Working supabase structure
This commit is contained in:
@@ -49,86 +49,3 @@ export async function GET(req: NextRequest) {
|
||||
|
||||
return NextResponse.json({ message: "ok", ...auth });
|
||||
}
|
||||
|
||||
/**
|
||||
* POST /api/auth
|
||||
* Called by the client to request a temporary relay token for a DM server.
|
||||
*
|
||||
* Body: { server_id: string }
|
||||
* Header: Authorization: Bearer <supabase_jwt>
|
||||
*/
|
||||
export async function POST(req: NextRequest) {
|
||||
const { server_id } = await req.json();
|
||||
const authHeader = req.cookies.get("token");
|
||||
|
||||
if (!server_id)
|
||||
return NextResponse.json(
|
||||
{ message: "Missing server_id in the json body" },
|
||||
{ status: StatusCodes.BAD_REQUEST }
|
||||
);
|
||||
|
||||
if (!authHeader)
|
||||
return NextResponse.json(
|
||||
{ message: "Missing Supabase Authorization header" },
|
||||
{ status: StatusCodes.BAD_REQUEST }
|
||||
);
|
||||
|
||||
const {
|
||||
data: { user },
|
||||
error,
|
||||
} = await supabase.auth.getUser(authHeader.value);
|
||||
|
||||
if (error || !user) {
|
||||
return NextResponse.json(
|
||||
{ message: "Invalid Supabase token" },
|
||||
{ status: StatusCodes.UNAUTHORIZED }
|
||||
);
|
||||
}
|
||||
|
||||
const { data: relayToken, error: errorRelay } = await supabase
|
||||
.from("server_auth")
|
||||
.insert({
|
||||
user_id: user.id,
|
||||
server_id,
|
||||
})
|
||||
.select()
|
||||
.maybeSingle();
|
||||
|
||||
if (!relayToken || errorRelay)
|
||||
return NextResponse.json(
|
||||
{ message: "Failed to create relay token" },
|
||||
{ status: StatusCodes.INTERNAL_SERVER_ERROR }
|
||||
);
|
||||
|
||||
return NextResponse.json({ message: "ok", token: relayToken.key });
|
||||
}
|
||||
|
||||
/**
|
||||
* PUT /api/auth
|
||||
* Called by the client to refresh the access token.
|
||||
*/
|
||||
export async function PUT(req: NextRequest) {
|
||||
const refresh_token = req.cookies.get("refresh_token")?.value;
|
||||
|
||||
if (!refresh_token)
|
||||
return NextResponse.json(
|
||||
{ message: "Missing refresh_token cookie" },
|
||||
{ status: StatusCodes.BAD_REQUEST }
|
||||
);
|
||||
|
||||
const session = await supabase.auth.refreshSession({ refresh_token });
|
||||
|
||||
if (session.error)
|
||||
return NextResponse.json(
|
||||
{
|
||||
message: session.error.message,
|
||||
},
|
||||
{ status: StatusCodes.INTERNAL_SERVER_ERROR }
|
||||
);
|
||||
|
||||
return NextResponse.json({
|
||||
message: "ok",
|
||||
access_token: session.data.session?.access_token,
|
||||
refresh_token: session.data.session?.refresh_token,
|
||||
});
|
||||
}
|
||||
|
||||
@@ -1,115 +0,0 @@
|
||||
import { StatusCodes } from "http-status-codes";
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import { supabase } from "../supa";
|
||||
import { ProfileSettings } from "@/types/settings";
|
||||
|
||||
/**
|
||||
* POST /api/profile
|
||||
* body { username, display_name, avatar_url }
|
||||
*/
|
||||
export async function POST(req: NextRequest) {
|
||||
const url = new URL(req.url);
|
||||
const token = req.cookies.get("token")?.value;
|
||||
const { username, display_name, avatar_url, node_address } =
|
||||
(await req.json()) as ProfileSettings;
|
||||
|
||||
if (!token)
|
||||
return NextResponse.json(
|
||||
{ message: "Token cookie not found" },
|
||||
{ status: StatusCodes.BAD_REQUEST }
|
||||
);
|
||||
|
||||
if (
