Files
peworkshop/app/api/clues/[clueId]/route.js
T

81 lines
2.2 KiB
JavaScript

import { queryOne } from "@/lib/db";
import { getToken } from "next-auth/jwt";
export const dynamic = "force-dynamic"; // Disable caching
export async function GET(request, context) {
try {
const token = await getToken({
req: request,
secret:
process.env.NEXTAUTH_SECRET ||
"your-fallback-secret-should-be-at-least-32-chars",
});
if (!token) {
return Response.json({ error: "Unauthorized" }, { status: 401 });
}
// Check if user has a team
if (!token.teamId) {
return Response.json(
{ error: "You must be part of a team to view clues" },
{ status: 403 }
);
}
// Get the clueId directly from the params
const { clueId } = context.params;
// Validate clueId is a number
if (isNaN(parseInt(clueId))) {
return Response.json({ error: "Invalid clue ID" }, { status: 400 });
}
// Get the specific clue
const clue = await queryOne(
"SELECT id, title, description, location FROM clues WHERE id = ?",
[clueId]
);
if (!clue) {
return Response.json({ error: "Clue not found" }, { status: 404 });
}
// Check if this team has found this clue before
const found = await queryOne(
"SELECT * FROM team_clues WHERE team_id = ? AND clue_id = ?",
[token.teamId, clueId]
);
// Add different cache headers for admins vs regular users
const cacheHeaders =
token.role === "admin"
? {
"Cache-Control": "private, max-age=10", // Allow 10 seconds of caching for admins
Pragma: "no-cache",
Expires: "0",
}
: {
"Cache-Control": "no-store, no-cache, must-revalidate",
Pragma: "no-cache",
Expires: "0",
};
return Response.json(
{
...clue,
found: !!found, // Only mark as found if it was previously found
isAdmin: token.role === "admin", // Add flag so client knows user is admin
},
{ headers: cacheHeaders }
);
} catch (error) {
console.error("Error fetching clue:", error);
return Response.json(
{ error: "Failed to fetch clue: " + error.message },
{ status: 500 }
);
}
}