import { sql } from '@vercel/postgres'; import { getUserFromRequest } from '../../../lib/permission-middleware'; export default async function handler(req, res) { if (req.method !== 'POST') { return res.status(405).json({ error: 'Method not allowed' }); } try { const user = await getUserFromRequest(req); if (!user) { return res.status(401).json({ error: 'Authentication required' }); } const { cardIds } = req.body || {}; if (!Array.isArray(cardIds) || cardIds.length === 0) { return res.status(400).json({ error: 'cardIds must be a non-empty array' }); } if (cardIds.length > 100) { return res.status(400).json({ error: 'cardIds cannot exceed 100 items' }); } const valid = cardIds.every( (id) => Number.isInteger(id) && id > 0 ); if (!valid) { return res.status(400).json({ error: 'All cardIds must be positive integers' }); } const result = await sql` SELECT card_id, SUM(quantity)::int AS total_quantity FROM user_cards WHERE user_id = ${user.userId} AND card_id = ANY(${cardIds}) GROUP BY card_id `; const ownership = {}; for (const row of result.rows) { ownership[row.card_id] = row.total_quantity; } return res.status(200).json({ ownership }); } catch (error) { console.error('[POST /api/cards/batch-ownership]', error); return res.status(500).json({ error: 'Internal server error' }); } }