import { assertCustomerMatch, parseServiceAuth } from "@/lib/api/auth-context"; import { enforceRateLimits } from "@/lib/api/rate-limit"; import { fail, ok } from "@/lib/response"; import { AuthError } from "@/modules/auth/errors"; import { msCheckoutSchema } from "@/modules/mothership/checkout-validation"; import { submitMsCheckoutFill } from "@/modules/mothership/checkout-service"; /** MotherShip 登录态:选承运商 + 保障 → fill-only 结账(不支付) */ export async function POST(request: Request) { let auth; try { auth = await parseServiceAuth(request); } catch (error) { if (error instanceof AuthError) { return fail(error.code, error.message, error.httpStatus); } throw error; } const rateLimited = await enforceRateLimits(request, auth.customerId); if (rateLimited) return rateLimited; let body: unknown; try { body = await request.json(); } catch { return fail("VALIDATION_FAILED", "请求体格式无效", 400); } const parsed = msCheckoutSchema.safeParse(body); if (!parsed.success) { return fail( "VALIDATION_FAILED", parsed.error.issues[0]?.message ?? "参数无效", 400, ); } try { assertCustomerMatch(auth, parsed.data.customer_id); const result = await submitMsCheckoutFill({ customerId: parsed.data.customer_id, quoteId: parsed.data.quote_id, preferredCarrier: parsed.data.preferred_carrier, coverage: parsed.data.coverage, cargoValueUsd: parsed.data.cargo_value_usd, mothershipDetails: parsed.data.mothership_details, pickupAccessorials: parsed.data.pickup_accessorials, deliveryAccessorials: parsed.data.delivery_accessorials, }); return ok(result); } catch (error) { if (error instanceof AuthError) { return fail(error.code, error.message, error.httpStatus); } const msg = error instanceof Error ? error.message : "提交结账失败"; return fail("VALIDATION_FAILED", msg, 400); } }