import { NextRequest, NextResponse } from "next/server";
import { backendUrl, isOpsAuthed, opsHeaders } from "@/lib/ops-auth";

export async function GET(req: NextRequest) {
  if (!isOpsAuthed(req)) {
    return NextResponse.json({ message: "No autorizado." }, { status: 401 });
  }
  const res = await fetch(backendUrl("/hooks/ot-ops/products"), {
    headers: opsHeaders(),
    cache: "no-store",
  });
  const data = await res.json().catch(() => ({}));
  return NextResponse.json(data, { status: res.status });
}

export async function POST(req: NextRequest) {
  if (!isOpsAuthed(req)) {
    return NextResponse.json({ message: "No autorizado." }, { status: 401 });
  }
  const body = await req.json().catch(() => ({}));
  const res = await fetch(backendUrl("/hooks/ot-ops/products"), {
    method: "POST",
    headers: opsHeaders(),
    body: JSON.stringify(body),
  });
  const data = await res.json().catch(() => ({}));
  return NextResponse.json(data, { status: res.status });
}
