feat: collections overhaul — reorder, search, edit/delete, tags (v0.53.0)

Seven related improvements to collections:

- Drag-and-drop reorder (dnd-kit, same pattern as the shopping list) — new
  collection_recipes.position column (migration 0049, backfilled from
  existing added_at order so nothing jumps around on upgrade).
- Search collections by name/description (server-side, list page) and
  search recipes within a collection (client-side filter, already loaded).
- Edit collection: name/description/tags/private notes via a new dialog;
  new collections.notes + collections.tags columns.
- Delete collection with a choice to also delete its recipes — only ones
  the deleting user actually owns, never recipes shared in by others.
- Collection detail (both owner and public view) now renders the same
  RecipeGridCard used on /recipes, instead of the older, plainer RecipeCard.
- Collection list cards redesigned — photo-collage preview (first 4 recipe
  covers/placeholders), tag badges, cleaner layout.
- Fixed the recipe count shown on a collection card: the query capped the
  `recipes` relation at 1 for thumbnail purposes and then read `.length`
  off that same capped array, so it never showed more than 1. Now a
  proper grouped count query, separate from the thumbnail fetch.

New/changed endpoints documented in OpenAPI: PATCH /collections/{id}/reorder,
DELETE /collections/{id}?deleteRecipes, PUT /collections/{id}'s new
notes/tags fields.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Arnaud
2026-07-19 18:44:08 +02:00
parent 5403a06348
commit e8c687e53a
19 changed files with 6300 additions and 82 deletions
@@ -0,0 +1,44 @@
import { NextRequest, NextResponse } from "next/server";
import { z } from "zod";
import { db, collections, collectionRecipes, eq, and, inArray } from "@epicure/db";
import { requireSessionOrApiKey } from "@/lib/api-auth";
type Params = { params: Promise<{ id: string }> };
const Schema = z.object({
recipeIds: z.array(z.string()).min(1).max(500),
});
export async function PATCH(req: NextRequest, { params }: Params) {
const { session, response } = await requireSessionOrApiKey(req);
if (response) return response;
const { id } = await params;
const existing = await db.query.collections.findFirst({
where: and(eq(collections.id, id), eq(collections.userId, session!.user.id)),
});
if (!existing) return NextResponse.json({ error: "Not found" }, { status: 404 });
const body = await req.json() as unknown;
const parsed = Schema.safeParse(body);
if (!parsed.success) return NextResponse.json({ error: "Validation error", issues: parsed.error.issues }, { status: 400 });
const current = await db.query.collectionRecipes.findMany({
where: eq(collectionRecipes.collectionId, id),
columns: { recipeId: true },
});
const currentIds = new Set(current.map((r) => r.recipeId));
const requestedIds = parsed.data.recipeIds.filter((rid) => currentIds.has(rid));
if (requestedIds.length === 0) return NextResponse.json({ error: "No matching recipes in this collection" }, { status: 400 });
await db.transaction(async (tx) => {
for (let i = 0; i < requestedIds.length; i++) {
await tx
.update(collectionRecipes)
.set({ position: i })
.where(and(eq(collectionRecipes.collectionId, id), inArray(collectionRecipes.recipeId, [requestedIds[i]!])));
}
});
return NextResponse.json({ ok: true });
}
+49 -4
View File
@@ -1,7 +1,8 @@
import { NextRequest, NextResponse } from "next/server";
import { z } from "zod";
import { db, collections, collectionRecipes, recipes, eq, and, or, ne, inArray } from "@epicure/db";
import { db, collections, collectionRecipes, recipes, ratings, eq, and, or, ne, inArray, isNotNull, sql } from "@epicure/db";
import { requireSessionOrApiKey } from "@/lib/api-auth";
import { deleteObject } from "@/lib/storage";
type Params = { params: Promise<{ id: string }> };
@@ -32,7 +33,9 @@ export async function PUT(req: NextRequest, { params }: Params) {
const body = await req.json() as unknown;
const parsed = z.object({
name: z.string().min(1).max(100).optional(),
description: z.string().max(500).optional(),
description: z.string().max(500).nullable().optional(),
notes: z.string().max(2000).nullable().optional(),
tags: z.array(z.string().min(1).max(50)).max(20).optional(),
isPublic: z.boolean().optional(),
addRecipeId: z.string().optional(),
addRecipeIds: z.array(z.string()).max(200).optional(),
@@ -42,10 +45,12 @@ export async function PUT(req: NextRequest, { params }: Params) {
if (!parsed.success) return NextResponse.json({ error: "Validation error" }, { status: 400 });
const data = parsed.data;
if (data.name || data.description !== undefined || data.isPublic !== undefined) {
if (data.name || data.description !== undefined || data.notes !== undefined || data.tags !== undefined || data.isPublic !== undefined) {
await db.update(collections).set({
...(data.name && { name: data.name }),
...(data.description !== undefined && { description: data.description }),
...(data.notes !== undefined && { notes: data.notes }),
...(data.tags !== undefined && { tags: data.tags }),
...(data.isPublic !== undefined && { isPublic: data.isPublic }),
updatedAt: new Date(),
}).where(eq(collections.id, id));
@@ -61,8 +66,13 @@ export async function PUT(req: NextRequest, { params }: Params) {
columns: { id: true },
});
if (owned.length > 0) {
const [maxPositionRow] = await db
.select({ max: sql<number | null>`max(${collectionRecipes.position})` })
.from(collectionRecipes)
.where(eq(collectionRecipes.collectionId, id));
let nextPosition = (maxPositionRow?.max ?? -1) + 1;
await db.insert(collectionRecipes)
.values(owned.map((r) => ({ collectionId: id, recipeId: r.id })))
.values(owned.map((r) => ({ collectionId: id, recipeId: r.id, position: nextPosition++ })))
.onConflictDoNothing();
}
}
@@ -87,6 +97,41 @@ export async function DELETE(req: NextRequest, { params }: Params) {
});
if (!existing) return NextResponse.json({ error: "Not found" }, { status: 404 });
const deleteRecipes = req.nextUrl.searchParams.get("deleteRecipes") === "true";
if (deleteRecipes) {
// Only recipes this user actually owns — a collection can contain other
// people's (non-private) recipes added via sharing/collab, and those
// must never be deleted just because this user deletes their collection.
const owned = await db.query.collectionRecipes.findMany({
where: eq(collectionRecipes.collectionId, id),
with: { recipe: { columns: { id: true, authorId: true }, with: { photos: true } } },
});
const ownRecipes = owned.flatMap((r) => (r.recipe && r.recipe.authorId === session!.user.id ? [r.recipe] : []));
if (ownRecipes.length > 0) {
const recipeIds = ownRecipes.map((r) => r.id);
const reviewPhotos = await db
.select({ photoKey: ratings.photoKey })
.from(ratings)
.where(and(inArray(ratings.recipeId, recipeIds), isNotNull(ratings.photoKey)));
const storageKeys = [
...ownRecipes.flatMap((r) => r.photos.map((p) => p.storageKey)),
...reviewPhotos.map((r) => r.photoKey).filter((k): k is string => k !== null),
];
await db.delete(recipes).where(inArray(recipes.id, recipeIds));
for (const key of storageKeys) {
try {
await deleteObject(key);
} catch (err) {
console.error(`Failed to delete storage object ${key} while deleting collection ${id}`, err);
}
}
}
}
await db.delete(collections).where(eq(collections.id, id));
return new NextResponse(null, { status: 204 });
}