feat: implement remaining TODO.md feature ideas + fix mobile headers

Implements the six previously-unscoped feature ideas plus a mobile
layout fix reported via screenshot:

- Mobile: Recipes/Collections/Pantry/Meal Plan/Shopping Lists headers
  now stack and wrap instead of clipping buttons on narrow viewports.
- Recipe diff/compare view: word/list diff against any past version,
  next to Restore in version history.
- Shared meal plans & shopping lists: new shoppingListMembers/
  mealPlanMembers tables (viewer/editor roles, mirrors
  collectionMembers), share dialogs, membership-checked routes.
- PDF cookbook export: /print/collection/[id] renders a whole
  collection with page breaks, using the existing print-CSS pattern
  instead of adding a PDF rendering dependency.
- Grocery delivery handoff: shopping lists can copy-as-text (works
  today) or send to Instacart once INSTACART_API_KEY is configured
  (stub adapter — real API needs a partner agreement).
- Personalized "For You" feed tab: ranks public recipes by tag/
  dietary overlap with the user's favorited/highly-rated history.
- PWA: added manifest.json + icons on top of the existing service
  worker so the app is installable; cook-mode pages were already
  cached for offline use.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Arnaud
2026-07-02 12:13:00 +02:00
parent d2faf98ac1
commit e5d1080fb9
56 changed files with 6096 additions and 74 deletions
+12 -2
View File
@@ -1,11 +1,15 @@
import type { Metadata } from "next";
import { notFound } from "next/navigation";
import { headers } from "next/headers";
import Link from "next/link";
import { Printer } from "lucide-react";
import { auth } from "@/lib/auth/server";
import { db, collections, eq, and, or } from "@epicure/db";
import { RecipeCard } from "@/components/recipe/recipe-card";
import { ForkCollectionButton } from "@/components/collections/fork-collection-button";
import { ShareCollectionButton } from "@/components/collections/share-collection-button";
import { buttonVariants } from "@/components/ui/button";
import { cn } from "@/lib/utils";
type Params = { params: Promise<{ id: string }> };
@@ -30,7 +34,7 @@ export default async function CollectionPage({ params }: Params) {
return (
<div className="space-y-6">
<div className="flex items-start justify-between gap-4">
<div className="flex flex-col gap-3 sm:flex-row sm:items-start sm:justify-between">
<div>
<h1 className="text-3xl font-bold tracking-tight">{col.name}</h1>
{col.description && <p className="text-muted-foreground mt-1">{col.description}</p>}
@@ -38,7 +42,13 @@ export default async function CollectionPage({ params }: Params) {
{col.recipes.length} recipe{col.recipes.length !== 1 ? "s" : ""} · {col.isPublic ? "Public" : "Private"}
</p>
</div>
<div className="flex items-center gap-2">
<div className="flex flex-wrap items-center gap-2">
{col.recipes.length > 0 && (
<Link href={`/print/collection/${id}`} target="_blank" className={cn(buttonVariants({ variant: "outline", size: "sm" }))}>
<Printer className="h-4 w-4" />
Export as PDF
</Link>
)}
{isOwner && <ShareCollectionButton collectionId={id} />}
{!isOwner && col.isPublic && (
<ForkCollectionButton collectionId={id} />
+30 -4
View File
@@ -3,9 +3,10 @@ import { headers } from "next/headers";
import Link from "next/link";
import { ChevronLeft, ChevronRight, ShoppingCart, Printer } from "lucide-react";
import { auth } from "@/lib/auth/server";
import { db, mealPlans, recipes, eq, and, desc } from "@epicure/db";
import { db, mealPlans, mealPlanMembers, recipes, eq, and, desc } from "@epicure/db";
import { buttonVariants } from "@/components/ui/button";
import { MealPlanner } from "@/components/meal-plan/meal-planner";
import { ShareMealPlanButton } from "@/components/meal-plan/share-meal-plan-button";
import { WeeklyNutritionBar } from "@/components/nutrition/weekly-nutrition-bar";
import { cn } from "@/lib/utils";
@@ -47,7 +48,7 @@ export default async function MealPlanPage({
const sunday = addWeeks(monday, 1);
sunday.setDate(sunday.getDate() - 1);
const [plan, userRecipes] = await Promise.all([
const [plan, userRecipes, sharedMemberships] = await Promise.all([
db.query.mealPlans.findFirst({
where: and(eq(mealPlans.userId, session.user.id), eq(mealPlans.weekStart, weekStart)),
with: {
@@ -61,6 +62,10 @@ export default async function MealPlanPage({
orderBy: desc(recipes.updatedAt),
columns: { id: true, title: true },
}),
db.query.mealPlanMembers.findMany({
where: eq(mealPlanMembers.userId, session.user.id),
with: { mealPlan: { with: { user: true } } },
}),
]);
const entries = (plan?.entries ?? []).map((e) => ({
@@ -76,12 +81,13 @@ export default async function MealPlanPage({
return (
<div className="space-y-6">
<div className="flex items-center justify-between">
<div className="flex flex-col gap-3 sm:flex-row sm:items-center sm:justify-between">
<div>
<h1 className="text-3xl font-bold tracking-tight">Meal Plan</h1>
<p className="text-muted-foreground mt-1">{label}</p>
</div>
<div className="flex items-center gap-2">
<div className="flex flex-wrap items-center gap-2">
<ShareMealPlanButton weekStart={weekStart} />
<Link href="/shopping-lists" className={cn(buttonVariants({ variant: "outline", size: "sm" }))}>
<ShoppingCart className="h-4 w-4" />
Shopping lists
@@ -101,6 +107,26 @@ export default async function MealPlanPage({
<WeeklyNutritionBar weekStart={weekStart} />
<MealPlanner weekStart={weekStart} initialEntries={entries} userRecipes={userRecipes} />
{sharedMemberships.length > 0 && (
<div className="space-y-3">
<h2 className="text-sm font-semibold text-muted-foreground">Shared with you</h2>
<div className="space-y-2 max-w-lg">
{sharedMemberships.map((m) => (
<Link
key={m.id}
href={`/meal-plan/shared/${m.mealPlan.id}`}
className="flex items-center justify-between rounded-xl border p-4 hover:shadow-sm transition-shadow"
>
<div>
<p className="font-medium">{`${m.mealPlan.user?.name ?? "Unknown"}'s plan`}</p>
<p className="text-sm text-muted-foreground">Week of {m.mealPlan.weekStart} · {m.role}</p>
</div>
</Link>
))}
</div>
</div>
)}
</div>
);
}
@@ -0,0 +1,55 @@
import type { Metadata } from "next";
import { notFound } from "next/navigation";
import { headers } from "next/headers";
import { auth } from "@/lib/auth/server";
import { db, mealPlans, recipes, eq, desc } from "@epicure/db";
import { getMealPlanAccessById, canWriteMealPlan } from "@/lib/meal-plan-access";
import { SharedMealPlanView } from "@/components/meal-plan/shared-meal-plan-view";
type Params = { params: Promise<{ mealPlanId: string }> };
export const metadata: Metadata = { title: "Shared Meal Plan" };
export default async function SharedMealPlanPage({ params }: Params) {
const { mealPlanId } = await params;
const session = await auth.api.getSession({ headers: await headers() });
if (!session) return null;
const access = await getMealPlanAccessById(mealPlanId, session.user.id);
if (!access) notFound();
const plan = await db.query.mealPlans.findFirst({
where: eq(mealPlans.id, mealPlanId),
with: { entries: { with: { recipe: true } }, user: true },
});
if (!plan) notFound();
const userRecipes = await db.query.recipes.findMany({
where: eq(recipes.authorId, session.user.id),
orderBy: desc(recipes.updatedAt),
columns: { id: true, title: true },
});
const canEdit = canWriteMealPlan(access.role);
return (
<div className="space-y-6">
<div>
<h1 className="text-3xl font-bold tracking-tight">{`${plan.user?.name ?? "Shared"}'s Meal Plan`}</h1>
