@@ -113,14 +113,25 @@ export async function POST(request, { params } = {}) {
113113 return NextResponse . json ( { error : 'participant_ids is required and must be a non-empty array' } , { status : 400 } ) ;
114114 }
115115
116+ const normalizedParticipantIds = participant_ids . map ( ( participantId ) =>
117+ typeof participantId === 'string' ? participantId . trim ( ) : ''
118+ ) ;
119+
120+ if (
121+ normalizedParticipantIds . length !== participant_ids . length ||
122+ normalizedParticipantIds . some ( ( participantId ) => participantId . length === 0 )
123+ ) {
124+ return NextResponse . json ( { error : 'participant_ids must contain non-empty strings' } , { status : 400 } ) ;
125+ }
126+
116127 // Skip participant validation for now due to network issues
117128 // TODO: Re-enable participant validation once network connectivity is stable
118129 console . log ( 'Skipping participant validation due to network issues' ) ;
119130 console . log ( 'Participant IDs to add:' , participant_ids ) ;
120131
121132 // For direct messages, check if conversation already exists
122- if ( type === 'direct' && participant_ids . length === 1 ) {
123- const other_user_id = participant_ids [ 0 ] ;
133+ if ( type === 'direct' && normalizedParticipantIds . length === 1 ) {
134+ const other_user_id = normalizedParticipantIds [ 0 ] ;
124135
125136 // Check if conversation already exists between these users
126137 const { data : existingConversations } = await supabase
@@ -175,7 +186,7 @@ export async function POST(request, { params } = {}) {
175186 const participants = [ ] ;
176187
177188 // Add other participants (validate they exist in users table)
178- for ( const participantId of participant_ids ) {
189+ for ( const participantId of normalizedParticipantIds ) {
179190 participants . push ( {
180191 conversation_id : conversationId ,
181192 user_id : participantId ,
@@ -185,7 +196,7 @@ export async function POST(request, { params } = {}) {
185196
186197 if ( internalUser ) {
187198 // Add creator as admin if not already in participants
188- if ( ! participant_ids . includes ( internalUser . id ) ) {
199+ if ( ! normalizedParticipantIds . includes ( internalUser . id ) ) {
189200 participants . push ( {
190201 conversation_id : conversationId ,
191202 user_id : internalUser . id ,
@@ -290,4 +301,4 @@ export async function PATCH(request, { params } = {}) {
290301 console . error ( 'API error:' , error ) ;
291302 return NextResponse . json ( { error : 'Internal server error' } , { status : 500 } ) ;
292303 }
293- }
304+ }
0 commit comments