diff --git a/src/app/api/client/sso/route.ts b/src/app/api/client/sso/route.ts deleted file mode 100644 index 50097e1f..00000000 --- a/src/app/api/client/sso/route.ts +++ /dev/null @@ -1,33 +0,0 @@ -import { headers } from "next/headers"; -import { auth } from "@/lib/auth"; -import { prisma } from "@/lib/prisma"; -import { clientIp, rateLimit } from "@/lib/rate-limit"; -import { siteSettings } from "@/lib/services/site-settings"; -import { issueSsoTicket } from "@/lib/auth/sso-ticket"; - -export const dynamic = "force-dynamic"; - -export async function GET() { - const session = await auth(); - if (!session?.user?.id) { - return new Response(JSON.stringify({ error: "Unauthorized" }), { status: 401 }); - } - - const userId = Number(session.user.id); - - // Throttle SSO ticket generation (5 per 30s per user) — prevent ticket spam. - if (!(await rateLimit(`sso:${userId}`, 5, 30_000)).ok) { - return new Response(JSON.stringify({ error: "Rate limited" }), { status: 429 }); - } - - const [hotelName, clientUrl] = await Promise.all([ - siteSettings.get("hotel_name", "Atom"), - siteSettings.get("nitro_client_url", ""), - ]); - - const ip = await clientIp(); - - const ticket = await issueSsoTicket(prisma, userId, hotelName ?? "Atom", ip); - - return Response.json({ ticket, hotelName: hotelName ?? "Atom", clientUrl }); -} \ No newline at end of file