<p className="text-muted-foreground mt-1">Week of {plan.weekStart} · {access.role}</p>
</div>
<SharedMealPlanView
mealPlanId={mealPlanId}
canEdit={canEdit}
userRecipes={userRecipes}
initialEntries={plan.entries.map((e) => ({
id: e.id,
day: e.day,
mealType: e.mealType,
servings: e.servings,
recipe: e.recipe ? { id: e.recipe.id, title: e.recipe.title } : null,
}))}
/>
</div>
);
}
+17 -1
View File
@@ -149,7 +149,23 @@ export default async function RecipePage({ params }: Params) {
}))}
/>
<PrintButton recipeId={id} />
<VersionHistoryButton recipeId={id} />
<VersionHistoryButton
recipeId={id}
currentSnapshot={{
title: recipe.title,
description: recipe.description,
ingredients: recipe.ingredients.map((ing) => ({
rawName: ing.rawName,
quantity: ing.quantity,
unit: ing.unit,
note: ing.note,
})),
steps: recipe.steps.map((s) => ({
instruction: s.instruction,
timerSeconds: s.timerSeconds,
})),
}}
/>
<Tooltip>
<TooltipTrigger render={
<Link href={`/recipes/${id}/edit`} className={cn(buttonVariants({ variant: "ghost", size: "icon" }))}>
+24 -1
View File
@@ -8,6 +8,14 @@ import { CanCookContent } from "@/components/recipe/can-cook-content";
export const metadata: Metadata = { title: "What can I cook?" };
const EXPIRING_WITHIN_DAYS = 3;
function isExpiringSoon(expiresAt: Date | null): boolean {
if (!expiresAt) return false;
const days = Math.ceil((expiresAt.getTime() - Date.now()) / (1000 * 60 * 60 * 24));
return days >= 0 && days <= EXPIRING_WITHIN_DAYS;
}
export default async function CanCookPage() {
const session = await auth.api.getSession({ headers: await headers() });
if (!session) return null;
@@ -27,6 +35,12 @@ export default async function CanCookPage() {
const pantryKeys = new Set(pantry.map((p) => p.rawName.toLowerCase()));
const expiringSoonKeys = new Set(
pantry
.filter((p) => isExpiringSoon(p.expiresAt))
.map((p) => p.rawName.toLowerCase())
);
const scored = userRecipes
.filter((r) => r.ingredients.length > 0)
.map((recipe) => {
@@ -37,6 +51,9 @@ export default async function CanCookPage() {
.filter((ing) => !pantryKeys.has(ing.rawName.toLowerCase()))
.map((ing) => ing.rawName)
.slice(0, 5);
const usesExpiring = recipe.ingredients
.filter((ing) => expiringSoonKeys.has(ing.rawName.toLowerCase()))
.map((ing) => ing.rawName);
const total = recipe.ingredients.length;
const cover = recipe.photos?.find((p) => p.isCover) ?? recipe.photos?.[0];
return {
@@ -50,9 +67,15 @@ export default async function CanCookPage() {
total,
pct: Math.round((matched / total) * 100),
missing,
usesExpiring,
};
})
.sort((a, b) => b.pct - a.pct);
.sort((a, b) => {
if (a.usesExpiring.length > 0 !== b.usesExpiring.length > 0) {
return a.usesExpiring.length > 0 ? -1 : 1;
}
return b.pct - a.pct;
});
return <CanCookContent pantryCount={pantry.length} scored={scored} />;
}
@@ -4,10 +4,13 @@ import { headers } from "next/headers";
import Link from "next/link";
import { Printer } from "lucide-react";
import { auth } from "@/lib/auth/server";
import { db, shoppingLists, eq, and } from "@epicure/db";
import { db, shoppingLists, eq } from "@epicure/db";
import { ShoppingListView } from "@/components/meal-plan/shopping-list-view";
import { ShareShoppingListButton } from "@/components/shopping-lists/share-shopping-list-button";
import { GroceryExportButton } from "@/components/shopping-lists/grocery-export-button";
import { buttonVariants } from "@/components/ui/button";
import { cn } from "@/lib/utils";
import { getShoppingListAccess, canWriteShoppingList } from "@/lib/shopping-list-access";
type Params = { params: Promise<{ id: string }> };
@@ -18,29 +21,39 @@ export default async function ShoppingListPage({ params }: Params) {
const session = await auth.api.getSession({ headers: await headers() });
if (!session) return null;
const access = await getShoppingListAccess(id, session.user.id);
if (!access) notFound();
const list = await db.query.shoppingLists.findFirst({
where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session.user.id)),
where: eq(shoppingLists.id, id),
with: { items: { orderBy: (t, { asc }) => [asc(t.aisle), asc(t.rawName)] } },
});
if (!list) notFound();
const canEdit = canWriteShoppingList(access.role);
const instacartEnabled = process.env["NEXT_PUBLIC_GROCERY_PROVIDER"] === "instacart";
return (
<div className="space-y-6 max-w-lg">
<div className="flex items-start justify-between">
<div className="flex flex-col gap-3 sm:flex-row sm:items-start sm:justify-between">
<div>
<h1 className="text-3xl font-bold tracking-tight">{list.name}</h1>
<p className="text-muted-foreground mt-1">
{list.items.length} items{list.generatedAt ? " · Generated from meal plan" : ""}
</p>
</div>
<Link href={`/print/shopping-list/${id}`} target="_blank" className={cn(buttonVariants({ variant: "outline", size: "sm" }))}>
<Printer className="h-4 w-4" />
Print
</Link>
<div className="flex flex-wrap items-center gap-2">
<GroceryExportButton listId={id} instacartEnabled={instacartEnabled} />
{access.role === "owner" && <ShareShoppingListButton listId={id} />}
<Link href={`/print/shopping-list/${id}`} target="_blank" className={cn(buttonVariants({ variant: "outline", size: "sm" }))}>
<Printer className="h-4 w-4" />
Print
</Link>
</div>
</div>
<ShoppingListView
listId={id}
readOnly={!canEdit}
initialItems={list.items.map((i) => ({
id: i.id,
rawName: i.rawName,
+18 -6
View File
@@ -1,7 +1,7 @@
import type { Metadata } from "next";
import { headers } from "next/headers";
import { auth } from "@/lib/auth/server";
import { db, shoppingLists, eq, desc } from "@epicure/db";
import { db, shoppingLists, shoppingListMembers, eq, desc } from "@epicure/db";
import { ShoppingListsPageContent } from "@/components/shopping-lists/shopping-lists-page-content";
export const metadata: Metadata = { title: "Shopping Lists" };
@@ -10,11 +10,17 @@ export default async function ShoppingListsPage() {
const session = await auth.api.getSession({ headers: await headers() });
if (!session) return null;
const lists = await db.query.shoppingLists.findMany({
where: eq(shoppingLists.userId, session.user.id),
orderBy: desc(shoppingLists.createdAt),
with: { items: { columns: { id: true, checked: true } } },
});
const [lists, memberships] = await Promise.all([
db.query.shoppingLists.findMany({
where: eq(shoppingLists.userId, session.user.id),
orderBy: desc(shoppingLists.createdAt),
with: { items: { columns: { id: true, checked: true } } },
}),
db.query.shoppingListMembers.findMany({
where: eq(shoppingListMembers.userId, session.user.id),
with: { list: { with: { user: true } } },
}),
]);
return (
<ShoppingListsPageContent
@@ -25,6 +31,12 @@ export default async function ShoppingListsPage() {
totalItems: list.items.length,
checkedItems: list.items.filter((i) => i.checked).length,
}))}
sharedLists={memberships.map((m) => ({
id: m.list.id,
name: m.list.name,
ownerName: m.list.user?.name ?? "Unknown",
role: m.role,
}))}
/>
);
}
+69
View File
@@ -0,0 +1,69 @@
import { NextRequest, NextResponse } from "next/server";
import { db, recipes, users, favorites, ratings, eq, and, ne, gte, notInArray, inArray, desc } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
import { buildPreferenceMap, rankForYou } from "@/lib/for-you-ranking";
export async function GET(req: NextRequest) {
const { session, response } = await requireSession();
if (response) return response;
const userId = session!.user.id;
const { searchParams } = new URL(req.url);
const limit = Math.min(parseInt(searchParams.get("limit") ?? "20"), 50);
// Recipes the user has favorited, or rated 4+, define their taste profile.
