import { NextResponse } from "next/server" import { db } from "@/lib/db" import { usage_events } from "@/lib/db/schema" import { getSessionUser } from "@/lib/session" import { buildUserDataExport } from "@/lib/gdpr/export" // GDPR data export (Articles 15/20) — downloads everything the platform stores // about the signed-in user as a single JSON file. Sensitive credentials are // excluded by the builder (see lib/gdpr/export.ts). export async function GET() { const user = await getSessionUser() if (!user) return NextResponse.json({ error: "Unauthorized" }, { status: 401 }) const data = await buildUserDataExport(user.id) // DSAR evidence: record that the export was served. await db.insert(usage_events).values({ user_id: user.id, event_type: "gdpr_data_export" }) const filename = `pmn-data-export-${new Date().toISOString().slice(0, 10)}.json` return new NextResponse(JSON.stringify(data, null, 2), { headers: { "Content-Type": "application/json", "Content-Disposition": `attachment; filename="${filename}"`, "Cache-Control": "no-store", }, }) }