import type {NextRequest} from 'next/server'; import {authApi} from '@/services/api/authApi'; import {serveUpstream} from '@/shared/services/bff'; import {toDeviceSession} from '@/features/settings/services/mapSession'; export const dynamic = 'force-dynamic'; /** * GET /api/auth/sessions — every device currently signed in as this person. * * `current: true` marks the one making this request. It is the reason this list * is worth showing at all: a session the user does not recognise is how they * find out a password has leaked, and they need to be able to tell it apart * from the browser they are reading the page in. */ export async function GET(req: NextRequest) { return serveUpstream(req, (token) => authApi.sessions(token), (list) => list.map(toDeviceSession), ); }