feat: profile picture
This commit is contained in:
@@ -5,6 +5,7 @@ import { importRouter } from "./routers/import";
|
||||
import { labelRouter } from "./routers/label";
|
||||
import { listRouter } from "./routers/list";
|
||||
import { memberRouter } from "./routers/member";
|
||||
import { userRouter } from "./routers/user";
|
||||
import { workspaceRouter } from "./routers/workspace";
|
||||
import { createTRPCRouter } from "./trpc";
|
||||
|
||||
@@ -16,6 +17,7 @@ export const appRouter = createTRPCRouter({
|
||||
list: listRouter,
|
||||
member: memberRouter,
|
||||
import: importRouter,
|
||||
user: userRouter,
|
||||
workspace: workspaceRouter,
|
||||
});
|
||||
|
||||
|
||||
@@ -1,52 +1,9 @@
|
||||
import { TRPCError } from "@trpc/server";
|
||||
import { z } from "zod";
|
||||
|
||||
import * as userRepo from "@kan/db/repository/user.repo";
|
||||
|
||||
import { createTRPCRouter, protectedProcedure, publicProcedure } from "../trpc";
|
||||
import { createTRPCRouter, publicProcedure } from "../trpc";
|
||||
|
||||
export const authRouter = createTRPCRouter({
|
||||
getUser: protectedProcedure
|
||||
.meta({
|
||||
openapi: {
|
||||
method: "GET",
|
||||
path: "/users/me",
|
||||
summary: "Get user",
|
||||
description:
|
||||
"Retrieves the currently authenticated user's profile information",
|
||||
tags: ["Users"],
|
||||
protect: true,
|
||||
},
|
||||
})
|
||||
.input(z.void())
|
||||
.output(
|
||||
z.object({
|
||||
id: z.string(),
|
||||
email: z.string(),
|
||||
name: z.string().nullable(),
|
||||
stripeCustomerId: z.string().nullable(),
|
||||
}),
|
||||
)
|
||||
.query(async ({ ctx }) => {
|
||||
const userId = ctx.user?.id;
|
||||
|
||||
if (!userId)
|
||||
throw new TRPCError({
|
||||
message: `User not authenticated`,
|
||||
code: "UNAUTHORIZED",
|
||||
});
|
||||
|
||||
const result = await userRepo.getById(ctx.db, userId);
|
||||
|
||||
if (!result?.name) {
|
||||
throw new TRPCError({
|
||||
message: `User not found`,
|
||||
code: "NOT_FOUND",
|
||||
});
|
||||
}
|
||||
|
||||
return result;
|
||||
}),
|
||||
loginWithEmail: publicProcedure
|
||||
.meta({
|
||||
openapi: {
|
||||
|
||||
93
packages/api/src/routers/user.ts
Normal file
93
packages/api/src/routers/user.ts
Normal file
@@ -0,0 +1,93 @@
|
||||
import { TRPCError } from "@trpc/server";
|
||||
import { z } from "zod";
|
||||
|
||||
import * as userRepo from "@kan/db/repository/user.repo";
|
||||
|
||||
import { createTRPCRouter, protectedProcedure } from "../trpc";
|
||||
|
||||
export const userRouter = createTRPCRouter({
|
||||
getUser: protectedProcedure
|
||||
.meta({
|
||||
openapi: {
|
||||
method: "GET",
|
||||
path: "/users/me",
|
||||
summary: "Get user",
|
||||
description:
|
||||
"Retrieves the currently authenticated user's profile information",
|
||||
tags: ["Users"],
|
||||
protect: true,
|
||||
},
|
||||
})
|
||||
.input(z.void())
|
||||
.output(
|
||||
z.object({
|
||||
id: z.string(),
|
||||
email: z.string(),
|
||||
name: z.string().nullable(),
|
||||
image: z.string().nullable(),
|
||||
stripeCustomerId: z.string().nullable(),
|
||||
}),
|
||||
)
|
||||
.query(async ({ ctx }) => {
|
||||
const userId = ctx.user?.id;
|
||||
|
||||
if (!userId)
|
||||
throw new TRPCError({
|
||||
message: `User not authenticated`,
|
||||
code: "UNAUTHORIZED",
|
||||
});
|
||||
|
||||
