54 lines
2.1 KiB
TypeScript
54 lines
2.1 KiB
TypeScript
/* eslint-disable @typescript-eslint/no-explicit-any */
|
|
import { NextRequest, NextResponse } from 'next/server'
|
|
import { createClient, createAdminClient } from '@/lib/supabase/server'
|
|
|
|
export async function POST(request: NextRequest) {
|
|
try {
|
|
const supabase = await createClient()
|
|
const { data: { user }, error: authError } = await supabase.auth.getUser()
|
|
if (authError || !user) return NextResponse.json({ error: 'Non autorisé' }, { status: 401 })
|
|
|
|
const { category_id, name } = await request.json()
|
|
if (!category_id || !name?.trim()) return NextResponse.json({ error: 'category_id et nom requis' }, { status: 400 })
|
|
|
|
const admin = createAdminClient() as any
|
|
|
|
// Vérifier que la catégorie existe (et appartient à l'utilisateur si created_by est disponible)
|
|
const { data: cat } = await admin
|
|
.from('categories')
|
|
.select('id, created_by')
|
|
.eq('id', category_id)
|
|
.single()
|
|
|
|
if (!cat) return NextResponse.json({ error: 'Catégorie introuvable' }, { status: 404 })
|
|
// Vérification de propriété uniquement si la colonne est remplie
|
|
if (cat.created_by && cat.created_by !== user.id) {
|
|
return NextResponse.json({ error: 'Accès refusé' }, { status: 403 })
|
|
}
|
|
|
|
// Tentative avec created_by (requiert la migration SQL)
|
|
let { data, error } = await admin
|
|
.from('subchapters')
|
|
.insert({ category_id, name: name.trim(), created_by: user.id })
|
|
.select()
|
|
.single()
|
|
|
|
// Fallback : si la colonne n'existe pas encore (migration non jouée)
|
|
if (error && error.message?.includes('created_by')) {
|
|
console.warn('[subchapters/create] colonne created_by manquante — migration SQL non jouée')
|
|
const fallback = await admin
|
|
.from('subchapters')
|
|
.insert({ category_id, name: name.trim() })
|
|
.select()
|
|
.single()
|
|
data = fallback.data
|
|
error = fallback.error
|
|
}
|
|
|
|
if (error) return NextResponse.json({ error: error.message }, { status: 500 })
|
|
return NextResponse.json({ success: true, subchapter: data })
|
|
} catch {
|
|
return NextResponse.json({ error: 'Erreur serveur' }, { status: 500 })
|
|
}
|
|
}
|