@@ -2,6 +2,7 @@ import { NextRequest, NextResponse } from "next/server";
|
||||
import { db } from "@/lib/db";
|
||||
import { ApprovalStatus } from "@prisma/client";
|
||||
import { recalcShotStatus } from "@/lib/shot-status";
|
||||
import { validateReviewToken } from "@/lib/review-auth";
|
||||
|
||||
async function getOrCreateClientUser(email: string, label?: string | null) {
|
||||
const existing = await db.user.findUnique({ where: { email } });
|
||||
@@ -16,22 +17,19 @@ async function getOrCreateClientUser(email: string, label?: string | null) {
|
||||
});
|
||||
}
|
||||
|
||||
async function validateToken(token: string) {
|
||||
const session = await db.reviewSession.findUnique({ where: { token } });
|
||||
if (!session || !session.isActive) return null;
|
||||
if (session.expiresAt && session.expiresAt < new Date()) return null;
|
||||
return session;
|
||||
}
|
||||
|
||||
export async function POST(
|
||||
req: NextRequest,
|
||||
{ params }: { params: Promise<{ token: string }> }
|
||||
) {
|
||||
const { token } = await params;
|
||||
const session = await validateToken(token);
|
||||
if (!session) {
|
||||
const result = await validateReviewToken(token, req);
|
||||
if (result.type === "requiresPassword") {
|
||||
return NextResponse.json({ requiresPassword: true }, { status: 401 });
|
||||
}
|
||||
if (result.type === "invalid") {
|
||||
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
|
||||
}
|
||||
const session = result.session;
|
||||
|
||||
const body = await req.json();
|
||||
const { versionId, shotId, action, status, notes } = body;
|
||||
|
||||
@@ -0,0 +1,48 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import { db } from "@/lib/db";
|
||||
import bcrypt from "bcryptjs";
|
||||
import { makeUnlockCookieValue } from "@/lib/review-auth";
|
||||
|
||||
export async function POST(
|
||||
req: NextRequest,
|
||||
{ params }: { params: Promise<{ token: string }> }
|
||||
) {
|
||||
const { token } = await params;
|
||||
|
||||
const body = await req.json().catch(() => ({}));
|
||||
const { password } = body as { password?: string };
|
||||
|
||||
if (!password || typeof password !== "string") {
|
||||
return NextResponse.json({ error: "Password required" }, { status: 400 });
|
||||
}
|
||||
|
||||
const session = await db.reviewSession.findUnique({ where: { token } });
|
||||
if (!session || !session.isActive) {
|
||||
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
|
||||
}
|
||||
if (session.expiresAt && session.expiresAt < new Date()) {
|
||||
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
|
||||
}
|
||||
|
||||
if (!session.passwordHash) {
|
||||
return NextResponse.json({ success: true });
|
||||
}
|
||||
|
||||
const valid = await bcrypt.compare(password, session.passwordHash);
|
||||
if (!valid) {
|
||||
return NextResponse.json({ error: "Incorrect password" }, { status: 401 });
|
||||
}
|
||||
|
||||
const cookieName = `rsauth_${token}`;
|
||||
const cookieValue = makeUnlockCookieValue(token);
|
||||
|
||||
const res = NextResponse.json({ success: true });
|
||||
res.cookies.set(cookieName, cookieValue, {
|
||||
httpOnly: true,
|
||||
sameSite: "lax",
|
||||
path: "/",
|
||||
expires: session.expiresAt,
|
||||
secure: process.env.NODE_ENV === "production",
|
||||
});
|
||||
return res;
|
||||
}
|
||||
@@ -1,6 +1,7 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import { db } from "@/lib/db";
|
||||
import { slackNotifyNewFeedback } from "@/lib/slack";
|
||||
import { validateReviewToken } from "@/lib/review-auth";
|
||||
|
||||
/** Find or create a guest user for the client reviewer based on the session email */
|
||||
