2021-08-19 12:27:01 +00:00
|
|
|
import type { NextApiRequest, NextApiResponse } from "next";
|
2021-09-22 19:52:38 +00:00
|
|
|
|
2021-09-03 20:51:21 +00:00
|
|
|
import { getSession } from "@lib/auth";
|
2021-12-09 23:51:30 +00:00
|
|
|
import prisma from "@lib/prisma";
|
2021-09-22 19:52:38 +00:00
|
|
|
|
2021-06-05 22:53:33 +00:00
|
|
|
export default async function handler(req: NextApiRequest, res: NextApiResponse) {
|
2021-08-19 12:27:01 +00:00
|
|
|
const session = await getSession({ req });
|
2021-06-05 22:53:33 +00:00
|
|
|
|
|
|
|
if (!session) {
|
2021-08-19 12:27:01 +00:00
|
|
|
res.status(401).json({ message: "Not authenticated" });
|
2021-06-05 22:53:33 +00:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2021-08-19 12:27:01 +00:00
|
|
|
const isTeamOwner = !!(await prisma.membership.findFirst({
|
2021-06-05 22:53:33 +00:00
|
|
|
where: {
|
2021-12-09 23:51:30 +00:00
|
|
|
userId: session.user?.id,
|
2021-08-19 12:27:01 +00:00
|
|
|
teamId: parseInt(req.query.team as string),
|
|
|
|
role: "OWNER",
|
|
|
|
},
|
|
|
|
}));
|
2021-06-05 22:53:33 +00:00
|
|
|
|
2021-08-19 12:27:01 +00:00
|
|
|
if (!isTeamOwner) {
|
|
|
|
res.status(403).json({ message: "You are not authorized to manage this team" });
|
2021-06-05 22:53:33 +00:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
// List members
|
|
|
|
if (req.method === "GET") {
|
|
|
|
const memberships = await prisma.membership.findMany({
|
|
|
|
where: {
|
2021-08-19 12:27:01 +00:00
|
|
|
teamId: parseInt(req.query.team as string),
|
|
|
|
},
|
2021-06-05 22:53:33 +00:00
|
|
|
});
|
|
|
|
|
|
|
|
let members = await prisma.user.findMany({
|
|
|
|
where: {
|
|
|
|
id: {
|
2021-08-19 12:27:01 +00:00
|
|
|
in: memberships.map((membership) => membership.userId),
|
|
|
|
},
|
|
|
|
},
|
2021-09-17 11:25:48 +00:00
|
|
|
select: {
|
|
|
|
id: true,
|
|
|
|
username: true,
|
|
|
|
name: true,
|
|
|
|
email: true,
|
|
|
|
bio: true,
|
|
|
|
avatar: true,
|
|
|
|
timeZone: true,
|
|
|
|
},
|
2021-06-05 22:53:33 +00:00
|
|
|
});
|
|
|
|
|
2021-08-19 12:27:01 +00:00
|
|
|
members = members.map((member) => {
|
|
|
|
const membership = memberships.find((membership) => member.id === membership.userId);
|
2021-06-05 22:53:33 +00:00
|
|
|
return {
|
|
|
|
...member,
|
2021-12-09 23:51:30 +00:00
|
|
|
role: membership?.accepted ? membership?.role : "INVITEE",
|
2021-08-19 12:27:01 +00:00
|
|
|
};
|
2021-06-05 22:53:33 +00:00
|
|
|
});
|
|
|
|
|
|
|
|
return res.status(200).json({ members: members });
|
|
|
|
}
|
|
|
|
|
|
|
|
// Cancel a membership (invite)
|
|
|
|
if (req.method === "DELETE") {
|
2021-08-19 12:27:01 +00:00
|
|
|
await prisma.membership.delete({
|
2021-06-05 22:53:33 +00:00
|
|
|
where: {
|
2021-12-09 23:51:30 +00:00
|
|
|
userId_teamId: { userId: req.body.userId, teamId: parseInt(req.query.team as string) },
|
2021-08-19 12:27:01 +00:00
|
|
|
},
|
2021-06-05 22:53:33 +00:00
|
|
|
});
|
|
|
|
return res.status(204).send(null);
|
|
|
|
}
|
|
|
|
|
|
|
|
// Promote or demote a member of the team
|
|
|
|
|
|
|
|
res.status(200).json({});
|
|
|
|
}
|