docs: correct the segment-decoding comment on the catch-all route

Review caught the stated invariant being false. Next splits the matched
suffix on literal `/` before decoding each piece, so a segment can be empty
(`api//mcp`) and a single segment can carry a decoded slash (`api%2Fmcp`).
Neither reaches the allowlist — both fail closed — but the comment claimed
an invariant the router does not provide.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-09-16 16:32:46 -07:00
co-authored by Claude Opus 5
parent f46f54d50b
commit 3be9135aee
@@ -41,8 +41,11 @@ export async function GET(
ctx: { params: Promise<{ path: string[] }> },
): Promise<NextResponse> {
const { path } = await ctx.params;
// Segments arrive already percent-decoded and never empty, but join and
// compare on the same normalized form the allowlist is written in.
// Next splits the matched suffix on literal `/` and only then decodes each
// piece, so a segment can be empty (`api//mcp` -> ["api","","mcp"]) and a
// single segment can itself contain a decoded slash (`api%2Fmcp` -> one
// element, "api/mcp"). Join and compare on the same normalized form the
// allowlist is written in, and let anything else fail closed.
const resourcePath = path.join("/");
if (!METADATA_RESOURCE_PATHS.has(resourcePath)) {