fixed a bit

This commit is contained in:
bobbert committed 2025-03-11 23:02:22 +00:00
1 parent 45b0f98971
commit a0fb2b9970
9 files changed
+314 -177

No files matched your search

+23 -15
View File
@@ -1,4 +1,4 @@
import { queryOne } from "../../../../lib/db";
import { queryOne, query } from "../../../../lib/db";
import { getServerSession } from "next-auth/next";
import { authOptions } from "../../auth/[...nextauth]/route";
@@ -6,32 +6,40 @@ export async function GET(request, { params }) {
const session = await getServerSession(authOptions);
if (!session) {
return Response.json({ error: "Unauthorised" }, { status: 401 });
return new Response(JSON.stringify({ error: "Unauthorized" }), {
status: 401,
});
}
try {
const { teamId } = params;
const teamId = parseInt(params.teamId, 10);
if (isNaN(teamId)) {
return new Response(JSON.stringify({ error: "Invalid team ID" }), {
status: 400,
});
}
// Single query to get team data with authorization check
const team = await queryOne(
`SELECT t.* FROM teams t
LEFT JOIN users u ON u.id = ?
WHERE t.id = ? AND (u.team_id = t.id OR ? = 'admin')`,
[session.user.id, teamId, session.user.role]
"SELECT id, name, code FROM teams WHERE id = ?",
[teamId]
);
if (!team) {
return Response.json(
{ error: "Team not found or unauthorized" },
{ status: 404 }
);
return new Response(JSON.stringify({ error: "Team not found" }), {
status: 404,
});
}
return Response.json(team);
const members = await query(
"SELECT id, username FROM users WHERE team_id = ?",
[teamId]
);
return new Response(JSON.stringify({ team, members }), { status: 200 });
} catch (error) {
console.error("Team fetch error:", error);
return Response.json(
{ error: "Failed to fetch team details" },
return new Response(
JSON.stringify({ error: "Failed to fetch team details" }),
{ status: 500 }
);
}