- Clone import: defer FurnitureData.json writes and append all entries in a single batched write instead of one read-modify-write per item, removing the main serialization bottleneck for large batches. - Clone import: raise SSE batch concurrency cap from 5 to 10 and bump the clone client/route default from 2 to 6. - Add a flush hook to runSseBatch so callers can batch deferred work before batch_complete is emitted, and surface flush errors as an error event. - Enable Next.js Cache Components (instant: false opt-out) and silence the related build warnings in next.config.ts. - Switch isomorphic-dompurify to dompurify and refresh dependencies.
54 lines
1.7 KiB
TypeScript
54 lines
1.7 KiB
TypeScript
import { existsSync } from "node:fs";
|
|
import { readFile } from "node:fs/promises";
|
|
import path from "node:path";
|
|
import { NextResponse } from "next/server";
|
|
import { MEDIA_ROOT, resolveMediaPath } from "@/lib/media-storage";
|
|
|
|
const ALLOWED_EXT = [".png", ".jpg", ".jpeg", ".gif", ".webp", ".svg", ".bmp"];
|
|
|
|
export async function GET(
|
|
_request: Request,
|
|
{ params }: { params: Promise<{ path: string[] }> },
|
|
) {
|
|
const { path: segments } = await params;
|
|
const name = segments.join("/");
|
|
// Prevent path traversal
|
|
if (name.includes("..") || name.includes("\\")) {
|
|
return new NextResponse("Forbidden", { status: 403 });
|
|
}
|
|
const ext = path.extname(name).toLowerCase();
|
|
if (!ALLOWED_EXT.includes(ext)) {
|
|
return new NextResponse("Forbidden", { status: 403 });
|
|
}
|
|
|
|
const baseDir = MEDIA_ROOT;
|
|
const filePath = resolveMediaPath(name);
|
|
if (!filePath.startsWith(baseDir + path.sep)) {
|
|
return new NextResponse("Forbidden", { status: 403 });
|
|
}
|
|
// eslint-disable-next-line security/detect-non-literal-fs-filename
|
|
if (!existsSync(filePath)) {
|
|
return new NextResponse("Not found", { status: 404 });
|
|
}
|
|
|
|
// eslint-disable-next-line security/detect-non-literal-fs-filename
|
|
const bytes = await readFile(filePath);
|
|
const mime: Record<string, string> = {
|
|
".png": "image/png",
|
|
".jpg": "image/jpeg",
|
|
".jpeg": "image/jpeg",
|
|
".gif": "image/gif",
|
|
".webp": "image/webp",
|
|
".svg": "image/svg+xml",
|
|
".bmp": "image/bmp",
|
|
};
|
|
|
|
return new NextResponse(bytes, {
|
|
headers: {
|
|
// eslint-disable-next-line security/detect-object-injection -- ext validated against ALLOWED_EXT
|
|
"Content-Type": mime[ext] ?? "application/octet-stream",
|
|
"Cache-Control": "public, max-age=3600, must-revalidate",
|
|
},
|
|
});
|
|
}
|