Phase 1 - Security & Bug Fixes: - Add requireApiAuth helper and protect all 25 unprotected API routes - Add org-tenant scoping to all card, job, stats, and notification queries - Fix SSRF in ai-test, mask secrets in settings API, fix middleware bypass - Fix cards pagination routing, stat filter sync, drag-drop file passing - Add PUT /api/auth/me for profile persistence, stuck job recovery - Fix email watcher MIME type detection Phase 2 - Dynamic Fields & Digital Survey: - Add FormTemplate, FormField, Person, PasswordResetToken models to schema - Add fieldData, formTemplateId, firstName, lastName, personId to ResponseCard - Build FormTemplate CRUD API with field management and org scoping - Build Form Builder UI with field ordering, type config, and section management - Refactor card detail page to render fields dynamically from templates - Add dynamic OCR prompt/schema generation from template fields - Build public survey page at /s/[orgSlug]/[formSlug] with branding - Add QR code generation API and share section component Phase 3 - People & Analytics: - Build People CRUD API with merge and batch auto-link endpoints - Build People list and detail pages with search, merge dialog - Add auto-link logic in OCR completion to match/create Person records - Add /api/stats/trends endpoint with time series and team activity - Build Reports page with Recharts (area charts, bar charts, pipeline) - Upgrade dashboard with sparklines and People stat card Phase 4 - UX Polish: - Replace silent error handling with toast notifications across all pages - Add loading skeletons, differentiated empty states - Add ARIA labels, skip-to-content link, accessible column toggle - Add forgot password flow, Cmd+K command palette, Collection Days pages - Unify Echo branding and theme toggle consistency Made-with: Cursor
47 lines
1.1 KiB
TypeScript
47 lines
1.1 KiB
TypeScript
import { NextResponse } from "next/server";
|
|
import { prisma } from "@/lib/db";
|
|
import { sendWebhook } from "@/lib/webhook";
|
|
import { requireApiAuth, handleApiError } from "@/lib/api-auth";
|
|
|
|
export async function POST() {
|
|
try {
|
|
await requireApiAuth();
|
|
const settings = await prisma.appSettings.findUnique({
|
|
where: { id: "singleton" },
|
|
});
|
|
|
|
if (!settings?.webhookUrl) {
|
|
return NextResponse.json(
|
|
{ error: "Webhook URL is not configured" },
|
|
{ status: 400 }
|
|
);
|
|
}
|
|
|
|
const testCard = {
|
|
id: "test_123",
|
|
name: "Test Card",
|
|
email: "test@example.com",
|
|
ocrStatus: "complete",
|
|
reviewStatus: "unreviewed",
|
|
ocrConfidence: 92,
|
|
};
|
|
|
|
const result = await sendWebhook(
|
|
settings.webhookUrl,
|
|
settings.webhookSecret,
|
|
"test",
|
|
testCard
|
|
);
|
|
|
|
if (result.ok) {
|
|
return NextResponse.json({ ok: true, message: "Test webhook sent successfully" });
|
|
} else {
|
|
return NextResponse.json(
|
|
{ ok: false, error: result.error },
|
|
{ status: 400 }
|
|
);
|
|
}
|
|
} catch (error) {
|
|
return handleApiError(error);
|
|
}
|
|
}
|