cal.pub0.org/pages/api/custom-inputs/[id]/_auth-middleware.ts

20 lines
726 B
TypeScript
Raw Normal View History

import type { NextApiRequest } from "next";
import { HttpError } from "@calcom/lib/http-error";
2022-11-25 13:56:58 +00:00
import { schemaQueryIdParseInt } from "~/lib/validations/shared/queryIdTransformParseInt";
async function authMiddleware(req: NextApiRequest) {
const { userId, isAdmin, prisma } = req;
const { id } = schemaQueryIdParseInt.parse(req.query);
// Admins can just skip this check
if (isAdmin) return;
// Check if the current user can access the event type of this input
const eventTypeCustomInput = await prisma.eventTypeCustomInput.findFirst({
where: { id, eventType: { userId } },
});
2022-10-14 23:41:28 +00:00
if (!eventTypeCustomInput) throw new HttpError({ statusCode: 403, message: "Forbidden" });
}
export default authMiddleware;