From 564be52b97fdebb4bff50f2bb4a687143471a42d Mon Sep 17 00:00:00 2001 From: lorentz Date: Sat, 11 Jul 2026 14:42:10 -0400 Subject: [PATCH] feat(14-05): harden companies-list route with requireAuth - companies-list now feeds the manual-search fallback for authenticated UI (Needs Review tab), closes previously-unauthenticated gap - response shape unchanged: [{ id, company_name }] --- app/api/data/companies-list/route.ts | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/app/api/data/companies-list/route.ts b/app/api/data/companies-list/route.ts index 0768a83..33dc84e 100644 --- a/app/api/data/companies-list/route.ts +++ b/app/api/data/companies-list/route.ts @@ -1,7 +1,11 @@ import { NextResponse } from 'next/server'; +import { requireAuth } from '@/lib/auth-utils'; import { postgresClient } from '@/lib/services/postgres-client'; export async function GET() { + const { error } = await requireAuth(); + if (error) return error; + try { const result = await postgresClient.query( `SELECT id, company_name FROM companies WHERE is_active = true AND is_deleted = false ORDER BY company_name ASC`