import { NextResponse } from "next/server" import { getSessionUser } from "@/lib/session" import { getAccountContext } from "@/lib/account" import { runFollowUpsForUser } from "@/lib/follow-ups" export async function POST() { const user = await getSessionUser() if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 401 }) // Sends real outbound follow-ups — a mutating action, so viewers are blocked. const ctx = await getAccountContext(user.id) if (!ctx.canWrite) return NextResponse.json({ error: "Forbidden" }, { status: 403 }) const result = await runFollowUpsForUser(ctx.ownerId) // Preserve the original response shape ({ sent, results }). The detailed // per-follow-up rows now live only in follow_up_log; the client re-fetches // rules for last_run_at and tolerates an empty results array. return NextResponse.json({ sent: result.sent, results: [] }) }