Commit Graph
5 Commits
Author SHA1 Message Date
Christian Vidal WolfandClaude Sonnet 4.6 e0484354b9 Security: Add HTTP security headers via vercel.json
Adds HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy,
and Permissions-Policy to all responses. CSP allowlist includes only
Supabase and Dropbox as external connect targets.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-23 10:04:33 +02:00
Christian Vidal Wolf 90e60017da feat: sync Excel data to Supabase on load - detect new Dropbox files automatically 2026-04-10 10:54:50 +02:00
christian.vidal 92f6ccb7b5 fix(vercel): simplify vercel.json to resolve runtime version error 2026-03-27 13:34:21 +01:00
christian.vidal 750e25db89 feat: show EOL not neccessary for OOC products with 0 stock 2026-03-27 13:26:16 +01:00
christian.vidalandClaude Sonnet 4.6 d6a2efaf7d fix(fetch): use Vite proxy + Vercel rewrites for reliable Dropbox loading
Replace unreliable third-party CORS proxies (allorigins, cors-anywhere,
thingproxy) with a local /dropbox-file route proxied server-side:
- vite.config.ts: add dev server proxy for /dropbox-file -> dl.dropboxusercontent.com
- vercel.json: add rewrite rule for the same route in production
- App.tsx: simplify fetch logic to use single reliable proxy path

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-27 12:28:30 +01:00