import { applyCors, isAllowedOrigin } from './_cors.js'; const DEFAULT_DROPBOX_SHARED_URL = 'https://www.dropbox.com/scl/fi/usa8me7ywgylrij2bt6hj/Data-Matrix.xlsx?rlkey=tsec8csrhye54u1fdvk15ped1&st=qbxxs4cn&dl=0'; function getDropboxConfig() { return { appKey: process.env.DROPBOX_APP_KEY, appSecret: process.env.DROPBOX_APP_SECRET, refreshToken: process.env.DROPBOX_REFRESH_TOKEN, sharedUrl: process.env.DROPBOX_SHARED_URL || DEFAULT_DROPBOX_SHARED_URL, }; } function normalizeDropboxSharedUrl(sharedUrl) { const url = new URL(sharedUrl); url.searchParams.delete('dl'); url.searchParams.delete('raw'); url.searchParams.delete('st'); return url.toString(); } function buildDropboxDownloadUrl(sharedUrl) { const url = new URL(normalizeDropboxSharedUrl(sharedUrl)); url.searchParams.set('raw', '1'); return url.toString(); } function setCors(req, res) { applyCors(req, res, 'GET, OPTIONS'); } async function getAccessToken() { const { appKey, appSecret, refreshToken } = getDropboxConfig(); if (!appKey || !appSecret || !refreshToken) { throw new Error('Dropbox auth env vars are not configured.'); } const response = await fetch('https://api.dropboxapi.com/oauth2/token', { method: 'POST', headers: { 'Content-Type': 'application/x-www-form-urlencoded' }, body: new URLSearchParams({ grant_type: 'refresh_token', refresh_token: refreshToken, client_id: appKey, client_secret: appSecret, }) }); const data = await response.json(); if (!data.access_token) { throw new Error('Failed to get access token: ' + JSON.stringify(data)); } return data.access_token; } export default async function handler(req, res) { setCors(req, res); if (req.method === 'OPTIONS') { return res.status(204).end(); } const origin = req.headers.origin; if (origin && !isAllowedOrigin(origin)) { return res.status(403).json({ error: 'Forbidden' }); } if (req.method === 'GET' && req.query.info === '1') { res.setHeader('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate'); res.setHeader('Pragma', 'no-cache'); res.setHeader('Expires', '0'); return res.json({ rev: 'new-url-v1', size: 0, server_modified: new Date().toISOString() }); } const { sharedUrl } = getDropboxConfig(); const sharingUrlForApi = normalizeDropboxSharedUrl(sharedUrl); const downloadUrl = buildDropboxDownloadUrl(sharedUrl); // Try authenticated Dropbox API first — bypasses CDN cache so we always get the latest version. // Falls back to the shared URL if credentials are not configured. let upstream = null; let usedAuth = false; try { const accessToken = await getAccessToken(); const apiRes = await fetch('https://content.dropboxapi.com/2/sharing/get_shared_link_file', { method: 'POST', headers: { 'Authorization': `Bearer ${accessToken}`, 'Dropbox-API-Arg': JSON.stringify({ url: sharingUrlForApi }), 'Content-Type': 'text/plain; charset=utf-8', }, }); if (apiRes.ok) { upstream = apiRes; usedAuth = true; console.log('Dropbox: downloaded via authenticated API (no CDN cache)'); } else { const errText = await apiRes.text(); console.warn('Dropbox API download failed, falling back to sharing link:', apiRes.status, errText.substring(0, 200)); } } catch (authErr) { console.warn('Dropbox auth unavailable, falling back to sharing link:', authErr?.message || String(authErr)); } try { if (!upstream) { upstream = await fetch(downloadUrl, { method: 'GET', headers: { 'Cache-Control': 'no-cache', 'Pragma': 'no-cache', 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36' } }); } const contentType = upstream.headers.get('content-type'); if (!usedAuth && contentType && contentType.includes('text/html')) { console.error('Dropbox returned HTML instead of file'); return res.status(500).send('Error: El enlace de Dropbox ha devuelto una página HTML en lugar del archivo. Es probable que el enlace haya caducado o necesite ser renovado.'); } if (!upstream.ok) { const errText = await upstream.text(); console.error('Dropbox URL error:', upstream.status, errText); return res.status(upstream.status).send( 'Dropbox error: ' + errText + '\n\nSet DROPBOX_SHARED_URL in Vercel if the sharing link changed.' ); } const buffer = await upstream.arrayBuffer(); res.setHeader('Content-Type', 'application/octet-stream'); res.setHeader('Cache-Control', 'no-store'); res.send(Buffer.from(buffer)); } catch (err) { console.error('Dropbox proxy error:', err); res.status(500).send('Proxy error: ' + (err?.message || String(err))); } }