import { readFile } from "node:fs/promises"; import { workspaceFile } from "@/lib/articles/workspace.mjs"; export const dynamic = "force-dynamic"; // GET ?ws=&rel= -- one workspace file, // READ-ONLY, only one that lib/articles/workspace.mjs lists. HTML is served // under a CSP sandbox (no scripts, no same-origin) for the page's sandboxed // iframe; markdown and JSON as plain text. export async function GET(request: Request) { const url = new URL(request.url); const f = await workspaceFile(url.searchParams.get("ws") ?? "", url.searchParams.get("rel") ?? ""); if (!f) return new Response("not a workspace file", { status: 404 }); const body = await readFile(/* turbopackIgnore: true */ f.real); const html = f.rel.endsWith(".html"); return new Response(body, { headers: { "content-type": html ? "text/html; charset=utf-8" : f.rel.endsWith(".json") ? "application/json; charset=utf-8" : "text/plain; charset=utf-8", "cache-control": "no-store", ...(html ? { "content-security-policy": "sandbox; default-src 'none'; img-src data:; style-src 'unsafe-inline'" } : {}), }, }); }