mirror of
https://github.com/mudabbir-ahmad/peworkshop.git
synced 2026-10-07 19:50:20 +00:00
fixed a bit
This commit is contained in:
1 parent
e9d831c0a2
commit
9326f2845e
8 files changed
+990
-584
No files matched your search
@@ -1,31 +1,38 @@
|
||||
import { queryOne } from '../../../../lib/db';
|
||||
import { getServerSession } from 'next-auth/next';
|
||||
import { authOptions } from '../../auth/[...nextauth]/route';
|
||||
import { queryOne } from "../../../../lib/db";
|
||||
import { getServerSession } from "next-auth/next";
|
||||
import { authOptions } from "../../auth/[...nextauth]/route";
|
||||
|
||||
export async function GET(request, { params }) {
|
||||
const session = await getServerSession(authOptions);
|
||||
const session = await getServerSession(authOptions);
|
||||
|
||||
if (!session) {
|
||||
return Response.json({ error: 'Unauthorised' }, { status: 401 });
|
||||
if (!session) {
|
||||
return Response.json({ error: "Unauthorised" }, { status: 401 });
|
||||
}
|
||||
|
||||
try {
|
||||
const { teamId } = params;
|
||||
|
||||
// Single query to get team data with authorization check
|
||||
const team = await queryOne(
|
||||
`SELECT t.* FROM teams t
|
||||
LEFT JOIN users u ON u.id = ?
|
||||
WHERE t.id = ? AND (u.team_id = t.id OR ? = 'admin')`,
|
||||
[session.user.id, teamId, session.user.role]
|
||||
);
|
||||
|
||||
if (!team) {
|
||||
return Response.json(
|
||||
{ error: "Team not found or unauthorized" },
|
||||
{ status: 404 }
|
||||
);
|
||||
}
|
||||
|
||||
try {
|
||||
const { teamId } = params;
|
||||
|
||||
// Ensure the user is requesting their own team or is an admin
|
||||
if (session.user.teamId != teamId && session.user.role !== 'admin') {
|
||||
return Response.json({ error: 'Not authorized to view this team' }, { status: 403 });
|
||||
}
|
||||
|
||||
const team = await queryOne('SELECT * FROM teams WHERE id = ?', [teamId]);
|
||||
|
||||
if (!team) {
|
||||
return Response.json({ error: 'Team not found' }, { status: 404 });
|
||||
}
|
||||
|
||||
return Response.json(team);
|
||||
} catch (error) {
|
||||
console.error('Team fetch error:', error);
|
||||
return Response.json({ error: 'Failed to fetch team details' }, { status: 500 });
|
||||
}
|
||||
}
|
||||
return Response.json(team);
|
||||
} catch (error) {
|
||||
console.error("Team fetch error:", error);
|
||||
return Response.json(
|
||||
{ error: "Failed to fetch team details" },
|
||||
{ status: 500 }
|
||||
);
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user