// Driver-side auth helper. Every driver-action endpoint first calls // requireDriverProfile: it proves the request is from a signed-in user and // that the user has completed onboarding (has a linked drivers row). A // driver-role user who hasn't onboarded yet gets a 403 so the client can // route them to the onboarding form rather than showing a bare 404. import { requireAuth } from "@/lib/jwt"; import { sql } from "@/lib/db"; import type { ServiceId } from "@/constants/services"; type Auth = { userId: string; email: string }; export type DriverProfile = { auth: Auth; driverId: number; service: ServiceId; online: boolean; }; export type AuthError = { error: Response }; const VALID_SERVICES = ["car", "moto", "courier", "chauffeur"] as const; export const isServiceId = (v: unknown): v is ServiceId => typeof v === "string" && (VALID_SERVICES as readonly string[]).includes(v); // Returns the driver profile for the authenticated user, or a 401/403 the // caller can return directly. A 403 with the onboarding code tells the client // to show the onboarding form instead of treating it as a hard error. export const requireDriverProfile = async ( req: Request, ): Promise => { const auth = requireAuth(req); if ("error" in auth) return { error: auth.error }; const rows = await sql<{ id: number; service: ServiceId; online: boolean }>` SELECT id, service, online FROM drivers WHERE user_id = ${auth.userId} `; if (!rows[0]) { return { error: Response.json( { error: "No driver profile — complete onboarding.", code: "ONBOARD" }, { status: 403 }, ), }; } const { id, service, online } = rows[0]; return { auth, driverId: id, service, online }; };