- /api/incidents/[id]/similar: embedding backfill on a closed incident hit the closure-lock trigger and turned the whole request into a 503; now skips persistence for closed incidents (vector still used for the query) - addenda: cap body at 5000 chars; include body text in audit_log entry - admin users PATCH: 404 when target user does not exist (was silent ok) - extract shared requireAdmin to lib/auth/require-admin.ts (was duplicated in admin users + sites routes) - extract escapeCsv/rowsToCsv to lib/csv.ts (was duplicated in dashboard export route and lib/reports/jkkp8.ts) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CPf5Rc8QPx6V8KLEEgfKEQ
19 lines
781 B
TypeScript
19 lines
781 B
TypeScript
import { createClient } from '@/lib/supabase/server'
|
|
import type { SupabaseClient } from '@supabase/supabase-js'
|
|
import type { User } from '@supabase/supabase-js'
|
|
|
|
// Shared guard for /api/admin/* routes: resolves the session and requires
|
|
// the admin role. Returns user: null when the caller must respond 403.
|
|
export async function requireAdmin(): Promise<{
|
|
supabase: SupabaseClient
|
|
user: User | null
|
|
}> {
|
|
const supabase = await createClient()
|
|
const { data: { user }, error } = await supabase.auth.getUser()
|
|
if (error || !user) return { supabase, user: null }
|
|
const { data: profile } = await supabase
|
|
.from('users').select('role').eq('id', user.id).single()
|
|
if (!profile || profile.role !== 'admin') return { supabase, user: null }
|
|
return { supabase, user }
|
|
}
|