// Partner-staff self-serve customer create. Forwards the user's access // token to platform-api POST /me/partner/tenants, which scopes the // new tenant to the caller's partner regardless of what the body says. // Returns the created tenant doc. import { getUserSession } from 'nuxt-oidc-auth/runtime/server/utils/session.js' export default defineEventHandler(async (event) => { const session = await getUserSession(event).catch(() => null) const accessToken = (session as { accessToken?: string } | null)?.accessToken if (!accessToken) { throw createError({ statusCode: 401, statusMessage: 'Not signed in' }) } const body = await readBody(event) const base = process.env.PLATFORM_API_INTERNAL_URL ?? 'http://platform-api:3001' try { return await $fetch(`${base}/me/partner/tenants`, { method: 'POST', headers: { Authorization: `Bearer ${accessToken}` }, body, }) } catch (err: unknown) { const e = err as { statusCode?: number; data?: unknown } throw createError({ statusCode: e.statusCode ?? 500, data: e.data }) } })