Turnstile bot protection (sign-in, sign-up, password-reset): - Register Better Auth's captcha plugin with the cloudflare-turnstile provider; endpoints listed explicitly rather than relying on defaults. /reset-password is intentionally excluded — it is reached only via a single-use emailed token. - Add an explicit-render Turnstile widget component. Tokens are single-use, so each form resets the challenge after a failed submit; submit stays disabled until a token is held. - Read the site key server-side and pass it down as a prop, so rotating it does not require a rebuild. - Fail fast in production when TURNSTILE_SECRET_KEY is missing, and when a secret is set without a site key (that combination would demand a token no form can produce, locking every user out). - Pass a throwaway secret during `next build` in the Dockerfile, mirroring the existing BETTER_AUTH_SECRET treatment, so image builds don't need it. CSP fixes in middleware (these blocked Turnstile entirely): - Add frame-src for challenges.cloudflare.com. Without it the widget's iframe fell back to default-src 'self' and was blocked outright. - Allow 'unsafe-eval' and websockets in DEVELOPMENT only. `next dev` compiles with eval(), so the strict policy threw EvalError and killed hydration — no client JS ran at all, which also meant form submit handlers never fired. Production policy is unchanged and still strict. Also included (concurrent work in the tree): - Admin organizations pages and lib/admin/orgs. - Episode moderation migration, SEO metadata (sitemap, robots, JSON-LD, OG/Twitter images, manifest), Umami analytics, not-found page. Local dev database: docker-compose.dev.yml provisions Postgres 18 on port 5443 (5432-5442 are in use by other local projects). Note: `npx tsc --noEmit` currently fails in app/(app)/team/page.tsx — an `invitations` prop the component does not accept. This predates the commit and will fail `next build` until fixed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
143 lines
4.7 KiB
TypeScript
143 lines
4.7 KiB
TypeScript
import { NextRequest } from "next/server";
|
|
import JSZip from "jszip";
|
|
import { getServerSession } from "@/lib/auth/guards";
|
|
import { prisma } from "@/lib/db";
|
|
import { storage } from "@/lib/storage";
|
|
import { rateLimit, LIMITS } from "@/lib/ratelimit";
|
|
import type { StructuredScript } from "@/lib/ai/types";
|
|
|
|
export const dynamic = "force-dynamic";
|
|
|
|
/**
|
|
* Bundle everything for an episode into a single .zip download:
|
|
* - audio.mp3 (the rendered episode, if present)
|
|
* - cover.png (the cover art, if present)
|
|
* - script.txt (the full transcript, speaker-labelled)
|
|
* - show-notes.md (title + section outline)
|
|
*
|
|
* Ownership-gated: only the owning user (or an admin) may export.
|
|
*/
|
|
export async function GET(
|
|
_req: NextRequest,
|
|
{ params }: { params: Promise<{ id: string }> }
|
|
) {
|
|
const { id } = await params;
|
|
|
|
const session = await getServerSession();
|
|
if (!session) return new Response("Unauthorized", { status: 401 });
|
|
|
|
// This handler buffers the full MP3 + cover into a JSZip in memory, so an
|
|
// authenticated user looping it is a cheap way to exhaust the heap.
|
|
const rl = await rateLimit("export", session.user.id, LIMITS.export);
|
|
if (!rl.ok) {
|
|
return new Response("Too many exports. Please slow down.", {
|
|
status: 429,
|
|
headers: { "Retry-After": String(rl.retryAfterSec ?? 60) },
|
|
});
|
|
}
|
|
|
|
const episode = await prisma.episode.findUnique({
|
|
where: { id },
|
|
include: {
|
|
script: true,
|
|
audioAsset: true,
|
|
coverArt: true,
|
|
speakers: true,
|
|
},
|
|
});
|
|
if (!episode) return new Response("Not found", { status: 404 });
|
|
if (episode.userId !== session.user.id && session.user.role !== "admin") {
|
|
return new Response("Forbidden", { status: 403 });
|
|
}
|
|
// Removed content stays downloadable for admins (evidence/appeals) but not
|
|
// for the owner, who would otherwise just re-publish it elsewhere.
