import { queryOne } from "../../../../lib/db"; import { getServerSession } from "next-auth/next"; import { authOptions } from "../../auth/[...nextauth]/route"; export async function GET(request, { params }) { const session = await getServerSession(authOptions); if (!session) { return Response.json({ error: "Unauthorised" }, { status: 401 }); } try { const { teamId } = params; // Single query to get team data with authorization check const team = await queryOne( `SELECT t.* FROM teams t LEFT JOIN users u ON u.id = ? WHERE t.id = ? AND (u.team_id = t.id OR ? = 'admin')`, [session.user.id, teamId, session.user.role] ); if (!team) { return Response.json( { error: "Team not found or unauthorized" }, { status: 404 } ); } return Response.json(team); } catch (error) { console.error("Team fetch error:", error); return Response.json( { error: "Failed to fetch team details" }, { status: 500 } ); } }