|
||||
!username ||
|
||||
!display_name ||
|
||||
avatar_url === undefined ||
|
||||
avatar_url === null ||
|
||||
node_address === undefined ||
|
||||
node_address === null
|
||||
)
|
||||
return NextResponse.json(
|
||||
{
|
||||
message:
|
||||
"Invalid body, requires username, display_name, avatar_url, node_address",
|
||||
},
|
||||
{ status: StatusCodes.BAD_REQUEST }
|
||||
);
|
||||
|
||||
const {
|
||||
data: { user },
|
||||
} = await supabase.auth.getUser(token);
|
||||
|
||||
if (!user)
|
||||
return NextResponse.json(
|
||||
{ message: "Invalid token" },
|
||||
{ status: StatusCodes.NOT_FOUND }
|
||||
);
|
||||
|
||||
const { error } = await supabase
|
||||
.from("profiles")
|
||||
.update({
|
||||
username,
|
||||
display_name,
|
||||
avatar_url,
|
||||
node_address,
|
||||
})
|
||||
.eq("id", user.id);
|
||||
|
||||
if (error) {
|
||||
return NextResponse.json(
|
||||
{ message: error.message },
|
||||
{ status: StatusCodes.INTERNAL_SERVER_ERROR }
|
||||
);
|
||||
}
|
||||
|
||||
return NextResponse.json({ message: "ok" });
|
||||
}
|
||||
|
||||
/**
|
||||
* GET /api/profile?id=<id>
|
||||
* or cookie-based lookup
|
||||
*/
|
||||
export async function GET(req: NextRequest) {
|
||||
const url = new URL(req.url);
|
||||
const id = url.searchParams.get("id");
|
||||
const username = url.searchParams.get("username");
|
||||
const token = req.cookies.get("token")?.value;
|
||||
|
||||
if (!token && !id && !username)
|
||||
return NextResponse.json(
|
||||
{ message: "Query arg should be token or id or username" },
|
||||
{ status: StatusCodes.BAD_REQUEST }
|
||||
);
|
||||
|
||||
const { data: profile, error } = id
|
||||
? await supabase
|
||||
.from("profiles")
|
||||
.select("id, username, display_name, avatar_url, node_address")
|
||||
.eq("id", id)
|
||||
.maybeSingle()
|
||||
: username
|
||||
? await supabase
|
||||
.from("profiles")
|
||||
.select("id, username, display_name, avatar_url, node_address")
|
||||
.eq("username", username)
|
||||
.maybeSingle()
|
||||
: await supabase
|
||||
.from("profiles")
|
||||
.select("id, username, display_name, avatar_url, node_address")
|
||||
.eq("id", (await supabase.auth.getUser(token)).data.user?.id)
|
||||
.maybeSingle();
|
||||
|
||||
if (error)
|
||||
return NextResponse.json(
|
||||
{ message: error.message },
|
||||
{ status: StatusCodes.INTERNAL_SERVER_ERROR }
|
||||
);
|
||||
|
||||
if (!profile)
|
||||
return NextResponse.json(
|
||||
{ message: "Profile not found" },
|
||||
{ status: StatusCodes.NOT_FOUND }
|
||||
);
|
||||
|
||||
return NextResponse.json({ message: "ok", ...profile });
|
||||
}
|
||||
@@ -98,25 +98,3 @@ export async function GET(req: NextRequest) {
|
||||
|
||||
return res;
|
||||
}
|
||||
|
||||
/**
|
||||
* DELETE /api/auth
|
||||
* Body: { username }
|
||||
*/
|
||||
export async function DELETE(req: NextRequest) {
|
||||
const { username } = await req.json();
|
||||
|
||||
// Delete both profile + auth user
|
||||
const { data: profile } = await supabase
|
||||
.from("profiles")
|
||||
.select("id")
|
||||
.eq("username", username)
|
||||
.maybeSingle();
|
||||
|
||||
if (profile) {
|
||||
await supabase.auth.admin.deleteUser(profile.id);
|
||||
await supabase.from("profiles").delete().eq("id", profile.id);
|
||||
}
|
||||
|
||||
return NextResponse.json({ message: "ok" });
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user