- Replace === with crypto.timingSafeEqual in all 7 cron routes via shared lib/auth/cron.ts - Add in-memory rate limiting (60 req/min) and expires_at support to calendar feed - Add exponential backoff on MFA verify after 3 failed attempts - Add 60s cooldown on password reset requests - Validate bank callback auth code format before API call - Redact session IDs from bank sync and callback logs - Validate OAuth redirect_uris against allowlist (claude.ai, claude.com, localhost) - Remove excessive PII/debug console logging from login page Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
52 lines
1.5 KiB
TypeScript
52 lines
1.5 KiB
TypeScript
import { createClient } from '@supabase/supabase-js'
|
|
import { NextResponse } from 'next/server'
|
|
import { updateDeadlineStatuses } from '@/lib/deadlines/status-engine'
|
|
import { verifyCronSecret } from '@/lib/auth/cron'
|
|
|
|
/**
|
|
* GET /api/deadlines/status/cron
|
|
* Daily cron job to update deadline statuses
|
|
* Runs at 06:00 every day
|
|
*
|
|
* Vercel Cron: "0 6 * * *"
|
|
*/
|
|
export async function GET(request: Request) {
|
|
const authError = verifyCronSecret(request)
|
|
if (authError) return authError
|
|
|
|
// Create a service role client for accessing all user data
|
|
const supabaseUrl = process.env.NEXT_PUBLIC_SUPABASE_URL
|
|
const supabaseServiceKey = process.env.SUPABASE_SERVICE_ROLE_KEY
|
|
|
|
if (!supabaseUrl || !supabaseServiceKey) {
|
|
return NextResponse.json(
|
|
{ error: 'Missing Supabase configuration' },
|
|
{ status: 500 }
|
|
)
|
|
}
|
|
|
|
const supabase = createClient(supabaseUrl, supabaseServiceKey)
|
|
|
|
try {
|
|
const result = await updateDeadlineStatuses(supabase)
|
|
|
|
console.log(
|
|
`Deadline status cron completed: ${result.updated} updated, ` +
|
|
`${result.newlyOverdue} newly overdue, ${result.newlyActionNeeded} newly action_needed`
|
|
)
|
|
|
|
return NextResponse.json({
|
|
success: true,
|
|
updated: result.updated,
|
|
newlyOverdue: result.newlyOverdue,
|
|
newlyActionNeeded: result.newlyActionNeeded,
|
|
})
|
|
} catch (error) {
|
|
console.error('Error in deadline status cron:', error)
|
|
return NextResponse.json(
|
|
{ error: 'Failed to update deadline statuses' },
|
|
{ status: 500 }
|
|
)
|
|
}
|
|
}
|