Files

64 lines
1.8 KiB
JavaScript

import { queryOne, query } from "@/lib/db";
import { getToken } from "next-auth/jwt";
export const dynamic = "force-dynamic"; // Disable static rendering and caching
export async function GET(request, context) {
try {
const token = await getToken({
req: request,
secret:
process.env.NEXTAUTH_SECRET ||
"your-fallback-secret-should-be-at-least-32-chars",
});
if (!token) {
return Response.json({ error: "Unauthorized" }, { status: 401 });
}
// Await context.params so its properties can be safely used
const { teamId } = await context.params;
// Validate that the token's teamId matches the requested teamId
if (!token.teamId || parseInt(token.teamId, 10) !== parseInt(teamId, 10)) {
return Response.json(
{ error: "Not authorized to view this team" },
{ status: 403 }
);
}
const team = await queryOne("SELECT * FROM teams WHERE id = ?", [
token.teamId,
]);
if (!team) {
return Response.json({ error: "Team not found" }, { status: 404 });
}
const members = await query(
"SELECT id, username FROM users WHERE team_id = ? ORDER BY username ASC",
[token.teamId]
);
const timestamp = new Date().toISOString(); // Add timestamp for debugging
// Add additional cache-busting headers
return Response.json(
{
success: true,
team,
members,
refreshed: timestamp,
lastUpdated: team.last_updated || timestamp,
},
{
status: 200,
headers: {
"Cache-Control": "no-store, must-revalidate, max-age=0",
Pragma: "no-cache",
Expires: "0",
},
}
);
} catch (error) {
console.error("Team route error:", error);
return Response.json({ error: "Server error" }, { status: 500 });
}
}