diff --git a/app/api/auth/[...all]/route.ts b/app/api/auth/[...all]/route.ts index e64481ca..27ac28b8 100644 --- a/app/api/auth/[...all]/route.ts +++ b/app/api/auth/[...all]/route.ts @@ -1,4 +1,35 @@ import { auth } from "@/lib/auth/auth"; import { toNextJsHandler } from "better-auth/next-js"; +import { NextRequest, NextResponse } from "next/server"; +import { headers } from "next/headers"; -export const { GET, POST } = toNextJsHandler(auth.handler); +const authHandler = toNextJsHandler(auth.handler); + +async function blockApiKeyCreateForRestrictedUsers(req: NextRequest): Promise { + const url = req.nextUrl; + if (req.method !== "POST" || !url.pathname.endsWith("/api-key/create")) { + return null; + } + const session = await auth.api.getSession({ headers: await headers() }); + if (!session?.user) { + return null; + } + // @ts-ignore + if (session.user.banned || (session.user.role as string) === "pending") { + return NextResponse.json( + { error: "Account not eligible to create API keys" }, + { status: 403 } + ); + } + return null; +} + +export async function GET(req: NextRequest) { + return authHandler.GET(req); +} + +export async function POST(req: NextRequest) { + const guard = await blockApiKeyCreateForRestrictedUsers(req); + if (guard) return guard; + return authHandler.POST(req); +} diff --git a/src/lib/api-v1/middleware.ts b/src/lib/api-v1/middleware.ts index f326cadc..dae571cf 100644 --- a/src/lib/api-v1/middleware.ts +++ b/src/lib/api-v1/middleware.ts @@ -78,6 +78,14 @@ export function withApiKey(handler: ApiKeyHandler) { throw new Error("Unable to find user") } + if (userFetched.banned) { + return NextResponse.json({ error: "Account suspended" }, { status: 403 }); + } + + if (userFetched.role === "pending") { + return NextResponse.json({ error: "Account pending approval" }, { status: 403 }); + } + const userPermissions = computeSystemPermissions(userFetched) const user = { diff --git a/src/lib/auth/auth.ts b/src/lib/auth/auth.ts index 60b4dc87..57b5b782 100644 --- a/src/lib/auth/auth.ts +++ b/src/lib/auth/auth.ts @@ -713,6 +713,7 @@ export const deleteApiKey = async (keyId: string) => { await auth.api.deleteApiKey({ body: { keyId: keyId, + configId: "standard", }, headers: await headers(), });