37 lines
1.8 KiB
TypeScript
37 lines
1.8 KiB
TypeScript
import { after } from "next/server";
|
|
import { sendCommentPush } from "@/lib/comments/push";
|
|
import { authorizeComment, commentId, getCommentViewer, listComments, mutateComment, requireCommentViewer } from "@/lib/comments/repository";
|
|
import { publishComment } from "@/lib/comments/publish";
|
|
import { errorResponse, requireSameOrigin } from "@/lib/security/http";
|
|
import { limitRequest } from "@/lib/security/rate-limit";
|
|
|
|
type Context = { params: Promise<{ id: string }> };
|
|
export async function GET(_request: Request, context: Context) {
|
|
try {
|
|
const viewer = await getCommentViewer();
|
|
const id = commentId((await context.params).id);
|
|
const authorized = await authorizeComment(id, viewer);
|
|
const result = await listComments({ viewer, target: authorized.destination.target, id });
|
|
return Response.json({ item: result.items[0], viewer }, { headers: { "Cache-Control": "private, no-store" } });
|
|
} catch (cause) { return errorResponse(cause); }
|
|
}
|
|
export async function PATCH(request: Request, context: Context) {
|
|
try {
|
|
requireSameOrigin(request);
|
|
const viewer = await requireCommentViewer();
|
|
await limitRequest("comment-publish", viewer.id, 20);
|
|
const result = await publishComment(request, viewer, { id: commentId((await context.params).id) });
|
|
after(async () => { await sendCommentPush(result.id, result.version).catch(() => console.error("Comment notification failed")); });
|
|
return Response.json(result);
|
|
} catch (cause) { return errorResponse(cause); }
|
|
}
|
|
export async function DELETE(request: Request, context: Context) {
|
|
try {
|
|
requireSameOrigin(request);
|
|
const viewer = await requireCommentViewer();
|
|
await limitRequest("comment-mutate", viewer.id, 60);
|
|
await mutateComment((await context.params).id, viewer, "delete");
|
|
return new Response(null, { status: 204 });
|
|
} catch (cause) { return errorResponse(cause); }
|
|
}
|