import { NextRequest, NextResponse } from "next/server";
import { backendUrl, isOpsAuthed, opsHeaders } from "@/lib/ops-auth";

export async function POST(
  req: NextRequest,
  { params }: { params: Promise<{ id: string }> }
) {
  if (!isOpsAuthed(req)) {
    return NextResponse.json({ message: "No autorizado." }, { status: 401 });
  }
  const { id } = await params;
  const body = await req.json().catch(() => ({}));
  const res = await fetch(backendUrl(`/hooks/ot-ops/orders/${id}/refund`), {
    method: "POST",
    headers: opsHeaders(),
    body: JSON.stringify(body),
  });
  const data = await res.json().catch(() => ({}));
  return NextResponse.json(data, { status: res.status });
}
