🔧 Fix SQL Template Literal Syntax Error
🐛 Critical SQL Fix: - Fixed malformed template literal concatenation in /api/collections - Replaced dynamic sql template concatenation with parameterized query - Used sql.query() with proper parameter binding (, , ) - Resolved 'syntax error at or near ' database error 🎯 Query Structure: - Maintains all existing functionality - Proper excludeSystem parameter handling - Clean parameterized query approach - Better SQL injection protection Collections page should now load properly! 🚀
This commit is contained in:
parent
4689424f3a
commit
fba8af1fe1
1 changed files with 15 additions and 5 deletions
|
|
@ -26,7 +26,7 @@ export default async function handler(req, res) {
|
|||
const { excludeSystem } = req.query; // New parameter to exclude system collections
|
||||
|
||||
// Get collections based on ownership, collaboration, or shared access (no public discovery)
|
||||
const result = await sql`
|
||||
let query = `
|
||||
SELECT DISTINCT
|
||||
c.*,
|
||||
u.email as creator_email,
|
||||
|
|
@ -34,7 +34,7 @@ export default async function handler(req, res) {
|
|||
COALESCE(SUM(cards.market_price * cc.quantity), 0) as total_value,
|
||||
cp.role as user_role,
|
||||
CASE
|
||||
WHEN c.user_id = ${currentUserId} THEN 'owner'
|
||||
WHEN c.user_id = $1 THEN 'owner'
|
||||
WHEN cp.role IS NOT NULL THEN cp.role
|
||||
ELSE NULL
|
||||
END as effective_role
|
||||
|
|
@ -42,14 +42,24 @@ export default async function handler(req, res) {
|
|||
LEFT JOIN users u ON c.user_id = u.id
|
||||
LEFT JOIN collection_cards cc ON c.id = cc.collection_id
|
||||
LEFT JOIN cards ON cc.card_id = cards.id
|
||||
LEFT JOIN collection_permissions cp ON c.id = cp.collection_id AND cp.user_id = ${currentUserId} AND cp.status = 'active'
|
||||
LEFT JOIN collection_permissions cp ON c.id = cp.collection_id AND cp.user_id = $2 AND cp.status = 'active'
|
||||
WHERE
|
||||
(c.user_id = ${currentUserId} OR cp.id IS NOT NULL)
|
||||
${excludeSystem === 'true' ? sql`AND (c.is_system_collection IS NULL OR c.is_system_collection = false)` : sql``}
|
||||
(c.user_id = $3 OR cp.id IS NOT NULL)
|
||||
`;
|
||||
|
||||
const params = [currentUserId, currentUserId, currentUserId];
|
||||
|
||||
if (excludeSystem === 'true') {
|
||||
query += ` AND (c.is_system_collection IS NULL OR c.is_system_collection = false)`;
|
||||
}
|
||||
|
||||
query += `
|
||||
GROUP BY c.id, u.email, cp.role
|
||||
ORDER BY c.updated_at DESC
|
||||
`;
|
||||
|
||||
const result = await sql.query(query, params);
|
||||
|
||||
const collections = result.rows.map(collection => ({
|
||||
id: collection.id,
|
||||
slug: collection.slug,
|
||||
|
|
|
|||
Loading…
Reference in a new issue