import { NextResponse } from 'next/server'; import { findStoredImage } from '@/lib/screen/service'; export const dynamic = 'force-dynamic'; const CONTENT_TYPES: Record = { bmp: 'image/bmp', png: 'image/png', }; /** * Serves a rendered panel image. * * The path is the hash of the bytes, so the content can never change under a * given URL: it is safe to cache forever, and it cannot be enumerated. No * authentication — the firmware fetches it as a plain image, and an * unguessable immutable URL is the protection. */ export async function GET(_request: Request, { params }: { params: Promise<{ hash: string }> }) { const { hash: raw } = await params; const [hash, extension] = raw.split('.'); if (!hash || !/^[0-9a-f]{8,64}$/.test(hash)) { return new NextResponse(null, { status: 404 }); } const image = await findStoredImage(hash); if (!image) { return new NextResponse(null, { status: 404 }); } const contentType = CONTENT_TYPES[extension ?? image.format] ?? 'application/octet-stream'; return new NextResponse(new Uint8Array(image.bytes), { headers: { 'Content-Type': contentType, 'Content-Length': String(image.bytes.length), 'Cache-Control': 'public, max-age=31536000, immutable', }, }); }