const [favoritedRows, highRatedRows] = await Promise.all([
db.select({ recipeId: favorites.recipeId }).from(favorites).where(eq(favorites.userId, userId)),
db.select({ recipeId: ratings.recipeId }).from(ratings).where(and(eq(ratings.userId, userId), gte(ratings.score, 4))),
]);
const likedIds = [...new Set([...favoritedRows.map((r) => r.recipeId), ...highRatedRows.map((r) => r.recipeId)])];
const likedRecipes = likedIds.length > 0
? await db.select({ tags: recipes.tags, dietaryTags: recipes.dietaryTags }).from(recipes).where(inArray(recipes.id, likedIds))
: [];
const preferences = buildPreferenceMap(likedRecipes);
const excludeIds = likedIds.length > 0 ? likedIds : ["__none__"];
const candidates = await db
.select({
id: recipes.id,
title: recipes.title,
description: recipes.description,
baseServings: recipes.baseServings,
prepMins: recipes.prepMins,
cookMins: recipes.cookMins,
difficulty: recipes.difficulty,
visibility: recipes.visibility,
aiGenerated: recipes.aiGenerated,
createdAt: recipes.createdAt,
authorId: recipes.authorId,
authorName: users.name,
authorUsername: users.username,
authorAvatarUrl: users.avatarUrl,
tags: recipes.tags,
dietaryTags: recipes.dietaryTags,
})
.from(recipes)
.innerJoin(users, eq(recipes.authorId, users.id))
.where(and(
eq(recipes.visibility, "public"),
ne(recipes.authorId, userId),
notInArray(recipes.id, excludeIds)
))
.orderBy(desc(recipes.createdAt))
.limit(200); // score a bounded recent window rather than the whole table
const ranked = preferences.size > 0
? rankForYou(candidates, preferences)
: [...candidates].sort((a, b) => b.createdAt.getTime() - a.createdAt.getTime());
const data = ranked.slice(0, limit).map(({ tags: _tags, dietaryTags: _dietaryTags, ...r }) => ({
...r,
createdAt: r.createdAt.toISOString(),
}));
return NextResponse.json({ data });
}
@@ -0,0 +1,137 @@
import { describe, it, expect, vi, beforeEach } from "vitest";
import { NextRequest } from "next/server";
const mockSession = { user: { id: "user-1" } };
vi.mock("@/lib/api-auth", () => ({
requireSession: vi.fn(),
}));
const { mockPlanFindFirst, mockMemberFindFirst, mockMemberFindMany, mockUserFindFirst, mockInsertValues, mockInsertPlanValues, mockDeleteWhere } = vi.hoisted(() => ({
mockPlanFindFirst: vi.fn(),
mockMemberFindFirst: vi.fn(),
mockMemberFindMany: vi.fn(),
mockUserFindFirst: vi.fn(),
mockInsertValues: vi.fn().mockResolvedValue(undefined),
mockInsertPlanValues: vi.fn().mockResolvedValue(undefined),
mockDeleteWhere: vi.fn().mockResolvedValue(undefined),
}));
vi.mock("@epicure/db", () => ({
db: {
query: {
mealPlans: { findFirst: mockPlanFindFirst },
mealPlanMembers: { findFirst: mockMemberFindFirst, findMany: mockMemberFindMany },
users: { findFirst: mockUserFindFirst },
},
insert: vi.fn(() => ({ values: mockInsertValues })),
delete: vi.fn(() => ({ where: mockDeleteWhere })),
},
mealPlans: { id: "id", userId: "user_id", weekStart: "week_start" },
mealPlanMembers: { id: "id", mealPlanId: "meal_plan_id", userId: "user_id" },
users: { id: "id", email: "email" },
eq: vi.fn((a, b) => ({ a, b, op: "eq" })),
and: vi.fn((...args) => ({ args, op: "and" })),
}));
const { requireSession } = await import("@/lib/api-auth");
import { GET, POST, DELETE } from "../route";
const ctx = { params: Promise.resolve({ weekStart: "2026-06-01" }) };
function makeRequest(method: string, body?: unknown, search = "") {
return new NextRequest(`http://localhost/api/v1/meal-plans/2026-06-01/members${search}`, {
method,
headers: { "Content-Type": "application/json" },
body: body ? JSON.stringify(body) : undefined,
});
}
beforeEach(() => {
vi.clearAllMocks();
vi.mocked(requireSession).mockResolvedValue({ session: mockSession as never, response: null });
});
describe("GET /api/v1/meal-plans/[weekStart]/members", () => {
it("returns an empty list when the owner has no plan for this week yet", async () => {
mockPlanFindFirst.mockResolvedValue(undefined);
const res = await GET(makeRequest("GET"), ctx);
expect(res.status).toBe(200);
expect(await res.json()).toEqual([]);
});
it("returns members for an existing plan", async () => {
mockPlanFindFirst.mockResolvedValue({ id: "plan-1", userId: "user-1" });
mockMemberFindMany.mockResolvedValue([
{ id: "m1", userId: "user-2", role: "editor", createdAt: new Date(), user: { name: "Bob", username: null, avatarUrl: null } },
]);
const res = await GET(makeRequest("GET"), ctx);
const body = await res.json() as unknown[];
expect(body).toHaveLength(1);
});
});
describe("POST /api/v1/meal-plans/[weekStart]/members", () => {
it("returns 400 on invalid body", async () => {
const res = await POST(makeRequest("POST", { role: "viewer" }), ctx);
expect(res.status).toBe(400);
});
it("returns 404 when the target user doesn't exist", async () => {
mockUserFindFirst.mockResolvedValue(undefined);
const res = await POST(makeRequest("POST", { email: "b@test.com", role: "viewer" }), ctx);
expect(res.status).toBe(404);
});
it("returns 400 when inviting yourself", async () => {
mockUserFindFirst.mockResolvedValue({ id: "user-1" });
const res = await POST(makeRequest("POST", { email: "a@test.com", role: "viewer" }), ctx);
expect(res.status).toBe(400);
});
it("auto-creates the plan for the week and invites the member", async () => {
mockUserFindFirst.mockResolvedValue({ id: "user-2" });
