Files
Arnaud 3e71bd29a2 security: widen API-key auth to content/AI routes (v0.27.0)
Convert requireSession -> requireSessionOrApiKey across recipes,
collections, meal-plans, shopping-lists, pantry, feed, and ai/*
(52 routes) so API keys work end-to-end, not just for the handful of
endpoints that supported them before. Scope was explicitly confirmed
per-resource-family with the user before any file was touched.

Left session-cookie-only, deliberately: users/me*, ai-keys/*,
webhooks/*, conversations/*, notifications/*, push/subscribe, admin/*
— account/credential-adjacent surface that shouldn't widen without a
separate, explicit decision.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-14 11:20:26 +02:00

97 lines
3.8 KiB
TypeScript

import { NextRequest, NextResponse } from "next/server";
import { z } from "zod";
import { db, recipes, cookingHistory, pantryItems, recipeIngredients, recipeBatchDishes, eq, and } from "@epicure/db";
import { requireSessionOrApiKey } from "@/lib/api-auth";
type Params = { params: Promise<{ id: string }> };
const Schema = z.object({
servings: z.number().int().min(1).max(1000).optional(),
notes: z.string().max(2000).optional(),
deductFromPantry: z.boolean().default(true),
batchDishId: z.string().optional(),
});
export async function POST(req: NextRequest, { params }: Params) {
const { session, response } = await requireSessionOrApiKey(req);
if (response) return response;
const { id } = await params;
const userId = session!.user.id;
const recipe = await db.query.recipes.findFirst({ where: eq(recipes.id, id) });
if (!recipe || (recipe.visibility === "private" && recipe.authorId !== userId)) {
return NextResponse.json({ error: "Not found" }, { status: 404 });
}
const body = await req.json().catch(() => ({})) as unknown;
const parsed = Schema.safeParse(body);
const data = parsed.success ? parsed.data : { deductFromPantry: true };
// Ingredients aren't attributable to individual batch dishes — they're one
// merged/shared list for the whole prep session (unlike steps, which have
// `appliesTo`). So pantry deduction for a batch-cook recipe happens once,
// on the first dish marked cooked, rather than per-dish.
let isFirstBatchCook = false;
if (data.batchDishId) {
const dish = await db.query.recipeBatchDishes.findFirst({
where: and(eq(recipeBatchDishes.id, data.batchDishId), eq(recipeBatchDishes.recipeId, id)),
});
if (!dish) return NextResponse.json({ error: "Dish not found" }, { status: 404 });
const priorCook = await db.query.cookingHistory.findFirst({
where: and(eq(cookingHistory.recipeId, id), eq(cookingHistory.userId, userId)),
});
isFirstBatchCook = !priorCook;
}
await db.insert(cookingHistory).values({
id: crypto.randomUUID(),
userId,
recipeId: id,
batchDishId: data.batchDishId,
servings: data.servings,
notes: data.notes,
cookedAt: new Date(),
});
if (data.deductFromPantry && (!data.batchDishId || isFirstBatchCook)) {
const ings = await db.query.recipeIngredients.findMany({
where: eq(recipeIngredients.recipeId, id),
});
// A batch session's merged ingredient list is deducted once as a whole,
// regardless of which single dish triggered the first cook — never
// scaled by that one dish's serving count.
const scale = data.batchDishId ? 1 : (data.servings ? data.servings / recipe.baseServings : 1);
const userPantry = await db.query.pantryItems.findMany({
where: eq(pantryItems.userId, userId),
});
for (const ing of ings) {
const key = ing.rawName.toLowerCase();
const pantryItem = userPantry.find(
(p) => p.rawName.toLowerCase() === key && (p.unit ?? "") === (ing.unit ?? "")
);
if (!pantryItem) continue;
const pantryQty = pantryItem.quantity ? parseFloat(pantryItem.quantity) : null;
const ingQty = ing.quantity ? parseFloat(ing.quantity) * scale : null;
if (pantryQty !== null && ingQty !== null && !isNaN(pantryQty) && !isNaN(ingQty)) {
const remaining = pantryQty - ingQty;
if (remaining <= 0) {
await db.delete(pantryItems).where(eq(pantryItems.id, pantryItem.id));
} else {
await db.update(pantryItems)
.set({ quantity: String(Math.round(remaining * 10000) / 10000) })
.where(eq(pantryItems.id, pantryItem.id));
}
} else {
// no numeric quantity to deduct — remove the item entirely
await db.delete(pantryItems).where(eq(pantryItems.id, pantryItem.id));
}
}
}
return NextResponse.json({ logged: true }, { status: 201 });
}