This commit is contained in:
1 parent
8efd032cc6
commit
df38dccbf1
735 files changed
+128321
-120870
No files matched your search
+44
-44
@@ -6,56 +6,56 @@
|
||||
|
||||
import { apiJson, apiUnavailable } from "@/lib/api";
|
||||
import { auth } from "@/lib/auth";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { sessionUserId } from "@/lib/auth/session-user";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
export async function GET(_req: Request) {
|
||||
const session = await auth();
|
||||
const id = sessionUserId(session?.user?.id);
|
||||
if (!id) {
|
||||
return apiJson({ user: null });
|
||||
}
|
||||
const session = await auth();
|
||||
const id = sessionUserId(session?.user?.id);
|
||||
if (!id) {
|
||||
return apiJson({ user: null });
|
||||
}
|
||||
|
||||
try {
|
||||
const user = await prisma.user.findUnique({
|
||||
where: { id },
|
||||
select: {
|
||||
id: true,
|
||||
username: true,
|
||||
look: true,
|
||||
motto: true,
|
||||
rank: true,
|
||||
credits: true,
|
||||
pixels: true,
|
||||
points: true,
|
||||
gender: true,
|
||||
online: true,
|
||||
accountCreated: true,
|
||||
},
|
||||
});
|
||||
try {
|
||||
const user = await prisma.user.findUnique({
|
||||
where: { id },
|
||||
select: {
|
||||
id: true,
|
||||
username: true,
|
||||
look: true,
|
||||
motto: true,
|
||||
rank: true,
|
||||
credits: true,
|
||||
pixels: true,
|
||||
points: true,
|
||||
gender: true,
|
||||
online: true,
|
||||
accountCreated: true,
|
||||
},
|
||||
});
|
||||
|
||||
if (!user) {
|
||||
return apiJson({ user: null });
|
||||
}
|
||||
if (!user) {
|
||||
return apiJson({ user: null });
|
||||
}
|
||||
|
||||
return apiJson({
|
||||
user: {
|
||||
id: user.id,
|
||||
username: user.username,
|
||||
look: user.look,
|
||||
motto: user.motto,
|
||||
rank: user.rank,
|
||||
credits: user.credits,
|
||||
pixels: user.pixels,
|
||||
points: user.points,
|
||||
gender: user.gender,
|
||||
online: user.online === "1",
|
||||
accountCreated: user.accountCreated,
|
||||
},
|
||||
});
|
||||
} catch {
|
||||
return apiUnavailable("Account data is temporarily unavailable");
|
||||
}
|
||||
return apiJson({
|
||||
user: {
|
||||
id: user.id,
|
||||
username: user.username,
|
||||
look: user.look,
|
||||
motto: user.motto,
|
||||
rank: user.rank,
|
||||
credits: user.credits,
|
||||
pixels: user.pixels,
|
||||
points: user.points,
|
||||
gender: user.gender,
|
||||
online: user.online === "1",
|
||||
accountCreated: user.accountCreated,
|
||||
},
|
||||
});
|
||||
} catch {
|
||||
return apiUnavailable("Account data is temporarily unavailable");
|
||||
}
|
||||
}
|
||||
@@ -10,54 +10,54 @@
|
||||
|
||||
import { apiError, apiJson, apiUnavailable, positiveBigInt } from "@/lib/api";
|
||||
import { auth } from "@/lib/auth";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { sessionUserId } from "@/lib/auth/session-user";
|
||||
import { personalTokenScope } from "@/lib/auth/personal-token-scope";
|
||||
import { sessionUserId } from "@/lib/auth/session-user";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
async function currentUserId(): Promise<number | null> {
|
||||
const session = await auth();
|
||||
return sessionUserId(session?.user?.id);
|
||||
const session = await auth();
|
||||
return sessionUserId(session?.user?.id);
|
||||
}
|
||||
|
||||
export async function GET(_req: Request) {
|
||||
const id = await currentUserId();
|
||||
if (!id) return apiError("Unauthorized", 401);
|
||||
const id = await currentUserId();
|
||||
if (!id) return apiError("Unauthorized", 401);
|
||||
|
||||
try {
|
||||
const tokens = await prisma.personalAccessTokens.findMany({
|
||||
where: personalTokenScope(id),
|
||||
select: { id: true, name: true, lastUsedAt: true },
|
||||
orderBy: { id: "desc" },
|
||||
});
|
||||
// Never expose the token hash.
|
||||
return apiJson({ data: tokens });
|
||||
} catch {
|
||||
return apiUnavailable("Token data is temporarily unavailable");
|
||||
}
|
||||
try {
|
||||
const tokens = await prisma.personalAccessTokens.findMany({
|
||||
where: personalTokenScope(id),
|
||||
select: { id: true, name: true, lastUsedAt: true },
|
||||
orderBy: { id: "desc" },
|
||||
});
|
||||
// Never expose the token hash.
|
||||
return apiJson({ data: tokens });
|
||||
} catch {
|
||||
return apiUnavailable("Token data is temporarily unavailable");
|
||||
}
|
||||
}
|
||||
|
||||
export async function DELETE(req: Request) {
|
||||
const id = await currentUserId();
|
||||
if (!id) return apiError("Unauthorized", 401);
|
||||
const id = await currentUserId();
|
||||
if (!id) return apiError("Unauthorized", 401);
|
||||
|
||||
const tokenId = new URL(req.url).searchParams.get("id");
|
||||
const parsedTokenId = positiveBigInt(tokenId);
|
||||
if (!parsedTokenId) {
|
||||
return apiError("A valid token id is required", 422);
|
||||
}
|
||||
const tokenId = new URL(req.url).searchParams.get("id");
|
||||
const parsedTokenId = positiveBigInt(tokenId);
|
||||
if (!parsedTokenId) {
|
||||
return apiError("A valid token id is required", 422);
|
||||
}
|
||||
|
||||
try {
|
||||
// Scope the delete to the owner so users cannot revoke others' tokens.
|
||||
const result = await prisma.personalAccessTokens.deleteMany({
|
||||
where: { id: parsedTokenId, ...personalTokenScope(id) },
|
||||
});
|
||||
if (result.count === 0) {
|
||||
return apiError("Token not found", 404);
|
||||
}
|
||||
return apiJson({ ok: true });
|
||||
} catch {
|
||||
return apiUnavailable("Could not revoke token");
|
||||
}
|
||||
try {
|
||||
// Scope the delete to the owner so users cannot revoke others' tokens.
|
||||
const result = await prisma.personalAccessTokens.deleteMany({
|
||||
where: { id: parsedTokenId, ...personalTokenScope(id) },
|
||||
});
|
||||
if (result.count === 0) {
|
||||
return apiError("Token not found", 404);
|
||||
}
|
||||
return apiJson({ ok: true });
|
||||
} catch {
|
||||
return apiUnavailable("Could not revoke token");
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user