"use server" import { revalidatePath } from "next/cache" import { and, eq } from "drizzle-orm" import { db } from "@/lib/db" import { leases } from "@/lib/db/schema" import { getSessionUser } from "@/lib/session" import { getAccountContext } from "@/lib/account" import { keyBelongsToOwner } from "@/lib/storage" import { sendLeaseForSignature, getAdapter, saveEsignConnection, disconnectEsign, type ESignProvider, } from "@/lib/esign" async function ownerGuard() { const user = await getSessionUser() if (!user) throw new Error("Unauthorized") const ctx = await getAccountContext(user.id) if (!ctx.isOwner) throw new Error("Only the account owner can manage integrations") return ctx } export async function sendLeaseForSignatureAction(leaseId: string, provider: string) { const user = await getSessionUser() if (!user) throw new Error("Unauthorized") const ctx = await getAccountContext(user.id) if (!ctx.canWrite) throw new Error("You don't have permission to do that") if (!getAdapter(provider)) throw new Error("Unknown provider") await sendLeaseForSignature(ctx.ownerId, leaseId, provider as ESignProvider) revalidatePath(`/leases/${leaseId}`) return { ok: true } } /** Connect Dropbox Sign by validating and storing the landlord's API key. */ export async function connectDropboxSign(apiKey: string) { const ctx = await ownerGuard() const adapter = getAdapter("dropbox_sign") if (!adapter) throw new Error("Unknown provider") const tokens = await adapter.connectApiKey(typeof apiKey === "string" ? apiKey : "") await saveEsignConnection(ctx.ownerId, "dropbox_sign", tokens) revalidatePath("/settings/integrations") return { ok: true, accountName: tokens.accountName } } export async function disconnectEsignAction(provider: string) { const ctx = await ownerGuard() if (!getAdapter(provider)) throw new Error("Unknown provider") await disconnectEsign(ctx.ownerId, provider as ESignProvider) revalidatePath("/settings/integrations") return { ok: true } } /** * Attach an already-uploaded document (via /api/upload) to a lease. Validates * the file belongs to the caller's namespace to prevent cross-tenant refs. */ export async function setLeaseDocument(leaseId: string, fileUrl: string) { const user = await getSessionUser() if (!user) throw new Error("Unauthorized") const ctx = await getAccountContext(user.id) if (!ctx.canWrite) throw new Error("You don't have permission to do that") const prefix = "/api/files/" if (typeof fileUrl !== "string" || !fileUrl.startsWith(prefix)) throw new Error("Invalid document reference") if (!keyBelongsToOwner(fileUrl.slice(prefix.length), ctx.ownerId)) throw new Error("Invalid document reference") const [row] = await db .update(leases) .set({ document_url: fileUrl }) .where(and(eq(leases.id, leaseId), eq(leases.user_id, ctx.ownerId))) .returning({ id: leases.id }) if (!row) throw new Error("Lease not found") revalidatePath(`/leases/${leaseId}`) return { ok: true, url: fileUrl } }