async function getOrCreateClientUser(email: string, label?: string | null) {
|
||||
@@ -16,22 +17,19 @@ async function getOrCreateClientUser(email: string, label?: string | null) {
|
||||
});
|
||||
}
|
||||
|
||||
async function validateToken(token: string) {
|
||||
const session = await db.reviewSession.findUnique({ where: { token } });
|
||||
if (!session || !session.isActive) return null;
|
||||
if (session.expiresAt && session.expiresAt < new Date()) return null;
|
||||
return session;
|
||||
}
|
||||
|
||||
export async function POST(
|
||||
req: NextRequest,
|
||||
{ params }: { params: Promise<{ token: string }> }
|
||||
) {
|
||||
const { token } = await params;
|
||||
const session = await validateToken(token);
|
||||
if (!session) {
|
||||
const result = await validateReviewToken(token, req);
|
||||
if (result.type === "requiresPassword") {
|
||||
return NextResponse.json({ requiresPassword: true }, { status: 401 });
|
||||
}
|
||||
if (result.type === "invalid") {
|
||||
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
|
||||
}
|
||||
const session = result.session;
|
||||
|
||||
const body = await req.json();
|
||||
const { versionId, frameNumber, timestamp, text } = body;
|
||||
|
||||
@@ -1,12 +1,6 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import { db } from "@/lib/db";
|
||||
|
||||
async function validateToken(token: string) {
|
||||
const session = await db.reviewSession.findUnique({ where: { token } });
|
||||
if (!session || !session.isActive) return null;
|
||||
if (session.expiresAt && session.expiresAt < new Date()) return null;
|
||||
return session;
|
||||
}
|
||||
import { validateReviewToken } from "@/lib/review-auth";
|
||||
|
||||
/** GET /api/client/[token]/project — returns project + shots with tasks that have client-visible versions */
|
||||
export async function GET(
|
||||
@@ -14,10 +8,14 @@ export async function GET(
|
||||
{ params }: { params: Promise<{ token: string }> }
|
||||
) {
|
||||
const { token } = await params;
|
||||
const session = await validateToken(token);
|
||||
if (!session) {
|
||||
const result = await validateReviewToken(token, req);
|
||||
if (result.type === "requiresPassword") {
|
||||
return NextResponse.json({ requiresPassword: true }, { status: 401 });
|
||||
}
|
||||
if (result.type === "invalid") {
|
||||
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
|
||||
}
|
||||
const session = result.session;
|
||||
|
||||
const project = await db.project.findUnique({
|
||||
where: { id: session.projectId },
|
||||
|
||||
@@ -1,12 +1,6 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import { db } from "@/lib/db";
|
||||
|
||||
async function validateToken(token: string) {
|
||||
const session = await db.reviewSession.findUnique({ where: { token } });
|
||||
if (!session || !session.isActive) return null;
|
||||
if (session.expiresAt && session.expiresAt < new Date()) return null;
|
||||
return session;
|
||||
}
|
||||
import { validateReviewToken } from "@/lib/review-auth";
|
||||
|
||||
/** GET /api/client/[token]/versions/[versionId] — returns version + comments for client portal */
|
||||
export async function GET(
|
||||
@@ -14,10 +8,14 @@ export async function GET(
|
||||
{ params }: { params: Promise<{ token: string; versionId: string }> }
|
||||
) {
|
||||
const { token, versionId } = await params;
|
||||
const session = await validateToken(token);
|
||||
if (!session) {
|
||||
const result = await validateReviewToken(token, req);
|
||||
if (result.type === "requiresPassword") {
|
||||
return NextResponse.json({ requiresPassword: true }, { status: 401 });
|
||||
}
|
||||
if (result.type === "invalid") {
|
||||
