mirror of
https://github.com/luckyyzh/pi-agent-integrated.git
synced 2026-10-03 11:09:34 +00:00
feat: integrate Pi backend and Pi Web
This commit is contained in:
@@ -0,0 +1,31 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import { getAllowedFileRoots, isExistingFilePathAllowed, isFilePathAllowed, isWindowsAbsolutePath } from "@/lib/file-access";
|
||||
import { getGitFileDiff } from "@/lib/git-changes";
|
||||
|
||||
export async function GET(request: NextRequest) {
|
||||
try {
|
||||
const cwd = request.nextUrl.searchParams.get("cwd")?.trim() ?? "";
|
||||
const filePath = request.nextUrl.searchParams.get("path")?.trim() ?? "";
|
||||
if (!cwd || (!cwd.startsWith("/") && !isWindowsAbsolutePath(cwd))) {
|
||||
return NextResponse.json({ error: "cwd must be an absolute path" }, { status: 400 });
|
||||
}
|
||||
if (!filePath || (!filePath.startsWith("/") && !isWindowsAbsolutePath(filePath))) {
|
||||
return NextResponse.json({ error: "path must be an absolute path" }, { status: 400 });
|
||||
}
|
||||
|
||||
const allowedRoots = await getAllowedFileRoots();
|
||||
if (!isFilePathAllowed(cwd, allowedRoots) || !isFilePathAllowed(filePath, allowedRoots)) {
|
||||
return NextResponse.json({ error: "Access denied" }, { status: 403 });
|
||||
}
|
||||
// The cwd must resolve inside an allowed root. The file itself may no
|
||||
// longer exist when Git reports it as deleted; getGitFileDiff verifies
|
||||
// that the requested path belongs to this repository and its status.
|
||||
if (!isExistingFilePathAllowed(cwd, allowedRoots)) {
|
||||
return NextResponse.json({ error: "Access denied" }, { status: 403 });
|
||||
}
|
||||
|
||||
return NextResponse.json(await getGitFileDiff(cwd, filePath));
|
||||
} catch (error) {
|
||||
return NextResponse.json({ error: error instanceof Error ? error.message : String(error) }, { status: 500 });
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user