46 lines
1.5 KiB
TypeScript
46 lines
1.5 KiB
TypeScript
import { type NextRequest, NextResponse } from "next/server";
|
|
import { z } from "zod";
|
|
import { requireSession } from "@/lib/api-auth";
|
|
import { db, recipes, eq, and, inArray } from "@epicure/db";
|
|
|
|
const BulkDeleteSchema = z.object({
|
|
ids: z.array(z.string()).min(1).max(100),
|
|
});
|
|
|
|
const BulkUpdateSchema = z.object({
|
|
ids: z.array(z.string()).min(1).max(100),
|
|
visibility: z.enum(["private", "unlisted", "public"]).optional(),
|
|
});
|
|
|
|
export async function DELETE(req: NextRequest) {
|
|
const { session, response } = await requireSession();
|
|
if (response) return response;
|
|
|
|
const body = BulkDeleteSchema.safeParse(await req.json());
|
|
if (!body.success) return NextResponse.json({ error: "Invalid request" }, { status: 400 });
|
|
|
|
await db
|
|
.delete(recipes)
|
|
.where(and(inArray(recipes.id, body.data.ids), eq(recipes.authorId, session!.user.id)));
|
|
|
|
return NextResponse.json({ ok: true });
|
|
}
|
|
|
|
export async function PATCH(req: NextRequest) {
|
|
const { session, response } = await requireSession();
|
|
if (response) return response;
|
|
|
|
const body = BulkUpdateSchema.safeParse(await req.json());
|
|
if (!body.success) return NextResponse.json({ error: "Invalid request" }, { status: 400 });
|
|
|
|
const { ids, visibility } = body.data;
|
|
if (!visibility) return NextResponse.json({ error: "Nothing to update" }, { status: 400 });
|
|
|
|
await db
|
|
.update(recipes)
|
|
.set({ visibility, updatedAt: new Date() })
|
|
.where(and(inArray(recipes.id, ids), eq(recipes.authorId, session!.user.id)));
|
|
|
|
return NextResponse.json({ ok: true });
|
|
}
|