import { toNextJsHandler } from "better-auth/next-js"; import { getAuth } from "@/lib/auth/server"; import { errorResponse, HttpError, readJson, requireSameOrigin } from "@/lib/security/http"; const handlers = toNextJsHandler((request) => getAuth().handler(request)); export const GET = handlers.GET; async function mutate(request: Request) { try { requireSameOrigin(request); const input = await readJson(request.clone()); const path = new URL(request.url).pathname; if (["/admin/create-user", "/admin/set-user-password"].some((endpoint) => path.endsWith(endpoint))) { const password = input && typeof input === "object" && "password" in input ? input.password : undefined; const newPassword = input && typeof input === "object" && "newPassword" in input ? input.newPassword : undefined; const value = password ?? newPassword; if (typeof value !== "string" || value.length < 6 || value.length > 128) { throw new HttpError(400, "invalid-password-length"); } } return await getAuth().handler(request); } catch (cause) { return errorResponse(cause); } } export const POST = mutate; export const PATCH = mutate; export const PUT = mutate; export const DELETE = mutate;