Aktueller Stand
This commit is contained in:
@@ -1,16 +1,66 @@
|
||||
import { NextResponse } from "next/server";
|
||||
import { getServerSession } from "next-auth";
|
||||
import { prisma } from "../../../lib/prisma";
|
||||
import { isAdminSession, requireSession } from "../../../lib/auth-helpers";
|
||||
import { authOptions } from "../../../lib/auth";
|
||||
import { getAccessSettings } from "../../../lib/system-settings";
|
||||
|
||||
export async function GET(request: Request) {
|
||||
const { session } = await requireSession();
|
||||
if (!session) {
|
||||
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
|
||||
const session = await getServerSession(authOptions);
|
||||
if (session?.user?.status && session.user.status !== "ACTIVE") {
|
||||
return NextResponse.json(
|
||||
{ error: "Account nicht freigeschaltet." },
|
||||
{ status: 403 }
|
||||
);
|
||||
}
|
||||
if (session?.user?.emailVerified === false) {
|
||||
return NextResponse.json(
|
||||
{ error: "E-Mail nicht verifiziert." },
|
||||
{ status: 403 }
|
||||
);
|
||||
}
|
||||
|
||||
const { searchParams } = new URL(request.url);
|
||||
const status = searchParams.get("status");
|
||||
const isAdmin = isAdminSession(session);
|
||||
const { publicAccessEnabled } = await getAccessSettings();
|
||||
|
||||
if (!session?.user?.email) {
|
||||
if (!publicAccessEnabled) {
|
||||
return NextResponse.json(
|
||||
{ error: "Öffentlicher Zugriff ist deaktiviert." },
|
||||
{ status: 403 }
|
||||
);
|
||||
}
|
||||
const events = await prisma.event.findMany({
|
||||
where: {
|
||||
status: "APPROVED",
|
||||
OR: [
|
||||
{ publicOverride: true },
|
||||
{ publicOverride: null, category: { isPublic: true } }
|
||||
]
|
||||
},
|
||||
orderBy: { startAt: "asc" },
|
||||
select: {
|
||||
id: true,
|
||||
title: true,
|
||||
location: true,
|
||||
locationPlaceId: true,
|
||||
locationLat: true,
|
||||
locationLng: true,
|
||||
startAt: true,
|
||||
endAt: true,
|
||||
status: true,
|
||||
category: {
|
||||
select: {
|
||||
id: true,
|
||||
name: true
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
return NextResponse.json(events);
|
||||
}
|
||||
|
||||
const where = isAdmin
|
||||
? status
|
||||
|
||||
Reference in New Issue
Block a user