const result = await userRepo.getById(ctx.db, userId);
|
||||
|
||||
if (!result?.name) {
|
||||
throw new TRPCError({
|
||||
message: `User not found`,
|
||||
code: "NOT_FOUND",
|
||||
});
|
||||
}
|
||||
|
||||
return result;
|
||||
}),
|
||||
update: protectedProcedure
|
||||
.meta({
|
||||
openapi: {
|
||||
method: "PUT",
|
||||
path: "/users",
|
||||
summary: "Update user",
|
||||
description:
|
||||
"Updates the currently authenticated user's profile information",
|
||||
tags: ["Users"],
|
||||
protect: true,
|
||||
},
|
||||
})
|
||||
.input(
|
||||
z.object({
|
||||
image: z.string(),
|
||||
}),
|
||||
)
|
||||
.output(
|
||||
z.object({
|
||||
image: z.string().nullable(),
|
||||
}),
|
||||
)
|
||||
.mutation(async ({ ctx, input }) => {
|
||||
const userId = ctx.user?.id;
|
||||
|
||||
if (!userId)
|
||||
throw new TRPCError({
|
||||
message: `User not authenticated`,
|
||||
code: "UNAUTHORIZED",
|
||||
});
|
||||
|
||||
const result = await userRepo.update(ctx.adminDb, userId, input);
|
||||
|
||||
if (!result) {
|
||||
throw new TRPCError({
|
||||
message: `User not found`,
|
||||
code: "NOT_FOUND",
|
||||
});
|
||||
}
|
||||
|
||||
return result;
|
||||
}),
|
||||
});
|
||||
@@ -712,4 +712,41 @@ FOR ALL
|
||||
TO authenticated
|
||||
USING (
|
||||
"createdBy" = auth.uid()
|
||||
);
|
||||
);
|
||||
|
||||
/* BUCKETS */
|
||||
insert into storage.buckets
|
||||
(id, name, public)
|
||||
values
|
||||
('avatars', 'avatars', true);
|
||||
|
||||
alter table storage.objects enable row level security;
|
||||
|
||||
CREATE POLICY "Users can upload their own avatar"
|
||||
ON storage.objects FOR INSERT
|
||||
TO authenticated
|
||||
WITH CHECK (
|
||||
bucket_id = 'avatars' AND
|
||||
(storage.foldername(name))[1] = auth.uid()::text
|
||||
);
|
||||
|
||||
CREATE POLICY "Users can update their own avatar"
|
||||
ON storage.objects FOR UPDATE
|
||||
TO authenticated
|
||||
USING (
|
||||
bucket_id = 'avatars' AND
|
||||
(storage.foldername(name))[1] = auth.uid()::text
|
||||
);
|
||||
|
||||
CREATE POLICY "Users can delete their own avatar"
|
||||
ON storage.objects FOR DELETE
|
||||
TO authenticated
|
||||
USING (
|
||||
bucket_id = 'avatars' AND
|
||||
(storage.foldername(name))[1] = auth.uid()::text
|
||||
);
|
||||
|
||||
CREATE POLICY "Avatar images are publicly accessible"
|
||||
ON storage.objects FOR SELECT
|
||||
TO anon, authenticated
|
||||
USING (bucket_id = 'avatars');
|
||||
@@ -5,7 +5,7 @@ import type { Database } from "@kan/db/types/database.types";
|
||||
export const getById = async (db: SupabaseClient<Database>, userId: string) => {
|
||||
const { data } = await db
|
||||
.from("user")
|
||||
.select(`id, name, email, stripeCustomerId`)
|
||||
.select(`id, name, email, image, stripeCustomerId`)
|
||||
.eq("id", userId)
|
||||
.limit(1)
|
||||
.single();
|
||||
@@ -44,3 +44,18 @@ export const create = async (
|
||||
|
||||
return data;
|
||||
};
|
||||
|
||||
export const update = async (
|
||||
db: SupabaseClient<Database>,
|
||||
userId: string,
|
||||
updates: { image: string | null },
|
||||
) => {
|
||||
const { data } = await db
|
||||
.from("user")
|
||||
.update({ image: updates.image })
|
||||
.eq("id", userId)
|
||||
.select(`image`)
|
||||
.single();
|
||||
|
||||
return data;
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user