import { NextResponse } from "next/server" import { asc, eq } from "drizzle-orm" import { db } from "@/lib/db" import { vendors } from "@/lib/db/schema" import { getSessionUser } from "@/lib/session" import { vendorSchema } from "@/lib/validations" import { ownsProperty } from "@/lib/db/ownership" export async function GET() { const user = await getSessionUser() if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 401 }) const data = await db .select() .from(vendors) .where(eq(vendors.user_id, user.id)) .orderBy(asc(vendors.name)) return NextResponse.json(data) } export async function POST(request: Request) { const user = await getSessionUser() if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 401 }) const body = await request.json() const parsed = vendorSchema.safeParse(body) if (!parsed.success) { return NextResponse.json({ error: parsed.error.issues[0]?.message ?? "Invalid input" }, { status: 400 }) } if (!(await ownsProperty(user.id, parsed.data.property_id))) { return NextResponse.json({ error: "Invalid reference" }, { status: 403 }) } try { const [data] = await db .insert(vendors) .values({ user_id: user.id, name: parsed.data.name, trade: parsed.data.trade || null, phone: parsed.data.phone || null, email: parsed.data.email || null, notes: parsed.data.notes || null, property_id: parsed.data.property_id || null, }) .returning() return NextResponse.json(data) } catch (e) { return NextResponse.json({ error: (e as Error).message }, { status: 500 }) } }