fix: P1 API security hardening — rate limits, auth guards, duplicate prevention
- verify/route.ts: setDate → setUTCDate to avoid timezone off-by-one on recheck date - triage-suggest, rca-draft, quality-check: 60s per-user rate limit via audit_log - quality-check: add write_audit_log (was missing, CLAUDE.md violation) - investigation POST: 409 if investigation already exists for incident - incidents POST: 60s per-user rate limit via audit_log - addenda GET: restrict to hse/admin/supervisor roles - dashboard/stats GET: restrict to hse/admin/management roles Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CPf5Rc8QPx6V8KLEEgfKEQ
This commit is contained in:
@@ -31,7 +31,7 @@ export async function POST(
|
||||
|
||||
const verifiedAt = new Date()
|
||||
const recheckDate = new Date(verifiedAt)
|
||||
recheckDate.setDate(recheckDate.getDate() + 30)
|
||||
recheckDate.setUTCDate(recheckDate.getUTCDate() + 30)
|
||||
|
||||
const update: Record<string, unknown> = {
|
||||
status: body.verdict,
|
||||
|
||||
Reference in New Issue
Block a user