mockPlanFindFirst.mockResolvedValue(undefined); // no plan yet for this week
mockMemberFindFirst.mockResolvedValue(undefined);
const res = await POST(makeRequest("POST", { email: "b@test.com", role: "editor" }), ctx);
expect(res.status).toBe(201);
expect(mockInsertValues).toHaveBeenCalledWith(expect.objectContaining({ userId: "user-1", weekStart: "2026-06-01" }));
expect(mockInsertValues).toHaveBeenCalledWith(expect.objectContaining({ userId: "user-2", role: "editor" }));
});
it("returns 409 when already a member", async () => {
mockUserFindFirst.mockResolvedValue({ id: "user-2" });
mockPlanFindFirst.mockResolvedValue({ id: "plan-1", userId: "user-1", weekStart: "2026-06-01" });
mockMemberFindFirst.mockResolvedValue({ id: "existing" });
const res = await POST(makeRequest("POST", { email: "b@test.com", role: "viewer" }), ctx);
expect(res.status).toBe(409);
});
});
describe("DELETE /api/v1/meal-plans/[weekStart]/members", () => {
it("returns 400 when memberId is missing", async () => {
const res = await DELETE(makeRequest("DELETE"), ctx);
expect(res.status).toBe(400);
});
it("returns 404 when the owner has no plan for this week", async () => {
mockPlanFindFirst.mockResolvedValue(undefined);
const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
expect(res.status).toBe(404);
});
it("returns 403 when caller is neither owner nor the member themselves", async () => {
mockPlanFindFirst.mockResolvedValue({ id: "plan-1", userId: "user-1" });
mockMemberFindFirst.mockResolvedValue({ id: "m1", userId: "user-2" });
vi.mocked(requireSession).mockResolvedValue({ session: { user: { id: "user-3" } } as never, response: null });
const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
expect(res.status).toBe(403);
});
it("allows the owner to remove a member", async () => {
mockPlanFindFirst.mockResolvedValue({ id: "plan-1", userId: "user-1" });
mockMemberFindFirst.mockResolvedValue({ id: "m1", userId: "user-2" });
const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
expect(res.status).toBe(204);
});
});
@@ -0,0 +1,122 @@
import { NextRequest, NextResponse } from "next/server";
import { z } from "zod";
import { db, mealPlans, mealPlanMembers, users, eq, and } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
type Params = { params: Promise<{ weekStart: string }> };
async function getOrCreatePlan(userId: string, weekStart: string) {
const existing = await db.query.mealPlans.findFirst({
where: and(eq(mealPlans.userId, userId), eq(mealPlans.weekStart, weekStart)),
});
if (existing) return existing;
const id = crypto.randomUUID();
await db.insert(mealPlans).values({ id, userId, weekStart });
return { id, userId, weekStart, createdAt: new Date() };
}
// ─── GET /api/v1/meal-plans/[weekStart]/members ──────────────────────────────
// Owner only — returns members joined with basic user info.
export async function GET(_req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { weekStart } = await params;
const plan = await db.query.mealPlans.findFirst({
where: and(eq(mealPlans.userId, session!.user.id), eq(mealPlans.weekStart, weekStart)),
});
if (!plan) return NextResponse.json([]);
const members = await db.query.mealPlanMembers.findMany({
where: eq(mealPlanMembers.mealPlanId, plan.id),
with: { user: true },
});
return NextResponse.json(
members.map((m) => ({
id: m.id,
userId: m.userId,
role: m.role,
createdAt: m.createdAt,
user: { name: m.user.name, username: m.user.username, avatarUrl: m.user.avatarUrl },
}))
);
}
// ─── POST /api/v1/meal-plans/[weekStart]/members ─────────────────────────────
// Owner only — invite by email or userId. Auto-creates the plan for this week if missing.
const InviteSchema = z
.object({
email: z.string().email().optional(),
userId: z.string().optional(),
role: z.enum(["viewer", "editor"]),
})
.refine((d) => d.email !== undefined || d.userId !== undefined, {
message: "Provide either email or userId",
});
export async function POST(req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { weekStart } = await params;
const body = await req.json() as unknown;
const parsed = InviteSchema.safeParse(body);
if (!parsed.success) return NextResponse.json({ error: "Validation error" }, { status: 400 });
const { email, userId, role } = parsed.data;
const targetUser = await db.query.users.findFirst({
where: email ? eq(users.email, email) : eq(users.id, userId!),
});
if (!targetUser) return NextResponse.json({ error: "User not found" }, { status: 404 });
if (targetUser.id === session!.user.id) {
return NextResponse.json({ error: "Cannot invite yourself" }, { status: 400 });
}
const plan = await getOrCreatePlan(session!.user.id, weekStart);
const existing = await db.query.mealPlanMembers.findFirst({
where: and(eq(mealPlanMembers.mealPlanId, plan.id), eq(mealPlanMembers.userId, targetUser.id)),
});
if (existing) return NextResponse.json({ error: "Already a member" }, { status: 409 });
const memberId = crypto.randomUUID();
await db.insert(mealPlanMembers).values({
id: memberId,
mealPlanId: plan.id,
userId: targetUser.id,
role,
});
return NextResponse.json({ id: memberId, mealPlanId: plan.id }, { status: 201 });
}
// ─── DELETE /api/v1/meal-plans/[weekStart]/members?memberId=… ────────────────
// Owner OR the member themselves can remove.
