import { requireAuth, requireCap } from '../auth.js' import { pool } from '../db.js' export async function configRoutes(app) { app.addHook('preHandler', requireAuth) // GET /api/config — all config keys as a flat object app.get('/api/config', { preHandler: requireCap('view') }, async () => { const { rows } = await pool.query('SELECT key, value FROM config ORDER BY key') return Object.fromEntries(rows.map(r => [r.key, r.value])) }) // PATCH /api/config/:key — update a single config key. Gated on 'admin' // (same cap that already gates the activity log) rather than a new // capability — nothing about notification settings warrants a separate one. app.patch('/api/config/:key', { preHandler: requireCap('admin') }, async (req, reply) => { const { key } = req.params const { value } = req.body || {} if (value === undefined) return reply.status(400).send({ error: 'value required' }) await pool.query( `INSERT INTO config (key, value, updated_at) VALUES ($1, $2, NOW()) ON CONFLICT (key) DO UPDATE SET value = EXCLUDED.value, updated_at = NOW()`, [key, JSON.stringify(value)] ) return { ok: true } }) }