Files
peworkshop/app/api/clues/[clueId]/route.js
T

71 lines
2.2 KiB
JavaScript

import { queryOne, run } from "@/lib/db";
import { cookies } from "next/headers";
import { verifyToken } from "@/app/api/auth/[...nextauth]/route";
export const dynamic = "force-dynamic"; // Disable caching
// GET endpoint to retrieve a specific clue
export async function GET(request, { params }) {
const { clueId } = params;
try {
// Check if the hunt is active first
const huntActiveSetting = await queryOne(
"SELECT value FROM settings WHERE key = 'hunt_active'"
);
const huntActive = huntActiveSetting && huntActiveSetting.value === "true";
// Only verify authentication when hunt is not active
if (!huntActive) {
const cookieStore = await cookies();
const sessionToken =
cookieStore.get("next-auth.session-token")?.value ||
cookieStore.get("__Secure-next-auth.session-token")?.value;
if (!sessionToken) {
return Response.json(
{ error: "Unauthorized", clue: null },
{ status: 401, headers: { "Content-Type": "application/json" } }
);
}
const userData = verifyToken(sessionToken);
if (!userData) {
return Response.json(
{ error: "Invalid session", clue: null },
{ status: 401, headers: { "Content-Type": "application/json" } }
);
}
// Admin can see clues even if hunt is not active
if (userData.role !== "admin") {
return Response.json(
{ error: "Hunt is not active", clue: null },
{ headers: { "Content-Type": "application/json" } }
);
}
}
// Fetch the specific clue
const clue = await queryOne("SELECT * FROM clues WHERE id = ?", [clueId]);
if (!clue) {
return Response.json(
{ error: "Clue not found", clue: null },
{ status: 404, headers: { "Content-Type": "application/json" } }
);
}
return Response.json(
{ clue },
{ headers: { "Content-Type": "application/json" } }
);
} catch (error) {
console.error("Error fetching clue details:", error);
return Response.json(
{ error: "Failed to fetch clue details: " + error.message, clue: null },
{ status: 500, headers: { "Content-Type": "application/json" } }
);
}
}