mirror of
https://github.com/mudabbir-ahmad/peworkshop.git
synced 2026-10-07 19:50:20 +00:00
Add hunts table and default row; improve error handling and UI for team management
This commit is contained in:
1 parent
cd9c106ba1
commit
a6ed24b2e6
8 files changed
+156
-52
No files matched your search
@@ -1,33 +1,49 @@
|
||||
export const runtime = "nodejs";
|
||||
import NextAuth from "next-auth";
|
||||
import CredentialsProvider from "next-auth/providers/credentials";
|
||||
import { validateCredentials } from "@/actions/auth";
|
||||
|
||||
// Ensure NEXTAUTH_SECRET is defined
|
||||
if (!process.env.NEXTAUTH_SECRET) {
|
||||
console.error("Warning: NEXTAUTH_SECRET is not defined");
|
||||
}
|
||||
|
||||
// Ensure NEXTAUTH_URL is defined
|
||||
if (!process.env.NEXTAUTH_URL) {
|
||||
console.error("Warning: NEXTAUTH_URL is not defined");
|
||||
}
|
||||
|
||||
export const authOptions = {
|
||||
debug: process.env.NODE_ENV === "development",
|
||||
providers: [
|
||||
CredentialsProvider({
|
||||
{
|
||||
id: "credentials",
|
||||
name: "Credentials",
|
||||
type: "credentials",
|
||||
credentials: {
|
||||
username: { label: "Username", type: "text" },
|
||||
password: { label: "Password", type: "password" },
|
||||
},
|
||||
async authorize(credentials) {
|
||||
if (!credentials?.username || !credentials?.password) return null;
|
||||
const user = await validateCredentials(
|
||||
credentials.username,
|
||||
credentials.password
|
||||
);
|
||||
return user
|
||||
? {
|
||||
id: user.id,
|
||||
username: user.username,
|
||||
role: user.role,
|
||||
teamId: user.teamId,
|
||||
}
|
||||
: null;
|
||||
try {
|
||||
if (!credentials?.username || !credentials?.password) return null;
|
||||
const user = await validateCredentials(
|
||||
credentials.username,
|
||||
credentials.password
|
||||
);
|
||||
return user
|
||||
? {
|
||||
id: user.id,
|
||||
username: user.username,
|
||||
role: user.role,
|
||||
teamId: user.teamId,
|
||||
}
|
||||
: null;
|
||||
} catch (error) {
|
||||
console.error("NextAuth authorize error:", error);
|
||||
return null;
|
||||
}
|
||||
},
|
||||
}),
|
||||
},
|
||||
],
|
||||
callbacks: {
|
||||
async jwt({ token, user }) {
|
||||
@@ -50,10 +66,11 @@ export const authOptions = {
|
||||
return session;
|
||||
},
|
||||
},
|
||||
pages: { signIn: "/login" },
|
||||
// no "pages" property
|
||||
session: { strategy: "jwt", maxAge: 30 * 24 * 60 * 60 },
|
||||
secret: process.env.NEXTAUTH_SECRET,
|
||||
};
|
||||
|
||||
// Creating the handler after exporting authOptions
|
||||
const handler = NextAuth(authOptions);
|
||||
export { handler as GET, handler as POST };
|
||||
@@ -0,0 +1,25 @@
|
||||
import { getServerSession } from "next-auth/next";
|
||||
import { authOptions } from "../auth/[...nextauth]/route";
|
||||
import { run } from "@/lib/db";
|
||||
|
||||
export async function POST(request) {
|
||||
const session = await getServerSession(authOptions);
|
||||
if (!session || session.user.role !== "admin") {
|
||||
return new Response(JSON.stringify({ error: "Unauthorized" }), {
|
||||
status: 401,
|
||||
});
|
||||
}
|
||||
|
||||
try {
|
||||
// Add a WHERE clause or provide an ID if you're updating a specific hunt record
|
||||
await run("UPDATE hunts SET active = 1, start_time = NOW() WHERE id = ?", [1]);
|
||||
// Or if you just have one hunt record: "UPDATE hunts SET active = 1, start_time = NOW()"
|
||||
|
||||
return new Response(JSON.stringify({ success: true }), { status: 200 });
|
||||
} catch (err) {
|
||||
console.error("Hunt start error:", err); // Add logging for better debugging
|
||||
return new Response(JSON.stringify({ error: err.message }), {
|
||||
status: 500,
|
||||
});
|
||||
}
|
||||
}
|
||||
@@ -1,50 +1,43 @@
|
||||
import { queryOne, query } from "../../../../lib/db";
|
||||
import { query, queryOne } from "@/lib/db";
|
||||
import { getServerSession } from "next-auth/next";
|
||||
import { authOptions } from "../../auth/[...nextauth]/route";
|
||||
|
||||
export async function GET({ params }) {
|
||||
export async function GET(request, context) {
|
||||
const session = await getServerSession(authOptions);
|
||||
|
||||
if (!session) {
|
||||
return new Response(JSON.stringify({ error: "Unauthorized" }), {
|
||||
status: 401,
|
||||
});
|
||||
return Response.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
try {
|
||||
const teamId = parseInt(params.teamId, 10);
|
||||
if (isNaN(teamId)) {
|
||||
return new Response(JSON.stringify({ error: "Invalid team ID" }), {
|
||||
status: 400,
|
||||
});
|
||||
const teamId = context.params.teamId;
|
||||
|
||||
// Validate teamId
|
||||
if (!teamId || isNaN(parseInt(teamId, 10))) {
|
||||
return Response.json({ error: "Invalid team ID" }, { status: 400 });
|
||||
}
|
||||
|
||||
const team = await queryOne(
|
||||
"SELECT id, name, code FROM teams WHERE id = ?",
|
||||
[teamId]
|
||||
);
|
||||
const team = await queryOne("SELECT * FROM teams WHERE id = ?", [teamId]);
|
||||
|
||||
if (!team) {
|
||||
return new Response(JSON.stringify({ error: "Team not found" }), {
|
||||
status: 404,
|
||||
});
|
||||
return Response.json({ error: "Team not found" }, { status: 404 });
|
||||
}
|
||||
|
||||
const members = await query(
|
||||
"SELECT id, username FROM users WHERE team_id = ?",
|
||||
"SELECT id, username FROM users WHERE team_id = ?",
|
||||
[teamId]
|
||||
);
|
||||
|
||||
return new Response(JSON.stringify({ team, members }), {
|
||||
status: 200,
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
},
|
||||
});
|
||||
return Response.json({
|
||||
success: true,
|
||||
team,
|
||||
members
|
||||
}, { status: 200 });
|
||||
|
||||
} catch (error) {
|
||||
console.error("Team fetch error:", error);
|
||||
return new Response(
|
||||
JSON.stringify({ error: "Failed to fetch team details" }),
|
||||
return Response.json(
|
||||
{ error: "Failed to fetch team data" },
|
||||
{ status: 500 }
|
||||
);
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user