import { NextResponse } from 'next/server' import { auth } from '@/lib/auth' /** * Sagt, ob die aktuelle Anfrage von einer angemeldeten Admin-Sitzung kommt. * Für Routen, die je nach Anmeldung unterschiedlich viel ausliefern, statt * die Anfrage abzuweisen. */ export async function isAdminSession() { const session = await auth() return ( !!session && (session.user.role === 'ADMIN' || session.user.role === 'SUPER_ADMIN') ) } /** * Prüft, ob eine angemeldete Sitzung mit Admin-Rolle vorliegt. * Gibt im Fehlerfall die fertige 401-Antwort zurück, sonst `null`. */ export async function requireAdmin() { if (!(await isAdminSession())) { return NextResponse.json( { error: 'Nicht autorisiert' }, { status: 401 } ) } return null }