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
|
||||
}
|
||||
const session = result.session;
|
||||
|
||||
const version = await db.version.findUnique({
|
||||
where: { id: versionId },
|
||||
|
||||
@@ -2,6 +2,7 @@ import { NextRequest, NextResponse } from "next/server";
|
||||
import { auth } from "@/auth";
|
||||
import { db } from "@/lib/db";
|
||||
import { addDays } from "date-fns";
|
||||
import bcrypt from "bcryptjs";
|
||||
|
||||
export async function GET(req: NextRequest) {
|
||||
const session = await auth();
|
||||
@@ -32,7 +33,7 @@ export async function POST(req: NextRequest) {
|
||||
}
|
||||
|
||||
const body = await req.json();
|
||||
const { projectId, label, email, expiresInDays = 30 } = body;
|
||||
const { projectId, label, email, expiresInDays = 30, password } = body;
|
||||
|
||||
if (!projectId) {
|
||||
return NextResponse.json({ error: "projectId is required" }, { status: 400 });
|
||||
@@ -43,11 +44,17 @@ export async function POST(req: NextRequest) {
|
||||
return NextResponse.json({ error: "Project not found" }, { status: 404 });
|
||||
}
|
||||
|
||||
const passwordHash =
|
||||
password && typeof password === "string" && password.length > 0
|
||||
? await bcrypt.hash(password, 12)
|
||||
: null;
|
||||
|
||||
const reviewSession = await db.reviewSession.create({
|
||||
data: {
|
||||
projectId,
|
||||
label: label || `Review — ${project.name}`,
|
||||
email: email || null,
|
||||
passwordHash,
|
||||
expiresAt: addDays(new Date(), expiresInDays),
|
||||
},
|
||||
});
|
||||
|
||||
+39
-13
@@ -15,6 +15,7 @@ import {
|
||||
} from 'lucide-react';
|
||||
import { cn } from '@/lib/utils';
|
||||
import { Montserrat } from 'next/font/google';
|
||||
import { ReviewPasswordGate } from '@/components/clients/ReviewPasswordGate';
|
||||
|
||||
const montserrat = Montserrat({
|
||||
subsets: ['latin'],
|
||||
@@ -121,6 +122,7 @@ export default function ClientPortalPage({
|
||||
const [sessionLabel, setSessionLabel] = useState<string>('');
|
||||
const [loading, setLoading] = useState(true);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [requiresPassword, setRequiresPassword] = useState(false);
|
||||
const [collapsedEpisodes, setCollapsedEpisodes] = useState<Set<string>>(new Set());
|
||||
|
||||
const toggleEpisode = (ep: string) => {
|
||||
@@ -134,22 +136,37 @@ export default function ClientPortalPage({
|
||||
useEffect(() => {
|
||||
params.then(({ token: t }) => {
|
||||
setToken(t);
|
||||
fetch(`/api/client/${t}/project`)
|
||||
.then((r) => {
|
||||
if (!r.ok) throw new Error('Invalid or expired review link');
|
||||
return r.json();
|
||||
})
|
||||
.then((data) => {
|
||||
setProject(data.project);
|
||||
setShots(data.shots ?? []);
|
||||
setAssetTasks(data.assetTasks ?? []);
|
||||
setSessionLabel(data.sessionLabel ?? '');
|
||||
})
|
||||
.catch((e) => setError(e.message))
|
||||
.finally(() => setLoading(false));
|
||||
loadProject(t);
|
||||
});
|
||||
}, [params]);
|
||||
|
||||
const loadProject = (t: string) => {
|
||||
setLoading(true);
|
||||
setError(null);
|
||||
fetch(`/api/client/${t}/project`)
|
||||
.then(async (r) => {
|
||||
if (r.status === 401) {
|
||||
const data = await r.json().catch(() => ({}));
|
||||
if (data.requiresPassword) {
|
||||
setRequiresPassword(true);
|
||||
return null;
|
||||
}
|
||||
}
|
||||
if (!r.ok) throw new Error('Invalid or expired review link');
|
||||
return r.json();
|
||||
})
|
||||
.then((data) => {
|
||||
if (!data) return;
|
||||
setProject(data.project);
|
||||
setShots(data.shots ?? []);
|
||||
setAssetTasks(data.assetTasks ?? []);
|
||||
setSessionLabel(data.sessionLabel ?? '');
|
||||
setRequiresPassword(false);
