Initial commit
This commit is contained in:
@@ -0,0 +1,77 @@
|
||||
// app/api/admin/update-user-role/route.ts
|
||||
import { NextResponse } from 'next/server';
|
||||
import { getServerSession } from 'next-auth';
|
||||
import { authOptions } from '@/lib/auth-options';
|
||||
import { prisma } from '@/lib/prisma';
|
||||
|
||||
export async function PATCH(req: Request) {
|
||||
try {
|
||||
const session = await getServerSession(authOptions);
|
||||
if (!session?.user?.email) {
|
||||
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 });
|
||||
}
|
||||
|
||||
// Only superadmins can assign roles
|
||||
const role = (session as any)?.user?.role ?? null;
|
||||
if (role !== 'superadmin') {
|
||||
return NextResponse.json(
|
||||
{ error: 'Only superadmins can assign roles' },
|
||||
{ status: 403 }
|
||||
);
|
||||
}
|
||||
|
||||
const body = await req.json();
|
||||
const { userId, newRole } = body;
|
||||
|
||||
if (!userId || !newRole) {
|
||||
return NextResponse.json(
|
||||
{ error: 'userId and newRole required' },
|
||||
{ status: 400 }
|
||||
);
|
||||
}
|
||||
|
||||
// Validate newRole
|
||||
const validRoles = ['user', 'admin', 'superadmin'];
|
||||
if (!validRoles.includes(newRole)) {
|
||||
return NextResponse.json(
|
||||
{ error: `Invalid role. Must be one of: ${validRoles.join(', ')}` },
|
||||
{ status: 400 }
|
||||
);
|
||||
}
|
||||
|
||||
// Prevent self-demotion from superadmin
|
||||
const currentUser = await prisma.user.findUnique({
|
||||
where: { email: session.user.email },
|
||||
});
|
||||
|
||||
if (currentUser?.id === userId && newRole !== 'superadmin') {
|
||||
return NextResponse.json(
|
||||
{ error: 'Cannot demote yourself from superadmin' },
|
||||
{ status: 400 }
|
||||
);
|
||||
}
|
||||
|
||||
// Update user role
|
||||
const updatedUser = await prisma.user.update({
|
||||
where: { id: userId },
|
||||
data: { role: newRole },
|
||||
select: {
|
||||
id: true,
|
||||
email: true,
|
||||
name: true,
|
||||
role: true,
|
||||
},
|
||||
});
|
||||
|
||||
return NextResponse.json({
|
||||
message: 'User role updated successfully',
|
||||
user: updatedUser,
|
||||
});
|
||||
} catch (err: any) {
|
||||
console.error('update user role error:', err);
|
||||
return NextResponse.json(
|
||||
{ error: err?.message ?? 'server error' },
|
||||
{ status: 500 }
|
||||
);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user