mirror of
https://github.com/christianvidalwolf-prog/Craze-Data-check.git
synced 2026-08-03 16:25:24 +02:00
fix vercel load errors
This commit is contained in:
@@ -0,0 +1,38 @@
|
|||||||
|
const LOCALHOST_ORIGIN_PREFIXES = ['http://localhost:', 'http://127.0.0.1:'];
|
||||||
|
|
||||||
|
export function isAllowedOrigin(origin) {
|
||||||
|
if (!origin) return false;
|
||||||
|
|
||||||
|
if (LOCALHOST_ORIGIN_PREFIXES.some(prefix => origin.startsWith(prefix))) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
const url = new URL(origin);
|
||||||
|
if (url.hostname === 'craze-data-check.vercel.app') return true;
|
||||||
|
if (url.hostname.endsWith('.vercel.app')) return true;
|
||||||
|
if (process.env.APP_URL) {
|
||||||
|
const appUrl = new URL(process.env.APP_URL);
|
||||||
|
if (url.hostname === appUrl.hostname) return true;
|
||||||
|
}
|
||||||
|
if (process.env.VERCEL_URL) {
|
||||||
|
const vercelHost = process.env.VERCEL_URL.replace(/^https?:\/\//, '');
|
||||||
|
if (url.hostname === vercelHost) return true;
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
export function applyCors(req, res, methods) {
|
||||||
|
const origin = req.headers.origin;
|
||||||
|
if (isAllowedOrigin(origin)) {
|
||||||
|
res.setHeader('Access-Control-Allow-Origin', origin);
|
||||||
|
}
|
||||||
|
res.setHeader('Access-Control-Allow-Methods', methods);
|
||||||
|
res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization, apikey');
|
||||||
|
res.setHeader('Access-Control-Max-Age', '86400');
|
||||||
|
res.setHeader('Vary', 'Origin');
|
||||||
|
}
|
||||||
+3
-15
@@ -1,21 +1,9 @@
|
|||||||
|
import { applyCors, isAllowedOrigin } from './_cors.js';
|
||||||
import * as XLSX from 'xlsx';
|
import * as XLSX from 'xlsx';
|
||||||
import { getBcConfig, getBCToken, fetchAllItems, buildWorkbook } from '../bc-runtime.js';
|
import { getBcConfig, getBCToken, fetchAllItems, buildWorkbook } from '../bc-runtime.js';
|
||||||
|
|
||||||
const ALLOWED_ORIGINS = [
|
|
||||||
'http://localhost:3000',
|
|
||||||
'http://localhost:4173',
|
|
||||||
'http://localhost:5173',
|
|
||||||
'https://craze-data-check.vercel.app',
|
|
||||||
];
|
|
||||||
|
|
||||||
function setCors(req, res) {
|
function setCors(req, res) {
|
||||||
const origin = req.headers.origin;
|
applyCors(req, res, 'GET, OPTIONS');
|
||||||
if (origin && ALLOWED_ORIGINS.includes(origin)) {
|
|
||||||
res.setHeader('Access-Control-Allow-Origin', origin);
|
|
||||||
}
|
|
||||||
res.setHeader('Access-Control-Allow-Methods', 'GET, OPTIONS');
|
|
||||||
res.setHeader('Access-Control-Allow-Headers', 'Content-Type');
|
|
||||||
res.setHeader('Vary', 'Origin');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
export default async function handler(req, res) {
|
export default async function handler(req, res) {
|
||||||
@@ -24,7 +12,7 @@ export default async function handler(req, res) {
|
|||||||
if (req.method === 'OPTIONS') return res.status(204).end();
|
if (req.method === 'OPTIONS') return res.status(204).end();
|
||||||
|
|
||||||
const origin = req.headers.origin;
|
const origin = req.headers.origin;
|
||||||
if (origin && !ALLOWED_ORIGINS.includes(origin)) {
|
if (origin && !isAllowedOrigin(origin)) {
|
||||||
return res.status(403).json({ error: 'Forbidden' });
