import { NextRequest, NextResponse } from "next/server"; import { z } from "zod"; import { requireSession } from "@/lib/api-auth"; import { createPresignedUploadPost } from "@/lib/storage"; import { checkAndIncrementTierLimit, TierLimitError } from "@/lib/tiers"; const ALLOWED_TYPES = ["image/jpeg", "image/png", "image/webp", "image/avif"] as const; type AllowedType = (typeof ALLOWED_TYPES)[number]; const MAX_FILE_SIZE = 5 * 1024 * 1024; const Schema = z.object({ contentType: z.string().refine((t): t is AllowedType => (ALLOWED_TYPES as readonly string[]).includes(t), { message: "Content type must be jpeg, png, webp, or avif", }), fileSize: z.number().int().positive().max(MAX_FILE_SIZE, "File exceeds 5MB limit"), }); export async function POST(req: NextRequest) { const { session, response } = await requireSession(); if (response) return response; const body = await req.json() as unknown; const parsed = Schema.safeParse(body); if (!parsed.success) { return NextResponse.json({ error: "Validation error", issues: parsed.error.issues }, { status: 400 }); } const { contentType, fileSize } = parsed.data; try { const sizeMb = Math.ceil(fileSize / (1024 * 1024)); await checkAndIncrementTierLimit(session!.user.id, session!.user.tier as "free" | "pro" | "family", "storage", sizeMb); } catch (err) { if (err instanceof TierLimitError) { return NextResponse.json({ error: "Storage limit reached for your tier" }, { status: 403 }); } throw err; } const ext = contentType.split("/")[1] ?? "jpg"; const key = `user-avatars/${session!.user.id}/${crypto.randomUUID()}.${ext}`; const { url, fields } = await createPresignedUploadPost(key, contentType, MAX_FILE_SIZE); return NextResponse.json({ url, fields, key }); }