feat(social): follows, favorites, comments, reactions, collections, public profiles

Follow/unfollow users. Recipe favorites. Threaded comments with emoji reactions.
Collections (public/private) with shared member invite. Activity feed.
Public profile pages at /u/[username].
This commit is contained in:
Arnaud
2026-07-01 08:10:30 +02:00
parent d9d58fd01a
commit 9d02a69250
23 changed files with 1825 additions and 0 deletions
@@ -0,0 +1,36 @@
import { NextRequest, NextResponse } from "next/server";
import { db, users, userFollows, eq, and } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
type Params = { params: Promise<{ username: string }> };
export async function POST(_req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { username } = await params;
const target = await db.query.users.findFirst({ where: eq(users.username, username) });
if (!target) return NextResponse.json({ error: "Not found" }, { status: 404 });
if (target.id === session!.user.id) return NextResponse.json({ error: "Cannot follow yourself" }, { status: 400 });
await db.insert(userFollows)
.values({ followerId: session!.user.id, followingId: target.id })
.onConflictDoNothing();
return NextResponse.json({ following: true });
}
export async function DELETE(_req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { username } = await params;
const target = await db.query.users.findFirst({ where: eq(users.username, username) });
if (!target) return NextResponse.json({ error: "Not found" }, { status: 404 });
await db.delete(userFollows).where(
and(eq(userFollows.followerId, session!.user.id), eq(userFollows.followingId, target.id))
);
return NextResponse.json({ following: false });
}
@@ -0,0 +1,57 @@
import { NextRequest, NextResponse } from "next/server";
import { headers } from "next/headers";
import { auth } from "@/lib/auth/server";
import { db, users, recipes, userFollows, eq, and, count } from "@epicure/db";
type Params = { params: Promise<{ username: string }> };
export async function GET(req: NextRequest, { params }: Params) {
const { username } = await params;
const user = await db.query.users.findFirst({ where: eq(users.username, username) });
if (!user) return NextResponse.json({ error: "Not found" }, { status: 404 });
const [followerCountRow, followingCountRow, recipeCountRow] = await Promise.all([
db
.select({ count: count() })
.from(userFollows)
.where(eq(userFollows.followingId, user.id)),
db
.select({ count: count() })
.from(userFollows)
.where(eq(userFollows.followerId, user.id)),
db
.select({ count: count() })
.from(recipes)
.where(and(eq(recipes.authorId, user.id), eq(recipes.visibility, "public"))),
]);
let isFollowing = false;
try {
const session = await auth.api.getSession({ headers: await headers() });
if (session && session.user.id !== user.id) {
const followRow = await db.query.userFollows.findFirst({
where: and(
eq(userFollows.followerId, session.user.id),
eq(userFollows.followingId, user.id),
),
});
isFollowing = !!followRow;
}
} catch {
// unauthenticated — isFollowing stays false
}
return NextResponse.json({
id: user.id,
name: user.name,
username: user.username,
avatarUrl: user.avatarUrl,
bio: user.bio,
createdAt: user.createdAt,
followerCount: followerCountRow[0]?.count ?? 0,
followingCount: followingCountRow[0]?.count ?? 0,
recipeCount: recipeCountRow[0]?.count ?? 0,
isFollowing,
});
}
@@ -0,0 +1,42 @@
import { type NextRequest, NextResponse } from "next/server";
import { z } from "zod";
import { requireSession } from "@/lib/api-auth";
import { db, userModelPrefs, eq } from "@epicure/db";
const Schema = z.object({
textProvider: z.string().nullable().optional(),
textModel: z.string().nullable().optional(),
visionProvider: z.string().nullable().optional(),
visionModel: z.string().nullable().optional(),
mealPlanProvider: z.string().nullable().optional(),
mealPlanModel: z.string().nullable().optional(),
});
export async function GET() {
const { session, response } = await requireSession();
if (response) return response;
const prefs = await db.query.userModelPrefs.findFirst({
where: eq(userModelPrefs.userId, session!.user.id),
});
return NextResponse.json(prefs ?? null);
}
export async function PUT(req: NextRequest) {
const { session, response } = await requireSession();
if (response) return response;
const body = Schema.safeParse(await req.json());
if (!body.success) return NextResponse.json({ error: "Invalid request" }, { status: 400 });
await db
.insert(userModelPrefs)
.values({ id: crypto.randomUUID(), userId: session!.user.id, ...body.data, updatedAt: new Date() })
.onConflictDoUpdate({
target: userModelPrefs.userId,
set: { ...body.data, updatedAt: new Date() },
});
return NextResponse.json({ ok: true });
}
@@ -0,0 +1,45 @@
import { NextRequest, NextResponse } from "next/server";
import { db, userNutritionGoals, eq } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
import { z } from "zod";
const PutSchema = z.object({
caloriesKcal: z.number().int().min(0).optional(),
proteinG: z.number().int().min(0).optional(),
carbsG: z.number().int().min(0).optional(),
fatG: z.number().int().min(0).optional(),
});
export async function GET() {
const { session, response } = await requireSession();
if (response) return response;
const goals = await db.query.userNutritionGoals.findFirst({
where: eq(userNutritionGoals.userId, session!.user.id),
});
return NextResponse.json({ data: goals ?? null });
}
export async function PUT(req: NextRequest) {
const { session, response } = await requireSession();
if (response) return response;
const parsed = PutSchema.safeParse(await req.json());
if (!parsed.success) {
return NextResponse.json({ error: parsed.error.flatten() }, { status: 400 });
}
const body = parsed.data;
const userId = session!.user.id;
await db
.insert(userNutritionGoals)
.values({ id: crypto.randomUUID(), userId, ...body, updatedAt: new Date() })
.onConflictDoUpdate({
target: userNutritionGoals.userId,
set: { ...body, updatedAt: new Date() },
});
return NextResponse.json({ ok: true });
}
+21
View File
@@ -0,0 +1,21 @@
import { NextResponse } from "next/server";
import { headers } from "next/headers";
import { auth } from "@/lib/auth/server";
import { db, users, eq } from "@epicure/db";
import { z } from "zod";
const PatchSchema = z.object({
name: z.string().min(1).max(100).optional(),
locale: z.string().max(10).optional(),
});
export async function PATCH(req: Request) {
const session = await auth.api.getSession({ headers: await headers() });
if (!session) return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
const body = PatchSchema.safeParse(await req.json());
if (!body.success) return NextResponse.json({ error: body.error.flatten() }, { status: 400 });
await db.update(users).set(body.data).where(eq(users.id, session.user.id));
return NextResponse.json({ ok: true });
}