import { queryOne, query } from "@/lib/db"; import { getToken } from "next-auth/jwt"; export const dynamic = "force-dynamic"; // Disable static rendering and caching export async function GET(request, context) { try { const token = await getToken({ req: request, secret: process.env.NEXTAUTH_SECRET || "your-fallback-secret-should-be-at-least-32-chars", }); if (!token) { return Response.json({ error: "Unauthorized" }, { status: 401 }); } // Use token.teamId for validation if ( !token.teamId || parseInt(token.teamId, 10) !== parseInt(context.params.teamId, 10) ) { return Response.json( { error: "Not authorized to view this team" }, { status: 403 } ); } const team = await queryOne("SELECT * FROM teams WHERE id = ?", [ token.teamId, ]); if (!team) { return Response.json({ error: "Team not found" }, { status: 404 }); } const members = await query( "SELECT id, username FROM users WHERE team_id = ? ORDER BY username ASC", [token.teamId] ); const timestamp = new Date().toISOString(); // Add timestamp for debugging // Add additional cache-busting headers return Response.json( { success: true, team, members, refreshed: timestamp, lastUpdated: team.last_updated || timestamp, }, { status: 200, headers: { "Cache-Control": "no-store, must-revalidate, max-age=0", Pragma: "no-cache", Expires: "0", }, } ); } catch (error) { console.error("Team route error:", error); return Response.json({ error: "Server error" }, { status: 500 }); } }