import { NextRequest, NextResponse } from "next/server"; import { z } from "zod"; import { db, comments, users, eq } from "@epicure/db"; import { requireSession } from "@/lib/api-auth"; type Params = { params: Promise<{ id: string }> }; export async function PUT(req: NextRequest, { params }: Params) { const { session, response } = await requireSession(); if (response) return response; const { id } = await params; const comment = await db.query.comments.findFirst({ where: eq(comments.id, id) }); if (!comment || comment.userId !== session!.user.id) { return NextResponse.json({ error: "Not found" }, { status: 404 }); } const body = await req.json() as unknown; const parsed = z.object({ content: z.string().min(1).max(5000) }).safeParse(body); if (!parsed.success) return NextResponse.json({ error: "Validation error" }, { status: 400 }); await db.update(comments).set({ content: parsed.data.content, updatedAt: new Date() }).where(eq(comments.id, id)); return NextResponse.json({ updated: true }); } export async function DELETE(_req: NextRequest, { params }: Params) { const { session, response } = await requireSession(); if (response) return response; const { id } = await params; const comment = await db.query.comments.findFirst({ where: eq(comments.id, id) }); if (!comment) return NextResponse.json({ error: "Not found" }, { status: 404 }); if (comment.userId !== session!.user.id) { // session.user.role comes from a 5-minute cookieCache — a just-demoted // moderator/admin would keep access for up to 5 minutes. Re-query fresh. const [dbUser] = await db .select({ role: users.role }) .from(users) .where(eq(users.id, session!.user.id)) .limit(1); if (dbUser?.role !== "admin" && dbUser?.role !== "moderator") { return NextResponse.json({ error: "Forbidden" }, { status: 403 }); } } await db.delete(comments).where(eq(comments.id, id)); return new NextResponse(null, { status: 204 }); }