Files
buzz-sheet/app/api/comments/[id]/route.ts
T
gunshiz 5812d99715
CI / Verify (push) Successful in 2m30s
CI / Build immutable images and deploy (push) Successful in 3m9s
feat : comment feature
2026-10-08 01:40:08 +07:00

33 lines
1.6 KiB
TypeScript

import { authorizeComment, commentId, getCommentViewer, listComments, mutateComment, requireCommentViewer } from "@/lib/comments/repository";
import { publishComment } from "@/lib/comments/publish";
import { errorResponse, requireSameOrigin } from "@/lib/security/http";
import { limitRequest } from "@/lib/security/rate-limit";
type Context = { params: Promise<{ id: string }> };
export async function GET(_request: Request, context: Context) {
try {
const viewer = await getCommentViewer();
const id = commentId((await context.params).id);
const authorized = await authorizeComment(id, viewer);
const result = await listComments({ viewer, target: authorized.destination.target, id });
return Response.json({ item: result.items[0], viewer }, { headers: { "Cache-Control": "private, no-store" } });
} catch (cause) { return errorResponse(cause); }
}
export async function PATCH(request: Request, context: Context) {
try {
requireSameOrigin(request);
const viewer = await requireCommentViewer();
await limitRequest("comment-publish", viewer.id, 20);
return Response.json(await publishComment(request, viewer, { id: commentId((await context.params).id) }));
} catch (cause) { return errorResponse(cause); }
}
export async function DELETE(request: Request, context: Context) {
try {
requireSameOrigin(request);
const viewer = await requireCommentViewer();
await limitRequest("comment-mutate", viewer.id, 60);
await mutateComment((await context.params).id, viewer, "delete");
return new Response(null, { status: 204 });
} catch (cause) { return errorResponse(cause); }
}