{"version":3,"file":"index.mjs","names":[],"sources":["../../../../../../src/astro/routes/api/content/[collection]/index.ts"],"sourcesContent":["/**\n * Content list and create endpoints - injected by EmDash integration\n *\n * GET  /_emdash/api/content/{collection} - List content\n * POST /_emdash/api/content/{collection} - Create content\n */\n\nimport { hasPermission } from \"@premium-cms/auth\";\nimport type { APIRoute } from \"astro\";\n\nimport { requirePerm, requireOwnerPerm } from \"#api/authorize.js\";\nimport { apiError, mapErrorStatus, unwrapResult } from \"#api/error.js\";\nimport { parseBody, parseQuery, isParseError } from \"#api/parse.js\";\nimport { contentListQuery, contentCreateBody } from \"#api/schemas.js\";\n\nexport const prerender = false;\n\nexport const GET: APIRoute = async ({ params, url, locals }) => {\n\tconst { emdash, user } = locals;\n\tif (!emdash?.handleContentList) {\n\t\treturn apiError(\"NOT_CONFIGURED\", \"EmDash is not initialized\", 500);\n\t}\n\tconst denied = requirePerm(user, \"content:read\");\n\tif (denied) return denied;\n\tconst collection = params.collection!;\n\tconst query = parseQuery(url, contentListQuery);\n\tif (isParseError(query)) return query;\n\n\t// Subscribers must only see published content; force the status filter\n\t// regardless of caller-supplied value. Any user with content:read_drafts\n\t// (CONTRIBUTOR+) keeps the requested filter.\n\tconst params_ = hasPermission(user, \"content:read_drafts\")\n\t\t? query\n\t\t: { ...query, status: \"published\" };\n\n\tconst result = await emdash.handleContentList(collection, params_);\n\n\treturn unwrapResult(result);\n};\n\nexport const POST: APIRoute = async ({ params, request, locals, cache }) => {\n\tconst { emdash, user } = locals;\n\tif (!emdash?.handleContentCreate || !emdash?.handleContentGet) {\n\t\treturn apiError(\"NOT_CONFIGURED\", \"EmDash is not initialized\", 500);\n\t}\n\tconst denied = requirePerm(user, \"content:create\");\n\tif (denied) return denied;\n\tconst collection = params.collection!;\n\tconst body = await parseBody(request, contentCreateBody);\n\tif (isParseError(body)) return body;\n\n\t// Creating a translation requires edit permission on the source item\n\tif (body.translationOf) {\n\t\tconst source = await emdash.handleContentGet(collection, body.translationOf);\n\t\tif (!source.success) {\n\t\t\treturn apiError(\n\t\t\t\tsource.error?.code ?? \"NOT_FOUND\",\n\t\t\t\tsource.error?.message ?? \"Translation source not found\",\n\t\t\t\tmapErrorStatus(source.error?.code),\n\t\t\t);\n\t\t}\n\t\tconst sourceAuthor = source.data.item.authorId ?? \"\";\n\t\tconst translationDenied = requireOwnerPerm(\n\t\t\tuser,\n\t\t\tsourceAuthor,\n\t\t\t\"content:edit_own\",\n\t\t\t\"content:edit_any\",\n\t\t);\n\t\tif (translationDenied) return translationDenied;\n\t}\n\n\t// Only EDITOR+ can write publishedAt / createdAt directly — incl. clearing to null.\n\tconst hasDateOverride = body.publishedAt !== undefined || body.createdAt !== undefined;\n\tif (hasDateOverride && !hasPermission(user, \"content:publish_any\")) {\n\t\treturn apiError(\n\t\t\t\"FORBIDDEN\",\n\t\t\t\"Writing publishedAt or createdAt requires content:publish_any permission\",\n\t\t\t403,\n\t\t);\n\t}\n\n\t// Auto-set authorId to current user when creating content\n\tconst result = await emdash.handleContentCreate(collection, {\n\t\t...body,\n\t\tauthorId: user?.id,\n\t\tlocale: body.locale,\n\t\ttranslationOf: body.translationOf,\n\t});\n\n\tif (!result.success) return unwrapResult(result);\n\n\tif (cache?.enabled) await cache.invalidate({ tags: [collection] });\n\n\treturn unwrapResult(result, 201);\n};\n"],"mappings":";;;;;;;;;;;;;;;;;;;;;AAeA,MAAa,YAAY;AAEzB,MAAa,MAAgB,OAAO,EAAE,QAAQ,KAAK,aAAa;CAC/D,MAAM,EAAE,QAAQ,SAAS;AACzB,KAAI,CAAC,QAAQ,kBACZ,QAAO,SAAS,kBAAkB,6BAA6B,IAAI;CAEpE,MAAM,SAAS,YAAY,MAAM,eAAe;AAChD,KAAI,OAAQ,QAAO;CACnB,MAAM,aAAa,OAAO;CAC1B,MAAM,QAAQ,WAAW,KAAK,iBAAiB;AAC/C,KAAI,aAAa,MAAM,CAAE,QAAO;CAKhC,MAAM,UAAU,cAAc,MAAM,sBAAsB,GACvD,QACA;EAAE,GAAG;EAAO,QAAQ;EAAa;AAIpC,QAAO,aAFQ,MAAM,OAAO,kBAAkB,YAAY,QAAQ,CAEvC;;AAG5B,MAAa,OAAiB,OAAO,EAAE,QAAQ,SAAS,QAAQ,YAAY;CAC3E,MAAM,EAAE,QAAQ,SAAS;AACzB,KAAI,CAAC,QAAQ,uBAAuB,CAAC,QAAQ,iBAC5C,QAAO,SAAS,kBAAkB,6BAA6B,IAAI;CAEpE,MAAM,SAAS,YAAY,MAAM,iBAAiB;AAClD,KAAI,OAAQ,QAAO;CACnB,MAAM,aAAa,OAAO;CAC1B,MAAM,OAAO,MAAM,UAAU,SAAS,kBAAkB;AACxD,KAAI,aAAa,KAAK,CAAE,QAAO;AAG/B,KAAI,KAAK,eAAe;EACvB,MAAM,SAAS,MAAM,OAAO,iBAAiB,YAAY,KAAK,cAAc;AAC5E,MAAI,CAAC,OAAO,QACX,QAAO,SACN,OAAO,OAAO,QAAQ,aACtB,OAAO,OAAO,WAAW,gCACzB,eAAe,OAAO,OAAO,KAAK,CAClC;EAGF,MAAM,oBAAoB,iBACzB,MAFoB,OAAO,KAAK,KAAK,YAAY,IAIjD,oBACA,mBACA;AACD,MAAI,kBAAmB,QAAO;;AAK/B,MADwB,KAAK,gBAAgB,UAAa,KAAK,cAAc,WACtD,CAAC,cAAc,MAAM,sBAAsB,CACjE,QAAO,SACN,aACA,4EACA,IACA;CAIF,MAAM,SAAS,MAAM,OAAO,oBAAoB,YAAY;EAC3D,GAAG;EACH,UAAU,MAAM;EAChB,QAAQ,KAAK;EACb,eAAe,KAAK;EACpB,CAAC;AAEF,KAAI,CAAC,OAAO,QAAS,QAAO,aAAa,OAAO;AAEhD,KAAI,OAAO,QAAS,OAAM,MAAM,WAAW,EAAE,MAAM,CAAC,WAAW,EAAE,CAAC;AAElE,QAAO,aAAa,QAAQ,IAAI"}