import { NextRequest, NextResponse } from "next/server";
import { backendUrl, isOpsAuthed, opsHeaders } from "@/lib/ops-auth";

type Ctx = { params: Promise<{ id: string }> };

export async function POST(req: NextRequest, ctx: Ctx) {
  if (!isOpsAuthed(req)) {
    return NextResponse.json({ message: "No autorizado." }, { status: 401 });
  }
  const { id } = await ctx.params;
  const body = await req.json().catch(() => ({}));
  const res = await fetch(backendUrl(`/hooks/ot-ops/products/${id}/status`), {
    method: "POST",
    headers: opsHeaders(),
    body: JSON.stringify(body),
  });
  const data = await res.json().catch(() => ({}));
  return NextResponse.json(data, { status: res.status });
}
