/** * GET /api/orders/[orderId] * * The activate page's data source. Signed-in callers only, and only for an * order they have already claimed — ownership is the same check the page * itself makes, repeated here because a route handler is reachable directly. * * Upstream failures are reported, not smoothed over. A page that cannot read * an order must say so; the one thing it must never do is draw a reassuring * placeholder while the eSIM behind it does not exist. */ import { auth } from "@clerk/nextjs/server"; import { NextResponse } from "next/server"; import { userOwnsOrder } from "@/lib/checkout-order-claim"; import { fetchOrder } from "@/vendor/carrier/client"; export const dynamic = "force-dynamic"; interface Context { params: Promise<{ orderId: string }>; } export async function GET(_req: Request, ctx: Context): Promise { const { userId } = await auth(); if (!userId) { return NextResponse.json({ error: "Unauthorized" }, { status: 401 }); } const { orderId } = await ctx.params; if (!orderId) { return NextResponse.json({ error: "orderId is required" }, { status: 400 }); } if (!(await userOwnsOrder(userId, orderId))) { return NextResponse.json({ error: "Order not found" }, { status: 404 }); } const lookup = await fetchOrder(orderId); if (lookup.ok) { return NextResponse.json({ order: lookup.order }); } if (lookup.reason === "not-found") { return NextResponse.json({ error: "Order not found", code: "not_found" }, { status: 404 }); } if (lookup.reason === "unconfigured") { console.error( "[orders] NEXT_PUBLIC_CARRIER_API_URL is unset — the storefront has no fulfilment origin to ask, " + "so no order can ever reach 'ready'", ); return NextResponse.json( { error: "Activation is not available yet. Please contact support with your order number.", code: "fulfilment_unconfigured", }, { status: 503 }, ); } console.error(`[orders] order lookup failed for ${orderId}: ${lookup.reason}`); return NextResponse.json( { error: "We could not reach your eSIM details right now. Please try again in a moment.", code: "fulfilment_unavailable", }, { status: 502 }, ); }