SPB Git forge

spb/spb-cloud

Public
10commits 1branches 0releases
3.2 MBsize
maindefault branch
yesterdaylast push
JavaScript 56.7% TypeScript 42.6%
2.3 KB · 71 lines typescript
Raw Blame History
1import { NextRequest, NextResponse } from "next/server";2import { getIronSession } from "iron-session";3import { SessionData, sessionOptions } from "@/lib/session";4import { prisma } from "@/lib/prisma";56export async function PATCH(7  request: NextRequest,8  { params }: { params: { id: string; commentId: string } }9) {10  const response = NextResponse.next();11  const session = await getIronSession<SessionData>(request, response, sessionOptions);12  if (!session.isLoggedIn || !session.userId) {13    return NextResponse.json({ error: "Unauthorized" }, { status: 401 });14  }1516  const comment = await prisma.comment.findUnique({17    where: { id: params.commentId },18  });19  if (!comment) {20    return NextResponse.json({ error: "Commentaire introuvable" }, { status: 404 });21  }22  if (comment.userId !== session.userId) {23    return NextResponse.json({ error: "Non autorise" }, { status: 403 });24  }2526  const { content } = await request.json();27  if (!content || !content.trim()) {28    return NextResponse.json({ error: "Le contenu est requis" }, { status: 400 });29  }3031  const updated = await prisma.comment.update({32    where: { id: params.commentId },33    data: { content: content.trim() },34    include: {35      user: {36        select: { id: true, name: true, username: true, avatarPath: true },37      },38    },39  });4041  return NextResponse.json(updated);42}4344export async function DELETE(45  request: NextRequest,46  { params }: { params: { id: string; commentId: string } }47) {48  const response = NextResponse.next();49  const session = await getIronSession<SessionData>(request, response, sessionOptions);50  if (!session.isLoggedIn || !session.userId) {51    return NextResponse.json({ error: "Unauthorized" }, { status: 401 });52  }5354  const comment = await prisma.comment.findUnique({55    where: { id: params.commentId },56  });57  if (!comment) {58    return NextResponse.json({ error: "Commentaire introuvable" }, { status: 404 });59  }6061  // Only author or admin can delete62  const isAuthor = comment.userId === session.userId;63  const isAdmin = session.userRole === "admin";64  if (!isAuthor && !isAdmin) {65    return NextResponse.json({ error: "Non autorise" }, { status: 403 });66  }6768  await prisma.comment.delete({ where: { id: params.commentId } });69  return NextResponse.json({ success: true });70}71