import { NextRequest, NextResponse } from "next/server"; import { getIronSession } from "iron-session"; import { SessionData, sessionOptions } from "@/lib/session"; import { prisma } from "@/lib/prisma"; export async function PATCH( request: NextRequest, { params }: { params: { id: string; commentId: string } } ) { const response = NextResponse.next(); const session = await getIronSession(request, response, sessionOptions); if (!session.isLoggedIn || !session.userId) { return NextResponse.json({ error: "Unauthorized" }, { status: 401 }); } const comment = await prisma.comment.findUnique({ where: { id: params.commentId }, }); if (!comment) { return NextResponse.json({ error: "Commentaire introuvable" }, { status: 404 }); } if (comment.userId !== session.userId) { return NextResponse.json({ error: "Non autorise" }, { status: 403 }); } const { content } = await request.json(); if (!content || !content.trim()) { return NextResponse.json({ error: "Le contenu est requis" }, { status: 400 }); } const updated = await prisma.comment.update({ where: { id: params.commentId }, data: { content: content.trim() }, include: { user: { select: { id: true, name: true, username: true, avatarPath: true }, }, }, }); return NextResponse.json(updated); } export async function DELETE( request: NextRequest, { params }: { params: { id: string; commentId: string } } ) { const response = NextResponse.next(); const session = await getIronSession(request, response, sessionOptions); if (!session.isLoggedIn || !session.userId) { return NextResponse.json({ error: "Unauthorized" }, { status: 401 }); } const comment = await prisma.comment.findUnique({ where: { id: params.commentId }, }); if (!comment) { return NextResponse.json({ error: "Commentaire introuvable" }, { status: 404 }); } // Only author or admin can delete const isAuthor = comment.userId === session.userId; const isAdmin = session.userRole === "admin"; if (!isAuthor && !isAdmin) { return NextResponse.json({ error: "Non autorise" }, { status: 403 }); } await prisma.comment.delete({ where: { id: params.commentId } }); return NextResponse.json({ success: true }); }