// app/api/teams/[teamId]/route.js import { queryOne } from "../../../../lib/db"; import { getServerSession } from "next-auth/next"; import { authOptions } from "../../../api/auth/[...nextauth]/route"; export async function GET(request, context) { const session = await getServerSession(authOptions); if (!session) { return new Response(JSON.stringify({ error: "Unauthorised" }), { status: 401, }); } try { const { teamId } = await context.params; // Await the params // Convert teamId to number for proper comparison const requestedTeamId = parseInt(teamId, 10); const userTeamId = parseInt(session.user.teamId, 10); // Log for debugging console.log("Requested team:", requestedTeamId); console.log("User team:", userTeamId); console.log("User role:", session.user.role); // Ensure the user is requesting their own team or is an admin if (userTeamId !== requestedTeamId && session.user.role !== "admin") { return new Response( JSON.stringify({ error: "Not authorized to view this team" }), { status: 403 } ); } const team = await queryOne("SELECT * FROM teams WHERE id = ?", [ requestedTeamId, ]); if (!team) { return new Response(JSON.stringify({ error: "Team not found" }), { status: 404, }); } return new Response(JSON.stringify(team), { status: 200 }); } catch (error) { console.error("Team fetch error:", error); return new Response( JSON.stringify({ error: "Failed to fetch team details" }), { status: 500 } ); } } export async function PATCH(request, context) { const session = await getServerSession(authOptions); if (!session) { return new Response(JSON.stringify({ error: "Unauthorised" }), { status: 401, }); } try { const { teamId } = await context.params; // Await the params const requestedTeamId = parseInt(teamId, 10); const { userId } = await request.json(); // Parse the request body // Log for debugging console.log("Requested team:", requestedTeamId); console.log("User role:", session.user.role); // Ensure the user is an admin or the user themselves if (session.user.role !== "admin" && session.user.id !== userId) { return new Response( JSON.stringify({ error: "Not authorized to change this team" }), { status: 403 } ); } // Update the user's team await queryOne("UPDATE users SET teamId = ? WHERE id = ?", [ requestedTeamId, userId, ]); // Update the session with the new teamId session.user.teamId = requestedTeamId; return new Response( JSON.stringify({ success: "Team updated successfully" }), { status: 200 } ); } catch (error) { console.error("Team update error:", error); return new Response( JSON.stringify({ error: "Failed to update team" }), { status: 500 } ); } }