import { NextResponse } from "next/server" import { eq } from "drizzle-orm" import { db } from "@/lib/db" import { profiles } from "@/lib/db/schema" import { getSessionUser } from "@/lib/session" import { cancelSubscription } from "@/lib/paypal/checkout" // Cancel the signed-in user's PayPal subscription. The account keeps access // until the paid period ends; the BILLING.SUBSCRIPTION.CANCELLED webhook does // the final downgrade to starter. export async function POST() { const user = await getSessionUser() if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 401 }) const profile = await db.query.profiles.findFirst({ where: eq(profiles.id, user.id), columns: { paypal_subscription_id: true }, }) if (!profile?.paypal_subscription_id) { return NextResponse.json({ error: "No PayPal subscription to cancel" }, { status: 400 }) } const ok = await cancelSubscription(profile.paypal_subscription_id) if (!ok) return NextResponse.json({ error: "PayPal cancellation failed" }, { status: 502 }) await db .update(profiles) .set({ subscription_status: "canceled" }) .where(eq(profiles.id, user.id)) return NextResponse.json({ ok: true }) }