24 lines
866 B
TypeScript
24 lines
866 B
TypeScript
import { json, error } from '@sveltejs/kit';
|
|
import type { RequestEvent } from '@sveltejs/kit';
|
|
import {
|
|
ACTIVE_COOKIE,
|
|
childSessionCookie,
|
|
clearChildSession,
|
|
clearActiveChild
|
|
} from '$lib/server/session';
|
|
|
|
// Remove ONE child profile from this device (picker ✕). Device-local cookie
|
|
// surgery only — no PB writes, no session required (the picker is reachable
|
|
// with no active user).
|
|
export async function POST(event: RequestEvent) {
|
|
const body = await event.request.json().catch(() => ({}));
|
|
const { userId } = body as { userId?: string };
|
|
if (!userId) throw error(400, 'Missing userId');
|
|
if (!event.cookies.get(childSessionCookie(userId))) {
|
|
throw error(400, 'No session on this device');
|
|
}
|
|
clearChildSession(event.cookies, userId);
|
|
if (event.cookies.get(ACTIVE_COOKIE) === userId) clearActiveChild(event.cookies);
|
|
return json({ ok: true });
|
|
}
|