import { applyCors, isAllowedOrigin } from './_cors.js'; import * as XLSX from 'xlsx'; import { getBcConfig, getBCToken, fetchAllItems, buildWorkbook } from '../bc-runtime.js'; function setCors(req, res) { applyCors(req, res, 'GET, OPTIONS'); } export default async function handler(req, res) { setCors(req, res); if (req.method === 'OPTIONS') return res.status(204).end(); const origin = req.headers.origin; if (origin && !isAllowedOrigin(origin)) { return res.status(403).json({ error: 'Forbidden' }); } if (req.method !== 'GET') { return res.status(405).json({ error: 'Method not allowed' }); } try { const config = getBcConfig(); const token = await getBCToken(config); const items = await fetchAllItems(config, token); if (req.query?.format === 'json') { return res.json({ success: true, count: items.length, items }); } const workbook = buildWorkbook(items); const buffer = XLSX.write(workbook, { bookType: 'xlsx', type: 'buffer' }); const dateStr = new Date().toISOString().split('T')[0]; res.setHeader('Content-Type', 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet'); res.setHeader('Content-Disposition', `attachment; filename="BusinessCentral_Items_${dateStr}.xlsx"`); res.setHeader('Cache-Control', 'no-store'); return res.status(200).send(buffer); } catch (err) { console.error('[bc-export] error:', err?.message || err); return res.status(500).json({ success: false, error: err?.message || String(err) }); } }