+ {col.recipes.length > 0 && (
+
+
+ Export as PDF
+
+ )}
{isOwner &&
}
{!isOwner && col.isPublic && (
diff --git a/apps/web/app/(app)/meal-plan/page.tsx b/apps/web/app/(app)/meal-plan/page.tsx
index 3464db9..7090923 100644
--- a/apps/web/app/(app)/meal-plan/page.tsx
+++ b/apps/web/app/(app)/meal-plan/page.tsx
@@ -3,9 +3,10 @@ import { headers } from "next/headers";
import Link from "next/link";
import { ChevronLeft, ChevronRight, ShoppingCart, Printer } from "lucide-react";
import { auth } from "@/lib/auth/server";
-import { db, mealPlans, recipes, eq, and, desc } from "@epicure/db";
+import { db, mealPlans, mealPlanMembers, recipes, eq, and, desc } from "@epicure/db";
import { buttonVariants } from "@/components/ui/button";
import { MealPlanner } from "@/components/meal-plan/meal-planner";
+import { ShareMealPlanButton } from "@/components/meal-plan/share-meal-plan-button";
import { WeeklyNutritionBar } from "@/components/nutrition/weekly-nutrition-bar";
import { cn } from "@/lib/utils";
@@ -47,7 +48,7 @@ export default async function MealPlanPage({
const sunday = addWeeks(monday, 1);
sunday.setDate(sunday.getDate() - 1);
- const [plan, userRecipes] = await Promise.all([
+ const [plan, userRecipes, sharedMemberships] = await Promise.all([
db.query.mealPlans.findFirst({
where: and(eq(mealPlans.userId, session.user.id), eq(mealPlans.weekStart, weekStart)),
with: {
@@ -61,6 +62,10 @@ export default async function MealPlanPage({
orderBy: desc(recipes.updatedAt),
columns: { id: true, title: true },
}),
+ db.query.mealPlanMembers.findMany({
+ where: eq(mealPlanMembers.userId, session.user.id),
+ with: { mealPlan: { with: { user: true } } },
+ }),
]);
const entries = (plan?.entries ?? []).map((e) => ({
@@ -76,12 +81,13 @@ export default async function MealPlanPage({
return (
-
+
-
+
+
Shopping lists
@@ -101,6 +107,26 @@ export default async function MealPlanPage({
+
+ {sharedMemberships.length > 0 && (
+
+
Shared with you
+
+ {sharedMemberships.map((m) => (
+
+
+
{`${m.mealPlan.user?.name ?? "Unknown"}'s plan`}
+
Week of {m.mealPlan.weekStart} · {m.role}
+
+
+ ))}
+
+
+ )}
);
}
diff --git a/apps/web/app/(app)/meal-plan/shared/[mealPlanId]/page.tsx b/apps/web/app/(app)/meal-plan/shared/[mealPlanId]/page.tsx
new file mode 100644
index 0000000..85bc513
--- /dev/null
+++ b/apps/web/app/(app)/meal-plan/shared/[mealPlanId]/page.tsx
@@ -0,0 +1,55 @@
+import type { Metadata } from "next";
+import { notFound } from "next/navigation";
+import { headers } from "next/headers";
+import { auth } from "@/lib/auth/server";
+import { db, mealPlans, recipes, eq, desc } from "@epicure/db";
+import { getMealPlanAccessById, canWriteMealPlan } from "@/lib/meal-plan-access";
+import { SharedMealPlanView } from "@/components/meal-plan/shared-meal-plan-view";
+
+type Params = { params: Promise<{ mealPlanId: string }> };
+
+export const metadata: Metadata = { title: "Shared Meal Plan" };
+
+export default async function SharedMealPlanPage({ params }: Params) {
+ const { mealPlanId } = await params;
+ const session = await auth.api.getSession({ headers: await headers() });
+ if (!session) return null;
+
+ const access = await getMealPlanAccessById(mealPlanId, session.user.id);
+ if (!access) notFound();
+
+ const plan = await db.query.mealPlans.findFirst({
+ where: eq(mealPlans.id, mealPlanId),
+ with: { entries: { with: { recipe: true } }, user: true },
+ });
+ if (!plan) notFound();
+
+ const userRecipes = await db.query.recipes.findMany({
+ where: eq(recipes.authorId, session.user.id),
+ orderBy: desc(recipes.updatedAt),
+ columns: { id: true, title: true },
+ });
+
+ const canEdit = canWriteMealPlan(access.role);
+
+ return (
+
+
+
{`${plan.user?.name ?? "Shared"}'s Meal Plan`}
+
Week of {plan.weekStart} · {access.role}
+
+
({
+ id: e.id,
+ day: e.day,
+ mealType: e.mealType,
+ servings: e.servings,
+ recipe: e.recipe ? { id: e.recipe.id, title: e.recipe.title } : null,
+ }))}
+ />
+
+ );
+}
diff --git a/apps/web/app/(app)/recipes/[id]/page.tsx b/apps/web/app/(app)/recipes/[id]/page.tsx
index a7bff94..e66bec6 100644
--- a/apps/web/app/(app)/recipes/[id]/page.tsx
+++ b/apps/web/app/(app)/recipes/[id]/page.tsx
@@ -149,7 +149,23 @@ export default async function RecipePage({ params }: Params) {
}))}
/>
-
+
({
+ rawName: ing.rawName,
+ quantity: ing.quantity,
+ unit: ing.unit,
+ note: ing.note,
+ })),
+ steps: recipe.steps.map((s) => ({
+ instruction: s.instruction,
+ timerSeconds: s.timerSeconds,
+ })),
+ }}
+ />
diff --git a/apps/web/app/(app)/recipes/can-cook/page.tsx b/apps/web/app/(app)/recipes/can-cook/page.tsx
index 3547eab..22687b6 100644
--- a/apps/web/app/(app)/recipes/can-cook/page.tsx
+++ b/apps/web/app/(app)/recipes/can-cook/page.tsx
@@ -8,6 +8,14 @@ import { CanCookContent } from "@/components/recipe/can-cook-content";
export const metadata: Metadata = { title: "What can I cook?" };
+const EXPIRING_WITHIN_DAYS = 3;
+
+function isExpiringSoon(expiresAt: Date | null): boolean {
+ if (!expiresAt) return false;
+ const days = Math.ceil((expiresAt.getTime() - Date.now()) / (1000 * 60 * 60 * 24));
+ return days >= 0 && days <= EXPIRING_WITHIN_DAYS;
+}
+
export default async function CanCookPage() {
const session = await auth.api.getSession({ headers: await headers() });
if (!session) return null;
@@ -27,6 +35,12 @@ export default async function CanCookPage() {
const pantryKeys = new Set(pantry.map((p) => p.rawName.toLowerCase()));
+ const expiringSoonKeys = new Set(
+ pantry
+ .filter((p) => isExpiringSoon(p.expiresAt))
+ .map((p) => p.rawName.toLowerCase())
+ );
+
const scored = userRecipes
.filter((r) => r.ingredients.length > 0)
.map((recipe) => {
@@ -37,6 +51,9 @@ export default async function CanCookPage() {
.filter((ing) => !pantryKeys.has(ing.rawName.toLowerCase()))
.map((ing) => ing.rawName)
.slice(0, 5);
+ const usesExpiring = recipe.ingredients
+ .filter((ing) => expiringSoonKeys.has(ing.rawName.toLowerCase()))
+ .map((ing) => ing.rawName);
const total = recipe.ingredients.length;
const cover = recipe.photos?.find((p) => p.isCover) ?? recipe.photos?.[0];
return {
@@ -50,9 +67,15 @@ export default async function CanCookPage() {
total,
pct: Math.round((matched / total) * 100),
missing,
+ usesExpiring,
};
})
- .sort((a, b) => b.pct - a.pct);
+ .sort((a, b) => {
+ if (a.usesExpiring.length > 0 !== b.usesExpiring.length > 0) {
+ return a.usesExpiring.length > 0 ? -1 : 1;
+ }
+ return b.pct - a.pct;
+ });
return ;
}
diff --git a/apps/web/app/(app)/shopping-lists/[id]/page.tsx b/apps/web/app/(app)/shopping-lists/[id]/page.tsx
index 16e48de..c6beefc 100644
--- a/apps/web/app/(app)/shopping-lists/[id]/page.tsx
+++ b/apps/web/app/(app)/shopping-lists/[id]/page.tsx
@@ -4,10 +4,13 @@ import { headers } from "next/headers";
import Link from "next/link";
import { Printer } from "lucide-react";
import { auth } from "@/lib/auth/server";
-import { db, shoppingLists, eq, and } from "@epicure/db";
+import { db, shoppingLists, eq } from "@epicure/db";
import { ShoppingListView } from "@/components/meal-plan/shopping-list-view";
+import { ShareShoppingListButton } from "@/components/shopping-lists/share-shopping-list-button";
+import { GroceryExportButton } from "@/components/shopping-lists/grocery-export-button";
import { buttonVariants } from "@/components/ui/button";
import { cn } from "@/lib/utils";
+import { getShoppingListAccess, canWriteShoppingList } from "@/lib/shopping-list-access";
type Params = { params: Promise<{ id: string }> };
@@ -18,29 +21,39 @@ export default async function ShoppingListPage({ params }: Params) {
