import { Controller, Get, Param, Req } from '@nestjs/common'; import { AuthedRequest } from '../auth/auth.guard'; import { AuthenticatedOnly } from '../permissions/permission.decorators'; import { PublicPageContent, PublicService } from './public.service'; /** * Authenticated read-rendering (issue #135). Returns a page's rendered read * HTML — plugin fallbacks, expanded page embeds, resolved media — for a * signed-in viewer with read access. The transclusion node view fetches this to * show an embedded page's content inline in the authenticated read view, which * must also work for pages that are not public and so are out of reach of the * `/public` endpoints. NOT `@Public`: the auth guard requires a session and the * service enforces read permission (a non-readable page 404s, no leak). */ @Controller('read') export class ReadContentController { constructor(private readonly publicPages: PublicService) {} // Session required (explicit access rule, issue #52); per-page read // permission is enforced in the service (resolve → canAccessPage → 404). @Get(':pondSlug/:pageSlug') @AuthenticatedOnly() async content( @Param('pondSlug') pondSlug: string, @Param('pageSlug') pageSlug: string, @Req() request: AuthedRequest, ): Promise { return this.publicPages.content(request.user ?? null, pondSlug, pageSlug); } }