export const dynamic = 'force-dynamic' import { NextRequest, NextResponse } from 'next/server' import { getSession } from '@/lib/auth/get-session' import { asAdmin } from '@/lib/db/with-user' import { users } from '@/lib/db/schema' import { eq } from 'drizzle-orm' import { verifyPassword, hashPassword } from '@/lib/auth/password' export async function POST(req: NextRequest) { const session = await getSession() if (!session) return NextResponse.json({ error: 'Unauthorized' }, { status: 401 }) const { currentPassword, newPassword } = await req.json() if (!currentPassword || !newPassword || newPassword.length < 8) { return NextResponse.json({ error: 'Invalid request' }, { status: 400 }) } const [user] = await asAdmin(db => db.select({ passwordHash: users.passwordHash }) .from(users).where(eq(users.id, session.sub)).limit(1) ) if (!user || !await verifyPassword(currentPassword, user.passwordHash)) { return NextResponse.json({ error: 'Current password is incorrect' }, { status: 400 }) } const newHash = await hashPassword(newPassword) await asAdmin(db => db.update(users).set({ passwordHash: newHash }).where(eq(users.id, session.sub))) return NextResponse.json({ ok: true }) }