2025-07-23 22:26:54 -04:00
|
|
|
import { sql } from '@vercel/postgres';
|
2026-05-24 23:59:59 -04:00
|
|
|
import { getUserFromRequest } from '../../../lib/permission-middleware';
|
|
|
|
|
import { checkImportRateLimit } from '../../../lib/rate-limit.js';
|
2025-07-23 22:26:54 -04:00
|
|
|
|
2025-07-24 11:30:21 -04:00
|
|
|
// Helper function to delay execution
|
|
|
|
|
const delay = (ms) => new Promise(resolve => setTimeout(resolve, ms));
|
|
|
|
|
|
|
|
|
|
// Helper function to fetch with retry logic
|
|
|
|
|
async function fetchWithRetry(url, maxRetries = 3, delayMs = 2000) {
|
|
|
|
|
for (let attempt = 1; attempt <= maxRetries; attempt++) {
|
|
|
|
|
try {
|
|
|
|
|
const response = await fetch(url, {
|
|
|
|
|
headers: {
|
feat(brand): in-repo display + comment sweep for Deck Hearth (B1 of 2)
Mechanical sweep of 7 internal files — AGENTS.md branding note, two
Cursor rules (ui-and-theming, auth-and-permissions), scripts/README.md,
two pages/api/cards/import-* User-Agent strings, scripts/import-lorcana.js
comment block. Applies D1 (Deck Hearth) + D2 (deck-hearth) per operator
gate-1 ratification.
EXCLUDES (B2 owns): lib/rate-limit.js Redis prefix, package.json name,
package-lock.json regen, README.md, TESTING_GUIDE.md, three seed scripts,
pages/login.js demo-credential pre-fill, test/lib/permission-middleware
regression-lock literal (PRESERVED per Risk 4).
Verification:
- npm run lint: 128 problems (baseline preserved)
- npm run test:run: 21/21 pass
- Grep: 0 hits for `TCG Vault` in B1's seven files; expected B2 hits remain
- git diff --name-only matches B1 spec exactly
Architect brief: .convoys/pick-a-name/brief-1-display-and-comment-sweep.md
Architect commit: 50ce9ab
Operator gate-1: D1+D2 ratified.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-25 02:50:33 -04:00
|
|
|
'User-Agent': 'Deck-Hearth/1.0',
|
2025-07-24 11:30:21 -04:00
|
|
|
'Accept': 'application/json'
|
|
|
|
|
},
|
|
|
|
|
timeout: 30000 // 30 second timeout
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
if (response.ok) {
|
|
|
|
|
return response;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// If it's a 404, don't retry
|
|
|
|
|
if (response.status === 404) {
|
|
|
|
|
throw new Error(`Set not found: ${response.status}`);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// If it's a 504 or 503, wait longer before retry
|
|
|
|
|
if (response.status === 504 || response.status === 503) {
|
|
|
|
|
console.log(`Attempt ${attempt}: Got ${response.status}, waiting ${delayMs * attempt}ms before retry...`);
|
|
|
|
|
await delay(delayMs * attempt);
|
|
|
|
|
continue;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
throw new Error(`Pokemon TCG API error: ${response.status}`);
|
|
|
|
|
} catch (error) {
|
|
|
|
|
if (attempt === maxRetries) {
|
|
|
|
|
throw error;
|
|
|
|
|
}
|
|
|
|
|
console.log(`Attempt ${attempt} failed:`, error.message);
|
|
|
|
|
await delay(delayMs * attempt);
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2025-07-23 22:26:54 -04:00
|
|
|
export default async function handler(req, res) {
|
|
|
|
|
if (req.method !== 'POST') {
|
|
|
|
|
return res.status(405).json({ error: 'Method not allowed' });
|
|
|
|
|
}
|
|
|
|
|
|
2026-05-24 23:59:59 -04:00
|
|
|
const user = await getUserFromRequest(req);
|
|
|
|
|
if (!user) {
|
|
|
|
|
return res.status(401).json({ error: 'Authentication required' });
|
|
|
|
|
}
|
|
|
|
|
if (user.role !== 'admin') {
|
|
|
|
|
return res.status(403).json({ error: 'Admin access required' });
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
const { allowed, reset } = await checkImportRateLimit(req, user.userId);
|
|
|
|
|
if (!allowed) {
|
|
|
|
|
res.setHeader('Retry-After', Math.ceil((reset - Date.now()) / 1000));
|
|
|
|
|
return res.status(429).json({ error: 'Too many attempts. Try again later.' });
|
|
|
|
|
}
|
|
|
|
|
|
2025-07-23 22:26:54 -04:00