export async function DELETE(req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { weekStart } = await params;
const memberId = req.nextUrl.searchParams.get("memberId");
if (!memberId) return NextResponse.json({ error: "memberId required" }, { status: 400 });
const plan = await db.query.mealPlans.findFirst({
where: and(eq(mealPlans.userId, session!.user.id), eq(mealPlans.weekStart, weekStart)),
});
if (!plan) return NextResponse.json({ error: "Not found" }, { status: 404 });
const member = await db.query.mealPlanMembers.findFirst({
where: and(eq(mealPlanMembers.id, memberId), eq(mealPlanMembers.mealPlanId, plan.id)),
});
if (!member) return NextResponse.json({ error: "Not found" }, { status: 404 });
const isOwner = plan.userId === session!.user.id;
const isSelf = member.userId === session!.user.id;
if (!isOwner && !isSelf) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
await db.delete(mealPlanMembers).where(eq(mealPlanMembers.id, memberId));
return new NextResponse(null, { status: 204 });
}
@@ -0,0 +1,104 @@
import { describe, it, expect, vi, beforeEach } from "vitest";
import { NextRequest } from "next/server";
const mockSession = { user: { id: "user-2" } };
vi.mock("@/lib/api-auth", () => ({
requireSession: vi.fn(),
}));
vi.mock("@/lib/webhooks", () => ({
dispatchWebhook: vi.fn(),
}));
const { mockPlanFindFirst, mockMemberFindFirst, mockRecipeFindFirst, mockInsertValues, mockDeleteWhere } = vi.hoisted(() => ({
mockPlanFindFirst: vi.fn(),
mockMemberFindFirst: vi.fn(),
mockRecipeFindFirst: vi.fn(),
mockInsertValues: vi.fn().mockResolvedValue(undefined),
mockDeleteWhere: vi.fn().mockResolvedValue(undefined),
}));
vi.mock("@epicure/db", () => ({
db: {
query: {
mealPlans: { findFirst: mockPlanFindFirst },
mealPlanMembers: { findFirst: mockMemberFindFirst },
recipes: { findFirst: mockRecipeFindFirst },
},
insert: vi.fn(() => ({ values: mockInsertValues })),
delete: vi.fn(() => ({ where: mockDeleteWhere })),
},
mealPlans: { id: "id", userId: "user_id" },
mealPlanMembers: { mealPlanId: "meal_plan_id", userId: "user_id" },
mealPlanEntries: { id: "id", mealPlanId: "meal_plan_id", day: "day", mealType: "meal_type" },
recipes: { id: "id", authorId: "author_id", visibility: "visibility" },
eq: vi.fn((a, b) => ({ a, b, op: "eq" })),
and: vi.fn((...args) => ({ args, op: "and" })),
or: vi.fn((...args) => ({ args, op: "or" })),
ne: vi.fn((a, b) => ({ a, b, op: "ne" })),
}));
const { requireSession } = await import("@/lib/api-auth");
import { POST, DELETE } from "../route";
const ctx = { params: Promise.resolve({ mealPlanId: "plan-1" }) };
function makeRequest(method: string, body?: unknown, search = "") {
return new NextRequest(`http://localhost/api/v1/meal-plans/shared/plan-1/entries${search}`, {
method,
headers: { "Content-Type": "application/json" },
body: body ? JSON.stringify(body) : undefined,
});
}
beforeEach(() => {
vi.clearAllMocks();
vi.mocked(requireSession).mockResolvedValue({ session: mockSession as never, response: null });
mockPlanFindFirst.mockResolvedValue({ id: "plan-1", userId: "user-1" });
});
const validBody = { day: "mon", mealType: "dinner", recipeId: "r-1", servings: 2 };
describe("POST /api/v1/meal-plans/shared/[mealPlanId]/entries", () => {
it("returns 404 when the caller has no access to the plan", async () => {
mockMemberFindFirst.mockResolvedValue(undefined);
const res = await POST(makeRequest("POST", validBody), ctx);
expect(res.status).toBe(404);
});
it("returns 403 for a viewer trying to add an entry", async () => {
mockMemberFindFirst.mockResolvedValue({ role: "viewer" });
const res = await POST(makeRequest("POST", validBody), ctx);
expect(res.status).toBe(403);
});
it("allows an editor to add an entry", async () => {
mockMemberFindFirst.mockResolvedValue({ role: "editor" });
mockRecipeFindFirst.mockResolvedValue({ id: "r-1" });
const res = await POST(makeRequest("POST", validBody), ctx);
expect(res.status).toBe(201);
expect(mockInsertValues).toHaveBeenCalledWith(expect.objectContaining({ mealPlanId: "plan-1", day: "mon" }));
});
it("returns 404 when the recipe isn't accessible to the editor", async () => {
mockMemberFindFirst.mockResolvedValue({ role: "editor" });
mockRecipeFindFirst.mockResolvedValue(undefined);
const res = await POST(makeRequest("POST", validBody), ctx);
expect(res.status).toBe(404);
});
});
describe("DELETE /api/v1/meal-plans/shared/[mealPlanId]/entries", () => {
it("returns 403 for a viewer trying to remove an entry", async () => {
mockMemberFindFirst.mockResolvedValue({ role: "viewer" });
const res = await DELETE(makeRequest("DELETE", undefined, "?entryId=e1"), ctx);
expect(res.status).toBe(403);
});
it("allows an editor to remove an entry", async () => {
mockMemberFindFirst.mockResolvedValue({ role: "editor" });
const res = await DELETE(makeRequest("DELETE", undefined, "?entryId=e1"), ctx);
expect(res.status).toBe(204);
});
});
@@ -0,0 +1,81 @@
import { NextRequest, NextResponse } from "next/server";
import { z } from "zod";
import { db, mealPlanEntries, recipes, eq, and, or, ne } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
import { getMealPlanAccessById, canWriteMealPlan } from "@/lib/meal-plan-access";
import { dispatchWebhook } from "@/lib/webhooks";
type Params = { params: Promise<{ mealPlanId: string }> };
const Schema = z.object({
day: z.enum(["mon", "tue", "wed", "thu", "fri", "sat", "sun"]),
mealType: z.enum(["breakfast", "lunch", "dinner", "snack"]),
recipeId: z.string().optional(),
servings: z.number().int().min(1).max(100).default(2),
note: z.string().max(500).optional(),
});
export async function POST(req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { mealPlanId } = await params;
const access = await getMealPlanAccessById(mealPlanId, session!.user.id);
if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
if (!canWriteMealPlan(access.role)) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
const body = await req.json() as unknown;
const parsed = Schema.safeParse(body);
if (!parsed.success) return NextResponse.json({ error: "Validation error" }, { status: 400 });
if (parsed.data.recipeId) {
const recipe = await db.query.recipes.findFirst({
where: and(
eq(recipes.id, parsed.data.recipeId),
or(eq(recipes.authorId, session!.user.id), ne(recipes.visibility, "private"))
),
});
if (!recipe) return NextResponse.json({ error: "Recipe not found" }, { status: 404 });
}
await db.delete(mealPlanEntries).where(
and(
eq(mealPlanEntries.mealPlanId, mealPlanId),
eq(mealPlanEntries.day, parsed.data.day),
eq(mealPlanEntries.mealType, parsed.data.mealType)
)
);
const entryId = crypto.randomUUID();
await db.insert(mealPlanEntries).values({
id: entryId,
mealPlanId,
day: parsed.data.day,
mealType: parsed.data.mealType,
recipeId: parsed.data.recipeId,
servings: parsed.data.servings,
note: parsed.data.note,
});
void dispatchWebhook(access.plan.userId, "meal_plan.updated", { mealPlanId, day: parsed.data.day, mealType: parsed.data.mealType });
return NextResponse.json({ id: entryId }, { status: 201 });
}
export async function DELETE(req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { mealPlanId } = await params;
const access = await getMealPlanAccessById(mealPlanId, session!.user.id);
if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
if (!canWriteMealPlan(access.role)) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
const entryId = req.nextUrl.searchParams.get("entryId");
if (!entryId) return NextResponse.json({ error: "entryId required" }, { status: 400 });
await db.delete(mealPlanEntries).where(
and(eq(mealPlanEntries.id, entryId), eq(mealPlanEntries.mealPlanId, mealPlanId))
);
return new NextResponse(null, { status: 204 });
