{"version":3,"file":"_...key_.mjs","names":[],"sources":["../../../../../../src/astro/routes/api/media/file/[...key].ts"],"sourcesContent":["/**\n * Serve uploaded media files\n *\n * GET /_emdash/api/media/file/:key - Serve file from storage\n */\n\nimport type { APIRoute } from \"astro\";\n\nimport { apiError, handleError } from \"#api/error.js\";\n\nexport const prerender = false;\n\n/**\n * Content types that are safe to display inline (simple raster/vector images, video, audio).\n * Everything else gets Content-Disposition: attachment to prevent script execution.\n */\nconst SAFE_INLINE_TYPES = new Set([\n\t\"image/jpeg\",\n\t\"image/png\",\n\t\"image/gif\",\n\t\"image/webp\",\n\t\"image/avif\",\n\t\"image/x-icon\",\n\t\"video/mp4\",\n\t\"video/webm\",\n\t\"audio/mpeg\",\n\t\"audio/wav\",\n\t\"audio/ogg\",\n]);\n\nexport const GET: APIRoute = async ({ params, locals }) => {\n\tconst { key } = params;\n\tconst { emdash } = locals;\n\n\tif (!key) {\n\t\treturn apiError(\"NOT_FOUND\", \"File not found\", 404);\n\t}\n\n\t// Backup archives share the storage bucket but hold the site's full\n\t// content export — they must never be reachable through the public,\n\t// unauthenticated media route. Admins download them via the\n\t// authenticated backups API.\n\tif (key.startsWith(\"backups/\")) {\n\t\treturn apiError(\"NOT_FOUND\", \"File not found\", 404);\n\t}\n\n\tif (!emdash?.storage) {\n\t\treturn apiError(\"NOT_CONFIGURED\", \"Storage not configured\", 500);\n\t}\n\n\ttry {\n\t\tconst result = await emdash.storage.download(key);\n\n\t\tconst headers: Record<string, string> = {\n\t\t\t\"Content-Type\": result.contentType,\n\t\t\t\"Cache-Control\": \"public, max-age=31536000, immutable\",\n\t\t\t\"X-Content-Type-Options\": \"nosniff\",\n\t\t\t// Sandbox CSP on all user-uploaded content — prevents script execution\n\t\t\t// even for SVGs navigated to directly or content types that support scripting.\n\t\t\t\"Content-Security-Policy\":\n\t\t\t\t\"sandbox; default-src 'none'; img-src 'self'; style-src 'unsafe-inline'\",\n\t\t};\n\n\t\tif (result.size) {\n\t\t\theaders[\"Content-Length\"] = String(result.size);\n\t\t}\n\n\t\t// Safe image/media types can render inline; everything else (SVG, PDF,\n\t\t// HTML, JS, etc.) must be downloaded to prevent stored XSS.\n\t\tif (SAFE_INLINE_TYPES.has(result.contentType)) {\n\t\t\theaders[\"Content-Disposition\"] = \"inline\";\n\t\t} else {\n\t\t\theaders[\"Content-Disposition\"] = \"attachment\";\n\t\t}\n\n\t\treturn new Response(result.body, { status: 200, headers });\n\t} catch (error) {\n\t\t// Check if it's a \"not found\" error\n\t\tif (\n\t\t\terror instanceof Error &&\n\t\t\t(error.message.includes(\"not found\") || error.message.includes(\"NOT_FOUND\"))\n\t\t) {\n\t\t\treturn apiError(\"NOT_FOUND\", \"File not found\", 404);\n\t\t}\n\t\treturn handleError(error, \"Failed to serve file\", \"FILE_SERVE_ERROR\");\n\t}\n};\n"],"mappings":";;;;;AAUA,MAAa,YAAY;;;;;AAMzB,MAAM,oBAAoB,IAAI,IAAI;CACjC;CACA;CACA;CACA;CACA;CACA;CACA;CACA;CACA;CACA;CACA;CACA,CAAC;AAEF,MAAa,MAAgB,OAAO,EAAE,QAAQ,aAAa;CAC1D,MAAM,EAAE,QAAQ;CAChB,MAAM,EAAE,WAAW;AAEnB,KAAI,CAAC,IACJ,QAAO,SAAS,aAAa,kBAAkB,IAAI;AAOpD,KAAI,IAAI,WAAW,WAAW,CAC7B,QAAO,SAAS,aAAa,kBAAkB,IAAI;AAGpD,KAAI,CAAC,QAAQ,QACZ,QAAO,SAAS,kBAAkB,0BAA0B,IAAI;AAGjE,KAAI;EACH,MAAM,SAAS,MAAM,OAAO,QAAQ,SAAS,IAAI;EAEjD,MAAM,UAAkC;GACvC,gBAAgB,OAAO;GACvB,iBAAiB;GACjB,0BAA0B;GAG1B,2BACC;GACD;AAED,MAAI,OAAO,KACV,SAAQ,oBAAoB,OAAO,OAAO,KAAK;AAKhD,MAAI,kBAAkB,IAAI,OAAO,YAAY,CAC5C,SAAQ,yBAAyB;MAEjC,SAAQ,yBAAyB;AAGlC,SAAO,IAAI,SAAS,OAAO,MAAM;GAAE,QAAQ;GAAK;GAAS,CAAC;UAClD,OAAO;AAEf,MACC,iBAAiB,UAChB,MAAM,QAAQ,SAAS,YAAY,IAAI,MAAM,QAAQ,SAAS,YAAY,EAE3E,QAAO,SAAS,aAAa,kBAAkB,IAAI;AAEpD,SAAO,YAAY,OAAO,wBAAwB,mBAAmB"}