Files
accounted/app/api/company/route.ts
T
Mattsson e11f70b347 Bug/gh issues fiz (#1103)
* refactor: optimize page loading and data fetching

* fix: resolve recurring production runtime errors

* feat: add MCP company and customer updates

* fix: handle year-end tax adjustments

* feat: harden annual report compliance

* fix: expand invoice logo and font support

* fix: sanitize API route error responses

* fix: sanitize user-facing error messages

* feat: persist onboarding and tax assessment notices

* fix: reduce cloud backup audit churn

* feat: refine invoice editor layout

* fix: show saved tax adjustments in INK2

* fix: complete annual report API mappings

* docs: record operational safeguards and decisions

* fix: harden annual report review findings

* fix: adjust column span for description based on VAT registration

* New css class name
2026-07-21 23:00:15 +02:00

55 lines
1.7 KiB
TypeScript

import { NextResponse } from 'next/server'
import { requireAuth } from '@/lib/auth/require-auth'
import { getErrorMessage as getUserErrorMessage } from '@/lib/errors/get-error-message'
/**
* GET /api/company?owned=true&archived=false
*
* Returns companies the caller has access to, filtered by query:
* - owned=true → only companies where caller's role is 'owner'
* - archived=false → only non-archived companies (default)
*
* Used by the account danger zone to show a blockers list before
* allowing account deletion. User-level (spans ALL memberships), so it uses
* requireAuth() directly — no single active-company context applies.
*/
export async function GET(request: Request) {
const auth = await requireAuth()
if (auth.error) return auth.error
const { user, supabase } = auth
const url = new URL(request.url)
const ownedOnly = url.searchParams.get('owned') === 'true'
const includeArchived = url.searchParams.get('archived') === 'true'
let query = supabase
.from('company_members')
.select('role, companies!inner(id, name, archived_at)')
.eq('user_id', user.id)
if (ownedOnly) query = query.eq('role', 'owner')
if (!includeArchived) query = query.is('companies.archived_at', null)
const { data, error } = await query
if (error) {
return NextResponse.json({ error: getUserErrorMessage(error) }, { status: 500 })
}
const companies = (data ?? []).map((row) => {
const company = (row.companies as unknown) as {
id: string
name: string
archived_at: string | null
}
return {
id: company.id,
name: company.name,
archived_at: company.archived_at,
role: row.role as string,
}
})
return NextResponse.json({ data: companies })
}