// Read a route's source through the plumbing API rather than mounting the prime // db directly. The prime db is no longer attachable to other structures, and // going through /plumbing means this read is owner-checked: forwarding the // caller's session cookie, plumbing 404s any route in a structure they can't // see, so the live editor can only open what the user is already allowed to edit. async function handler(req, res) { const base = `${req.protocol}://${req.get("host")}`; const response = await fetch(`${base}/plumbing/routes/${req.params.id}`, { headers: { cookie: req.headers.cookie || "" }, }); if (!response.ok) return res.status(response.status).send("Route not found"); const artifact = await response.json(); res.render("inspector/artifact_editor", { kind: "route", artifact }); }