c31ab8771a
Widens the tier enum from free/pro to free/pro/team and every "free" | "pro" cast that assumed exactly two tiers (~30 call sites: every AI route's withAiQuota/checkAndIncrementTierLimit call, admin user/invite management, upload quota checks, OpenAPI schemas). Team sits above Pro with genuinely unlimited recipes/public-recipes (the -1 sentinel, which Pro doesn't actually use — Pro uses large finite numbers instead) and a higher AI-call/storage cap. Seeded via db:seed, editable afterward from Admin > Tiers. role (user/moderator/admin — permissions) and tier (free/pro/team — billing limits) stay separate concepts, as they already were; this does not touch role-based permissions. Requires migration 0043 to run against a live DB — not applied in this sandbox (no Docker here); run `pnpm db:migrate` then `pnpm db:seed`. v0.44.0
57 lines
1.8 KiB
TypeScript
57 lines
1.8 KiB
TypeScript
import { NextRequest, NextResponse } from "next/server";
|
|
import { requireAdmin } from "@/lib/api-auth";
|
|
import { db, tierDefinitions, auditLogs, eq } from "@epicure/db";
|
|
import { randomUUID } from "crypto";
|
|
import { UNLIMITED } from "@/lib/tiers";
|
|
|
|
interface RouteContext {
|
|
params: Promise<{ tier: string }>;
|
|
}
|
|
|
|
const NUMERIC_FIELDS = ["maxRecipes", "aiCallsPerMonth", "storageMb", "maxPublicRecipes"] as const;
|
|
type NumericField = (typeof NUMERIC_FIELDS)[number];
|
|
|
|
export async function PATCH(req: NextRequest, { params }: RouteContext) {
|
|
const { session, response } = await requireAdmin();
|
|
if (response) return response;
|
|
|
|
const { tier } = await params;
|
|
if (tier !== "free" && tier !== "pro" && tier !== "team") {
|
|
return NextResponse.json({ error: "Invalid tier" }, { status: 400 });
|
|
}
|
|
|
|
const body = (await req.json()) as Partial<Record<NumericField, number>>;
|
|
const updateData: Partial<Record<NumericField, number>> = {};
|
|
|
|
for (const field of NUMERIC_FIELDS) {
|
|
const value = body[field];
|
|
if (value === undefined) continue;
|
|
if (!Number.isInteger(value) || (value < 0 && value !== UNLIMITED)) {
|
|
return NextResponse.json({ error: `Invalid value for ${field}` }, { status: 400 });
|
|
}
|
|
updateData[field] = value;
|
|
}
|
|
|
|
const [updated] = await db
|
|
.update(tierDefinitions)
|
|
.set(updateData)
|
|
.where(eq(tierDefinitions.tier, tier))
|
|
.returning();
|
|
|
|
if (!updated) {
|
|
return NextResponse.json({ error: "Tier not found" }, { status: 404 });
|
|
}
|
|
|
|
await db.insert(auditLogs).values({
|
|
id: randomUUID(),
|
|
userId: session!.user.id,
|
|
action: "admin.tier.update",
|
|
targetType: "tier_definition",
|
|
targetId: tier,
|
|
metadata: JSON.stringify(updateData),
|
|
createdAt: new Date(),
|
|
});
|
|
|
|
return NextResponse.json({ tierDefinition: updated });
|
|
}
|