import { NextRequest, NextResponse } from 'next/server';
import { getIronSession } from 'iron-session';
import { sessionOptions, SessionData } from '../../../session';
import { cookies } from 'next/headers';

export async function POST(request: NextRequest) {
  try {
    const body = await request.json();
    const { email, fullName, password } = body;

    // Validate input
    if (!email || !fullName || !password) {
      return NextResponse.json(
        { error: 'Missing required fields' },
        { status: 400 }
      );
    }

    // Get session
    const session = await getIronSession<SessionData>(await cookies(), sessionOptions);

    // Store signup data in encrypted session
    session.signupData = {
      email,
      fullName,
      password, // Will be encrypted by iron-session
    };

    await session.save();

    return NextResponse.json({ success: true });
  } catch (error) {
    console.error('Signup step 1 error:', error);
    return NextResponse.json(
      { error: 'Internal server error' },
      { status: 500 }
    );
  }
}