All files / invitations decline.js

100% Statements 19/19
100% Branches 8/8
100% Functions 1/1
100% Lines 19/19

Press n or j to go to the next uncovered block, b, p or k for the previous block.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 871x 1x   1x 1x   1x 10x 10x 10x   10x 2x                     8x                   7x 1x                   6x 1x                     5x                   4x                 2x 2x                    
const { DynamoDBClient } = require('@aws-sdk/client-dynamodb')
const { DynamoDBDocumentClient, DeleteCommand, GetCommand } = require('@aws-sdk/lib-dynamodb')
 
const client = new DynamoDBClient({})
const docClient = DynamoDBDocumentClient.from(client)
 
exports.handler = async (event) => {
  try {
    const tenantId = event.pathParameters?.tenantId
    const userId = event.requestContext?.authorizer?.claims?.sub
 
    if (!userId || !tenantId) {
      return {
        statusCode: 401,
        headers: {
          'Content-Type': 'application/json',
          'Access-Control-Allow-Origin': '*'
        },
        body: JSON.stringify({ error: 'Unauthorized' })
      }
    }
 
    // Verify the invitation exists and belongs to this user
    const existing = await docClient.send(
      new GetCommand({
        TableName: process.env.MEMBERSHIPS_TABLE_NAME,
        Key: {
          userId: userId,
          tenantId: tenantId
        }
      })
    )
 
    if (!existing.Item) {
      return {
        statusCode: 404,
        headers: {
          'Content-Type': 'application/json',
          'Access-Control-Allow-Origin': '*'
        },
        body: JSON.stringify({ error: 'Invitation not found' })
      }
    }
 
    if (existing.Item.status !== 'pending') {
      return {
        statusCode: 400,
        headers: {
          'Content-Type': 'application/json',
          'Access-Control-Allow-Origin': '*'
        },
        body: JSON.stringify({ error: 'Invitation already processed' })
      }
    }
 
    // Delete the invitation
    await docClient.send(
      new DeleteCommand({
        TableName: process.env.MEMBERSHIPS_TABLE_NAME,
        Key: {
          userId: userId,
          tenantId: tenantId
        }
      })
    )
 
    return {
      statusCode: 204,
      headers: {
        'Content-Type': 'application/json',
        'Access-Control-Allow-Origin': '*'
      },
      body: ''
    }
  } catch (error) {
    console.error('Error declining invitation:', error)
    return {
      statusCode: 500,
      headers: {
        'Content-Type': 'application/json',
        'Access-Control-Allow-Origin': '*'
      },
      body: JSON.stringify({ error: 'Failed to decline invitation' })
    }
  }
}