import { getCustomerSession, isSudlohOidcEnabled } from "@/lib/auth/server"; import { refreshLinkedSudlohProfile, validateSudlohSession } from "@/lib/auth/sudloh"; import { errorResponse, HttpError, requireSameOrigin } from "@/lib/security/http"; export async function POST(request: Request) { try { requireSameOrigin(request); const session = await getCustomerSession(); if (!session) throw new HttpError(401, "unauthorized"); if (isSudlohOidcEnabled() && process.env.SUDLOH_OIDC_ONLY === "true") { if (!await validateSudlohSession(session.user.id, session.session.id, true)) throw new HttpError(401, "sudloh-session-expired"); } else await refreshLinkedSudlohProfile(session.user.id); return Response.json({ ok: true }, { headers: { "Cache-Control": "no-store" } }); } catch (cause) { return errorResponse(cause); } }