|
return res.status(403).json({ error: 'Forbidden' });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+3
-15
@@ -1,20 +1,8 @@
|
|||||||
|
import { applyCors, isAllowedOrigin } from './_cors.js';
|
||||||
import { getBcConfig, getBCToken, findItem, patchItemCpnpNo } from '../bc-runtime.js';
|
import { getBcConfig, getBCToken, findItem, patchItemCpnpNo } from '../bc-runtime.js';
|
||||||
|
|
||||||
const ALLOWED_ORIGINS = [
|
|
||||||
'http://localhost:3000',
|
|
||||||
'http://localhost:4173',
|
|
||||||
'http://localhost:5173',
|
|
||||||
'https://craze-data-check.vercel.app',
|
|
||||||
];
|
|
||||||
|
|
||||||
function setCors(req, res) {
|
function setCors(req, res) {
|
||||||
const origin = req.headers.origin;
|
applyCors(req, res, 'POST, OPTIONS');
|
||||||
if (origin && ALLOWED_ORIGINS.includes(origin)) {
|
|
||||||
res.setHeader('Access-Control-Allow-Origin', origin);
|
|
||||||
}
|
|
||||||
res.setHeader('Access-Control-Allow-Methods', 'POST, OPTIONS');
|
|
||||||
res.setHeader('Access-Control-Allow-Headers', 'Content-Type');
|
|
||||||
res.setHeader('Vary', 'Origin');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
export default async function handler(req, res) {
|
export default async function handler(req, res) {
|
||||||
@@ -23,7 +11,7 @@ export default async function handler(req, res) {
|
|||||||
if (req.method === 'OPTIONS') return res.status(204).end();
|
if (req.method === 'OPTIONS') return res.status(204).end();
|
||||||
|
|
||||||
const origin = req.headers.origin;
|
const origin = req.headers.origin;
|
||||||
if (origin && !ALLOWED_ORIGINS.includes(origin)) {
|
if (origin && !isAllowedOrigin(origin)) {
|
||||||
return res.status(403).json({ error: 'Forbidden' });
|
return res.status(403).json({ error: 'Forbidden' });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+3
-15
@@ -1,21 +1,9 @@
|
|||||||
|
import { applyCors, isAllowedOrigin } from './_cors.js';
|
||||||
import { getBcConfig, getBCToken } from '../bc-runtime.js';
|
import { getBcConfig, getBCToken } from '../bc-runtime.js';
|
||||||
import { applyBusinessCentralCpnp, applyBusinessCentralSync } from '../bc-sync-runtime.js';
|
import { applyBusinessCentralCpnp, applyBusinessCentralSync } from '../bc-sync-runtime.js';
|
||||||
|
|
||||||
const ALLOWED_ORIGINS = [
|
|
||||||
'http://localhost:3000',
|
|
||||||
'http://localhost:4173',
|
|
||||||
'http://localhost:5173',
|
|
||||||
'https://craze-data-check.vercel.app',
|
|
||||||
];
|
|
||||||
|
|
||||||
function setCors(req, res) {
|
function setCors(req, res) {
|
||||||
const origin = req.headers.origin;
|
applyCors(req, res, 'POST, OPTIONS');
|
||||||
if (origin && ALLOWED_ORIGINS.includes(origin)) {
|
|
||||||
res.setHeader('Access-Control-Allow-Origin', origin);
|
|
||||||
}
|
|
||||||
res.setHeader('Access-Control-Allow-Methods', 'POST, OPTIONS');
|
|
||||||
res.setHeader('Access-Control-Allow-Headers', 'Content-Type');
|
|
||||||
res.setHeader('Vary', 'Origin');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
export default async function handler(req, res) {
|
export default async function handler(req, res) {
|
||||||
@@ -24,7 +12,7 @@ export default async function handler(req, res) {
|
|||||||
if (req.method === 'OPTIONS') return res.status(204).end();
