import { resolveRendition } from "@/lib/browse"; import { resolveToken } from "@/lib/compares"; import { serveFile } from "@/lib/range"; export const dynamic = "force-dynamic"; // The bytes behind a blind pairing, addressed by an opaque token. // // This route exists so that nothing on the page names the file: not the src, // not the network panel, not the right-click menu. The token resolves to a rel // only in this process, and only for the life of the pairing. export async function GET(request: Request) { const t = new URL(request.url).searchParams.get("t") ?? ""; const hit = resolveToken(t); if (!hit) return new Response("no such pairing", { status: 404 }); const abs = resolveRendition(hit.song, hit.rel); if (!abs) return new Response("outside the roots", { status: 400 }); return serveFile(abs, request); }