diff --git a/app/(main)/clue/[clueId]/page.js b/app/(main)/clue/[clueId]/page.js
index 8b1f3fb..bc966ba 100644
--- a/app/(main)/clue/[clueId]/page.js
+++ b/app/(main)/clue/[clueId]/page.js
@@ -339,7 +339,7 @@ export default function CluePage({ params }) {
πΊοΈ
Map
-
+
π
Stats
diff --git a/app/(main)/create-team/page.js b/app/(main)/create-team/page.js
index 11ff6de..c0bafcc 100644
--- a/app/(main)/create-team/page.js
+++ b/app/(main)/create-team/page.js
@@ -31,17 +31,17 @@ export default function CreateTeam() {
setError("");
try {
- // Add a check to ensure session is valid
+ // Check session status before proceeding
if (status !== "authenticated") {
throw new Error("You must be logged in to create a team");
}
- const response = await fetch("/api/teams", {
+ const response = await fetch("/api/teams/create", {
method: "POST",
headers: {
"Content-Type": "application/json",
},
- credentials: "include", // Important: include credentials
+ credentials: "include", // Important: include credentials with the request
body: JSON.stringify({ name: teamName }),
});
@@ -59,7 +59,7 @@ export default function CreateTeam() {
credentials: "include",
});
- // Hard navigation to make sure we're going to the right page
+ // Use window.location for a hard navigation to ensure session is fully updated
window.location.href = `/${data.teamId}`;
} catch (err) {
console.error("Team creation error:", err);
diff --git a/app/(main)/map/page.js b/app/(main)/map/page.js
index 9c8f55f..a6cd1ee 100644
--- a/app/(main)/map/page.js
+++ b/app/(main)/map/page.js
@@ -615,7 +615,7 @@ export default function MapPage() {
πΊοΈ
Map
-
+
π
Stats
diff --git a/app/api/teams/create/route.js b/app/api/teams/create/route.js
index 3f8a8cb..3539ebb 100644
--- a/app/api/teams/create/route.js
+++ b/app/api/teams/create/route.js
@@ -1,84 +1,65 @@
-import { queryOne, run } from "@/lib/db";
-import { cookies } from "next/headers";
-import { verifyToken } from "@/app/api/auth/[...nextauth]/route";
+import { getToken } from "next-auth/jwt";
+import { query, queryOne, run } from "@/lib/db";
import { nanoid } from "nanoid";
export async function POST(request) {
try {
- const cookieStore = await cookies();
- // Check for both possible cookie names
- const sessionToken =
- cookieStore.get("next-auth.session-token")?.value ||
- cookieStore.get("__Secure-next-auth.session-token")?.value;
+ // Get user token from session
+ const token = await getToken({
+ req: request,
+ secret:
+ process.env.NEXTAUTH_SECRET ||
+ "your-fallback-secret-should-be-at-least-32-chars",
+ });
- if (!sessionToken) {
- return Response.json({ error: "Unauthorized" }, { status: 401 });
- }
-
- const userData = verifyToken(sessionToken);
- if (!userData) {
- // Add debugging info to help diagnose the issue
- console.log(
- "Invalid session token:",
- sessionToken.substring(0, 10) + "..."
- );
+ if (!token) {
return Response.json({ error: "Invalid session" }, { status: 401 });
}
- if (userData.role === "admin") {
+ // Extract user ID from the token
+ const userId = token.id;
+ if (!userId) {
return Response.json(
- { error: "Admins cannot create teams" },
- { status: 403 }
+ { error: "Invalid user information in session" },
+ { status: 401 }
);
}
- const { name } = await request.json();
+ // Parse request body
+ const body = await request.json();
+ const { name } = body;
+
if (!name || name.trim() === "") {
return Response.json({ error: "Team name is required" }, { status: 400 });
}
- const teamCode = nanoid(6).toUpperCase();
- await run("INSERT INTO teams (name, code) VALUES (?, ?)", [name, teamCode]);
- const newTeam = await queryOne("SELECT id FROM teams WHERE code = ?", [
- teamCode,
- ]);
- if (!newTeam || !newTeam.id) {
- throw new Error("Failed to create team");
- }
+ // Generate a unique team code
+ const code = nanoid(6).toUpperCase();
- // Update the user's team association in DB
- await run("UPDATE users SET team_id = ? WHERE id = ?", [
- newTeam.id,
- userData.id,
+ // Create the team - updated schema to match actual database (no created_by column)
+ await run(`
+ CREATE TABLE IF NOT EXISTS teams (
+ id INTEGER PRIMARY KEY AUTOINCREMENT,
+ name TEXT NOT NULL,
+ code TEXT UNIQUE NOT NULL,
+ created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
+ )
+ `);
+
+ // Insert team without created_by field
+ const result = await run("INSERT INTO teams (name, code) VALUES (?, ?)", [
+ name,
+ code,
]);
- // Include the Set-Cookie header to update the session token with the new teamId
- const updatedUserData = {
- ...userData,
- teamId: newTeam.id,
- iat: Math.floor(Date.now() / 1000),
- exp: Math.floor(Date.now() / 1000) + 30 * 24 * 60 * 60, // 30 days
- };
+ const teamId = result.lastID;
- const { createToken } = await import("@/app/api/auth/[...nextauth]/route");
- const newToken = createToken(updatedUserData);
+ // Update the user's team_id
+ await run("UPDATE users SET team_id = ? WHERE id = ?", [teamId, userId]);
- // Calculate expiration date for cookie
- const expiryDate = new Date();
- expiryDate.setDate(expiryDate.getDate() + 30);
-
- return new Response(
- JSON.stringify({ success: true, teamId: newTeam.id, teamName: name }),
- {
- status: 201,
- headers: {
- "Content-Type": "application/json",
- "Set-Cookie": `next-auth.session-token=${newToken}; Path=/; HttpOnly; SameSite=Lax; Expires=${expiryDate.toUTCString()}`,
- },
- }
- );
+ return Response.json({ success: true, teamId, code });
} catch (error) {
- console.error("Team creation error:", error);
+ console.error("Create team error:", error);
return Response.json(
{ error: "Failed to create team: " + error.message },
{ status: 500 }
diff --git a/clue_hunt.db b/clue_hunt.db
index 8b4894b..d719858 100644
Binary files a/clue_hunt.db and b/clue_hunt.db differ