import { NextRequest, NextResponse } from "next/server"; import { z } from "zod"; import { requireSession } from "@/lib/api-auth"; import { createPresignedUploadUrl } from "@/lib/storage"; const ALLOWED_TYPES = ["image/jpeg", "image/png", "image/webp", "image/avif"] as const; type AllowedType = (typeof ALLOWED_TYPES)[number]; const Schema = z.object({ contentType: z.string().refine((t): t is AllowedType => (ALLOWED_TYPES as readonly string[]).includes(t), { message: "Content type must be jpeg, png, webp, or avif", }), recipeId: z.string().uuid(), }); export async function POST(req: NextRequest) { const { session, response } = await requireSession(); if (response) return response; const body = await req.json() as unknown; const parsed = Schema.safeParse(body); if (!parsed.success) { return NextResponse.json({ error: "Validation error", issues: parsed.error.issues }, { status: 400 }); } const ext = parsed.data.contentType.split("/")[1] ?? "jpg"; const key = `recipes/${parsed.data.recipeId}/photos/${session!.user.id}-${crypto.randomUUID()}.${ext}`; const url = await createPresignedUploadUrl(key, parsed.data.contentType); return NextResponse.json({ url, key }); }