import { NextRequest, NextResponse } from 'next/server'; import { readFile } from 'fs/promises'; import path from 'path'; const MIME: Record = { '.jpg': 'image/jpeg', '.jpeg': 'image/jpeg', '.png': 'image/png', '.webp': 'image/webp', '.avif': 'image/avif', '.gif': 'image/gif', }; /** * Serves uploaded product images dynamically from disk on every request. * Mirrors the behaviour of the admin app so newly uploaded images are * immediately available without a rebuild. */ export async function GET( _request: NextRequest, { params }: { params: Promise<{ filename: string }> }, ) { const { filename } = await params; const safe = path.basename(filename); if (safe !== filename || filename.includes('..')) { return NextResponse.json({ error: 'Invalid filename' }, { status: 400 }); } const ext = path.extname(safe).toLowerCase(); const filePath = path.join(process.cwd(), 'public', 'uploads', safe); try { const buffer = await readFile(filePath); return new NextResponse(buffer, { headers: { 'Content-Type': MIME[ext] ?? 'application/octet-stream', 'Cache-Control': 'public, max-age=31536000, immutable', 'X-Content-Type-Options': 'nosniff', }, }); } catch { return NextResponse.json({ error: 'Not found' }, { status: 404 }); } }