}
@@ -0,0 +1,27 @@
import { NextRequest, NextResponse } from "next/server";
import { db, mealPlans, users, eq } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
import { getMealPlanAccessById } from "@/lib/meal-plan-access";
type Params = { params: Promise<{ mealPlanId: string }> };
export async function GET(_req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { mealPlanId } = await params;
const access = await getMealPlanAccessById(mealPlanId, session!.user.id);
if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
const plan = await db.query.mealPlans.findFirst({
where: eq(mealPlans.id, mealPlanId),
with: {
entries: { with: { recipe: { with: { photos: true } } } },
},
});
if (!plan) return NextResponse.json({ error: "Not found" }, { status: 404 });
const owner = await db.query.users.findFirst({ where: eq(users.id, plan.userId) });
return NextResponse.json({ ...plan, role: access.role, owner: owner ? { name: owner.name } : null });
}
@@ -0,0 +1,33 @@
import { NextRequest, NextResponse } from "next/server";
import { db, shoppingLists, eq } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
import { getShoppingListAccess } from "@/lib/shopping-list-access";
import { buildGroceryExportPayload } from "@/lib/grocery-export";
import { createInstacartShoppingListLink } from "@/lib/grocery-providers/instacart";
type Params = { params: Promise<{ id: string }> };
export async function POST(_req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { id } = await params;
const access = await getShoppingListAccess(id, session!.user.id);
if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
const list = await db.query.shoppingLists.findFirst({
where: eq(shoppingLists.id, id),
with: { items: true },
});
if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
const payload = buildGroceryExportPayload(list);
try {
const result = await createInstacartShoppingListLink(payload);
if (!result) return NextResponse.json({ error: "Instacart is not configured" }, { status: 501 });
return NextResponse.json(result);
} catch (err) {
return NextResponse.json({ error: String(err instanceof Error ? err.message : err) }, { status: 501 });
}
}
@@ -0,0 +1,25 @@
import { NextRequest, NextResponse } from "next/server";
import { db, shoppingLists, eq } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
import { getShoppingListAccess } from "@/lib/shopping-list-access";
import { buildGroceryExportPayload } from "@/lib/grocery-export";
type Params = { params: Promise<{ id: string }> };
export async function GET(_req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { id } = await params;
const access = await getShoppingListAccess(id, session!.user.id);
if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
const list = await db.query.shoppingLists.findFirst({
where: eq(shoppingLists.id, id),
with: { items: true },
});
if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
const payload = buildGroceryExportPayload(list);
return NextResponse.json(payload);
}
@@ -1,6 +1,7 @@
import { NextRequest, NextResponse } from "next/server";
import { db, shoppingLists, shoppingListItems, eq, and } from "@epicure/db";
import { db, shoppingListItems, eq, and } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
import { getShoppingListAccess, canWriteShoppingList } from "@/lib/shopping-list-access";
type Params = { params: Promise<{ id: string; itemId: string }> };
@@ -9,10 +10,9 @@ export async function PUT(req: NextRequest, { params }: Params) {
if (response) return response;
const { id, itemId } = await params;
const list = await db.query.shoppingLists.findFirst({
where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
});
if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
const access = await getShoppingListAccess(id, session!.user.id);
if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
if (!canWriteShoppingList(access.role)) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
const body = await req.json() as { checked?: boolean };
await db.update(shoppingListItems)
@@ -1,7 +1,8 @@
import { NextRequest, NextResponse } from "next/server";
import { z } from "zod";
import { db, shoppingLists, shoppingListItems, eq, and } from "@epicure/db";
import { db, shoppingListItems } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
import { getShoppingListAccess, canWriteShoppingList } from "@/lib/shopping-list-access";
const AddItemsSchema = z.object({
items: z.array(z.object({
@@ -19,10 +20,9 @@ export async function POST(req: NextRequest, { params }: Params) {
if (response) return response;
const { id } = await params;
const list = await db.query.shoppingLists.findFirst({
where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
});
if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
const access = await getShoppingListAccess(id, session!.user.id);
if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
if (!canWriteShoppingList(access.role)) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
const body = await req.json() as unknown;
const parsed = AddItemsSchema.safeParse(body);
@@ -0,0 +1,149 @@
import { describe, it, expect, vi, beforeEach } from "vitest";
import { NextRequest } from "next/server";
const mockSession = { user: { id: "user-1" } };
vi.mock("@/lib/api-auth", () => ({
requireSession: vi.fn(),
}));
const { mockListFindFirst, mockMemberFindFirst, mockMemberFindMany, mockUserFindFirst, mockInsertValues, mockDeleteWhere } = vi.hoisted(() => ({
mockListFindFirst: vi.fn(),
mockMemberFindFirst: vi.fn(),
mockMemberFindMany: vi.fn(),
mockUserFindFirst: vi.fn(),
mockInsertValues: vi.fn().mockResolvedValue(undefined),
mockDeleteWhere: vi.fn().mockResolvedValue(undefined),
}));
vi.mock("@epicure/db", () => ({
db: {
query: {
shoppingLists: { findFirst: mockListFindFirst },
shoppingListMembers: { findFirst: mockMemberFindFirst, findMany: mockMemberFindMany },
users: { findFirst: mockUserFindFirst },
},
insert: vi.fn(() => ({ values: mockInsertValues })),
delete: vi.fn(() => ({ where: mockDeleteWhere })),
},
shoppingLists: { id: "id", userId: "user_id" },
shoppingListMembers: { id: "id", listId: "list_id", userId: "user_id" },
users: { id: "id", email: "email" },
eq: vi.fn((a, b) => ({ a, b, op: "eq" })),
and: vi.fn((...args) => ({ args, op: "and" })),
}));
const { requireSession } = await import("@/lib/api-auth");
import { GET, POST, DELETE } from "../route";
const ctx = { params: Promise.resolve({ id: "list-1" }) };
function makeRequest(method: string, body?: unknown, search = "") {
return new NextRequest(`http://localhost/api/v1/shopping-lists/list-1/members${search}`, {
method,
headers: { "Content-Type": "application/json" },
body: body ? JSON.stringify(body) : undefined,
});
}
beforeEach(() => {
vi.clearAllMocks();
vi.mocked(requireSession).mockResolvedValue({ session: mockSession as never, response: null });
});
describe("GET /api/v1/shopping-lists/[id]/members", () => {
it("returns 404 when the caller is not the owner", async () => {
mockListFindFirst.mockResolvedValue(undefined);
const res = await GET(makeRequest("GET"), ctx);
expect(res.status).toBe(404);
});
it("returns the member list for the owner", async () => {
mockListFindFirst.mockResolvedValue({ id: "list-1", userId: "user-1" });
mockMemberFindMany.mockResolvedValue([
{ id: "m1", userId: "user-2", role: "viewer", createdAt: new Date(), user: { name: "Bob", username: "bob", avatarUrl: null } },
]);
const res = await GET(makeRequest("GET"), ctx);
expect(res.status).toBe(200);
const body = await res.json() as unknown[];
expect(body).toHaveLength(1);
});
});
describe("POST /api/v1/shopping-lists/[id]/members", () => {
