9c545a5bb3
- Private accounts: users.isPrivate hides a user from search and their recipes from search/trending/for-you discovery surfaces (follow-aware where the route already has session context, blanket exclusion where it doesn't); existing followers and direct links are unaffected, no follow-request approval flow was built (explicit scope limit) - Merged /people into the Explore tab (tab=people query param); the old standalone route now redirects there - "Get Ideas" vs "Surprise Me" were doing the same empty-prompt call; Surprise Me now injects a real random constraint (5-ingredient, one-pot, etc.), matching the existing pattern in the AI recipe-generate dialog - Meal-plan day cells now link to their recipe (was dead text) and gained a one-click "mark as cooked" action - Theme toggle is now a real three-way light/dark/system control instead of a binary flip - Nutrition goals form had zero i18n wiring; fully localized now New migration 0027 (users.is_private) generated, left unapplied like the others. Verified with typecheck, lint, and a clean --no-cache docker build. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
25 lines
948 B
TypeScript
25 lines
948 B
TypeScript
import { NextResponse } from "next/server";
|
|
import { headers } from "next/headers";
|
|
import { auth } from "@/lib/auth/server";
|
|
import { db, users, eq } from "@epicure/db";
|
|
import { z } from "zod";
|
|
|
|
const PatchSchema = z.object({
|
|
name: z.string().min(1).max(100).optional(),
|
|
locale: z.string().max(10).optional(),
|
|
bio: z.string().max(500).optional().nullable(),
|
|
privateBio: z.string().max(2000).optional().nullable(),
|
|
isPrivate: z.boolean().optional(),
|
|
});
|
|
|
|
export async function PATCH(req: Request) {
|
|
const session = await auth.api.getSession({ headers: await headers() });
|
|
if (!session) return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
|
|
|
const body = PatchSchema.safeParse(await req.json());
|
|
if (!body.success) return NextResponse.json({ error: body.error.flatten() }, { status: 400 });
|
|
|
|
await db.update(users).set(body.data).where(eq(users.id, session.user.id));
|
|
return NextResponse.json({ ok: true });
|
|
}
|