import { NextResponse } from 'next/server' import { auth } from '@/lib/auth' /** * Prüft, ob eine angemeldete Sitzung mit Admin-Rolle vorliegt. * Gibt im Fehlerfall die fertige 401-Antwort zurück, sonst `null`. */ export async function requireAdmin() { const session = await auth() if ( !session || (session.user.role !== 'ADMIN' && session.user.role !== 'SUPER_ADMIN') ) { return NextResponse.json( { error: 'Nicht autorisiert' }, { status: 401 } ) } return null }