echos-ocr/src/app/api/form-templates/[id]/route.ts

113 lines
3.2 KiB
TypeScript
Raw Normal View History

Add dynamic fields, people directory, analytics, security hardening, and UX polish Phase 1 - Security & Bug Fixes: - Add requireApiAuth helper and protect all 25 unprotected API routes - Add org-tenant scoping to all card, job, stats, and notification queries - Fix SSRF in ai-test, mask secrets in settings API, fix middleware bypass - Fix cards pagination routing, stat filter sync, drag-drop file passing - Add PUT /api/auth/me for profile persistence, stuck job recovery - Fix email watcher MIME type detection Phase 2 - Dynamic Fields & Digital Survey: - Add FormTemplate, FormField, Person, PasswordResetToken models to schema - Add fieldData, formTemplateId, firstName, lastName, personId to ResponseCard - Build FormTemplate CRUD API with field management and org scoping - Build Form Builder UI with field ordering, type config, and section management - Refactor card detail page to render fields dynamically from templates - Add dynamic OCR prompt/schema generation from template fields - Build public survey page at /s/[orgSlug]/[formSlug] with branding - Add QR code generation API and share section component Phase 3 - People & Analytics: - Build People CRUD API with merge and batch auto-link endpoints - Build People list and detail pages with search, merge dialog - Add auto-link logic in OCR completion to match/create Person records - Add /api/stats/trends endpoint with time series and team activity - Build Reports page with Recharts (area charts, bar charts, pipeline) - Upgrade dashboard with sparklines and People stat card Phase 4 - UX Polish: - Replace silent error handling with toast notifications across all pages - Add loading skeletons, differentiated empty states - Add ARIA labels, skip-to-content link, accessible column toggle - Add forgot password flow, Cmd+K command palette, Collection Days pages - Unify Echo branding and theme toggle consistency Made-with: Cursor
2026-04-17 00:29:26 -04:00
import { NextRequest, NextResponse } from "next/server";
import { prisma } from "@/lib/db";
import { requireApiAuthWithOrg, handleApiError } from "@/lib/api-auth";
type RouteContext = { params: Promise<{ id: string }> };
async function getOwnedTemplate(templateId: string, orgId: string) {
const template = await prisma.formTemplate.findUnique({
where: { id: templateId },
include: {
fields: { orderBy: { sortOrder: "asc" } },
_count: { select: { cards: true } },
},
});
if (!template || template.organizationId !== orgId) return null;
return template;
}
export async function GET(_request: NextRequest, ctx: RouteContext) {
try {
const session = await requireApiAuthWithOrg();
const { id } = await ctx.params;
const template = await getOwnedTemplate(id, session.user.orgId!);
if (!template) {
return NextResponse.json(
{ error: "Template not found" },
{ status: 404 }
);
}
return NextResponse.json(template);
} catch (error) {
return handleApiError(error);
}
}
export async function PUT(request: NextRequest, ctx: RouteContext) {
try {
const session = await requireApiAuthWithOrg();
const { id } = await ctx.params;
const existing = await getOwnedTemplate(id, session.user.orgId!);
if (!existing) {
return NextResponse.json(
{ error: "Template not found" },
{ status: 404 }
);
}
const body = await request.json();
const { name, description, isActive, branding, settings } = body as {
name?: string;
description?: string;
isActive?: boolean;
branding?: Record<string, unknown>;
settings?: Record<string, unknown>;
};
const data: Record<string, unknown> = {};
if (name !== undefined) data.name = name.trim();
if (description !== undefined) data.description = description?.trim() || null;
if (isActive !== undefined) data.isActive = Boolean(isActive);
if (branding !== undefined) data.branding = branding;
if (settings !== undefined) data.settings = settings;
const updated = await prisma.formTemplate.update({
where: { id },
data,
include: {
fields: { orderBy: { sortOrder: "asc" } },
_count: { select: { cards: true } },
},
});
return NextResponse.json(updated);
} catch (error) {
return handleApiError(error);
}
}
export async function DELETE(_request: NextRequest, ctx: RouteContext) {
try {
const session = await requireApiAuthWithOrg();
const { id } = await ctx.params;
const existing = await getOwnedTemplate(id, session.user.orgId!);
if (!existing) {
return NextResponse.json(
{ error: "Template not found" },
{ status: 404 }
);
}
if (existing._count.cards > 0) {
const deactivated = await prisma.formTemplate.update({
where: { id },
data: { isActive: false },
});
return NextResponse.json({
...deactivated,
_deactivated: true,
_reason: "Template has associated cards and was deactivated instead of deleted",
});
}
await prisma.formTemplate.delete({ where: { id } });
return NextResponse.json({ deleted: true });
} catch (error) {
return handleApiError(error);
}
}