{"version":3,"file":"_id_.mjs","names":[],"sources":["../../../../../../src/astro/routes/api/admin/api-tokens/[id].ts"],"sourcesContent":["/**\n * Single API token endpoint\n *\n * DELETE /_emdash/api/admin/api-tokens/:id — Revoke a token\n *\n * Like creation, revocation is refused when the caller is authenticated by\n * a token: a compromised token must not be able to revoke its siblings.\n */\n\nimport type { APIRoute } from \"astro\";\n\nimport { requirePerm } from \"#api/authorize.js\";\nimport { apiError, handleError, unwrapResult } from \"#api/error.js\";\nimport { handleApiTokenRevoke } from \"#api/handlers/api-tokens.js\";\n\nexport const prerender = false;\n\nexport const DELETE: APIRoute = async ({ params, locals }) => {\n\tconst { emdash, user } = locals;\n\n\tif (!emdash?.db) {\n\t\treturn apiError(\"NOT_CONFIGURED\", \"EmDash is not initialized\", 500);\n\t}\n\n\tif (locals.tokenAuth) {\n\t\treturn apiError(\n\t\t\t\"TOKEN_AUTH_FORBIDDEN\",\n\t\t\t\"API tokens cannot be created or revoked using an API token. Sign in to the admin to manage tokens.\",\n\t\t\t403,\n\t\t);\n\t}\n\n\tconst denied = requirePerm(user, \"api_tokens:manage\");\n\tif (denied) return denied;\n\n\tconst tokenId = params.id;\n\tif (!tokenId) {\n\t\treturn apiError(\"VALIDATION_ERROR\", \"Token ID is required\", 400);\n\t}\n\n\ttry {\n\t\tconst result = await handleApiTokenRevoke(emdash.db, tokenId, user!.id);\n\t\treturn unwrapResult(result);\n\t} catch (error) {\n\t\treturn handleError(error, \"Failed to revoke API token\", \"TOKEN_REVOKE_ERROR\");\n\t}\n};\n"],"mappings":";;;;;;;;AAeA,MAAa,YAAY;AAEzB,MAAa,SAAmB,OAAO,EAAE,QAAQ,aAAa;CAC7D,MAAM,EAAE,QAAQ,SAAS;AAEzB,KAAI,CAAC,QAAQ,GACZ,QAAO,SAAS,kBAAkB,6BAA6B,IAAI;AAGpE,KAAI,OAAO,UACV,QAAO,SACN,wBACA,sGACA,IACA;CAGF,MAAM,SAAS,YAAY,MAAM,oBAAoB;AACrD,KAAI,OAAQ,QAAO;CAEnB,MAAM,UAAU,OAAO;AACvB,KAAI,CAAC,QACJ,QAAO,SAAS,oBAAoB,wBAAwB,IAAI;AAGjE,KAAI;AAEH,SAAO,aADQ,MAAM,qBAAqB,OAAO,IAAI,SAAS,KAAM,GAAG,CAC5C;UACnB,OAAO;AACf,SAAO,YAAY,OAAO,8BAA8B,qBAAqB"}