ec27228a8e
Em dashes (—) and en dashes (–) had spread across comments, docs, tests, and a few UI strings, reading as AI-generated boilerplate rather than house style. Replaced each with punctuation matching its context: colon for explanatory clauses, comma for asides, plain hyphen for numeric/legal ranges (e.g. "21-23§"), "to"/"till" for date ranges, parentheses for paired-dash asides. messages/en.json and messages/sv.json were fixed by hand together to keep sv/en in sync. Left untouched where the dash is the functional subject rather than decorative punctuation: date-range-parser.ts's separator regex, charset-repair.ts's CP1252 byte-mapping table (and its test), the SIE encoding mojibake docs, generic-csv.ts's minus-sign normalizer, the agent system-prompt files that already instruct against em dashes, and a golden iXBRL test fixture compared byte-for-byte. Also fixes two bugs surfaced along the way: an off-by-one in ApiKeysPanel's scope-label split (a leftover from an earlier partial pass), and a charset-repair test that had lost the literal en-dash it exists to verify. Regenerated the agent atom seed migration (skills:generate) since 27 SKILL.md files changed. Added a CLAUDE.md rule against em/en dashes, with an explicit carve-out for the functional-dash cases above. Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
67 lines
2.3 KiB
TypeScript
67 lines
2.3 KiB
TypeScript
import { NextResponse } from 'next/server'
|
|
import { z } from 'zod'
|
|
import { requireAuth } from '@/lib/auth/require-auth'
|
|
import { createServiceClient } from '@/lib/supabase/server'
|
|
import { createLogger } from '@/lib/logger'
|
|
|
|
const log = createLogger('user/profile')
|
|
|
|
// User-scoped (not company-scoped): same shape as /api/user/locale, so it
|
|
// opts out of withRouteContext and calls requireAuth() directly (MFA still
|
|
// enforced on hosted).
|
|
const BodySchema = z.object({
|
|
full_name: z.string().min(1).max(100),
|
|
})
|
|
|
|
export async function POST(request: Request) {
|
|
const { user, supabase, error } = await requireAuth()
|
|
if (error) return error
|
|
|
|
let body: unknown
|
|
try {
|
|
body = await request.json()
|
|
} catch {
|
|
return NextResponse.json({ error: 'Invalid JSON body' }, { status: 400 })
|
|
}
|
|
|
|
const parsed = BodySchema.safeParse(body)
|
|
if (!parsed.success) {
|
|
return NextResponse.json({ error: 'Invalid name' }, { status: 400 })
|
|
}
|
|
|
|
const fullName = parsed.data.full_name.trim()
|
|
if (!fullName) {
|
|
return NextResponse.json({ error: 'Invalid name' }, { status: 400 })
|
|
}
|
|
|
|
// Source of truth: profiles.full_name. Read by the account menu
|
|
// (app/(dashboard)/layout.tsx), the first-name greetings, the agent context,
|
|
// and the AGI/KU contact-person field. RLS scopes the update to the caller's
|
|
// own row (profiles_update policy: auth.uid() = id).
|
|
const { error: updateError } = await supabase
|
|
.from('profiles')
|
|
.update({ full_name: fullName })
|
|
.eq('id', user.id)
|
|
|
|
if (updateError) {
|
|
return NextResponse.json({ error: 'Could not save name' }, { status: 500 })
|
|
}
|
|
|
|
// Best-effort: keep auth user_metadata.full_name in sync so the two stores
|
|
// don't drift. It seeds profiles via the handle_new_user trigger at signup
|
|
// and is wiped on account deletion as a display-name store. updateUserById
|
|
// REPLACES user_metadata wholesale, so read-merge-write to keep other keys.
|
|
try {
|
|
const admin = createServiceClient()
|
|
const { data: current } = await admin.auth.admin.getUserById(user.id)
|
|
const priorMeta = current?.user?.user_metadata ?? {}
|
|
await admin.auth.admin.updateUserById(user.id, {
|
|
user_metadata: { ...priorMeta, full_name: fullName },
|
|
})
|
|
} catch (syncError) {
|
|
log.warn('user_metadata full_name sync failed (non-blocking)', syncError)
|
|
}
|
|
|
|
return NextResponse.json({ data: { full_name: fullName } })
|
|
}
|