Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
64 changes: 46 additions & 18 deletions app/api/profile/route.ts
Original file line number Diff line number Diff line change
@@ -1,26 +1,41 @@
import { NextRequest, NextResponse } from "next/server";
import { createClient } from "@/lib/supabase/server";

export async function GET() {
export async function GET(request: NextRequest) {
const supabase = await createClient();

try {
// Get the authenticated user
const { data: { user }, error: authError } = await supabase.auth.getUser();

if (authError || !user) {
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
// Try to get user ID from multiple sources
let userId: string | null = null;
let userEmail: string | null = null;

// First, try Supabase auth (for existing sessions)
const { data: { user: supabaseUser }, error: authError } = await supabase.auth.getUser();
if (supabaseUser && !authError) {
userId = supabaseUser.id;
userEmail = supabaseUser.email || null;
} else {
// If no Supabase session, try to get from request headers or query
const userIdFromHeader = request.headers.get('X-User-ID');
const userIdFromQuery = request.nextUrl.searchParams.get('userId');

userId = userIdFromHeader || userIdFromQuery;

if (!userId) {
return NextResponse.json({ error: "No user session found. Please log in again." }, { status: 401 });
}

Copilot AI Sep 4, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Accepting user IDs from headers or query parameters without proper authentication is a serious security vulnerability. Anyone can impersonate any user by providing a different user ID. This bypasses all authentication mechanisms.

Suggested change
// If no Supabase session, try to get from request headers or query
const userIdFromHeader = request.headers.get('X-User-ID');
const userIdFromQuery = request.nextUrl.searchParams.get('userId');
userId = userIdFromHeader || userIdFromQuery;
if (!userId) {
return NextResponse.json({ error: "No user session found. Please log in again." }, { status: 401 });
}
// No Supabase session, reject the request
return NextResponse.json({ error: "No user session found. Please log in again." }, { status: 401 });

Copilot uses AI. Check for mistakes.
}

// Get user profile
// Get user profile using the userId
const { data: profile, error: profileError } = await supabase
.from('user_profiles')
.select('*')
.eq('id', user.id)
.eq('id', userId)
.single();

if (profileError) {
return NextResponse.json({ error: profileError.message }, { status: 500 });
console.error('Profile error:', profileError);
return NextResponse.json({ error: "Profile not found. Please try logging in again." }, { status: 404 });
}

// Get user's items
Expand All @@ -30,7 +45,7 @@ export async function GET() {
*,
categories (name)
`)
.eq('seller_id', user.id)
.eq('seller_id', userId)
.order('created_at', { ascending: false });

if (itemsError) {
Expand Down Expand Up @@ -67,7 +82,7 @@ export async function GET() {
const responseData = {
profile: {
...profile,
email: user.email
email: userEmail || profile.email
},
items: itemsWithStats,
stats: {
Expand All @@ -93,15 +108,27 @@ export async function PUT(req: NextRequest) {
const supabase = await createClient();

try {
// Get the authenticated user
const { data: { user }, error: authError } = await supabase.auth.getUser();

if (authError || !user) {
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
// Try to get user ID from multiple sources
let userId: string | null = null;

// First, try Supabase auth (for existing sessions)
const { data: { user: supabaseUser }, error: authError } = await supabase.auth.getUser();
if (supabaseUser && !authError) {
userId = supabaseUser.id;
} else {
// If no Supabase session, try to get from request headers or query
const userIdFromHeader = req.headers.get('X-User-ID');
const userIdFromQuery = req.nextUrl.searchParams.get('userId');

userId = userIdFromHeader || userIdFromQuery;

if (!userId) {
return NextResponse.json({ error: "No user session found. Please log in again." }, { status: 401 });
}
}

const body = await req.json();
const { name, bio, phone, year_of_study, branch, location } = body;
const { name, bio, phone, nickname, year_of_study, branch, location } = body;

// Update user profile
const { data, error } = await supabase
Expand All @@ -110,12 +137,13 @@ export async function PUT(req: NextRequest) {
name,
bio,
phone,
nickname,
year_of_study,
branch,
location,
updated_at: new Date().toISOString()
})
.eq('id', user.id)
.eq('id', userId)
.select()
.single();

Expand Down
Loading