mirror of
https://github.com/mudabbir-ahmad/peworkshop.git
synced 2026-10-07 19:50:20 +00:00
FIX OF ALL ISSUES WITH LOG IN PAGE. EVERYTHING TO THE POINT OF TESTING THE MAP WORKS SO FAR.
This commit is contained in:
1 parent
84f010cb87
commit
c79a9636a7
10 files changed
+228
-233
No files matched your search
@@ -1,12 +1,21 @@
|
||||
import { query } from "../../../../lib/db";
|
||||
import { getServerSession } from "next-auth/next";
|
||||
import { authOptions } from "../../auth/[...nextauth]/route";
|
||||
import { cookies } from "next/headers";
|
||||
import { verifyToken } from "@/app/api/auth/[...nextauth]/route";
|
||||
|
||||
export async function GET(request, context) {
|
||||
const session = await getServerSession(authOptions);
|
||||
// Use cookie-based verification instead of getServerSession
|
||||
const cookieStore = await cookies();
|
||||
const sessionToken =
|
||||
cookieStore.get("next-auth.session-token")?.value ||
|
||||
cookieStore.get("__Secure-next-auth.session-token")?.value;
|
||||
|
||||
if (!session) {
|
||||
return Response.json({ error: "Unauthorised" }, { status: 401 });
|
||||
if (!sessionToken) {
|
||||
return Response.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
const userData = verifyToken(sessionToken);
|
||||
if (!userData) {
|
||||
return Response.json({ error: "Invalid session" }, { status: 401 });
|
||||
}
|
||||
|
||||
try {
|
||||
@@ -14,15 +23,15 @@ export async function GET(request, context) {
|
||||
|
||||
// Convert teamId to number for proper comparison
|
||||
const requestedTeamId = parseInt(teamId, 10);
|
||||
const userTeamId = parseInt(session.user.teamId, 10);
|
||||
const userTeamId = parseInt(userData.teamId, 10);
|
||||
|
||||
// Log for debugging
|
||||
console.log("Requested team:", requestedTeamId);
|
||||
console.log("User team:", userTeamId);
|
||||
console.log("User role:", session.user.role);
|
||||
console.log("User role:", userData.role);
|
||||
|
||||
// Ensure the user is requesting their own team or is an admin
|
||||
if (userTeamId !== requestedTeamId && session.user.role !== "admin") {
|
||||
if (userTeamId !== requestedTeamId && userData.role !== "admin") {
|
||||
return Response.json(
|
||||
{ error: "Not authorized to view this team" },
|
||||
{ status: 403 }
|
||||
|
||||
Reference in new issue
Block a user