|
|
if (episode.moderatedAt && session.user.role !== "admin") {
|
|
return new Response("This episode was removed for a policy violation.", { status: 451 });
|
|
}
|
|
|
|
const speakerNames: Record<string, string> = {};
|
|
for (const s of episode.speakers) speakerNames[s.speakerKey] = s.displayName;
|
|
|
|
const zip = new JSZip();
|
|
|
|
// Audio (if rendered).
|
|
if (episode.audioAsset && (await storage().exists(episode.audioAsset.storageKey))) {
|
|
const audio = await storage().get(episode.audioAsset.storageKey);
|
|
const ext = episode.audioAsset.format || "mp3";
|
|
zip.file(`audio.${ext}`, audio);
|
|
}
|
|
|
|
// Cover art (if present).
|
|
if (episode.coverArt && (await storage().exists(episode.coverArt.storageKey))) {
|
|
const art = await storage().get(episode.coverArt.storageKey);
|
|
const ext = episode.coverArt.storageKey.split(".").pop()?.toLowerCase() ?? "png";
|
|
zip.file(`cover.${ext}`, art);
|
|
}
|
|
|
|
// Transcript + show notes derived from the structured script.
|
|
if (episode.script) {
|
|
const script = episode.script.content as unknown as StructuredScript;
|
|
zip.file("script.txt", buildTranscript(episode.title, script, speakerNames));
|
|
zip.file("show-notes.md", buildShowNotes(episode, script));
|
|
}
|
|
|
|
const blob = await zip.generateAsync({ type: "nodebuffer" });
|
|
const filename = `${slugify(episode.title) || "episode"}.zip`;
|
|
|
|
return new Response(blob as BodyInit, {
|
|
headers: {
|
|
"Content-Type": "application/zip",
|
|
"Content-Length": String(blob.byteLength),
|
|
"Content-Disposition": `attachment; filename="${filename}"`,
|
|
"Cache-Control": "private, no-store",
|
|
},
|
|
});
|
|
}
|
|
|
|
function buildTranscript(
|
|
title: string,
|
|
script: StructuredScript,
|
|
speakerNames: Record<string, string>
|
|
): string {
|
|
const lines: string[] = [title, "=".repeat(title.length), ""];
|
|
for (const section of script.sections ?? []) {
|
|
lines.push(`## ${section.title}`, "");
|
|
for (const turn of section.turns ?? []) {
|
|
const name = speakerNames[turn.speakerKey] ?? turn.speakerKey;
|
|
lines.push(`${name}: ${turn.text}`, "");
|
|
}
|
|
}
|
|
return lines.join("\n").trimEnd() + "\n";
|
|
}
|
|
|
|
function buildShowNotes(
|
|
episode: { title: string; topic: string; format: string; language: string; targetLengthMin: number },
|
|
script: StructuredScript
|
|
): string {
|
|
const lines: string[] = [
|
|
`# ${episode.title}`,
|
|
"",
|
|
episode.topic,
|
|
"",
|
|
`- **Format:** ${episode.format.replace("_", "-").toLowerCase()}`,
|
|
`- **Language:** ${episode.language.toUpperCase()}`,
|
|
`- **Target length:** ${episode.targetLengthMin} min`,
|
|
"",
|
|
"## In this episode",
|
|
"",
|
|
];
|
|
for (const section of script.sections ?? []) {
|
|
lines.push(`- ${section.title}`);
|
|
}
|
|
lines.push("", "---", "Generated with Podcast Distribution AI.");
|
|
return lines.join("\n") + "\n";
|
|
}
|
|
|
|
function slugify(s: string): string {
|
|
return s
|
|
.toLowerCase()
|
|
.replace(/[^a-z0-9]+/g, "-")
|
|
.replace(/^-+|-+$/g, "")
|
|
.slice(0, 60);
|
|
}
|