|
|
|
try {
|
|
|
|
|
const { setCode } = req.body;
|
|
|
|
|
|
|
|
|
|
if (!setCode) {
|
|
|
|
|
return res.status(400).json({ error: 'Set code is required' });
|
|
|
|
|
}
|
|
|
|
|
|
2025-07-24 11:30:21 -04:00
|
|
|
console.log(`Starting import for Pokemon set: ${setCode}`);
|
2025-07-23 22:26:54 -04:00
|
|
|
|
2025-07-24 11:30:21 -04:00
|
|
|
// Fetch cards from Pokemon TCG API with retry logic
|
|
|
|
|
const response = await fetchWithRetry(`https://api.pokemontcg.io/v2/cards?q=set.id:${setCode}&pageSize=250`);
|
|
|
|
|
|
2025-07-23 22:26:54 -04:00
|
|
|
const data = await response.json();
|
|
|
|
|
const cards = data.data || [];
|
|
|
|
|
|
2025-07-24 11:30:21 -04:00
|
|
|
if (cards.length === 0) {
|
|
|
|
|
return res.status(200).json({
|
|
|
|
|
success: true,
|
|
|
|
|
message: `No cards found for set ${setCode}`,
|
|
|
|
|
imported: 0,
|
|
|
|
|
skipped: 0,
|
|
|
|
|
total: 0
|
|
|
|
|
});
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
console.log(`Found ${cards.length} cards for set ${setCode}`);
|
|
|
|
|
|
2025-07-23 22:26:54 -04:00
|
|
|
let importedCount = 0;
|
|
|
|
|
let skippedCount = 0;
|
|
|
|
|
|
|
|
|
|
for (const card of cards) {
|
|
|
|
|
try {
|
|
|
|
|
// Check if card already exists
|
|
|
|
|
const existingCard = await sql`
|
|
|
|
|
SELECT id FROM cards WHERE scryfall_id = ${card.id}
|
|
|
|
|
`;
|
|
|
|
|
|
|
|
|
|
if (existingCard.rows.length > 0) {
|
|
|
|
|
skippedCount++;
|
|
|
|
|
continue;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Extract price data from TCGPlayer
|
|
|
|
|
let currentPrice = null;
|
|
|
|
|
if (card.tcgplayer?.prices?.normal?.market) {
|
|
|
|
|
currentPrice = parseFloat(card.tcgplayer.prices.normal.market);
|
|
|
|
|
} else if (card.tcgplayer?.prices?.holofoil?.market) {
|
|
|
|
|
currentPrice = parseFloat(card.tcgplayer.prices.holofoil.market);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Determine rarity
|
|
|
|
|
let rarity = card.rarity || 'Unknown';
|
|
|
|
|
if (rarity.includes('Holo')) {
|
|
|
|
|
rarity = 'Holographic';
|
|
|
|
|
} else if (rarity.includes('Secret')) {
|
|
|
|
|
rarity = 'Secret Rare';
|
|
|
|
|
} else if (rarity.includes('Ultra')) {
|
|
|
|
|
rarity = 'Ultra Rare';
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Insert card into database
|
|
|
|
|
await sql`
|
|
|
|
|
INSERT INTO cards (
|
|
|
|
|
name, set_name, set_code, card_number, rarity, game,
|
|
|
|
|
mana_cost, cmc, card_type, colors, oracle_text,
|
|
|
|
|
power, toughness, image_url, stock_image_url,
|
|
|
|
|
current_price, market_price, scryfall_id, verified
|
|
|
|
|
) VALUES (
|
|
|
|
|
${card.name}, ${card.set.name}, ${card.set.id}, ${card.number},
|
|
|
|
|
${rarity}, 'Pokemon', null, null, ${card.supertype || 'Pokemon'},
|
|
|
|
|
${JSON.stringify(card.types || [])}, ${card.flavorText || null},
|
|
|
|
|
${card.attacks?.[0]?.damage || null}, null,
|
|
|
|
|
${card.images?.small || null}, ${card.images?.large || null},
|
|
|
|
|
${currentPrice}, null, ${card.id}, true
|
|
|
|
|
)
|
|
|
|
|
`;
|
|
|
|
|
|
|
|
|
|
importedCount++;
|
|
|
|
|
} catch (error) {
|
|
|
|
|
console.error(`Error importing card ${card.name}:`, error);
|
|
|
|
|
skippedCount++;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2025-07-24 11:30:21 -04:00
|
|
|
console.log(`Import completed for set ${setCode}: ${importedCount} imported, ${skippedCount} skipped`);
|
|
|
|
|
|
2025-07-23 22:26:54 -04:00
|
|
|
res.status(200).json({
|
|
|
|
|
success: true,
|
|
|
|
|
message: `Import completed for set ${setCode}`,
|
|
|
|
|
imported: importedCount,
|
|
|
|
|
skipped: skippedCount,
|
|
|
|
|
total: cards.length
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
} catch (error) {
|
|
|
|
|
console.error('Card import error:', error);
|
|
|
|
|
res.status(500).json({
|
|
|
|
|
error: 'Import failed',
|
|
|
|
|
details: error.message
|
|
|
|
|
});
|
|
|
|
|
}
|
|
|
|
|
}
|