Files
property-management-network/app/api/documents/[id]/route.ts
T

45 lines
1.6 KiB
TypeScript
Raw Normal View History

import { NextResponse } from "next/server"
import { and, eq } from "drizzle-orm"
import { db } from "@/lib/db"
import { documents } from "@/lib/db/schema"
import { getSessionUser } from "@/lib/session"
import { deleteFile } from "@/lib/storage"
export async function GET(_: Request, { params }: { params: Promise<{ id: string }> }) {
const user = await getSessionUser()
if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 401 })
const { id } = await params
const doc = await db.query.documents.findFirst({
where: and(eq(documents.id, id), eq(documents.user_id, user.id)),
})
if (!doc) return NextResponse.json({ error: "Not found" }, { status: 404 })
// file_url already points at the auth-gated /api/files route; expose it as
// signed_url for compatibility with the existing client.
return NextResponse.json({ ...doc, signed_url: doc.file_url })
}
export async function DELETE(_: Request, { params }: { params: Promise<{ id: string }> }) {
const user = await getSessionUser()
if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 401 })
const { id } = await params
const doc = await db.query.documents.findFirst({
where: and(eq(documents.id, id), eq(documents.user_id, user.id)),
columns: { storage_path: true },
})
if (!doc) return NextResponse.json({ error: "Not found" }, { status: 404 })
await db.delete(documents).where(and(eq(documents.id, id), eq(documents.user_id, user.id)))
if (doc.storage_path) {
await deleteFile(doc.storage_path)
}
return NextResponse.json({ success: true })
}