Files

48 lines
1.4 KiB
JavaScript

import { queryOne } from "@/lib/db";
import { getToken } from "next-auth/jwt";
import { cookies } from "next/headers";
export const dynamic = "force-dynamic"; // Disable caching
export async function GET(request) {
try {
// Use next-auth's getToken to safely decode the session token
const token = await getToken({
req: request,
secret:
process.env.NEXTAUTH_SECRET ||
"your-fallback-secret-should-be-at-least-32-chars",
});
if (!token) {
return Response.json({ error: "Unauthorized" }, { status: 401 });
}
// Fetch fresh user data from DB using token id
const freshUserData = await queryOne(
"SELECT id, username, role, team_id FROM users WHERE id = ?",
[token.id]
);
if (!freshUserData) {
return Response.json({ error: "User not found" }, { status: 404 });
}
return Response.json(
{
id: freshUserData.id,
username: freshUserData.username,
role: freshUserData.role,
teamId: freshUserData.team_id,
timestamp: new Date().toISOString(),
},
{
headers: {
"Cache-Control": "no-store, must-revalidate",
Pragma: "no-cache",
Expires: "0",
},
}
);
} catch (error) {
console.error("User API error:", error);
return Response.json({ error: "Server error" }, { status: 500 });
}
}