[session.user.id, teamId, session.user.role]
);
if (!team) {
return Response.json(
{ error: "Team not found or unauthorized" },
{ status: 404 }
);
}
try {
const { teamId } = params;
// Ensure the user is requesting their own team or is an admin
if (session.user.teamId != teamId && session.user.role !== 'admin') {
return Response.json({ error: 'Not authorized to view this team' }, { status: 403 });
}
const team = await queryOne('SELECT * FROM teams WHERE id = ?', [teamId]);
if (!team) {
return Response.json({ error: 'Team not found' }, { status: 404 });
}
return Response.json(team);
} catch (error) {
console.error('Team fetch error:', error);
return Response.json({ error: 'Failed to fetch team details' }, { status: 500 });
}
}
return Response.json(team);
} catch (error) {
console.error("Team fetch error:", error);
return Response.json(
{ error: "Failed to fetch team details" },
{ status: 500 }
);
}
}