c8f4b50ef3
All literal "team" tier-value references renamed to "family" across API routes, admin UI, OpenAPI schemas, and lib/tiers.ts. The DB enum value itself is renamed in place via ALTER TYPE ... RENAME VALUE (migration 0044) rather than drizzle-kit's auto-generated drop-and-recreate-the-enum migration, which would have failed against any existing row still holding 'team' — RENAME VALUE preserves existing data with no cast/backfill needed. Also adds STRIPE_PLAN.md — a full Stripe billing integration plan (Checkout+Portal, tier→Price mapping, admin billing dashboard, and a multi-user Family-group design since Family is meant to cover several accounts under one subscription, not one payer). Planning only, no Stripe code yet. v0.47.0
57 lines
1.8 KiB
TypeScript
57 lines
1.8 KiB
TypeScript
import { NextRequest, NextResponse } from "next/server";
|
|
import { requireAdmin } from "@/lib/api-auth";
|
|
import { db, users, auditLogs, eq } from "@epicure/db";
|
|
import { randomUUID } from "crypto";
|
|
|
|
interface RouteContext {
|
|
params: Promise<{ id: string }>;
|
|
}
|
|
|
|
export async function PATCH(req: NextRequest, { params }: RouteContext) {
|
|
const { session, response } = await requireAdmin();
|
|
if (response) return response;
|
|
|
|
const { id } = await params;
|
|
const body = await req.json() as { role?: string; tier?: string };
|
|
const { role, tier } = body;
|
|
|
|
const validRoles = ["user", "moderator", "admin"] as const;
|
|
const validTiers = ["free", "pro", "family"] as const;
|
|
|
|
if (role !== undefined && !validRoles.includes(role as typeof validRoles[number])) {
|
|
return NextResponse.json({ error: "Invalid role" }, { status: 400 });
|
|
}
|
|
if (tier !== undefined && !validTiers.includes(tier as typeof validTiers[number])) {
|
|
return NextResponse.json({ error: "Invalid tier" }, { status: 400 });
|
|
}
|
|
|
|
const updateData: Partial<{ role: "user" | "moderator" | "admin"; tier: "free" | "pro" | "family"; updatedAt: Date }> = {
|
|
updatedAt: new Date(),
|
|
};
|
|
if (role) updateData.role = role as "user" | "moderator" | "admin";
|
|
if (tier) updateData.tier = tier as "free" | "pro" | "family";
|
|
|
|
const [updated] = await db
|
|
.update(users)
|
|
.set(updateData)
|
|
.where(eq(users.id, id))
|
|
.returning({ id: users.id, role: users.role, tier: users.tier });
|
|
|
|
if (!updated) {
|
|
return NextResponse.json({ error: "User not found" }, { status: 404 });
|
|
}
|
|
|
|
// Write audit log
|
|
await db.insert(auditLogs).values({
|
|
id: randomUUID(),
|
|
userId: session!.user.id,
|
|
action: "admin.user.update",
|
|
targetType: "user",
|
|
targetId: id,
|
|
metadata: JSON.stringify({ role, tier }),
|
|
createdAt: new Date(),
|
|
});
|
|
|
|
return NextResponse.json({ user: updated });
|
|
}
|