import { NextRequest, NextResponse } from "next/server"; import { queryRaw } from "@/lib/db"; import { getCurrentUser } from "@/lib/auth"; // A split may be settled by the transaction's effective owner or by the // participant the split belongs to. const SCOPE = ` AND EXISTS ( SELECT 1 FROM transactions t LEFT JOIN statements s ON s.id = t.statement_id WHERE t.id = transaction_splits.transaction_id AND (COALESCE(t.owner_id, s.owner_id) = $2 OR transaction_splits.participant_id = $2) )`; export async function POST(req: NextRequest) { const user = await getCurrentUser(req); if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 403 }); const body = await req.json(); const { participant_id, split_ids } = body as { participant_id?: number; split_ids?: number[]; }; if (participant_id) { const rows = await queryRaw<{ id: number }>( `UPDATE transaction_splits SET settled = true, settled_at = NOW() WHERE participant_id = $1 AND settled = false ${SCOPE} RETURNING id`, [participant_id, user.id] ); return NextResponse.json({ settled: rows.length }); } if (split_ids?.length) { const rows = await queryRaw<{ id: number }>( `UPDATE transaction_splits SET settled = true, settled_at = NOW() WHERE id = ANY($1::int[]) AND settled = false ${SCOPE} RETURNING id`, [split_ids, user.id] ); return NextResponse.json({ settled: rows.length }); } return NextResponse.json({ error: "participant_id or split_ids required" }, { status: 400 }); }