- Rewrote Drizzle schema: 20 tables with enums, relations, indexes - Generated migration with DROP TABLE records (v1 EAV removal) - Added passkey auth routes (register/login) - Added requireWorkspaceAccess helper - Added seedDefaultData for Personal workspace + welcome note - Updated SSE endpoint for v2 entities + workspace_id filtering - Created recordActivity helper (insert + pg_notify) - Updated sidebar: Graph replaces Reports, removed Analytics - Updated command palette for v2 entities - Created AGENTS.md with locked contract - Created llm-wiki scaffold (5 stubs) - Added inline AGENT INSTRUCTION comments to all 50 API route files - Fixed globals.css border-border class conflict - Updated database.ts stub for v1 compatibility
50 lines
1.5 KiB
TypeScript
50 lines
1.5 KiB
TypeScript
// AGENT INSTRUCTION: After every write (INSERT/UPDATE/DELETE), you MUST:
|
|
// 1. Insert activity feed entry
|
|
// 2. Call pg.notify('project_e_events', JSON.stringify({ type, action, id, workspace_id }))
|
|
// See AGENTS.md for full rules.
|
|
|
|
import { NextRequest, NextResponse } from 'next/server';
|
|
import { getAuthUser } from '@/lib/auth';
|
|
import { db, users } from '@project-e/db';
|
|
import { eq } from 'drizzle-orm';
|
|
|
|
// POST /api/auth/passkey/register — Start passkey registration
|
|
export async function POST(request: NextRequest) {
|
|
try {
|
|
const user = await getAuthUser(request);
|
|
if (!user) {
|
|
return NextResponse.json(
|
|
{ error: { code: 'UNAUTHORIZED', message: 'Not authenticated' } },
|
|
{ status: 401 }
|
|
);
|
|
}
|
|
|
|
const body = await request.json();
|
|
const { credentialId, publicKey, counter } = body;
|
|
|
|
if (!credentialId || !publicKey) {
|
|
return NextResponse.json(
|
|
{ error: { code: 'VALIDATION_ERROR', message: 'credentialId and publicKey are required' } },
|
|
{ status: 400 }
|
|
);
|
|
}
|
|
|
|
await db
|
|
.update(users)
|
|
.set({
|
|
passkeyCredentialId: credentialId,
|
|
passkeyPublicKey: publicKey,
|
|
passkeyCounter: counter ?? 0,
|
|
})
|
|
.where(eq(users.id, user.id));
|
|
|
|
return NextResponse.json({ success: true });
|
|
} catch (error) {
|
|
console.error('[passkey/register] error:', error);
|
|
return NextResponse.json(
|
|
{ error: { code: 'INTERNAL_ERROR', message: 'Failed to register passkey' } },
|
|
{ status: 500 }
|
|
);
|
|
}
|
|
}
|