fix: P1 API security hardening — rate limits, auth guards, duplicate prevention
- verify/route.ts: setDate → setUTCDate to avoid timezone off-by-one on recheck date - triage-suggest, rca-draft, quality-check: 60s per-user rate limit via audit_log - quality-check: add write_audit_log (was missing, CLAUDE.md violation) - investigation POST: 409 if investigation already exists for incident - incidents POST: 60s per-user rate limit via audit_log - addenda GET: restrict to hse/admin/supervisor roles - dashboard/stats GET: restrict to hse/admin/management roles Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CPf5Rc8QPx6V8KLEEgfKEQ
This commit is contained in:
@@ -24,6 +24,13 @@ export async function POST(
|
||||
if (incident.status !== 'triaged')
|
||||
return NextResponse.json({ error: 'Incident must be triaged first' }, { status: 409 })
|
||||
|
||||
const { count: existingCount } = await supabase
|
||||
.from('investigations')
|
||||
.select('id', { count: 'exact', head: true })
|
||||
.eq('incident_id', id)
|
||||
if ((existingCount ?? 0) > 0)
|
||||
return NextResponse.json({ error: 'Investigation already exists for this incident' }, { status: 409 })
|
||||
|
||||
const body = await request.json()
|
||||
const method: 'five_why' | 'fishbone' | 'other' = body.method ?? 'five_why'
|
||||
|
||||
|
||||
Reference in New Issue
Block a user