Commit Graph

3 Commits

Author SHA1 Message Date
MBO-Tech-IT a26cc3f8f2 fix: use rightmost X-Forwarded-For entry and add per-email rate-limit dimension
Fixes an XFF-spoofing bypass of the flyer rate limiter (leftmost entry is
attacker-controlled, not proxy-verified) and adds a second rate-limit
dimension keyed on the submitted email so spamming one address still gets
blocked even if IP-based limiting is ever defeated. Also bounds the
in-memory rate-limit Map via a call-count-triggered sweep.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LhY1QhDXGWfyhrxaJvfpNt
2026-07-21 14:21:34 +02:00
MBO-Tech-IT 60af2e1621 fix: add IP rate limiting and guard non-string email in flyer route
Adds an in-memory, IP-based fixed-window rate limit (max 3 req/hour)
to app/api/familyguard-flyer/route.ts to mitigate an email-spam/abuse
vector where any client could trigger outbound emails and DB inserts
with no limit. Also guards against a non-string `email` field in the
request body, which previously threw an uncaught TypeError (HTTP 500)
instead of the intended 400 validation response.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LhY1QhDXGWfyhrxaJvfpNt
2026-07-21 14:12:50 +02:00
MBO-Tech-IT 7c04450b57 feat: add API route for FamilyGuard flyer email-gate download
Creates POST /api/familyguard-flyer endpoint that validates email format
and DSGVO consent, records download intent in Supabase flyer_downloads table,
and sends notification and download link emails (fire-and-forget) before
returning the flyer download URL.

Implements Task 4 of 7-task email-gated flyer download feature.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LhY1QhDXGWfyhrxaJvfpNt
2026-07-21 11:36:37 +02:00