feat(swift): voeg agenda backend API's toe (E3)
Epic 3 compleet: Backend integratie voor Swift Agenda Planning. Nieuwe endpoints: - GET /api/swift/agenda - Query afspraken op datumrange - POST /api/swift/agenda/create - Nieuwe afspraak aanmaken - POST /api/swift/agenda/cancel - Afspraak annuleren - POST /api/swift/agenda/reschedule - Afspraak verzetten - GET /api/swift/patients/search - Fuzzy patiënt zoeken Alle endpoints bevatten: - Supabase authenticatie + resource ownership checks - Zod validatie met Nederlandse foutmeldingen - Hergebruik van bestaande agenda server actions Test documentatie: docs/swift/test-plan-epic3-backend.md Progress: 3/7 Epics compleet (E0, E1, E2, E3) Story points: 11 SP (E3.S1: 3, E3.S2: 3, E3.S3: 3, E3.S4: 2)
This commit is contained in:
104
app/api/swift/agenda/cancel/route.ts
Normal file
104
app/api/swift/agenda/cancel/route.ts
Normal file
@@ -0,0 +1,104 @@
|
||||
import { NextRequest, NextResponse } from 'next/server';
|
||||
import { createClient } from '@/lib/auth/server';
|
||||
import { cancelEncounter } from '@/app/epd/agenda/actions';
|
||||
import { z } from 'zod';
|
||||
|
||||
/**
|
||||
* Swift Cancel Appointment API
|
||||
*
|
||||
* POST /api/swift/agenda/cancel
|
||||
*
|
||||
* Cancels an appointment (soft delete: status → 'cancelled').
|
||||
*/
|
||||
|
||||
// Request body schema
|
||||
const CancelAppointmentSchema = z.object({
|
||||
encounterId: z.string().uuid({ message: 'encounterId moet een geldige UUID zijn' }),
|
||||
});
|
||||
|
||||
export async function POST(request: NextRequest) {
|
||||
try {
|
||||
// Auth check
|
||||
const supabase = await createClient();
|
||||
const {
|
||||
data: { user },
|
||||
error: authError,
|
||||
} = await supabase.auth.getUser();
|
||||
|
||||
if (authError || !user) {
|
||||
return NextResponse.json(
|
||||
{ error: 'Niet geautoriseerd. Log opnieuw in.' },
|
||||
{ status: 401 }
|
||||
);
|
||||
}
|
||||
|
||||
// Parse and validate request body
|
||||
const body = await request.json();
|
||||
const validation = CancelAppointmentSchema.safeParse(body);
|
||||
|
||||
if (!validation.success) {
|
||||
const errorMessage = validation.error.issues
|
||||
.map((e) => `${e.path.join('.')}: ${e.message}`)
|
||||
.join(', ');
|
||||
return NextResponse.json({ error: errorMessage }, { status: 400 });
|
||||
}
|
||||
|
||||
const { encounterId } = validation.data;
|
||||
|
||||
// Verify the encounter belongs to the current user (security check)
|
||||
const { data: encounter, error: fetchError } = await supabase
|
||||
.from('encounters')
|
||||
.select('id, practitioner_id, patient_id, period_start, status')
|
||||
.eq('id', encounterId)
|
||||
.single();
|
||||
|
||||
if (fetchError || !encounter) {
|
||||
return NextResponse.json(
|
||||
{ error: 'Afspraak niet gevonden' },
|
||||
{ status: 404 }
|
||||
);
|
||||
}
|
||||
|
||||
if (encounter.practitioner_id !== user.id) {
|
||||
return NextResponse.json(
|
||||
{ error: 'Je hebt geen toegang tot deze afspraak' },
|
||||
{ status: 403 }
|
||||
);
|
||||
}
|
||||
|
||||
if (encounter.status === 'cancelled') {
|
||||
return NextResponse.json(
|
||||
{ error: 'Deze afspraak is al geannuleerd' },
|
||||
{ status: 400 }
|
||||
);
|
||||
}
|
||||
|
||||
// Cancel the encounter
|
||||
const result = await cancelEncounter(encounterId);
|
||||
|
||||
if (!result.success) {
|
||||
return NextResponse.json(
|
||||
{ error: result.error || 'Fout bij het annuleren van de afspraak' },
|
||||
{ status: 500 }
|
||||
);
|
||||
}
|
||||
|
||||
return NextResponse.json(
|
||||
{
|
||||
success: true,
|
||||
encounterId,
|
||||
message: 'Afspraak succesvol geannuleerd',
|
||||
},
|
||||
{ status: 200 }
|
||||
);
|
||||
} catch (error) {
|
||||
console.error('Error in cancel appointment API:', error);
|
||||
return NextResponse.json(
|
||||
{
|
||||
error:
|
||||
'Er ging iets mis bij het annuleren van de afspraak. Probeer het opnieuw.',
|
||||
},
|
||||
{ status: 500 }
|
||||
);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user