Property Management Network — Next.js 16 (App Router), Better Auth, Drizzle ORM over PostgreSQL, Stripe, OpenAI, Resend. Includes: - Security hardening: access-control/IDOR fixes, TLS-by-default DB layer, constant-time cron auth, strict security headers, atomic AI quota gating, HTML/email output encoding, demo-backdoor disabled in production. - Superadmin dashboard at /admin (overview/MRR, server-paginated users with ban/impersonate/plan/delete, billing, platform activity + admin audit log, AI usage, system health) via the Better Auth admin plugin. - Seed/migration utility scripts under scripts/. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
14 lines
503 B
TypeScript
14 lines
503 B
TypeScript
import { timingSafeEqual } from "crypto"
|
|
|
|
/** Constant-time check of the cron bearer token. Fails closed if CRON_SECRET is unset. */
|
|
export function isAuthorizedCron(request: Request): boolean {
|
|
const secret = process.env.CRON_SECRET
|
|
if (!secret) return false
|
|
const header = request.headers.get("authorization") ?? ""
|
|
const expected = `Bearer ${secret}`
|
|
const a = Buffer.from(header)
|
|
const b = Buffer.from(expected)
|
|
if (a.length !== b.length) return false
|
|
return timingSafeEqual(a, b)
|
|
}
|