Files
pi-agent-integrated/pi-web/app/api/git/status/route.ts

36 lines
1.3 KiB
TypeScript

import fs from "fs";
import { NextRequest, NextResponse } from "next/server";
import { getAllowedFileRoots, isExistingFilePathAllowed, isFilePathAllowed, isWindowsAbsolutePath } from "@/lib/file-access";
import { getGitStatus } from "@/lib/git-changes";
export async function GET(request: NextRequest) {
try {
const cwd = request.nextUrl.searchParams.get("cwd")?.trim() ?? "";
if (!cwd || (!cwd.startsWith("/") && !isWindowsAbsolutePath(cwd))) {
return NextResponse.json({ error: "cwd must be an absolute path" }, { status: 400 });
}
const allowedRoots = await getAllowedFileRoots();
if (!isFilePathAllowed(cwd, allowedRoots)) {
return NextResponse.json({ error: "Access denied" }, { status: 403 });
}
let stat: fs.Stats;
try {
stat = fs.statSync(cwd);
} catch {
return NextResponse.json({ error: "Directory not found" }, { status: 404 });
}
if (!stat.isDirectory()) {
return NextResponse.json({ error: "Not a directory" }, { status: 400 });
}
if (!isExistingFilePathAllowed(cwd, allowedRoots)) {
return NextResponse.json({ error: "Access denied" }, { status: 403 });
}
return NextResponse.json(await getGitStatus(cwd));
} catch (error) {
return NextResponse.json({ error: error instanceof Error ? error.message : String(error) }, { status: 500 });
}
}