const session = await auth.api.getSession({ headers: await headers() });
if (!session) return null;
+ const access = await getShoppingListAccess(id, session.user.id);
+ if (!access) notFound();
+
const list = await db.query.shoppingLists.findFirst({
- where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session.user.id)),
+ where: eq(shoppingLists.id, id),
with: { items: { orderBy: (t, { asc }) => [asc(t.aisle), asc(t.rawName)] } },
});
-
if (!list) notFound();
+ const canEdit = canWriteShoppingList(access.role);
+ const instacartEnabled = process.env["NEXT_PUBLIC_GROCERY_PROVIDER"] === "instacart";
+
return (
-
+
{list.name}
{list.items.length} items{list.generatedAt ? " · Generated from meal plan" : ""}
-
-
- Print
-
+
+
+ {access.role === "owner" &&
}
+
+
+ Print
+
+
({
id: i.id,
rawName: i.rawName,
diff --git a/apps/web/app/(app)/shopping-lists/page.tsx b/apps/web/app/(app)/shopping-lists/page.tsx
index 57e13f2..5d009d6 100644
--- a/apps/web/app/(app)/shopping-lists/page.tsx
+++ b/apps/web/app/(app)/shopping-lists/page.tsx
@@ -1,7 +1,7 @@
import type { Metadata } from "next";
import { headers } from "next/headers";
import { auth } from "@/lib/auth/server";
-import { db, shoppingLists, eq, desc } from "@epicure/db";
+import { db, shoppingLists, shoppingListMembers, eq, desc } from "@epicure/db";
import { ShoppingListsPageContent } from "@/components/shopping-lists/shopping-lists-page-content";
export const metadata: Metadata = { title: "Shopping Lists" };
@@ -10,11 +10,17 @@ export default async function ShoppingListsPage() {
const session = await auth.api.getSession({ headers: await headers() });
if (!session) return null;
- const lists = await db.query.shoppingLists.findMany({
- where: eq(shoppingLists.userId, session.user.id),
- orderBy: desc(shoppingLists.createdAt),
- with: { items: { columns: { id: true, checked: true } } },
- });
+ const [lists, memberships] = await Promise.all([
+ db.query.shoppingLists.findMany({
+ where: eq(shoppingLists.userId, session.user.id),
+ orderBy: desc(shoppingLists.createdAt),
+ with: { items: { columns: { id: true, checked: true } } },
+ }),
+ db.query.shoppingListMembers.findMany({
+ where: eq(shoppingListMembers.userId, session.user.id),
+ with: { list: { with: { user: true } } },
+ }),
+ ]);
return (
i.checked).length,
}))}
+ sharedLists={memberships.map((m) => ({
+ id: m.list.id,
+ name: m.list.name,
+ ownerName: m.list.user?.name ?? "Unknown",
+ role: m.role,
+ }))}
/>
);
}
diff --git a/apps/web/app/api/v1/feed/for-you/route.ts b/apps/web/app/api/v1/feed/for-you/route.ts
new file mode 100644
index 0000000..04cd924
--- /dev/null
+++ b/apps/web/app/api/v1/feed/for-you/route.ts
@@ -0,0 +1,69 @@
+import { NextRequest, NextResponse } from "next/server";
+import { db, recipes, users, favorites, ratings, eq, and, ne, gte, notInArray, inArray, desc } from "@epicure/db";
+import { requireSession } from "@/lib/api-auth";
+import { buildPreferenceMap, rankForYou } from "@/lib/for-you-ranking";
+
+export async function GET(req: NextRequest) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+ const userId = session!.user.id;
+
+ const { searchParams } = new URL(req.url);
+ const limit = Math.min(parseInt(searchParams.get("limit") ?? "20"), 50);
+
+ // Recipes the user has favorited, or rated 4+, define their taste profile.
+ const [favoritedRows, highRatedRows] = await Promise.all([
+ db.select({ recipeId: favorites.recipeId }).from(favorites).where(eq(favorites.userId, userId)),
+ db.select({ recipeId: ratings.recipeId }).from(ratings).where(and(eq(ratings.userId, userId), gte(ratings.score, 4))),
+ ]);
+
+ const likedIds = [...new Set([...favoritedRows.map((r) => r.recipeId), ...highRatedRows.map((r) => r.recipeId)])];
+
+ const likedRecipes = likedIds.length > 0
+ ? await db.select({ tags: recipes.tags, dietaryTags: recipes.dietaryTags }).from(recipes).where(inArray(recipes.id, likedIds))
+ : [];
+
+ const preferences = buildPreferenceMap(likedRecipes);
+
+ const excludeIds = likedIds.length > 0 ? likedIds : ["__none__"];
+
+ const candidates = await db
+ .select({
+ id: recipes.id,
+ title: recipes.title,
+ description: recipes.description,
+ baseServings: recipes.baseServings,
+ prepMins: recipes.prepMins,
+ cookMins: recipes.cookMins,
+ difficulty: recipes.difficulty,
+ visibility: recipes.visibility,
+ aiGenerated: recipes.aiGenerated,
+ createdAt: recipes.createdAt,
+ authorId: recipes.authorId,
+ authorName: users.name,
+ authorUsername: users.username,
+ authorAvatarUrl: users.avatarUrl,
+ tags: recipes.tags,
+ dietaryTags: recipes.dietaryTags,
+ })
+ .from(recipes)
+ .innerJoin(users, eq(recipes.authorId, users.id))
+ .where(and(
+ eq(recipes.visibility, "public"),
+ ne(recipes.authorId, userId),
+ notInArray(recipes.id, excludeIds)
+ ))
+ .orderBy(desc(recipes.createdAt))
+ .limit(200); // score a bounded recent window rather than the whole table
+
+ const ranked = preferences.size > 0
+ ? rankForYou(candidates, preferences)
+ : [...candidates].sort((a, b) => b.createdAt.getTime() - a.createdAt.getTime());
+
+ const data = ranked.slice(0, limit).map(({ tags: _tags, dietaryTags: _dietaryTags, ...r }) => ({
+ ...r,
+ createdAt: r.createdAt.toISOString(),
+ }));
+
+ return NextResponse.json({ data });
+}
diff --git a/apps/web/app/api/v1/meal-plans/[weekStart]/members/__tests__/route.test.ts b/apps/web/app/api/v1/meal-plans/[weekStart]/members/__tests__/route.test.ts
new file mode 100644
index 0000000..7d8bf80
--- /dev/null
+++ b/apps/web/app/api/v1/meal-plans/[weekStart]/members/__tests__/route.test.ts
@@ -0,0 +1,137 @@
+import { describe, it, expect, vi, beforeEach } from "vitest";
+import { NextRequest } from "next/server";
+
+const mockSession = { user: { id: "user-1" } };
+
+vi.mock("@/lib/api-auth", () => ({
+ requireSession: vi.fn(),
+}));
+
+const { mockPlanFindFirst, mockMemberFindFirst, mockMemberFindMany, mockUserFindFirst, mockInsertValues, mockInsertPlanValues, mockDeleteWhere } = vi.hoisted(() => ({
+ mockPlanFindFirst: vi.fn(),
+ mockMemberFindFirst: vi.fn(),
+ mockMemberFindMany: vi.fn(),
+ mockUserFindFirst: vi.fn(),
+ mockInsertValues: vi.fn().mockResolvedValue(undefined),
+ mockInsertPlanValues: vi.fn().mockResolvedValue(undefined),
+ mockDeleteWhere: vi.fn().mockResolvedValue(undefined),
+}));
+
+vi.mock("@epicure/db", () => ({
+ db: {
+ query: {
+ mealPlans: { findFirst: mockPlanFindFirst },
+ mealPlanMembers: { findFirst: mockMemberFindFirst, findMany: mockMemberFindMany },
+ users: { findFirst: mockUserFindFirst },
+ },
+ insert: vi.fn(() => ({ values: mockInsertValues })),
+ delete: vi.fn(() => ({ where: mockDeleteWhere })),
+ },
+ mealPlans: { id: "id", userId: "user_id", weekStart: "week_start" },
+ mealPlanMembers: { id: "id", mealPlanId: "meal_plan_id", userId: "user_id" },
+ users: { id: "id", email: "email" },
+ eq: vi.fn((a, b) => ({ a, b, op: "eq" })),
+ and: vi.fn((...args) => ({ args, op: "and" })),
+}));
+
+const { requireSession } = await import("@/lib/api-auth");
+import { GET, POST, DELETE } from "../route";
+
+const ctx = { params: Promise.resolve({ weekStart: "2026-06-01" }) };
+
+function makeRequest(method: string, body?: unknown, search = "") {
+ return new NextRequest(`http://localhost/api/v1/meal-plans/2026-06-01/members${search}`, {
+ method,
+ headers: { "Content-Type": "application/json" },
+ body: body ? JSON.stringify(body) : undefined,
+ });
+}
+
+beforeEach(() => {
+ vi.clearAllMocks();
