feat : ask for noti
This commit is contained in:
@@ -0,0 +1,27 @@
|
||||
import * as z from 'zod';
|
||||
import { requireCommissionUser } from '@/lib/commission/server';
|
||||
import { listNotifications, readNotifications } from '@/lib/notifications/repository';
|
||||
import { errorResponse, HttpError, readJson, requireSameOrigin } from '@/lib/security/http';
|
||||
import { limitRequest } from '@/lib/security/rate-limit';
|
||||
export async function GET(request: Request) {
|
||||
try {
|
||||
const user = await requireCommissionUser();
|
||||
const raw = new URL(request.url).searchParams.get('before');
|
||||
const parts = raw?.split('|');
|
||||
const parsed = parts ? z.object({ time: z.iso.datetime(), id: z.uuid() }).safeParse({ time: parts[0], id: parts[1] }) : undefined;
|
||||
if (raw && (!parsed?.success || parts?.length !== 2)) throw new HttpError(400, 'invalid-cursor');
|
||||
const before = parsed?.success ? parsed.data : undefined;
|
||||
return Response.json(await listNotifications(user, before), { headers: { 'Cache-Control': 'private, no-store' } });
|
||||
} catch (cause) { return errorResponse(cause); }
|
||||
}
|
||||
export async function POST(request: Request) {
|
||||
try {
|
||||
requireSameOrigin(request);
|
||||
const user = await requireCommissionUser();
|
||||
await limitRequest('notification-read', user.id, 120);
|
||||
const parsed = z.object({ id: z.uuid().optional() }).safeParse(await readJson(request, 1024));
|
||||
if (!parsed.success) throw new HttpError(400, 'invalid-notification');
|
||||
await readNotifications(user.id, parsed.data.id);
|
||||
return new Response(null, { status: 204 });
|
||||
} catch (cause) { return errorResponse(cause); }
|
||||
}
|
||||
Reference in New Issue
Block a user