import { Controller, Get, Param, ParseUUIDPipe, Query, Res, } from "@nestjs/common"; import { ApiBearerAuth, ApiOperation, ApiQuery, ApiTags } from "@nestjs/swagger"; import { Response } from "express"; import { FilesService } from "./files.service"; @ApiTags("files") @ApiBearerAuth() @Controller("files") export class FilesController { constructor(private readonly filesService: FilesService) {} @Get(":fileId") // Authenticated: no @Public, so the global JwtGuard applies. Unguessable file // UUIDs are obscurity, not authorization — raw byte streams must require auth. // Browser inline previews (/