- Created admin authentication system with useIsAdmin hook - Added AdminProtected component for route protection - Added prominent 'Edit Card (Admin)' button on card detail pages - Protected all admin routes (/admin/*) with authentication - Added admin navigation item to main layout sidebar - Updated auth verification API to return mock admin user - Integrated admin edit button that redirects to card editor with card ID - Added proper access denied page for non-admin users - Admin-only features now show/hide based on user role - Seamless workflow: spot incorrect card → click edit → fix immediately
36 lines
No EOL
1 KiB
JavaScript
36 lines
No EOL
1 KiB
JavaScript
import { verifyToken, getUserById } from '../auth-utils.js';
|
|
|
|
export default async function handler(req, res) {
|
|
// Set CORS headers
|
|
res.setHeader('Access-Control-Allow-Origin', '*');
|
|
res.setHeader('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS');
|
|
res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization');
|
|
|
|
// Handle preflight requests
|
|
if (req.method === 'OPTIONS') {
|
|
res.status(200).end();
|
|
return;
|
|
}
|
|
|
|
if (req.method !== 'GET') {
|
|
return res.status(405).json({ error: 'Method not allowed' });
|
|
}
|
|
|
|
try {
|
|
// For development purposes, return mock admin user
|
|
// In production, implement proper JWT/session verification
|
|
const mockAdminUser = {
|
|
id: 1,
|
|
email: 'admin@tcgvault.com',
|
|
role: 'admin',
|
|
name: 'Admin User',
|
|
created_at: new Date().toISOString()
|
|
};
|
|
|
|
res.status(200).json(mockAdminUser);
|
|
|
|
} catch (error) {
|
|
console.error('Token verification error:', error);
|
|
res.status(500).json({ error: 'Internal server error' });
|
|
}
|
|
}
|