+ vi.mocked(requireSession).mockResolvedValue({ session: mockSession as never, response: null });
+});
+
+describe("GET /api/v1/meal-plans/[weekStart]/members", () => {
+ it("returns an empty list when the owner has no plan for this week yet", async () => {
+ mockPlanFindFirst.mockResolvedValue(undefined);
+ const res = await GET(makeRequest("GET"), ctx);
+ expect(res.status).toBe(200);
+ expect(await res.json()).toEqual([]);
+ });
+
+ it("returns members for an existing plan", async () => {
+ mockPlanFindFirst.mockResolvedValue({ id: "plan-1", userId: "user-1" });
+ mockMemberFindMany.mockResolvedValue([
+ { id: "m1", userId: "user-2", role: "editor", createdAt: new Date(), user: { name: "Bob", username: null, avatarUrl: null } },
+ ]);
+ const res = await GET(makeRequest("GET"), ctx);
+ const body = await res.json() as unknown[];
+ expect(body).toHaveLength(1);
+ });
+});
+
+describe("POST /api/v1/meal-plans/[weekStart]/members", () => {
+ it("returns 400 on invalid body", async () => {
+ const res = await POST(makeRequest("POST", { role: "viewer" }), ctx);
+ expect(res.status).toBe(400);
+ });
+
+ it("returns 404 when the target user doesn't exist", async () => {
+ mockUserFindFirst.mockResolvedValue(undefined);
+ const res = await POST(makeRequest("POST", { email: "b@test.com", role: "viewer" }), ctx);
+ expect(res.status).toBe(404);
+ });
+
+ it("returns 400 when inviting yourself", async () => {
+ mockUserFindFirst.mockResolvedValue({ id: "user-1" });
+ const res = await POST(makeRequest("POST", { email: "a@test.com", role: "viewer" }), ctx);
+ expect(res.status).toBe(400);
+ });
+
+ it("auto-creates the plan for the week and invites the member", async () => {
+ mockUserFindFirst.mockResolvedValue({ id: "user-2" });
+ mockPlanFindFirst.mockResolvedValue(undefined); // no plan yet for this week
+ mockMemberFindFirst.mockResolvedValue(undefined);
+ const res = await POST(makeRequest("POST", { email: "b@test.com", role: "editor" }), ctx);
+ expect(res.status).toBe(201);
+ expect(mockInsertValues).toHaveBeenCalledWith(expect.objectContaining({ userId: "user-1", weekStart: "2026-06-01" }));
+ expect(mockInsertValues).toHaveBeenCalledWith(expect.objectContaining({ userId: "user-2", role: "editor" }));
+ });
+
+ it("returns 409 when already a member", async () => {
+ mockUserFindFirst.mockResolvedValue({ id: "user-2" });
+ mockPlanFindFirst.mockResolvedValue({ id: "plan-1", userId: "user-1", weekStart: "2026-06-01" });
+ mockMemberFindFirst.mockResolvedValue({ id: "existing" });
+ const res = await POST(makeRequest("POST", { email: "b@test.com", role: "viewer" }), ctx);
+ expect(res.status).toBe(409);
+ });
+});
+
+describe("DELETE /api/v1/meal-plans/[weekStart]/members", () => {
+ it("returns 400 when memberId is missing", async () => {
+ const res = await DELETE(makeRequest("DELETE"), ctx);
+ expect(res.status).toBe(400);
+ });
+
+ it("returns 404 when the owner has no plan for this week", async () => {
+ mockPlanFindFirst.mockResolvedValue(undefined);
+ const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
+ expect(res.status).toBe(404);
+ });
+
+ it("returns 403 when caller is neither owner nor the member themselves", async () => {
+ mockPlanFindFirst.mockResolvedValue({ id: "plan-1", userId: "user-1" });
+ mockMemberFindFirst.mockResolvedValue({ id: "m1", userId: "user-2" });
+ vi.mocked(requireSession).mockResolvedValue({ session: { user: { id: "user-3" } } as never, response: null });
+ const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
+ expect(res.status).toBe(403);
+ });
+
+ it("allows the owner to remove a member", async () => {
+ mockPlanFindFirst.mockResolvedValue({ id: "plan-1", userId: "user-1" });
+ mockMemberFindFirst.mockResolvedValue({ id: "m1", userId: "user-2" });
+ const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
+ expect(res.status).toBe(204);
+ });
+});
diff --git a/apps/web/app/api/v1/meal-plans/[weekStart]/members/route.ts b/apps/web/app/api/v1/meal-plans/[weekStart]/members/route.ts
new file mode 100644
index 0000000..4a638fa
--- /dev/null
+++ b/apps/web/app/api/v1/meal-plans/[weekStart]/members/route.ts
@@ -0,0 +1,122 @@
+import { NextRequest, NextResponse } from "next/server";
+import { z } from "zod";
+import { db, mealPlans, mealPlanMembers, users, eq, and } from "@epicure/db";
+import { requireSession } from "@/lib/api-auth";
+
+type Params = { params: Promise<{ weekStart: string }> };
+
+async function getOrCreatePlan(userId: string, weekStart: string) {
+ const existing = await db.query.mealPlans.findFirst({
+ where: and(eq(mealPlans.userId, userId), eq(mealPlans.weekStart, weekStart)),
+ });
+ if (existing) return existing;
+
+ const id = crypto.randomUUID();
+ await db.insert(mealPlans).values({ id, userId, weekStart });
+ return { id, userId, weekStart, createdAt: new Date() };
+}
+
+// ─── GET /api/v1/meal-plans/[weekStart]/members ──────────────────────────────
+// Owner only — returns members joined with basic user info.
+export async function GET(_req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+ const { weekStart } = await params;
+
+ const plan = await db.query.mealPlans.findFirst({
+ where: and(eq(mealPlans.userId, session!.user.id), eq(mealPlans.weekStart, weekStart)),
+ });
+ if (!plan) return NextResponse.json([]);
+
+ const members = await db.query.mealPlanMembers.findMany({
+ where: eq(mealPlanMembers.mealPlanId, plan.id),
+ with: { user: true },
+ });
+
+ return NextResponse.json(
+ members.map((m) => ({
+ id: m.id,
+ userId: m.userId,
+ role: m.role,
+ createdAt: m.createdAt,
+ user: { name: m.user.name, username: m.user.username, avatarUrl: m.user.avatarUrl },
+ }))
+ );
+}
+
+// ─── POST /api/v1/meal-plans/[weekStart]/members ─────────────────────────────
+// Owner only — invite by email or userId. Auto-creates the plan for this week if missing.
+const InviteSchema = z
+ .object({
+ email: z.string().email().optional(),
+ userId: z.string().optional(),
+ role: z.enum(["viewer", "editor"]),
+ })
+ .refine((d) => d.email !== undefined || d.userId !== undefined, {
+ message: "Provide either email or userId",
+ });
+
+export async function POST(req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+ const { weekStart } = await params;
+
+ const body = await req.json() as unknown;
+ const parsed = InviteSchema.safeParse(body);
+ if (!parsed.success) return NextResponse.json({ error: "Validation error" }, { status: 400 });
+
+ const { email, userId, role } = parsed.data;
+
+ const targetUser = await db.query.users.findFirst({
+ where: email ? eq(users.email, email) : eq(users.id, userId!),
+ });
+ if (!targetUser) return NextResponse.json({ error: "User not found" }, { status: 404 });
+
+ if (targetUser.id === session!.user.id) {
+ return NextResponse.json({ error: "Cannot invite yourself" }, { status: 400 });
+ }
+
+ const plan = await getOrCreatePlan(session!.user.id, weekStart);
+
+ const existing = await db.query.mealPlanMembers.findFirst({
+ where: and(eq(mealPlanMembers.mealPlanId, plan.id), eq(mealPlanMembers.userId, targetUser.id)),
+ });
+ if (existing) return NextResponse.json({ error: "Already a member" }, { status: 409 });
+
+ const memberId = crypto.randomUUID();
+ await db.insert(mealPlanMembers).values({
+ id: memberId,
+ mealPlanId: plan.id,
+ userId: targetUser.id,
+ role,
+ });
+
+ return NextResponse.json({ id: memberId, mealPlanId: plan.id }, { status: 201 });
+}
+
+// ─── DELETE /api/v1/meal-plans/[weekStart]/members?memberId=… ────────────────
+// Owner OR the member themselves can remove.
