import { NextResponse } from "next/server" import { and, asc, eq } from "drizzle-orm" import { db } from "@/lib/db" import { units } from "@/lib/db/schema" import { getSessionUser } from "@/lib/session" import { unitSchema } from "@/lib/validations" import { ownsProperty } from "@/lib/db/ownership" import { getEffectiveOwnerId, getAccountContext } from "@/lib/account" export async function GET(request: Request) { const user = await getSessionUser() if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 401 }) const ownerId = await getEffectiveOwnerId(user.id) const { searchParams } = new URL(request.url) const propertyId = searchParams.get("property_id") const data = await db.query.units.findMany({ where: and( eq(units.user_id, ownerId), propertyId ? eq(units.property_id, propertyId) : undefined ), with: { current_tenant: { columns: { first_name: true, last_name: true } }, }, orderBy: asc(units.unit_number), }) return NextResponse.json(data) } export async function POST(request: Request) { const user = await getSessionUser() if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 401 }) const ctx = await getAccountContext(user.id) const ownerId = ctx.ownerId if (!ctx.canWrite) return NextResponse.json({ error: "Forbidden" }, { status: 403 }) const body = await request.json() const parsed = unitSchema.safeParse(body) if (!parsed.success) return NextResponse.json({ error: parsed.error.flatten() }, { status: 400 }) if (!(await ownsProperty(ownerId, parsed.data.property_id))) { return NextResponse.json({ error: "Invalid reference" }, { status: 403 }) } const [data] = await db .insert(units) .values({ ...parsed.data, user_id: ownerId }) .returning() return NextResponse.json(data, { status: 201 }) }