import { timingSafeEqual } from "crypto" /** Constant-time check of the cron bearer token. Fails closed if CRON_SECRET is unset. */ export function isAuthorizedCron(request: Request): boolean { const secret = process.env.CRON_SECRET if (!secret) return false const header = request.headers.get("authorization") ?? "" const expected = `Bearer ${secret}` const a = Buffer.from(header) const b = Buffer.from(expected) if (a.length !== b.length) return false return timingSafeEqual(a, b) }