import { createRedisNamedEventResponse } from "@/lib/events/redis-stream"; import { getCommentTarget, getCommentViewer, requireCommentAdmin } from "@/lib/comments/repository"; import { errorResponse, HttpError } from "@/lib/security/http"; import { limitRequest, trustedClientAddress } from "@/lib/security/rate-limit"; export async function GET(request: Request) { try { await limitRequest("stream-open", trustedClientAddress(request.headers), 60); const query = new URL(request.url).searchParams; const viewer = await getCommentViewer(); let topic: string; if (query.get("scope") === "admin") { requireCommentAdmin(viewer); topic = "comments:admin"; } else { const target = query.get("target"); if (!target) throw new HttpError(400, "target-required"); const destination = await getCommentTarget(target, viewer); topic = `comments:${destination.target}`; } // Events contain no comment text, images, or author information. // Every refresh rechecks current guide visibility and viewer permissions. return await createRedisNamedEventResponse(topic, "changed", request.signal); } catch (cause) { return errorResponse(cause); } }