diff --git a/app/api/login/route.ts b/app/api/login/route.ts index 05fa9eb..522e6af 100644 --- a/app/api/login/route.ts +++ b/app/api/login/route.ts @@ -3,21 +3,37 @@ import { NextResponse } from 'next/server'; import { AUTH_USERNAME, AUTH_PASSWORD, COOKIE_NAME, COOKIE_MAX_AGE } from '@/lib/constants'; export async function POST(request: Request) { - const body = await request.json(); - const { username, password } = body; + try { + const body = await request.json(); + const { username, password } = body; - if (username === AUTH_USERNAME && password === AUTH_PASSWORD) { - const response = NextResponse.json({ success: true }); - response.cookies.set(COOKIE_NAME, 'ok', { - httpOnly: true, - maxAge: COOKIE_MAX_AGE, - path: '/', - }); - return response; + if (!username || !password) { + return NextResponse.json( + { error: 'Username and password are required' }, + { status: 400 } + ); + } + + if (username === AUTH_USERNAME && password === AUTH_PASSWORD) { + const response = NextResponse.json({ success: true }); + response.cookies.set(COOKIE_NAME, 'ok', { + httpOnly: true, + secure: process.env.NODE_ENV === 'production', + sameSite: 'lax', + maxAge: COOKIE_MAX_AGE, + path: '/', + }); + return response; + } + + return NextResponse.json( + { error: 'Invalid credentials' }, + { status: 401 } + ); + } catch (error) { + return NextResponse.json( + { error: 'Invalid request' }, + { status: 400 } + ); } - - return NextResponse.json( - { error: 'Invalid credentials' }, - { status: 401 } - ); }