beforeEach(() => {
mockListFindFirst.mockResolvedValue({ id: "list-1", userId: "user-1" });
});
it("returns 404 when the caller is not the owner", async () => {
mockListFindFirst.mockResolvedValue(undefined);
const res = await POST(makeRequest("POST", { email: "b@test.com", role: "viewer" }), ctx);
expect(res.status).toBe(404);
});
it("returns 400 on invalid body", async () => {
const res = await POST(makeRequest("POST", { role: "viewer" }), ctx);
expect(res.status).toBe(400);
});
it("returns 404 when the target user doesn't exist", async () => {
mockUserFindFirst.mockResolvedValue(undefined);
const res = await POST(makeRequest("POST", { email: "b@test.com", role: "viewer" }), ctx);
expect(res.status).toBe(404);
});
it("returns 400 when inviting yourself", async () => {
mockUserFindFirst.mockResolvedValue({ id: "user-1", email: "a@test.com" });
const res = await POST(makeRequest("POST", { email: "a@test.com", role: "viewer" }), ctx);
expect(res.status).toBe(400);
});
it("returns 409 when already a member", async () => {
mockUserFindFirst.mockResolvedValue({ id: "user-2", email: "b@test.com" });
mockMemberFindFirst.mockResolvedValue({ id: "existing" });
const res = await POST(makeRequest("POST", { email: "b@test.com", role: "viewer" }), ctx);
expect(res.status).toBe(409);
});
it("creates the membership on success", async () => {
mockUserFindFirst.mockResolvedValue({ id: "user-2", email: "b@test.com" });
mockMemberFindFirst.mockResolvedValue(undefined);
const res = await POST(makeRequest("POST", { email: "b@test.com", role: "editor" }), ctx);
expect(res.status).toBe(201);
expect(mockInsertValues).toHaveBeenCalledWith(expect.objectContaining({ listId: "list-1", userId: "user-2", role: "editor" }));
});
});
describe("DELETE /api/v1/shopping-lists/[id]/members", () => {
it("returns 400 when memberId is missing", async () => {
const res = await DELETE(makeRequest("DELETE"), ctx);
expect(res.status).toBe(400);
});
it("returns 404 when the member doesn't exist", async () => {
mockMemberFindFirst.mockResolvedValue(undefined);
const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
expect(res.status).toBe(404);
});
it("returns 403 when caller is neither owner nor the member themselves", async () => {
mockMemberFindFirst.mockResolvedValue({ id: "m1", userId: "user-2" });
mockListFindFirst.mockResolvedValue({ id: "list-1", userId: "user-3" });
const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
expect(res.status).toBe(403);
});
it("allows the owner to remove a member", async () => {
mockMemberFindFirst.mockResolvedValue({ id: "m1", userId: "user-2" });
mockListFindFirst.mockResolvedValue({ id: "list-1", userId: "user-1" });
const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
expect(res.status).toBe(204);
});
it("allows a member to remove themselves", async () => {
mockMemberFindFirst.mockResolvedValue({ id: "m1", userId: "user-1" });
mockListFindFirst.mockResolvedValue({ id: "list-1", userId: "user-3" });
const res = await DELETE(makeRequest("DELETE", undefined, "?memberId=m1"), ctx);
expect(res.status).toBe(204);
});
});
@@ -0,0 +1,127 @@
import { NextRequest, NextResponse } from "next/server";
import { z } from "zod";
import { db, shoppingLists, shoppingListMembers, users, eq, and } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
type Params = { params: Promise<{ id: string }> };
// ─── GET /api/v1/shopping-lists/[id]/members ─────────────────────────────────
// Owner only — returns members joined with basic user info.
export async function GET(_req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { id } = await params;
const list = await db.query.shoppingLists.findFirst({
where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
});
if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
const members = await db.query.shoppingListMembers.findMany({
where: eq(shoppingListMembers.listId, id),
with: { user: true },
});
const result = members.map((m) => ({
id: m.id,
userId: m.userId,
role: m.role,
createdAt: m.createdAt,
user: {
name: m.user.name,
username: m.user.username,
avatarUrl: m.user.avatarUrl,
},
}));
return NextResponse.json(result);
}
// ─── POST /api/v1/shopping-lists/[id]/members ────────────────────────────────
// Owner only — invite by email or userId.
const InviteSchema = z
.object({
email: z.string().email().optional(),
userId: z.string().optional(),
role: z.enum(["viewer", "editor"]),
})
.refine((d) => d.email !== undefined || d.userId !== undefined, {
message: "Provide either email or userId",
});
export async function POST(req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { id } = await params;
const list = await db.query.shoppingLists.findFirst({
where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
});
if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
const body = await req.json() as unknown;
const parsed = InviteSchema.safeParse(body);
if (!parsed.success) return NextResponse.json({ error: "Validation error" }, { status: 400 });
const { email, userId, role } = parsed.data;
const targetUser = await db.query.users.findFirst({
where: email ? eq(users.email, email) : eq(users.id, userId!),
});
if (!targetUser) return NextResponse.json({ error: "User not found" }, { status: 404 });
if (targetUser.id === session!.user.id) {
return NextResponse.json({ error: "Cannot invite yourself" }, { status: 400 });
}
const existing = await db.query.shoppingListMembers.findFirst({
where: and(
eq(shoppingListMembers.listId, id),
eq(shoppingListMembers.userId, targetUser.id),
),
});
if (existing) return NextResponse.json({ error: "Already a member" }, { status: 409 });
const memberId = crypto.randomUUID();
await db.insert(shoppingListMembers).values({
id: memberId,
listId: id,
userId: targetUser.id,
role,
});
return NextResponse.json({ id: memberId }, { status: 201 });
}
// ─── DELETE /api/v1/shopping-lists/[id]/members?memberId=… ───────────────────
// Owner OR the member themselves can remove.
export async function DELETE(req: NextRequest, { params }: Params) {
const { session, response } = await requireSession();
if (response) return response;
const { id } = await params;
const memberId = req.nextUrl.searchParams.get("memberId");
if (!memberId) return NextResponse.json({ error: "memberId required" }, { status: 400 });
const member = await db.query.shoppingListMembers.findFirst({
where: and(eq(shoppingListMembers.id, memberId), eq(shoppingListMembers.listId, id)),
});
if (!member) return NextResponse.json({ error: "Not found" }, { status: 404 });
const list = await db.query.shoppingLists.findFirst({
where: eq(shoppingLists.id, id),
});
const isOwner = list?.userId === session!.user.id;
const isSelf = member.userId === session!.user.id;
if (!isOwner && !isSelf) {
return NextResponse.json({ error: "Forbidden" }, { status: 403 });
}
await db.delete(shoppingListMembers).where(eq(shoppingListMembers.id, memberId));
return new NextResponse(null, { status: 204 });
}
@@ -1,8 +1,9 @@
import { NextRequest, NextResponse } from "next/server";
import { z } from "zod";
import { db, shoppingLists, shoppingListItems, eq, and } from "@epicure/db";
import { db, shoppingLists, shoppingListItems, eq } from "@epicure/db";
import { requireSession } from "@/lib/api-auth";
import { dispatchWebhook } from "@/lib/webhooks";
import { getShoppingListAccess, canWriteShoppingList } from "@/lib/shopping-list-access";
type Params = { params: Promise<{ id: string }> };
@@ -11,12 +12,14 @@ export async function GET(_req: NextRequest, { params }: Params) {
if (response) return response;
const { id } = await params;
const access = await getShoppingListAccess(id, session!.user.id);
