import "server-only"; import { headers } from "next/headers"; import { getAuth } from "@/lib/auth/server"; import { getDb } from "@/db"; import { users } from "@/db/schema"; import { eq } from "drizzle-orm"; import { HttpError } from "@/lib/security/http"; import { getRedisClient, redisEventChannel } from "@/lib/redis/client"; export async function requireCommissionUser() { const session = await getAuth().api.getSession({ headers: await headers() }); if (!session?.user) throw new HttpError(401, "unauthorized"); const [user] = await getDb().select().from(users).where(eq(users.id, session.user.id)).limit(1); if (!user || user.banned) throw new HttpError(401, "unauthorized"); return user; } export async function notifyCommission(ticketId: string, userId: string, payload = "changed") { try { const client = await getRedisClient(); await Promise.all([ client.publish(redisEventChannel(`commission:ticket:${ticketId}`), payload), client.publish(redisEventChannel(`commission:user:${userId}`), payload), client.publish(redisEventChannel("commission:admin"), payload), ]); } catch { // The database is authoritative; a reconnect or page refresh catches up. } }