import path from "node:path"; import { readFile } from "node:fs/promises"; import { getPaths } from "yt-dlp-transcript-common/lib/paths"; export const dynamic = "force-dynamic"; // Serves built export artifacts (stats/summaries/transcripts JSON) from // exportPublicDir so the editor's charts authoring tab can preview real data. // The static viewer serves these as plain files; the editor proxies them. export async function GET( _request: Request, { params }: { params: Promise<{ path: string[] }> }, ) { const { path: segments } = await params; // Reject path traversal / absolute escapes. if (segments.some((s) => s === ".." || s.includes("\0") || path.isAbsolute(s))) { return new Response("Bad request", { status: 400 }); } const root = getPaths().exportPublicDir; const target = path.join(root, ...segments); if (!target.startsWith(root + path.sep)) { return new Response("Bad request", { status: 400 }); } try { const body = await readFile(target); const type = target.endsWith(".json") ? "application/json" : "application/octet-stream"; return new Response(body, { headers: { "content-type": type, "cache-control": "no-store" }, }); } catch { return new Response("Not found", { status: 404 }); } }