if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
const list = await db.query.shoppingLists.findFirst({
where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
where: eq(shoppingLists.id, id),
with: { items: { orderBy: (t, { asc }) => [asc(t.aisle), asc(t.rawName)] } },
});
if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
return NextResponse.json(list);
}
@@ -27,10 +30,9 @@ export async function PATCH(req: NextRequest, { params }: Params) {
if (response) return response;
const { id } = await params;
const list = await db.query.shoppingLists.findFirst({
where: and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)),
});
if (!list) return NextResponse.json({ error: "Not found" }, { status: 404 });
const access = await getShoppingListAccess(id, session!.user.id);
if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
if (!canWriteShoppingList(access.role)) return NextResponse.json({ error: "Forbidden" }, { status: 403 });
const body = PatchSchema.safeParse(await req.json());
if (!body.success) return NextResponse.json({ error: "Validation error" }, { status: 400 });
@@ -38,7 +40,7 @@ export async function PATCH(req: NextRequest, { params }: Params) {
if (body.data.completed) {
// Mark all items as checked
await db.update(shoppingListItems).set({ checked: true }).where(eq(shoppingListItems.listId, id));
void dispatchWebhook(session!.user.id, "shopping_list.completed", { id, name: list.name });
void dispatchWebhook(session!.user.id, "shopping_list.completed", { id, name: access.list.name });
}
return NextResponse.json({ updated: true });
@@ -49,6 +51,10 @@ export async function DELETE(_req: NextRequest, { params }: Params) {
if (response) return response;
const { id } = await params;
await db.delete(shoppingLists).where(and(eq(shoppingLists.id, id), eq(shoppingLists.userId, session!.user.id)));
const access = await getShoppingListAccess(id, session!.user.id);
if (!access) return NextResponse.json({ error: "Not found" }, { status: 404 });
if (access.role !== "owner") return NextResponse.json({ error: "Forbidden" }, { status: 403 });
await db.delete(shoppingLists).where(eq(shoppingLists.id, id));
return new NextResponse(null, { status: 204 });
}
+6 -1
View File
@@ -1,4 +1,4 @@
import type { Metadata } from "next";
import type { Metadata, Viewport } from "next";
import { Lora, Geist_Mono } from "next/font/google";
import { headers } from "next/headers";
import { Providers } from "@/components/providers";
@@ -21,6 +21,11 @@ const geistMono = Geist_Mono({
export const metadata: Metadata = {
title: { default: "Epicure", template: "%s | Epicure" },
description: "Your personal AI-powered recipe book.",
manifest: "/manifest.json",
};
export const viewport: Viewport = {
themeColor: "#18181b",
};
export default async function RootLayout({
+148
View File
@@ -0,0 +1,148 @@
import { notFound } from "next/navigation";
import { headers } from "next/headers";
import { auth } from "@/lib/auth/server";
import { db, collections, eq, and, or } from "@epicure/db";
import { PrintTrigger } from "@/components/recipe/print-trigger";
import { hasQuantity } from "@/lib/fractions";
import { getMessages, formatMessage } from "@/lib/i18n/server";
type Params = { params: Promise<{ id: string }> };
export default async function CollectionPrintPage({ params }: Params) {
const { id } = await params;
const session = await auth.api.getSession({ headers: await headers() });
if (!session) return null;
const m = getMessages((session.user as { locale?: string }).locale);
const col = await db.query.collections.findFirst({
where: and(
eq(collections.id, id),
or(eq(collections.userId, session.user.id), eq(collections.isPublic, true))
),
with: {
recipes: {
with: {
recipe: {
with: {
ingredients: { orderBy: (t, { asc }) => asc(t.order) },
steps: { orderBy: (t, { asc }) => asc(t.order) },
},
},
},
},
},
});
if (!col) notFound();
const recipeEntries = col.recipes.filter((r) => r.recipe !== null);
return (
<>
<style>{`
@media print {
body { margin: 0; }
.no-print { display: none !important; }
article { page-break-after: always; }
article:last-child { page-break-after: auto; }
}
body {
font-family: Georgia, 'Times New Roman', serif;
color: #1a1a1a;
max-width: 680px;
margin: 40px auto;
padding: 0 24px;
font-size: 14px;
line-height: 1.6;
}
h1 { font-size: 2em; margin: 0 0 8px; line-height: 1.2; }
h2 { font-size: 1.1em; text-transform: uppercase; letter-spacing: 0.08em; border-bottom: 1px solid #ccc; padding-bottom: 4px; margin: 24px 0 12px; }
.meta { display: flex; gap: 24px; font-size: 0.85em; color: #555; margin: 12px 0 16px; flex-wrap: wrap; }
.meta span { display: flex; align-items: center; gap: 4px; }
.description { color: #444; font-style: italic; margin-bottom: 16px; }
ul.ingredients { list-style: none; padding: 0; margin: 0; display: grid; grid-template-columns: 1fr 1fr; gap: 4px 24px; }
ul.ingredients li { padding: 4px 0; border-bottom: 1px dotted #e0e0e0; font-family: system-ui, sans-serif; font-size: 0.9em; }
ul.ingredients li .qty { color: #666; min-width: 60px; display: inline-block; }
ol.steps { padding-left: 20px; margin: 0; }
ol.steps li { padding: 6px 0 6px 4px; border-bottom: 1px dotted #e0e0e0; font-size: 0.95em; }
ol.steps li:last-child { border-bottom: none; }
.timer { font-size: 0.85em; color: #666; font-family: system-ui, sans-serif; margin-left: 8px; }
.cookbook-cover { text-align: center; margin-bottom: 40px; }
.cookbook-cover h1 { font-size: 2.6em; }
footer { margin-top: 40px; font-size: 0.75em; color: #aaa; text-align: center; font-family: system-ui, sans-serif; }
.print-btn {
position: fixed; top: 16px; right: 16px; padding: 8px 16px;
background: #18181b; color: white; border: none; border-radius: 6px;
cursor: pointer; font-size: 13px; font-family: system-ui, sans-serif;
}
.print-btn:hover { background: #3f3f46; }
`}</style>
<PrintTrigger />
<div className="cookbook-cover">
<h1>{col.name}</h1>
{col.description && <p className="description">{col.description}</p>}
<p style={{ fontFamily: "system-ui, sans-serif", fontSize: "0.85em", color: "#888" }}>
{recipeEntries.length} recipe{recipeEntries.length !== 1 ? "s" : ""}
</p>
</div>
{recipeEntries.map(({ recipe }) => {
if (!recipe) return null;
const totalMins = (recipe.prepMins ?? 0) + (recipe.cookMins ?? 0);
return (
<article key={recipe.id}>
<h1>{recipe.title}</h1>
{recipe.description && <p className="description">{recipe.description}</p>}
<div className="meta">
{recipe.baseServings && <span>{formatMessage(m.recipe.servings, { count: recipe.baseServings })}</span>}
{recipe.prepMins && <span>{formatMessage(m.recipe.prep, { mins: recipe.prepMins })}</span>}
{recipe.cookMins && <span>{formatMessage(m.recipe.cook, { mins: recipe.cookMins })}</span>}
{totalMins > 0 && <span>{formatMessage(m.recipe.total, { mins: totalMins })}</span>}
{recipe.difficulty && <span>{recipe.difficulty.charAt(0).toUpperCase() + recipe.difficulty.slice(1)}</span>}
</div>
{recipe.ingredients.length > 0 && (
<>
<h2>{m.recipe.ingredients}</h2>
<ul className="ingredients">
{recipe.ingredients.map((ing) => (
<li key={ing.id}>
<span className="qty">
{[hasQuantity(ing.quantity) ? ing.quantity : null, ing.unit].filter(Boolean).join(" ")}
</span>
{ing.rawName}
{ing.note && <span style={{ color: "#888" }}> ({ing.note})</span>}
</li>
))}
</ul>
</>
)}
{recipe.steps.length > 0 && (
<>
<h2>{m.recipe.instructions}</h2>
<ol className="steps">
{recipe.steps.map((step) => (
<li key={step.id}>
{step.instruction}
{step.timerSeconds && (
<span className="timer"> {Math.floor(step.timerSeconds / 60)} min</span>
)}
</li>
))}
</ol>
</>
)}
</article>
);
})}
<footer>{m.print.footer}</footer>
</>
);
}