- PRD: vollständige Produktspezifikation (5 Module, Scope, Akzeptanzkriterien) - ARCHITECTURE: Tech Stack, Ordnerstruktur, Multi-Tenancy, Push, Kosten - DATABASE_SCHEMA: Vollständiges SQL-Schema mit RLS Policies und Views - USER_STORIES: 40+ Stories nach Rolle (Admin, Mitglied, Azubi, Obermeister) - PERSONAS: 5 detaillierte Nutzerprofile mit Alltag, Zitaten und Erwartungen - BUSINESS_MODEL: Preistabellen, Unit Economics, Revenue-Projektionen, Distribution - ROADMAP: 6 Phasen, Sprint-Planung, Meilensteine und KPIs - COMPETITIVE_ANALYSIS: Wettbewerbsmatrix, USPs, Preispositionierung - API_DESIGN: Supabase Query Patterns, Edge Functions, Realtime Subscriptions - ONBOARDING_FLOWS: 7 User Flows von Setup bis Fehlerfall - GTM_STRATEGY: 3-Phasen-Vertrieb, Outreach-Sequenz, Einwandbehandlung - AZUBI_MODULE: Video-Feed, 1-Click-Apply, Chat, Berichtsheft, Quiz - DSGVO_KONZEPT: Rechtsgrundlagen, TOMs, AVV, Minderjährige, Incident Response - FEATURES_BACKLOG: 72 Features nach MoSCoW + Technische Schulden Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
42 lines
1.2 KiB
TypeScript
42 lines
1.2 KiB
TypeScript
import { NextRequest, NextResponse } from 'next/server'
|
|
import { readFile } from 'fs/promises'
|
|
import path from 'path'
|
|
|
|
const UPLOAD_DIR = process.env.UPLOAD_DIR ?? './uploads'
|
|
|
|
export async function GET(
|
|
req: NextRequest,
|
|
{ params }: { params: { path: string[] } }
|
|
) {
|
|
try {
|
|
const filePath = path.join(process.cwd(), UPLOAD_DIR, ...params.path)
|
|
|
|
// Security: prevent path traversal
|
|
const resolved = path.resolve(filePath)
|
|
const uploadDir = path.resolve(path.join(process.cwd(), UPLOAD_DIR))
|
|
if (!resolved.startsWith(uploadDir)) {
|
|
return new NextResponse('Forbidden', { status: 403 })
|
|
}
|
|
|
|
const file = await readFile(resolved)
|
|
const ext = path.extname(resolved).toLowerCase()
|
|
const mimeTypes: Record<string, string> = {
|
|
'.pdf': 'application/pdf',
|
|
'.png': 'image/png',
|
|
'.jpg': 'image/jpeg',
|
|
'.jpeg': 'image/jpeg',
|
|
'.gif': 'image/gif',
|
|
'.webp': 'image/webp',
|
|
}
|
|
|
|
return new NextResponse(file, {
|
|
headers: {
|
|
'Content-Type': mimeTypes[ext] ?? 'application/octet-stream',
|
|
'Cache-Control': 'public, max-age=86400',
|
|
},
|
|
})
|
|
} catch {
|
|
return new NextResponse('Not Found', { status: 404 })
|
|
}
|
|
}
|