+export async function DELETE(req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+ const { weekStart } = await params;
+ const memberId = req.nextUrl.searchParams.get("memberId");
+ if (!memberId) return NextResponse.json({ error: "memberId required" }, { status: 400 });
+
+ const plan = await db.query.mealPlans.findFirst({
+ where: and(eq(mealPlans.userId, session!.user.id), eq(mealPlans.weekStart, weekStart)),
+ });
+ if (!plan) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const member = await db.query.mealPlanMembers.findFirst({
+ where: and(eq(mealPlanMembers.id, memberId), eq(mealPlanMembers.mealPlanId, plan.id)),
+ });
+ if (!member) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const isOwner = plan.userId === session!.user.id;
+ const isSelf = member.userId === session!.user.id;
+ if (!isOwner && !isSelf) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
+
+ await db.delete(mealPlanMembers).where(eq(mealPlanMembers.id, memberId));
+ return new NextResponse(null, { status: 204 });
+}
diff --git a/apps/web/app/api/v1/meal-plans/shared/[mealPlanId]/entries/__tests__/route.test.ts b/apps/web/app/api/v1/meal-plans/shared/[mealPlanId]/entries/__tests__/route.test.ts
new file mode 100644
index 0000000..a084bb4
--- /dev/null
+++ b/apps/web/app/api/v1/meal-plans/shared/[mealPlanId]/entries/__tests__/route.test.ts
@@ -0,0 +1,104 @@
+import { describe, it, expect, vi, beforeEach } from "vitest";
+import { NextRequest } from "next/server";
+
+const mockSession = { user: { id: "user-2" } };
+
+vi.mock("@/lib/api-auth", () => ({
+ requireSession: vi.fn(),
+}));
+
+vi.mock("@/lib/webhooks", () => ({
+ dispatchWebhook: vi.fn(),
+}));
+
+const { mockPlanFindFirst, mockMemberFindFirst, mockRecipeFindFirst, mockInsertValues, mockDeleteWhere } = vi.hoisted(() => ({
+ mockPlanFindFirst: vi.fn(),
+ mockMemberFindFirst: vi.fn(),
+ mockRecipeFindFirst: vi.fn(),
+ mockInsertValues: vi.fn().mockResolvedValue(undefined),
+ mockDeleteWhere: vi.fn().mockResolvedValue(undefined),
+}));
+
+vi.mock("@epicure/db", () => ({
+ db: {
+ query: {
+ mealPlans: { findFirst: mockPlanFindFirst },
+ mealPlanMembers: { findFirst: mockMemberFindFirst },
+ recipes: { findFirst: mockRecipeFindFirst },
+ },
+ insert: vi.fn(() => ({ values: mockInsertValues })),
+ delete: vi.fn(() => ({ where: mockDeleteWhere })),
+ },
+ mealPlans: { id: "id", userId: "user_id" },
+ mealPlanMembers: { mealPlanId: "meal_plan_id", userId: "user_id" },
+ mealPlanEntries: { id: "id", mealPlanId: "meal_plan_id", day: "day", mealType: "meal_type" },
+ recipes: { id: "id", authorId: "author_id", visibility: "visibility" },
+ eq: vi.fn((a, b) => ({ a, b, op: "eq" })),
+ and: vi.fn((...args) => ({ args, op: "and" })),
+ or: vi.fn((...args) => ({ args, op: "or" })),
+ ne: vi.fn((a, b) => ({ a, b, op: "ne" })),
+}));
+
+const { requireSession } = await import("@/lib/api-auth");
+import { POST, DELETE } from "../route";
+
+const ctx = { params: Promise.resolve({ mealPlanId: "plan-1" }) };
+
+function makeRequest(method: string, body?: unknown, search = "") {
+ return new NextRequest(`http://localhost/api/v1/meal-plans/shared/plan-1/entries${search}`, {
+ method,
+ headers: { "Content-Type": "application/json" },
+ body: body ? JSON.stringify(body) : undefined,
+ });
+}
+
+beforeEach(() => {
+ vi.clearAllMocks();
+ vi.mocked(requireSession).mockResolvedValue({ session: mockSession as never, response: null });
+ mockPlanFindFirst.mockResolvedValue({ id: "plan-1", userId: "user-1" });
+});
+
+const validBody = { day: "mon", mealType: "dinner", recipeId: "r-1", servings: 2 };
+
+describe("POST /api/v1/meal-plans/shared/[mealPlanId]/entries", () => {
+ it("returns 404 when the caller has no access to the plan", async () => {
+ mockMemberFindFirst.mockResolvedValue(undefined);
+ const res = await POST(makeRequest("POST", validBody), ctx);
+ expect(res.status).toBe(404);
+ });
+
+ it("returns 403 for a viewer trying to add an entry", async () => {
+ mockMemberFindFirst.mockResolvedValue({ role: "viewer" });
+ const res = await POST(makeRequest("POST", validBody), ctx);
+ expect(res.status).toBe(403);
+ });
+
+ it("allows an editor to add an entry", async () => {
+ mockMemberFindFirst.mockResolvedValue({ role: "editor" });
+ mockRecipeFindFirst.mockResolvedValue({ id: "r-1" });
+ const res = await POST(makeRequest("POST", validBody), ctx);
+ expect(res.status).toBe(201);
+ expect(mockInsertValues).toHaveBeenCalledWith(expect.objectContaining({ mealPlanId: "plan-1", day: "mon" }));
+ });
+
+ it("returns 404 when the recipe isn't accessible to the editor", async () => {
+ mockMemberFindFirst.mockResolvedValue({ role: "editor" });
+ mockRecipeFindFirst.mockResolvedValue(undefined);
+ const res = await POST(makeRequest("POST", validBody), ctx);
+ expect(res.status).toBe(404);
+ });
+});
+
+describe("DELETE /api/v1/meal-plans/shared/[mealPlanId]/entries", () => {
+ it("returns 403 for a viewer trying to remove an entry", async () => {
+ mockMemberFindFirst.mockResolvedValue({ role: "viewer" });
+ const res = await DELETE(makeRequest("DELETE", undefined, "?entryId=e1"), ctx);
+ expect(res.status).toBe(403);
+ });
+
+ it("allows an editor to remove an entry", async () => {
+ mockMemberFindFirst.mockResolvedValue({ role: "editor" });
+ const res = await DELETE(makeRequest("DELETE", undefined, "?entryId=e1"), ctx);
+ expect(res.status).toBe(204);
+ });
+});
diff --git a/apps/web/app/api/v1/meal-plans/shared/[mealPlanId]/entries/route.ts b/apps/web/app/api/v1/meal-plans/shared/[mealPlanId]/entries/route.ts
new file mode 100644
index 0000000..9318ba4
--- /dev/null
+++ b/apps/web/app/api/v1/meal-plans/shared/[mealPlanId]/entries/route.ts
@@ -0,0 +1,81 @@
+import { NextRequest, NextResponse } from "next/server";
+import { z } from "zod";
+import { db, mealPlanEntries, recipes, eq, and, or, ne } from "@epicure/db";
+import { requireSession } from "@/lib/api-auth";
+import { getMealPlanAccessById, canWriteMealPlan } from "@/lib/meal-plan-access";
+import { dispatchWebhook } from "@/lib/webhooks";
+
+type Params = { params: Promise<{ mealPlanId: string }> };
+
+const Schema = z.object({
+ day: z.enum(["mon", "tue", "wed", "thu", "fri", "sat", "sun"]),
+ mealType: z.enum(["breakfast", "lunch", "dinner", "snack"]),
+ recipeId: z.string().optional(),
+ servings: z.number().int().min(1).max(100).default(2),
+ note: z.string().max(500).optional(),
+});
+
+export async function POST(req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+ const { mealPlanId } = await params;
+
+ const access = await getMealPlanAccessById(mealPlanId, session!.user.id);
+ if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
+ if (!canWriteMealPlan(access.role)) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
+
+ const body = await req.json() as unknown;
+ const parsed = Schema.safeParse(body);
+ if (!parsed.success) return NextResponse.json({ error: "Validation error" }, { status: 400 });
+
+ if (parsed.data.recipeId) {
+ const recipe = await db.query.recipes.findFirst({
+ where: and(
+ eq(recipes.id, parsed.data.recipeId),
+ or(eq(recipes.authorId, session!.user.id), ne(recipes.visibility, "private"))
+ ),
+ });
+ if (!recipe) return NextResponse.json({ error: "Recipe not found" }, { status: 404 });
+ }
+
+ await db.delete(mealPlanEntries).where(
+ and(
+ eq(mealPlanEntries.mealPlanId, mealPlanId),
+ eq(mealPlanEntries.day, parsed.data.day),
+ eq(mealPlanEntries.mealType, parsed.data.mealType)
+ )
+ );
+
+ const entryId = crypto.randomUUID();
+ await db.insert(mealPlanEntries).values({
+ id: entryId,
+ mealPlanId,
+ day: parsed.data.day,
+ mealType: parsed.data.mealType,
+ recipeId: parsed.data.recipeId,
+ servings: parsed.data.servings,
+ note: parsed.data.note,
+ });
+
+ void dispatchWebhook(access.plan.userId, "meal_plan.updated", { mealPlanId, day: parsed.data.day, mealType: parsed.data.mealType });
+ return NextResponse.json({ id: entryId }, { status: 201 });
+}
+
+export async function DELETE(req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+ const { mealPlanId } = await params;
+
+ const access = await getMealPlanAccessById(mealPlanId, session!.user.id);
+ if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
+ if (!canWriteMealPlan(access.role)) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
