Add all REST API endpoints for mobile app consumption: Routes: - GET /api/v1/routes — paginated list with cursor, Zod validation - GET /api/v1/routes/:id — full detail with GPX, versions - POST /api/v1/routes — create with Zod-validated body - PUT /api/v1/routes/:id — update, creates new version - DELETE /api/v1/routes/:id — returns 204 Activities: - GET /api/v1/activities — paginated list with cursor - GET /api/v1/activities/:id — full detail - POST /api/v1/activities — create with GPX stat extraction - DELETE /api/v1/activities/:id — returns 204 Supporting: - POST /api/v1/routes/compute — BRouter proxy - POST /api/v1/uploads — presigned upload URL generation Device management: - GET /api/v1/auth/devices — list connected devices with isCurrent - DELETE /api/v1/auth/devices/:id — revoke device token - Store device_name on token exchange Infrastructure: - requireApiUser() guard — returns 401 with structured error - apiError() helper for consistent error responses - All endpoints use Zod schemas from @trails-cool/api for validation Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
23 lines
717 B
TypeScript
23 lines
717 B
TypeScript
import { getAuthenticatedUser } from "./oauth.server.ts";
|
|
import { ERROR_CODES } from "@trails-cool/api";
|
|
|
|
/**
|
|
* Require authentication for an API route. Returns the user or throws a 401 Response.
|
|
*/
|
|
export async function requireApiUser(request: Request) {
|
|
const user = await getAuthenticatedUser(request);
|
|
if (!user) {
|
|
throw Response.json(
|
|
{ error: "Unauthorized", code: ERROR_CODES.UNAUTHORIZED },
|
|
{ status: 401 },
|
|
);
|
|
}
|
|
return user;
|
|
}
|
|
|
|
/**
|
|
* Return a structured API error response.
|
|
*/
|
|
export function apiError(status: number, code: string, message: string, fields?: Array<{ field: string; message: string }>) {
|
|
return Response.json({ error: message, code, fields }, { status });
|
|
}
|