import { NextResponse } from "next/server";
import { hasPermission } from "@/lib/adminAuth";
import { generateStoryRecap } from "@/lib/storyRecap";

// Nur fürs Team (nicht der Kunde) — Instagram-Story-Recap aus den
// höchstbewerteten Fotos eines Auftrags, 1080×1920 mit Rakku-Branding.
export async function GET(_req: Request, { params }: { params: Promise<{ orderId: string }> }) {
  if (!(await hasPermission("orders_edit"))) return new NextResponse("Unauthorized", { status: 401 });
  const { orderId } = await params;

  const image = await generateStoryRecap(orderId);
  if (!image) return new NextResponse("Keine Fotos für diesen Auftrag gefunden.", { status: 404 });

  return new NextResponse(new Uint8Array(image), {
    headers: {
      "Content-Type": "image/jpeg",
      "Content-Disposition": `attachment; filename="story-recap-${orderId}.jpg"`,
      "Cache-Control": "private, max-age=0, no-store",
    },
  });
}
