// Read a template's source through the plumbing API rather than mounting the // prime db directly (see route-editor.js for the why). Forwarding the caller's // session cookie keeps the read owner-checked: plumbing 404s any template in a // structure the user can't see. async function handler(req, res) { const base = `${req.protocol}://${req.get("host")}`; const response = await fetch(`${base}/plumbing/templates/${req.params.id}`, { headers: { cookie: req.headers.cookie || "" }, }); if (!response.ok) return res.status(response.status).send("Template not found"); const artifact = await response.json(); res.render("inspector/artifact_editor", { kind: "template", artifact }); }