import { requireAuth } from "@/lib/jwt"; import { sql } from "@/lib/db"; export async function GET(req: Request) { const auth = requireAuth(req); if ("error" in auth) return auth.error; try { const response = await sql` SELECT id, name, email, phone, role FROM users WHERE id = ${auth.userId} `; return Response.json({ data: response[0] ?? null }); } catch (error) { console.log("[GET_USER]: ", error); return Response.json({ error }, { status: 500 }); } } // PATCH — one-time role selection, straight after sign-up. // // The role is write-once. It used to be freely re-assignable, which meant any // account could flip itself to 'driver' on demand; combined with self-service // onboarding that was a rider account away from receiving live pickups. Role // is no longer a credential on its own (driver profiles are vetted), but it // still shouldn't be a toggle: a user who genuinely needs to switch goes // through support, which leaves a record. Re-sending the same role is a no-op // so a retried request from the role screen still succeeds. export async function PATCH(req: Request) { const auth = requireAuth(req); if ("error" in auth) return auth.error; const { role } = await req.json(); if (!["rider", "driver"].includes(role)) { return Response.json({ error: "Invalid role." }, { status: 400 }); } try { const response = await sql` UPDATE users SET role = ${role} WHERE id = ${auth.userId} AND (role IS NULL OR role = ${role}) RETURNING id, role `; if (response.length === 0) { const existing = await sql<{ role: string | null }>` SELECT role FROM users WHERE id = ${auth.userId} `; if (!existing[0]) { return Response.json({ error: "User not found." }, { status: 404 }); } return Response.json( { error: "Your account role has already been set.", code: "ROLE_ALREADY_SET", role: existing[0].role, }, { status: 409 }, ); } return Response.json({ data: response[0] }); } catch (error) { console.log("[PATCH_USER]: ", error); return Response.json({ error }, { status: 500 }); } }