import { fail, redirect } from '@sveltejs/kit'; import type { Actions, PageServerLoad } from './$types'; import { changePassword, listUserSessions } from '$lib/server/pocketbase'; import { log } from '$lib/server/logger'; export const load: PageServerLoad = async ({ locals }) => { if (!locals.user) { redirect(302, '/login'); } let sessions: Awaited> = []; try { sessions = await listUserSessions(locals.user.id); } catch (e) { log.warn('profile', 'listUserSessions failed (non-fatal)', { err: String(e) }); } return { user: locals.user, sessions: sessions.map((s) => ({ id: s.id, user_agent: s.user_agent, ip: s.ip, created_at: s.created_at, last_seen: s.last_seen, is_current: s.session_id === locals.user!.authSessionId })) }; }; export const actions: Actions = { changePassword: async ({ request, locals }) => { if (!locals.user) { return fail(401, { error: 'Not logged in.' }); } const data = await request.formData(); const current = (data.get('current') as string | null) ?? ''; const next = (data.get('next') as string | null) ?? ''; const confirm = (data.get('confirm') as string | null) ?? ''; if (!current || !next || !confirm) { return fail(400, { error: 'All fields are required.' }); } if (next.length < 8) { return fail(400, { error: 'New password must be at least 8 characters.' }); } if (next !== confirm) { return fail(400, { error: 'New passwords do not match.' }); } let ok: boolean; try { ok = await changePassword(locals.user.id, current, next); } catch (e) { log.error('profile', 'changePassword failed', { err: String(e) }); return fail(500, { error: 'An error occurred. Please try again.' }); } if (!ok) { return fail(401, { error: 'Current password is incorrect.' }); } return { success: true }; } };