+
+ const entryId = req.nextUrl.searchParams.get("entryId");
+ if (!entryId) return NextResponse.json({ error: "entryId required" }, { status: 400 });
+
+ await db.delete(mealPlanEntries).where(
+ and(eq(mealPlanEntries.id, entryId), eq(mealPlanEntries.mealPlanId, mealPlanId))
+ );
+
+ return new NextResponse(null, { status: 204 });
+}
diff --git a/apps/web/app/api/v1/meal-plans/shared/[mealPlanId]/route.ts b/apps/web/app/api/v1/meal-plans/shared/[mealPlanId]/route.ts
new file mode 100644
index 0000000..f211f47
--- /dev/null
+++ b/apps/web/app/api/v1/meal-plans/shared/[mealPlanId]/route.ts
@@ -0,0 +1,27 @@
+import { NextRequest, NextResponse } from "next/server";
+import { db, mealPlans, users, eq } from "@epicure/db";
+import { requireSession } from "@/lib/api-auth";
+import { getMealPlanAccessById } from "@/lib/meal-plan-access";
+
+type Params = { params: Promise<{ mealPlanId: string }> };
+
+export async function GET(_req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+ const { mealPlanId } = await params;
+
+ const access = await getMealPlanAccessById(mealPlanId, session!.user.id);
+ if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const plan = await db.query.mealPlans.findFirst({
+ where: eq(mealPlans.id, mealPlanId),
+ with: {
+ entries: { with: { recipe: { with: { photos: true } } } },
+ },
+ });
+ if (!plan) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const owner = await db.query.users.findFirst({ where: eq(users.id, plan.userId) });
+
+ return NextResponse.json({ ...plan, role: access.role, owner: owner ? { name: owner.name } : null });
+}
diff --git a/apps/web/app/api/v1/shopping-lists/[id]/export/instacart/route.ts b/apps/web/app/api/v1/shopping-lists/[id]/export/instacart/route.ts
new file mode 100644
index 0000000..49116d3
--- /dev/null
+++ b/apps/web/app/api/v1/shopping-lists/[id]/export/instacart/route.ts
@@ -0,0 +1,33 @@
+import { NextRequest, NextResponse } from "next/server";
+import { db, shoppingLists, eq } from "@epicure/db";
+import { requireSession } from "@/lib/api-auth";
+import { getShoppingListAccess } from "@/lib/shopping-list-access";
+import { buildGroceryExportPayload } from "@/lib/grocery-export";
+import { createInstacartShoppingListLink } from "@/lib/grocery-providers/instacart";
+
+type Params = { params: Promise<{ id: string }> };
+
+export async function POST(_req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+ const { id } = await params;
+
+ const access = await getShoppingListAccess(id, session!.user.id);
+ if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const list = await db.query.shoppingLists.findFirst({
+ where: eq(shoppingLists.id, id),
+ with: { items: true },
+ });
+ if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const payload = buildGroceryExportPayload(list);
+
+ try {
+ const result = await createInstacartShoppingListLink(payload);
+ if (!result) return NextResponse.json({ error: "Instacart is not configured" }, { status: 501 });
+ return NextResponse.json(result);
+ } catch (err) {
+ return NextResponse.json({ error: String(err instanceof Error ? err.message : err) }, { status: 501 });
+ }
+}
diff --git a/apps/web/app/api/v1/shopping-lists/[id]/export/route.ts b/apps/web/app/api/v1/shopping-lists/[id]/export/route.ts
new file mode 100644
index 0000000..1245ebf
--- /dev/null
+++ b/apps/web/app/api/v1/shopping-lists/[id]/export/route.ts
@@ -0,0 +1,25 @@
+import { NextRequest, NextResponse } from "next/server";
+import { db, shoppingLists, eq } from "@epicure/db";
+import { requireSession } from "@/lib/api-auth";
+import { getShoppingListAccess } from "@/lib/shopping-list-access";
+import { buildGroceryExportPayload } from "@/lib/grocery-export";
+
+type Params = { params: Promise<{ id: string }> };
+
+export async function GET(_req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+ const { id } = await params;
+
+ const access = await getShoppingListAccess(id, session!.user.id);
+ if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const list = await db.query.shoppingLists.findFirst({
+ where: eq(shoppingLists.id, id),
+ with: { items: true },
+ });
+ if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const payload = buildGroceryExportPayload(list);
+ return NextResponse.json(payload);
+}
diff --git a/apps/web/app/api/v1/shopping-lists/[id]/items/[itemId]/route.ts b/apps/web/app/api/v1/shopping-lists/[id]/items/[itemId]/route.ts
index 95157a9..b092c77 100644
--- a/apps/web/app/api/v1/shopping-lists/[id]/items/[itemId]/route.ts
+++ b/apps/web/app/api/v1/shopping-lists/[id]/items/[itemId]/route.ts
@@ -1,6 +1,7 @@
import { NextRequest, NextResponse } from "next/server";
-import { db, shoppingLists, shoppingListItems, eq, and } from "@epicure/db";
+import { db, shoppingListItems, eq, and } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
+import { getShoppingListAccess, canWriteShoppingList } from "@/lib/shopping-list-access";
type Params = { params: Promise<{ id: string; itemId: string }> };
@@ -9,10 +10,9 @@ export async function PUT(req: NextRequest, { params }: Params) {
if (response) return response;
const { id, itemId } = await params;
- const list = await db.query.shoppingLists.findFirst({
- where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
- });
- if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
+ const access = await getShoppingListAccess(id, session!.user.id);
+ if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
+ if (!canWriteShoppingList(access.role)) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
const body = await req.json() as { checked?: boolean };
await db.update(shoppingListItems)
diff --git a/apps/web/app/api/v1/shopping-lists/[id]/items/route.ts b/apps/web/app/api/v1/shopping-lists/[id]/items/route.ts
index 80e0119..75626e0 100644
--- a/apps/web/app/api/v1/shopping-lists/[id]/items/route.ts
+++ b/apps/web/app/api/v1/shopping-lists/[id]/items/route.ts
@@ -1,7 +1,8 @@
import { NextRequest, NextResponse } from "next/server";
import { z } from "zod";
-import { db, shoppingLists, shoppingListItems, eq, and } from "@epicure/db";
+import { db, shoppingListItems } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
+import { getShoppingListAccess, canWriteShoppingList } from "@/lib/shopping-list-access";
const AddItemsSchema = z.object({
items: z.array(z.object({
@@ -19,10 +20,9 @@ export async function POST(req: NextRequest, { params }: Params) {
if (response) return response;
const { id } = await params;
- const list = await db.query.shoppingLists.findFirst({
- where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
- });
- if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
+ const access = await getShoppingListAccess(id, session!.user.id);
+ if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
+ if (!canWriteShoppingList(access.role)) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
const body = await req.json() as unknown;
const parsed = AddItemsSchema.safeParse(body);
diff --git a/apps/web/app/api/v1/shopping-lists/[id]/members/__tests__/route.test.ts b/apps/web/app/api/v1/shopping-lists/[id]/members/__tests__/route.test.ts
new file mode 100644
index 0000000..c79b789
--- /dev/null
+++ b/apps/web/app/api/v1/shopping-lists/[id]/members/__tests__/route.test.ts
@@ -0,0 +1,149 @@
+import { describe, it, expect, vi, beforeEach } from "vitest";
+import { NextRequest } from "next/server";
+
+const mockSession = { user: { id: "user-1" } };
+
+vi.mock("@/lib/api-auth", () => ({
+ requireSession: vi.fn(),
+}));
+
+const { mockListFindFirst, mockMemberFindFirst, mockMemberFindMany, mockUserFindFirst, mockInsertValues, mockDeleteWhere } = vi.hoisted(() => ({
+ mockListFindFirst: vi.fn(),
+ mockMemberFindFirst: vi.fn(),
+ mockMemberFindMany: vi.fn(),
+ mockUserFindFirst: vi.fn(),
+ mockInsertValues: vi.fn().mockResolvedValue(undefined),
+ mockDeleteWhere: vi.fn().mockResolvedValue(undefined),
+}));
+
+vi.mock("@epicure/db", () => ({
+ db: {
+ query: {
+ shoppingLists: { findFirst: mockListFindFirst },
+ shoppingListMembers: { findFirst: mockMemberFindFirst, findMany: mockMemberFindMany },
+ users: { findFirst: mockUserFindFirst },
+ },
+ insert: vi.fn(() => ({ values: mockInsertValues })),
