import { NextResponse } from "next/server" import { and, eq } from "drizzle-orm" import { db } from "@/lib/db" import { notifications } from "@/lib/db/schema" import { getSessionUser } from "@/lib/session" import { getAccountContext } from "@/lib/account" // PATCH /api/notifications/read — mark all of the user's notifications as read. export async function PATCH() { const user = await getSessionUser() if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 401 }) const ctx = await getAccountContext(user.id) const ownerId = ctx.ownerId if (!ctx.canWrite) return NextResponse.json({ error: "Forbidden" }, { status: 403 }) await db .update(notifications) .set({ read: true }) .where(and(eq(notifications.user_id, ownerId), eq(notifications.read, false))) return NextResponse.json({ ok: true }) }