|
if (req.method === 'OPTIONS') return res.status(204).end();
|
||||||
|
|
||||||
const origin = req.headers.origin;
|
const origin = req.headers.origin;
|
||||||
if (origin && !ALLOWED_ORIGINS.includes(origin)) {
|
if (origin && !isAllowedOrigin(origin)) {
|
||||||
return res.status(403).json({ error: 'Forbidden' });
|
return res.status(403).json({ error: 'Forbidden' });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+3
-15
@@ -1,21 +1,9 @@
|
|||||||
|
import { applyCors, isAllowedOrigin } from './_cors.js';
|
||||||
import { getBcConfig, getBCToken } from '../bc-runtime.js';
|
import { getBcConfig, getBCToken } from '../bc-runtime.js';
|
||||||
import { previewBusinessCentralCpnp, previewBusinessCentralSync } from '../bc-sync-runtime.js';
|
import { previewBusinessCentralCpnp, previewBusinessCentralSync } from '../bc-sync-runtime.js';
|
||||||
|
|
||||||
const ALLOWED_ORIGINS = [
|
|
||||||
'http://localhost:3000',
|
|
||||||
'http://localhost:4173',
|
|
||||||
'http://localhost:5173',
|
|
||||||
'https://craze-data-check.vercel.app',
|
|
||||||
];
|
|
||||||
|
|
||||||
function setCors(req, res) {
|
function setCors(req, res) {
|
||||||
const origin = req.headers.origin;
|
applyCors(req, res, 'POST, OPTIONS');
|
||||||
if (origin && ALLOWED_ORIGINS.includes(origin)) {
|
|
||||||
res.setHeader('Access-Control-Allow-Origin', origin);
|
|
||||||
}
|
|
||||||
res.setHeader('Access-Control-Allow-Methods', 'POST, OPTIONS');
|
|
||||||
res.setHeader('Access-Control-Allow-Headers', 'Content-Type');
|
|
||||||
res.setHeader('Vary', 'Origin');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
export default async function handler(req, res) {
|
export default async function handler(req, res) {
|
||||||
@@ -24,7 +12,7 @@ export default async function handler(req, res) {
|
|||||||
if (req.method === 'OPTIONS') return res.status(204).end();
|
if (req.method === 'OPTIONS') return res.status(204).end();
|
||||||
|
|
||||||
const origin = req.headers.origin;
|
const origin = req.headers.origin;
|
||||||
if (origin && !ALLOWED_ORIGINS.includes(origin)) {
|
if (origin && !isAllowedOrigin(origin)) {
|
||||||
return res.status(403).json({ error: 'Forbidden' });
|
return res.status(403).json({ error: 'Forbidden' });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+14
-13
@@ -1,17 +1,15 @@
|
|||||||
|
import { applyCors, isAllowedOrigin } from './_cors.js';
|
||||||
|
|
||||||
const DROPBOX_APP_KEY = process.env.DROPBOX_APP_KEY;
|
const DROPBOX_APP_KEY = process.env.DROPBOX_APP_KEY;
|
||||||
const DROPBOX_APP_SECRET = process.env.DROPBOX_APP_SECRET;
|
const DROPBOX_APP_SECRET = process.env.DROPBOX_APP_SECRET;
|
||||||
const DROPBOX_REFRESH_TOKEN = process.env.DROPBOX_REFRESH_TOKEN;
|
const DROPBOX_REFRESH_TOKEN = process.env.DROPBOX_REFRESH_TOKEN;
|
||||||
|
const DROPBOX_SHARED_URL =
|
||||||
const ALLOWED_ORIGIN = 'https://craze-data-check.vercel.app';
|
process.env.DROPBOX_SHARED_URL ||
|
||||||
|
process.env.DROPBOX_FILE_URL ||
|
||||||
|
'https://www.dropbox.com/scl/fi/usa8me7ywgylrij2bt6hj/Data-Matrix.xlsx?rlkey=tsec8csrhye54u1fdvk15ped1&dl=1';
|
||||||
|
|
||||||
function setCors(req, res) {
|
function setCors(req, res) {
|
||||||
const origin = req.headers.origin;
|
applyCors(req, res, 'GET, OPTIONS');