+ delete: vi.fn(() => ({ where: mockDeleteWhere })),
+ },
+ shoppingLists: { id: "id", userId: "user_id" },
+ shoppingListMembers: { id: "id", listId: "list_id", userId: "user_id" },
+ users: { id: "id", email: "email" },
+ eq: vi.fn((a, b) => ({ a, b, op: "eq" })),
+ and: vi.fn((...args) => ({ args, op: "and" })),
+}));
+
+const { requireSession } = await import("@/lib/api-auth");
+import { GET, POST, DELETE } from "../route";
+
+const ctx = { params: Promise.resolve({ id: "list-1" }) };
+
+function makeRequest(method: string, body?: unknown, search = "") {
+ return new NextRequest(`http://localhost/api/v1/shopping-lists/list-1/members${search}`, {
+ method,
+ headers: { "Content-Type": "application/json" },
+ body: body ? JSON.stringify(body) : undefined,
+ });
+}
+
+beforeEach(() => {
+ vi.clearAllMocks();
+ vi.mocked(requireSession).mockResolvedValue({ session: mockSession as never, response: null });
+});
+
+describe("GET /api/v1/shopping-lists/[id]/members", () => {
+ it("returns 404 when the caller is not the owner", async () => {
+ mockListFindFirst.mockResolvedValue(undefined);
+ const res = await GET(makeRequest("GET"), ctx);
+ expect(res.status).toBe(404);
+ });
+
+ it("returns the member list for the owner", async () => {
+ mockListFindFirst.mockResolvedValue({ id: "list-1", userId: "user-1" });
+ mockMemberFindMany.mockResolvedValue([
+ { id: "m1", userId: "user-2", role: "viewer", createdAt: new Date(), user: { name: "Bob", username: "bob", avatarUrl: null } },
+ ]);
+ const res = await GET(makeRequest("GET"), ctx);
+ expect(res.status).toBe(200);
+ const body = await res.json() as unknown[];
+ expect(body).toHaveLength(1);
+ });
+});
+
+describe("POST /api/v1/shopping-lists/[id]/members", () => {
+ beforeEach(() => {
+ mockListFindFirst.mockResolvedValue({ id: "list-1", userId: "user-1" });
+ });
+
+ it("returns 404 when the caller is not the owner", async () => {
+ mockListFindFirst.mockResolvedValue(undefined);
+ const res = await POST(makeRequest("POST", { email: "b@test.com", role: "viewer" }), ctx);
+ expect(res.status).toBe(404);
+ });
+
+ it("returns 400 on invalid body", async () => {
+ const res = await POST(makeRequest("POST", { role: "viewer" }), ctx);
+ expect(res.status).toBe(400);
+ });
+
+ it("returns 404 when the target user doesn't exist", async () => {
+ mockUserFindFirst.mockResolvedValue(undefined);
+ const res = await POST(makeRequest("POST", { email: "b@test.com", role: "viewer" }), ctx);
+ expect(res.status).toBe(404);
+ });
+
+ it("returns 400 when inviting yourself", async () => {
+ mockUserFindFirst.mockResolvedValue({ id: "user-1", email: "a@test.com" });
+ const res = await POST(makeRequest("POST", { email: "a@test.com", role: "viewer" }), ctx);
+ expect(res.status).toBe(400);
+ });
+
+ it("returns 409 when already a member", async () => {
+ mockUserFindFirst.mockResolvedValue({ id: "user-2", email: "b@test.com" });
+ mockMemberFindFirst.mockResolvedValue({ id: "existing" });
+ const res = await POST(makeRequest("POST", { email: "b@test.com", role: "viewer" }), ctx);
+ expect(res.status).toBe(409);
+ });
+
+ it("creates the membership on success", async () => {
+ mockUserFindFirst.mockResolvedValue({ id: "user-2", email: "b@test.com" });
+ mockMemberFindFirst.mockResolvedValue(undefined);
+ const res = await POST(makeRequest("POST", { email: "b@test.com", role: "editor" }), ctx);
+ expect(res.status).toBe(201);
+ expect(mockInsertValues).toHaveBeenCalledWith(expect.objectContaining({ listId: "list-1", userId: "user-2", role: "editor" }));
+ });
+});
+
+describe("DELETE /api/v1/shopping-lists/[id]/members", () => {
+ it("returns 400 when memberId is missing", async () => {
+ const res = await DELETE(makeRequest("DELETE"), ctx);
+ expect(res.status).toBe(400);
+ });
+
+ it("returns 404 when the member doesn't exist", async () => {
+ mockMemberFindFirst.mockResolvedValue(undefined);
+ const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
+ expect(res.status).toBe(404);
+ });
+
+ it("returns 403 when caller is neither owner nor the member themselves", async () => {
+ mockMemberFindFirst.mockResolvedValue({ id: "m1", userId: "user-2" });
+ mockListFindFirst.mockResolvedValue({ id: "list-1", userId: "user-3" });
+ const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
+ expect(res.status).toBe(403);
+ });
+
+ it("allows the owner to remove a member", async () => {
+ mockMemberFindFirst.mockResolvedValue({ id: "m1", userId: "user-2" });
+ mockListFindFirst.mockResolvedValue({ id: "list-1", userId: "user-1" });
+ const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
+ expect(res.status).toBe(204);
+ });
+
+ it("allows a member to remove themselves", async () => {
+ mockMemberFindFirst.mockResolvedValue({ id: "m1", userId: "user-1" });
+ mockListFindFirst.mockResolvedValue({ id: "list-1", userId: "user-3" });
+ const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
+ expect(res.status).toBe(204);
+ });
+});
diff --git a/apps/web/app/api/v1/shopping-lists/[id]/members/route.ts b/apps/web/app/api/v1/shopping-lists/[id]/members/route.ts
new file mode 100644
index 0000000..d7b7319
--- /dev/null
+++ b/apps/web/app/api/v1/shopping-lists/[id]/members/route.ts
@@ -0,0 +1,127 @@
+import { NextRequest, NextResponse } from "next/server";
+import { z } from "zod";
+import { db, shoppingLists, shoppingListMembers, users, eq, and } from "@epicure/db";
+import { requireSession } from "@/lib/api-auth";
+
+type Params = { params: Promise<{ id: string }> };
+
+// ─── GET /api/v1/shopping-lists/[id]/members ─────────────────────────────────
+// Owner only — returns members joined with basic user info.
+export async function GET(_req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+
+ const { id } = await params;
+
+ const list = await db.query.shoppingLists.findFirst({
+ where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
+ });
+ if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const members = await db.query.shoppingListMembers.findMany({
+ where: eq(shoppingListMembers.listId, id),
+ with: { user: true },
+ });
+
+ const result = members.map((m) => ({
+ id: m.id,
+ userId: m.userId,
+ role: m.role,
+ createdAt: m.createdAt,
+ user: {
+ name: m.user.name,
+ username: m.user.username,
+ avatarUrl: m.user.avatarUrl,
+ },
+ }));
+
+ return NextResponse.json(result);
+}
+
+// ─── POST /api/v1/shopping-lists/[id]/members ────────────────────────────────
+// Owner only — invite by email or userId.
+const InviteSchema = z
+ .object({
+ email: z.string().email().optional(),
+ userId: z.string().optional(),
+ role: z.enum(["viewer", "editor"]),
+ })
+ .refine((d) => d.email !== undefined || d.userId !== undefined, {
+ message: "Provide either email or userId",
+ });
+
+export async function POST(req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+
+ const { id } = await params;
+
+ const list = await db.query.shoppingLists.findFirst({
+ where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
+ });
+ if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const body = await req.json() as unknown;
+ const parsed = InviteSchema.safeParse(body);
+ if (!parsed.success) return NextResponse.json({ error: "Validation error" }, { status: 400 });
+
+ const { email, userId, role } = parsed.data;
+
+ const targetUser = await db.query.users.findFirst({
+ where: email ? eq(users.email, email) : eq(users.id, userId!),
+ });
+ if (!targetUser) return NextResponse.json({ error: "User not found" }, { status: 404 });
+
+ if (targetUser.id === session!.user.id) {
+ return NextResponse.json({ error: "Cannot invite yourself" }, { status: 400 });
+ }
+
+ const existing = await db.query.shoppingListMembers.findFirst({
+ where: and(
+ eq(shoppingListMembers.listId, id),
+ eq(shoppingListMembers.userId, targetUser.id),
+ ),
+ });
+ if (existing) return NextResponse.json({ error: "Already a member" }, { status: 409 });
+
+ const memberId = crypto.randomUUID();
+ await db.insert(shoppingListMembers).values({
+ id: memberId,
+ listId: id,
+ userId: targetUser.id,
+ role,
+ });
+
+ return NextResponse.json({ id: memberId }, { status: 201 });
+}
+
+// ─── DELETE /api/v1/shopping-lists/[id]/members?memberId=… ───────────────────
+// Owner OR the member themselves can remove.