|
||||
})
|
||||
.catch((e) => setError(e.message))
|
||||
.finally(() => setLoading(false));
|
||||
};
|
||||
|
||||
if (loading) {
|
||||
return (
|
||||
<div className="min-h-screen bg-zinc-950 flex items-center justify-center">
|
||||
@@ -158,6 +175,15 @@ export default function ClientPortalPage({
|
||||
);
|
||||
}
|
||||
|
||||
if (requiresPassword) {
|
||||
return (
|
||||
<ReviewPasswordGate
|
||||
token={token}
|
||||
onUnlocked={() => loadProject(token)}
|
||||
/>
|
||||
);
|
||||
}
|
||||
|
||||
if (error || !project) {
|
||||
return (
|
||||
<div className="min-h-screen bg-zinc-950 flex flex-col items-center justify-center gap-4 text-center px-4">
|
||||
|
||||
@@ -28,6 +28,7 @@ import {
|
||||
Clock,
|
||||
} from "lucide-react";
|
||||
import { useReviewStore } from "@/hooks/use-review-player";
|
||||
import { ReviewPasswordGate } from "@/components/clients/ReviewPasswordGate";
|
||||
|
||||
interface Comment {
|
||||
id: string;
|
||||
@@ -80,6 +81,8 @@ export default function ClientReviewPage({
|
||||
const [comments, setComments] = useState<Comment[]>([]);
|
||||
const [loading, setLoading] = useState(true);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [requiresPassword, setRequiresPassword] = useState(false);
|
||||
const [versionId, setVersionId] = useState("");
|
||||
|
||||
const currentFrame = useReviewStore((s) => s.currentFrame);
|
||||
|
||||
@@ -101,23 +104,39 @@ export default function ClientReviewPage({
|
||||
const { toast } = useToast();
|
||||
|
||||
useEffect(() => {
|
||||
params.then(({ token: t, versionId }) => {
|
||||
params.then(({ token: t, versionId: vId }) => {
|
||||
setToken(t);
|
||||
fetch(`/api/client/${t}/versions/${versionId}`)
|
||||
.then((r) => {
|
||||
if (!r.ok) throw new Error("Invalid or expired review link");
|
||||
return r.json();
|
||||
})
|
||||
.then((data) => {
|
||||
setVersion(data.version);
|
||||
setComments(data.comments);
|
||||
setCurrentApprovalStatus(data.version.approvalStatus);
|
||||
})
|
||||
.catch((e) => setError(e.message))
|
||||
.finally(() => setLoading(false));
|
||||
setVersionId(vId);
|
||||
loadVersion(t, vId);
|
||||
});
|
||||
}, [params]);
|
||||
|
||||
const loadVersion = (t: string, vId: string) => {
|
||||
setLoading(true);
|
||||
setError(null);
|
||||
fetch(`/api/client/${t}/versions/${vId}`)
|
||||
.then(async (r) => {
|
||||
if (r.status === 401) {
|
||||
const data = await r.json().catch(() => ({}));
|
||||
if (data.requiresPassword) {
|
||||
setRequiresPassword(true);
|
||||
return null;
|
||||
}
|
||||
}
|
||||
if (!r.ok) throw new Error("Invalid or expired review link");
|
||||
return r.json();
|
||||
})
|
||||
.then((data) => {
|
||||
if (!data) return;
|
||||
setVersion(data.version);
|
||||
setComments(data.comments);
|
||||
setCurrentApprovalStatus(data.version.approvalStatus);
|
||||
setRequiresPassword(false);
|
||||
})
|
||||
.catch((e) => setError(e.message))
|
||||
.finally(() => setLoading(false));
|
||||
};
|
||||
|
||||
const refreshComments = useCallback(async (t: string, vId: string) => {
|
||||
const res = await fetch(`/api/client/${t}/versions/${vId}`);
|
||||
if (res.ok) {
|
||||
@@ -201,6 +220,15 @@ export default function ClientReviewPage({
|
||||
);
|
||||
}
|
||||
|
||||
if (requiresPassword) {
|
||||
return (
|
||||
<ReviewPasswordGate
|
||||
token={token}
|
||||
onUnlocked={() => loadVersion(token, versionId)}
|
||||
/>
|
||||
);
|
||||
}
|
||||
|
||||
if (error || !version) {
|
||||
return (
|
||||
<div className="min-h-screen bg-zinc-950 flex flex-col items-center justify-center gap-4 text-center px-4">
|
||||
|
||||
Reference in New Issue
Block a user