|
||||||
if (origin === ALLOWED_ORIGIN) {
|
|
||||||
res.setHeader('Access-Control-Allow-Origin', ALLOWED_ORIGIN);
|
|
||||||
}
|
|
||||||
res.setHeader('Access-Control-Allow-Methods', 'GET, OPTIONS');
|
|
||||||
res.setHeader('Access-Control-Allow-Headers', 'Content-Type');
|
|
||||||
res.setHeader('Vary', 'Origin');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
async function getAccessToken() {
|
async function getAccessToken() {
|
||||||
@@ -40,7 +38,7 @@ export default async function handler(req, res) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
const origin = req.headers.origin;
|
const origin = req.headers.origin;
|
||||||
if (origin && origin !== ALLOWED_ORIGIN) {
|
if (origin && !isAllowedOrigin(origin)) {
|
||||||
return res.status(403).json({ error: 'Forbidden' });
|
return res.status(403).json({ error: 'Forbidden' });
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -58,8 +56,7 @@ export default async function handler(req, res) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const sharingUrl = 'https://www.dropbox.com/scl/fi/usa8me7ywgylrij2bt6hj/Data-Matrix.xlsx?rlkey=tsec8csrhye54u1fdvk15ped1&dl=1';
|
const upstream = await fetch(DROPBOX_SHARED_URL, {
|
||||||
const upstream = await fetch(sharingUrl, {
|
|
||||||
method: 'GET',
|
method: 'GET',
|
||||||
headers: {
|
headers: {
|
||||||
'Cache-Control': 'no-cache',
|
'Cache-Control': 'no-cache',
|
||||||
@@ -76,7 +73,11 @@ export default async function handler(req, res) {
|
|||||||
if (!upstream.ok) {
|
if (!upstream.ok) {
|
||||||
const errText = await upstream.text();
|
const errText = await upstream.text();
|
||||||
console.error('Dropbox URL error:', upstream.status, errText);
|
console.error('Dropbox URL error:', upstream.status, errText);
|
||||||
return res.status(upstream.status).send('Dropbox error: ' + errText);
|
return res.status(upstream.status).send(
|
||||||
|
'Dropbox error: ' +
|
||||||
|
errText +
|
||||||
|
'\n\nSet DROPBOX_SHARED_URL in Vercel if the sharing link changed.'
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
const buffer = await upstream.arrayBuffer();
|
const buffer = await upstream.arrayBuffer();
|
||||||
|
|||||||
+3
-9
@@ -1,19 +1,13 @@
|
|||||||
|
import { applyCors, isAllowedOrigin } from './_cors.js';
|
||||||
import { createClient } from '@supabase/supabase-js';
|
import { createClient } from '@supabase/supabase-js';
|
||||||
|
|
||||||
const SUPABASE_URL = process.env.SUPABASE_URL || 'https://hwithddwaapyhnfwcesj.supabase.co';
|
const SUPABASE_URL = process.env.SUPABASE_URL || 'https://hwithddwaapyhnfwcesj.supabase.co';
|
||||||
const SUPABASE_KEY = process.env.SUPABASE_SERVICE_KEY || 'sb_publishable_fGXkh0bSrAOqSk2jWKAzSg_NJD9YPCv';
|
const SUPABASE_KEY = process.env.SUPABASE_SERVICE_KEY || 'sb_publishable_fGXkh0bSrAOqSk2jWKAzSg_NJD9YPCv';
|
||||||
const ALLOWED_ORIGIN = 'https://craze-data-check.vercel.app';
|
|
||||||
|
|
||||||
const supabase = createClient(SUPABASE_URL, SUPABASE_KEY);
|
const supabase = createClient(SUPABASE_URL, SUPABASE_KEY);
|
||||||
|
|
||||||
function setCors(req, res) {
|
function setCors(req, res) {
|
||||||
const origin = req.headers.origin;
|
applyCors(req, res, 'POST, OPTIONS');
|
||||||
if (origin === ALLOWED_ORIGIN) {
|
|