+export async function DELETE(req: NextRequest, { params }: Params) {
+ const { session, response } = await requireSession();
+ if (response) return response;
+
+ const { id } = await params;
+ const memberId = req.nextUrl.searchParams.get("memberId");
+ if (!memberId) return NextResponse.json({ error: "memberId required" }, { status: 400 });
+
+ const member = await db.query.shoppingListMembers.findFirst({
+ where: and(eq(shoppingListMembers.id, memberId), eq(shoppingListMembers.listId, id)),
+ });
+ if (!member) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
+ const list = await db.query.shoppingLists.findFirst({
+ where: eq(shoppingLists.id, id),
+ });
+
+ const isOwner = list?.userId === session!.user.id;
+ const isSelf = member.userId === session!.user.id;
+
+ if (!isOwner && !isSelf) {
+ return NextResponse.json({ error: "Forbidden" }, { status: 403 });
+ }
+
+ await db.delete(shoppingListMembers).where(eq(shoppingListMembers.id, memberId));
+
+ return new NextResponse(null, { status: 204 });
+}
diff --git a/apps/web/app/api/v1/shopping-lists/[id]/route.ts b/apps/web/app/api/v1/shopping-lists/[id]/route.ts
index e643dbf..6455159 100644
--- a/apps/web/app/api/v1/shopping-lists/[id]/route.ts
+++ b/apps/web/app/api/v1/shopping-lists/[id]/route.ts
@@ -1,8 +1,9 @@
import { NextRequest, NextResponse } from "next/server";
import { z } from "zod";
-import { db, shoppingLists, shoppingListItems, eq, and } from "@epicure/db";
+import { db, shoppingLists, shoppingListItems, eq } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
import { dispatchWebhook } from "@/lib/webhooks";
+import { getShoppingListAccess, canWriteShoppingList } from "@/lib/shopping-list-access";
type Params = { params: Promise<{ id: string }> };
@@ -11,12 +12,14 @@ export async function GET(_req: NextRequest, { params }: Params) {
if (response) return response;
const { id } = await params;
+ const access = await getShoppingListAccess(id, session!.user.id);
+ if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
+
const list = await db.query.shoppingLists.findFirst({
- where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
+ where: eq(shoppingLists.id, id),
with: { items: { orderBy: (t, { asc }) => [asc(t.aisle), asc(t.rawName)] } },
});
- if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
return NextResponse.json(list);
}
@@ -27,10 +30,9 @@ export async function PATCH(req: NextRequest, { params }: Params) {
if (response) return response;
const { id } = await params;
- const list = await db.query.shoppingLists.findFirst({
- where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
- });
- if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
+ const access = await getShoppingListAccess(id, session!.user.id);
+ if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
+ if (!canWriteShoppingList(access.role)) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
const body = PatchSchema.safeParse(await req.json());
if (!body.success) return NextResponse.json({ error: "Validation error" }, { status: 400 });
@@ -38,7 +40,7 @@ export async function PATCH(req: NextRequest, { params }: Params) {
if (body.data.completed) {
// Mark all items as checked
await db.update(shoppingListItems).set({ checked: true }).where(eq(shoppingListItems.listId, id));
- void dispatchWebhook(session!.user.id, "shopping_list.completed", { id, name: list.name });
+ void dispatchWebhook(session!.user.id, "shopping_list.completed", { id, name: access.list.name });
}
return NextResponse.json({ updated: true });
@@ -49,6 +51,10 @@ export async function DELETE(_req: NextRequest, { params }: Params) {
if (response) return response;
const { id } = await params;
- await db.delete(shoppingLists).where(and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)));
+ const access = await getShoppingListAccess(id, session!.user.id);
+ if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
+ if (access.role !== "owner") return NextResponse.json({ error: "Forbidden" }, { status: 403 });
+
+ await db.delete(shoppingLists).where(eq(shoppingLists.id, id));
return new NextResponse(null, { status: 204 });
}
diff --git a/apps/web/app/layout.tsx b/apps/web/app/layout.tsx
index ff86d0f..fcdb168 100644
--- a/apps/web/app/layout.tsx
+++ b/apps/web/app/layout.tsx
@@ -1,4 +1,4 @@
-import type { Metadata } from "next";
+import type { Metadata, Viewport } from "next";
import { Lora, Geist_Mono } from "next/font/google";
import { headers } from "next/headers";
import { Providers } from "@/components/providers";
@@ -21,6 +21,11 @@ const geistMono = Geist_Mono({
export const metadata: Metadata = {
title: { default: "Epicure", template: "%s | Epicure" },
description: "Your personal AI-powered recipe book.",
+ manifest: "/manifest.json",
+};
+
+export const viewport: Viewport = {
+ themeColor: "#18181b",
};
export default async function RootLayout({
diff --git a/apps/web/app/print/collection/[id]/page.tsx b/apps/web/app/print/collection/[id]/page.tsx
new file mode 100644
index 0000000..d437ae2
--- /dev/null
+++ b/apps/web/app/print/collection/[id]/page.tsx
@@ -0,0 +1,148 @@
+import { notFound } from "next/navigation";
+import { headers } from "next/headers";
+import { auth } from "@/lib/auth/server";
+import { db, collections, eq, and, or } from "@epicure/db";
+import { PrintTrigger } from "@/components/recipe/print-trigger";
+import { hasQuantity } from "@/lib/fractions";
+import { getMessages, formatMessage } from "@/lib/i18n/server";
+
+type Params = { params: Promise<{ id: string }> };
+
+export default async function CollectionPrintPage({ params }: Params) {
+ const { id } = await params;
+ const session = await auth.api.getSession({ headers: await headers() });
+ if (!session) return null;
+
+ const m = getMessages((session.user as { locale?: string }).locale);
+
+ const col = await db.query.collections.findFirst({
+ where: and(
+ eq(collections.id, id),
+ or(eq(collections.userId, session.user.id), eq(collections.isPublic, true))
+ ),
+ with: {
+ recipes: {
+ with: {
+ recipe: {
+ with: {
+ ingredients: { orderBy: (t, { asc }) => asc(t.order) },
+ steps: { orderBy: (t, { asc }) => asc(t.order) },
+ },
+ },
+ },
+ },
+ },
+ });
+
+ if (!col) notFound();
+
+ const recipeEntries = col.recipes.filter((r) => r.recipe !== null);
+
+ return (
+ <>
+
+
+
+
+
+
{col.name}
+ {col.description &&
{col.description}
}
+
+ {recipeEntries.length} recipe{recipeEntries.length !== 1 ? "s" : ""}
+
+
+
+ {recipeEntries.map(({ recipe }) => {
+ if (!recipe) return null;
+ const totalMins = (recipe.prepMins ?? 0) + (recipe.cookMins ?? 0);
+ return (
+
+ {recipe.title}
+
+ {recipe.description && {recipe.description}
}
+
+
+ {recipe.baseServings && {formatMessage(m.recipe.servings, { count: recipe.baseServings })}}
+ {recipe.prepMins && {formatMessage(m.recipe.prep, { mins: recipe.prepMins })}}
+ {recipe.cookMins && {formatMessage(m.recipe.cook, { mins: recipe.cookMins })}}
+ {totalMins > 0 && {formatMessage(m.recipe.total, { mins: totalMins })}}
+ {recipe.difficulty && {recipe.difficulty.charAt(0).toUpperCase() + recipe.difficulty.slice(1)}}
+
+
+ {recipe.ingredients.length > 0 && (
+ <>
+ {m.recipe.ingredients}
+
+ {recipe.ingredients.map((ing) => (
+ -
+
+ {[hasQuantity(ing.quantity) ? ing.quantity : null, ing.unit].filter(Boolean).join(" ")}
+
+ {ing.rawName}
+ {ing.note && ({ing.note})}
+
+ ))}
+
+ >
+ )}
+
+ {recipe.steps.length > 0 && (
+ <>
+ {m.recipe.instructions}
+
+ {recipe.steps.map((step) => (
+ -
+ {step.instruction}
+ {step.timerSeconds && (
+ ⏱ {Math.floor(step.timerSeconds / 60)} min
+ )}
+
+ ))}
+
+ >
+ )}
+
+ );
+ })}
+
+
+ >
+ );
+}
diff --git a/apps/web/components/collections/collections-page-content.tsx b/apps/web/components/collections/collections-page-content.tsx
index b81398b..09c7dda 100644
--- a/apps/web/components/collections/collections-page-content.tsx
+++ b/apps/web/components/collections/collections-page-content.tsx
@@ -22,7 +22,7 @@ export function CollectionsPageContent({ collections }: Props) {
return (
-
+
{t("title")}
{t("subtitle")}
diff --git a/apps/web/components/feed/feed-page-content.tsx b/apps/web/components/feed/feed-page-content.tsx
index e9f2580..b3251d9 100644
--- a/apps/web/components/feed/feed-page-content.tsx
+++ b/apps/web/components/feed/feed-page-content.tsx
@@ -2,7 +2,7 @@
import { useState, useEffect } from "react";
import { useTranslations } from "next-intl";
