import { queryOne } from '../../../../lib/db'; import { getServerSession } from 'next-auth/next'; import { authOptions } from '../../auth/[...nextauth]/route'; export async function GET(request, { params }) { const session = await getServerSession(authOptions); if (!session) { return Response.json({ error: 'Unauthorized' }, { status: 401 }); } try { const { teamId } = params; // Ensure the user is requesting their own team or is an admin if (session.user.teamId != teamId && session.user.role !== 'admin') { return Response.json({ error: 'Not authorized to view this team' }, { status: 403 }); } const team = await queryOne('SELECT * FROM teams WHERE id = ?', [teamId]); if (!team) { return Response.json({ error: 'Team not found' }, { status: 404 }); } return Response.json(team); } catch (error) { console.error('Team fetch error:', error); return Response.json({ error: 'Failed to fetch team details' }, { status: 500 }); } }