Files
accounted/app/api/sandbox/cleanup/cron/route.ts
T
MattssonandClaude Opus 4.6 550cadcb06 fix: harden auth, cron secrets, and provider flows (GNU-17) (#148)
- Replace === with crypto.timingSafeEqual in all 7 cron routes via shared lib/auth/cron.ts
- Add in-memory rate limiting (60 req/min) and expires_at support to calendar feed
- Add exponential backoff on MFA verify after 3 failed attempts
- Add 60s cooldown on password reset requests
- Validate bank callback auth code format before API call
- Redact session IDs from bank sync and callback logs
- Validate OAuth redirect_uris against allowlist (claude.ai, claude.com, localhost)
- Remove excessive PII/debug console logging from login page

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-29 23:49:09 +02:00

45 lines
1.2 KiB
TypeScript

import { createClient } from '@supabase/supabase-js'
import { NextResponse } from 'next/server'
import { verifyCronSecret } from '@/lib/auth/cron'
/**
* GET /api/sandbox/cleanup/cron
* Daily cron job to clean up expired sandbox users (>24h old).
* Runs at 04:00 UTC every day.
*/
export async function GET(request: Request) {
const authError = verifyCronSecret(request)
if (authError) return authError
const supabaseUrl = process.env.NEXT_PUBLIC_SUPABASE_URL
const supabaseServiceKey = process.env.SUPABASE_SERVICE_ROLE_KEY
if (!supabaseUrl || !supabaseServiceKey) {
return NextResponse.json(
{ error: 'Missing Supabase configuration' },
{ status: 500 }
)
}
const supabase = createClient(supabaseUrl, supabaseServiceKey)
try {
const { data, error } = await supabase.rpc('cleanup_expired_sandbox_users', {
p_max_age_hours: 24,
})
if (error) throw error
const cleaned = data ?? 0
console.log(`Sandbox cleanup cron completed: ${cleaned} users removed`)
return NextResponse.json({ success: true, cleaned })
} catch (error) {
console.error('Error in sandbox cleanup cron:', error)
return NextResponse.json(
{ error: 'Failed to clean up sandbox users' },
{ status: 500 }
)
}
}