Files
peworkshop/app/api/teams/[teamId]/leave/route.js
T

90 lines
2.7 KiB
JavaScript

import { run } from "@/lib/db";
import { cookies } from "next/headers";
import { verifyToken, createToken } from "@/app/api/auth/[...nextauth]/route";
export async function POST(request, context) {
try {
// Verify user authentication
const cookieStore = await cookies();
const sessionToken = cookieStore.get("next-auth.session-token")?.value;
if (!sessionToken) {
return Response.json({ error: "Unauthorized" }, { status: 401 });
}
const userData = verifyToken(sessionToken);
if (!userData) {
return Response.json({ error: "Invalid session" }, { status: 401 });
}
// Get teamId from URL params
const params = await Promise.resolve(context.params);
const teamId = params?.teamId;
// Validate teamId
if (!teamId || isNaN(parseInt(teamId, 10))) {
return Response.json({ error: "Invalid team ID" }, { status: 400 });
}
// Check if user is actually in this team
if (userData.teamId != teamId) {
return Response.json(
{ error: "You are not part of this team" },
{ status: 403 }
);
}
// Update the user record to remove team association
await run("UPDATE users SET team_id = NULL WHERE id = ?", [userData.id]);
// Try to update the team's last_updated timestamp but don't fail if column doesn't exist
try {
await run("UPDATE teams SET last_updated = ? WHERE id = ?", [
new Date().toISOString(),
teamId,
]);
} catch (updateError) {
// Log but don't fail if we can't update timestamp
console.warn(
"Failed to update last_updated timestamp:",
updateError.message
);
}
// Create a new token with updated user data (without teamId)
const newUserData = {
...userData,
teamId: null, // Remove team association in token
iat: Math.floor(Date.now() / 1000),
exp: Math.floor(Date.now() / 1000) + 30 * 24 * 60 * 60, // 30 days
};
const newToken = createToken(newUserData);
// Calculate expiration date for cookie
const expiryDate = new Date();
expiryDate.setDate(expiryDate.getDate() + 30);
// Return success with updated session token
return new Response(
JSON.stringify({
success: true,
message: "Successfully left the team",
}),
{
status: 200,
headers: {
"Content-Type": "application/json",
"Set-Cookie": `next-auth.session-token=${newToken}; Path=/; HttpOnly; SameSite=Lax; Expires=${expiryDate.toUTCString()}`,
},
}
);
} catch (error) {
console.error("Leave team error:", error);
return Response.json(
{ error: "Failed to leave team: " + error.message },
{ status: 500 }
);
}
}