||||||
res.setHeader('Access-Control-Allow-Origin', ALLOWED_ORIGIN);
|
|
||||||
}
|
|
||||||
res.setHeader('Access-Control-Allow-Methods', 'POST, OPTIONS');
|
|
||||||
res.setHeader('Access-Control-Allow-Headers', 'Content-Type');
|
|
||||||
res.setHeader('Vary', 'Origin');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
export default async function handler(req, res) {
|
export default async function handler(req, res) {
|
||||||
@@ -24,7 +18,7 @@ export default async function handler(req, res) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
const origin = req.headers.origin;
|
const origin = req.headers.origin;
|
||||||
if (origin && origin !== ALLOWED_ORIGIN) {
|
if (origin && !isAllowedOrigin(origin)) {
|
||||||
return res.status(403).json({ error: 'Forbidden' });
|
return res.status(403).json({ error: 'Forbidden' });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+8
-9
@@ -1,7 +1,8 @@
|
|||||||
|
import { applyCors, isAllowedOrigin } from './_cors.js';
|
||||||
|
|
||||||
const SUPABASE_URL = process.env.SUPABASE_URL || 'https://hwithddwaapyhnfwcesj.supabase.co';
|
const SUPABASE_URL = process.env.SUPABASE_URL || 'https://hwithddwaapyhnfwcesj.supabase.co';
|
||||||
const SUPABASE_SERVICE_KEY = process.env.SUPABASE_SERVICE_KEY;
|
const SUPABASE_SERVICE_KEY = process.env.SUPABASE_SERVICE_KEY;
|
||||||
const SUPABASE_ANON_KEY = 'sb_publishable_fGXkh0bSrAOqSk2jWKAzSg_NJD9YPCv';
|
const SUPABASE_ANON_KEY = 'sb_publishable_fGXkh0bSrAOqSk2jWKAzSg_NJD9YPCv';
|
||||||
const ALLOWED_ORIGIN = 'https://craze-data-check.vercel.app';
|
|
||||||
|
|
||||||
const MASTER_USERS = new Set([
|
const MASTER_USERS = new Set([
|
||||||
'christian.vidal@craze-group.com',
|
'christian.vidal@craze-group.com',
|
||||||
@@ -9,14 +10,7 @@ const MASTER_USERS = new Set([
|
|||||||
]);
|
]);
|
||||||
|
|
||||||
function setCors(req, res) {
|
function setCors(req, res) {
|
||||||
const origin = req.headers.origin;
|
applyCors(req, res, 'POST, OPTIONS');
|
||||||
if (origin === ALLOWED_ORIGIN || (origin && (origin.startsWith('http://localhost:') || origin.startsWith('http://127.0.0.1:')))) {
|
|
||||||
res.setHeader('Access-Control-Allow-Origin', origin);
|
|
||||||
}
|
|
||||||
res.setHeader('Access-Control-Allow-Methods', 'POST, OPTIONS');
|
|
||||||
res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization, apikey');
|
|
||||||
res.setHeader('Access-Control-Max-Age', '86400');
|
|
||||||
res.setHeader('Vary', 'Origin');
|
|
||||||
}
|
}
|
||||||
|
|
||||||
export default async function handler(req, res) {
|
export default async function handler(req, res) {
|
||||||
@@ -26,6 +20,11 @@ export default async function handler(req, res) {
|
|||||||
return res.status(204).end();
|
return res.status(204).end();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const origin = req.headers.origin;
|
||||||
|
if (origin && !isAllowedOrigin(origin)) {
|
||||||
|
return res.status(403).json({ error: 'Forbidden' });
|
||||||
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
if (req.method !== 'POST') {
|
if (req.method !== 'POST') {
|
||||||
return res.status(405).json({ error: 'Method not allowed' });
|
return res.status(405).json({ error: 'Method not allowed' });
|
||||||
|
|||||||
Reference in New Issue
Block a user