import Link from "next/link";
-import { Clock, Users, ChefHat, Flame, Heart } from "lucide-react";
+import { Clock, Users, ChefHat, Flame, Heart, Sparkles } from "lucide-react";
import { Avatar, AvatarFallback, AvatarImage } from "@/components/ui/avatar";
import { Badge } from "@/components/ui/badge";
import { useLocale } from "@/lib/i18n/provider";
@@ -99,10 +99,36 @@ function TrendingTab() {
);
}
+function ForYouTab() {
+ const { locale } = useLocale();
+ const t = useTranslations("feed");
+ const [recipes, setRecipes] = useState
([]);
+ const [loading, setLoading] = useState(true);
+
+ useEffect(() => {
+ fetch("/api/v1/feed/for-you")
+ .then((r) => r.json() as Promise<{ data: FeedRecipe[] }>)
+ .then(({ data }) => setRecipes(data))
+ .catch(() => {})
+ .finally(() => setLoading(false));
+ }, []);
+
+ if (loading) return {t("loading")}
;
+ if (recipes.length === 0) return {t("forYouEmpty")}
;
+
+ return (
+
+ {recipes.map((recipe) => (
+
+ ))}
+
+ );
+}
+
export function FeedPageContent({ followedCount, feedRecipes }: Props) {
const t = useTranslations("feed");
const { locale } = useLocale();
- const [tab, setTab] = useState<"following" | "trending">("following");
+ const [tab, setTab] = useState<"following" | "trending" | "forYou">("following");
return (
@@ -131,6 +157,17 @@ export function FeedPageContent({ followedCount, feedRecipes }: Props) {
{t("trending")}
+
{tab === "following" ? (
@@ -147,8 +184,10 @@ export function FeedPageContent({ followedCount, feedRecipes }: Props) {
))}
)
- ) : (
+ ) : tab === "trending" ? (
+ ) : (
+
)}
);
diff --git a/apps/web/components/meal-plan/share-meal-plan-button.tsx b/apps/web/components/meal-plan/share-meal-plan-button.tsx
new file mode 100644
index 0000000..4ef32dc
--- /dev/null
+++ b/apps/web/components/meal-plan/share-meal-plan-button.tsx
@@ -0,0 +1,191 @@
+"use client";
+
+import { useState } from "react";
+import { UserPlus, X } from "lucide-react";
+import { toast } from "sonner";
+import {
+ Dialog,
+ DialogContent,
+ DialogDescription,
+ DialogHeader,
+ DialogTitle,
+} from "@/components/ui/dialog";
+import { Button } from "@/components/ui/button";
+import { Input } from "@/components/ui/input";
+import {
+ Select,
+ SelectContent,
+ SelectItem,
+ SelectTrigger,
+ SelectValue,
+} from "@/components/ui/select";
+import { Badge } from "@/components/ui/badge";
+
+type Role = "viewer" | "editor";
+
+interface Member {
+ id: string;
+ userId: string;
+ role: Role;
+ createdAt: string;
+ user: {
+ name: string;
+ username: string | null;
+ avatarUrl: string | null;
+ };
+}
+
+interface Props {
+ weekStart: string;
+}
+
+export function ShareMealPlanButton({ weekStart }: Props) {
+ const [open, setOpen] = useState(false);
+ const [email, setEmail] = useState("");
+ const [role, setRole] = useState
("viewer");
+ const [members, setMembers] = useState([]);
+ const [loading, setLoading] = useState(false);
+ const [inviting, setInviting] = useState(false);
+
+ async function fetchMembers() {
+ setLoading(true);
+ try {
+ const res = await fetch(`/api/v1/meal-plans/${weekStart}/members`);
+ if (!res.ok) throw new Error("Failed to load members");
+ const data = await res.json() as Member[];
+ setMembers(data);
+ } catch {
+ toast.error("Could not load members");
+ } finally {
+ setLoading(false);
+ }
+ }
+
+ function handleOpenChange(next: boolean) {
+ setOpen(next);
+ if (next) {
+ void fetchMembers();
+ } else {
+ setEmail("");
+ setRole("viewer");
+ }
+ }
+
+ async function handleInvite() {
+ if (!email.trim()) {
+ toast.error("Enter an email address");
+ return;
+ }
+ setInviting(true);
+ try {
+ const res = await fetch(`/api/v1/meal-plans/${weekStart}/members`, {
+ method: "POST",
+ headers: { "Content-Type": "application/json" },
+ body: JSON.stringify({ email: email.trim(), role }),
+ });
+ if (res.status === 409) { toast.error("Already a member"); return; }
+ if (res.status === 404) { toast.error("User not found"); return; }
+ if (!res.ok) { toast.error("Could not invite user"); return; }
+ toast.success("Invitation sent");
+ setEmail("");
+ await fetchMembers();
+ } catch {
+ toast.error("Could not invite user");
+ } finally {
+ setInviting(false);
+ }
+ }
+
+ async function handleRemove(memberId: string) {
+ try {
+ const res = await fetch(
+ `/api/v1/meal-plans/${weekStart}/members?memberId=${memberId}`,
+ { method: "DELETE" },
+ );
+ if (!res.ok) { toast.error("Could not remove member"); return; }
+ setMembers((prev) => prev.filter((m) => m.id !== memberId));
+ toast.success("Member removed");
+ } catch {
+ toast.error("Could not remove member");
+ }
+ }
+
+ return (
+ <>
+
+
+
+ >
+ );
+}
diff --git a/apps/web/components/meal-plan/shared-meal-plan-view.tsx b/apps/web/components/meal-plan/shared-meal-plan-view.tsx
new file mode 100644
index 0000000..9082ae5
--- /dev/null
+++ b/apps/web/components/meal-plan/shared-meal-plan-view.tsx
@@ -0,0 +1,128 @@
+"use client";
+
+import { useState } from "react";
+import { toast } from "sonner";
+import { Trash2 } from "lucide-react";
+import { Button } from "@/components/ui/button";
+import { Select, SelectContent, SelectItem, SelectTrigger, SelectValue } from "@/components/ui/select";
+
+type Day = "mon" | "tue" | "wed" | "thu" | "fri" | "sat" | "sun";
+type MealType = "breakfast" | "lunch" | "dinner" | "snack";
+
+const DAYS: Day[] = ["mon", "tue", "wed", "thu", "fri", "sat", "sun"];
+const MEAL_TYPES: MealType[] = ["breakfast", "lunch", "dinner", "snack"];
+
+type Entry = {
+ id: string;
+ day: Day;
+ mealType: MealType;
+ servings: number;
+ recipe: { id: string; title: string } | null;
+};
+
+type UserRecipe = { id: string; title: string };
+
+export function SharedMealPlanView({
+ mealPlanId,
+ initialEntries,
+ userRecipes,
+ canEdit,
+}: {
+ mealPlanId: string;
+ initialEntries: Entry[];
+ userRecipes: UserRecipe[];
+ canEdit: boolean;
+}) {
+ const [entries, setEntries] = useState(initialEntries);
+ const [addingCell, setAddingCell] = useState(null);
+
+ function cellKey(day: Day, mealType: MealType) {
+ return `${day}-${mealType}`;
+ }
+
+ async function addEntry(day: Day, mealType: MealType, recipeId: string) {
+ const res = await fetch(`/api/v1/meal-plans/shared/${mealPlanId}/entries`, {
+ method: "POST",
+ headers: { "Content-Type": "application/json" },
+ body: JSON.stringify({ day, mealType, recipeId, servings: 2 }),
+ });
+ if (!res.ok) { toast.error("Could not add recipe"); return; }
+ const { id } = await res.json() as { id: string };
+ const recipe = userRecipes.find((r) => r.id === recipeId) ?? null;
+ setEntries((prev) => [
+ ...prev.filter((e) => !(e.day === day && e.mealType === mealType)),
+ { id, day, mealType, servings: 2, recipe },
+ ]);
+ setAddingCell(null);
+ }
+
+ async function removeEntry(entry: Entry) {
+ const res = await fetch(`/api/v1/meal-plans/shared/${mealPlanId}/entries?entryId=${entry.id}`, {
+ method: "DELETE",
+ });
+ if (!res.ok) { toast.error("Could not remove entry"); return; }
+ setEntries((prev) => prev.filter((e) => e.id !== entry.id));
+ }
+
+ return (
+
+
+
+
+ |
+ {DAYS.map((day) => (
+ {day} |
+ ))}
+
+
+
+ {MEAL_TYPES.map((mealType) => (
+
+ | {mealType} |
+ {DAYS.map((day) => {
+ const entry = entries.find((e) => e.day === day && e.mealType === mealType);
+ const key = cellKey(day, mealType);
+ return (
+
+ {entry ? (
+
+ {entry.recipe?.title ?? "—"}
+ {canEdit && (
+
+ )}
+
+ ) : canEdit ? (
+ addingCell === key ? (
+
+ ) : (
+
+ )
+ ) : (
+ —
+ )}
+ |
+ );
+ })}
+
+ ))}
+
+
+
+ );
+}
diff --git a/apps/web/components/meal-plan/shopping-list-view.tsx b/apps/web/components/meal-plan/shopping-list-view.tsx
index 9d94836..e1470dd 100644
--- a/apps/web/components/meal-plan/shopping-list-view.tsx
+++ b/apps/web/components/meal-plan/shopping-list-view.tsx
@@ -20,9 +20,11 @@ type Item = {
export function ShoppingListView({
listId,
initialItems,
+ readOnly = false,
}: {
listId: string;
initialItems: Item[];
+ readOnly?: boolean;
}) {
const t = useTranslations("mealPlan");
const tShopping = useTranslations("shoppingLists");
@@ -54,6 +56,7 @@ export function ShoppingListView({
}
async function toggleItem(item: Item) {
+ if (readOnly) return;
const next = !item.checked;
setItems((prev) => prev.map((i) => i.id === item.id ? { ...i, checked: next } : i));
await fetch(`/api/v1/shopping-lists/${listId}/items/${item.id}`, {
@@ -97,7 +100,8 @@ export function ShoppingListView({