/** Cabeceras HTTP para bytes de documento cifrado ya descifrados. */ export function documentServeHeaders( doc: { original_name: string; mime?: string }, opts: { inline?: boolean } = {}, ): Record { const inline = opts.inline !== false; const mime = (doc.mime || "").trim() || "application/octet-stream"; const name = doc.original_name || "documento"; const disposition = inline ? "inline" : "attachment"; return { "Content-Type": mime, "X-Content-Type-Options": "nosniff", "Content-Disposition": `${disposition}; filename="${encodeURIComponent(name)}"`, "Cache-Control": "private, max-age=60", }; } export function wantsInlineDocumentDisposition(url: URL | string): boolean { const u = typeof url === "string" ? new URL(url, "http://local") : url; const d = (u.searchParams.get("disposition") || u.searchParams.get("inline") || "").toLowerCase(); if (d === "attachment" || d === "download" || d === "0" || d === "false") return false; if (d === "inline" || d === "1" || d === "true") return true; return true; }