From 048f3cfb9bedbb17bd6aea2d6d3c235150cda12c Mon Sep 17 00:00:00 2001 From: Miguel Risco-Castillo Date: Wed, 16 Sep 2026 20:58:35 -0500 Subject: [PATCH 1/5] Update index.ts Change deno imports due to the error: TypeError: Relative import path "@std/dotenv/load" not prefixed with / or ./ or ../ at file:///var/task/api/index.ts:5:8 at async processEvents (file:///vercel/path0/.vercel/builders/node_modules/vercel-deno/dist/runtime.ts:81:17) { code: "ERR_MODULE_NOT_FOUND" } --- api/index.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/api/index.ts b/api/index.ts index 8ad6aa0b..a3663b81 100644 --- a/api/index.ts +++ b/api/index.ts @@ -2,7 +2,7 @@ import { Card } from "../src/card.ts"; import { CONSTANTS, parseParams } from "../src/utils.ts"; import { COLORS, Theme } from "../src/theme.ts"; import { Error400 } from "../src/error_page.ts"; -import "@std/dotenv/load"; +import "https://deno.land/std@0.224.0/dotenv/load.ts"; import { staticRenderRegeneration } from "../src/StaticRenderRegeneration/index.ts"; import { GithubRepositoryService } from "../src/Repository/GithubRepository.ts"; import { GithubApiService } from "../src/Services/GithubApiService.ts"; From acf401f7843636cab49e2b1e1f261aa6e30e76bc Mon Sep 17 00:00:00 2001 From: Miguel Risco-Castillo Date: Wed, 16 Sep 2026 21:19:24 -0500 Subject: [PATCH 2/5] Update index.ts Access is restricted to authorised users only. --- api/index.ts | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/api/index.ts b/api/index.ts index a3663b81..fcee5cda 100644 --- a/api/index.ts +++ b/api/index.ts @@ -39,6 +39,19 @@ export default (request: Request) => async function app(req: Request): Promise { const params = parseParams(req); const username = params.get("username"); + + // 🔒 Validación de usuario permitido + const allowedUser = "mriscoc"; + if (username !== allowedUser) { + return new Response("Usuario no autorizado", { + status: 403, + headers: new Headers({ + "Content-Type": "text/plain", + "Cache-Control": cacheControlHeader, + }), + }); + } + const row = params.getNumberValue("row", CONSTANTS.DEFAULT_MAX_ROW); const column = params.getNumberValue("column", CONSTANTS.DEFAULT_MAX_COLUMN); const themeParam: string = params.getStringValue("theme", "default"); From 1c2e953c534cffdf0310a6cba535493175b31629 Mon Sep 17 00:00:00 2001 From: Miguel Risco-Castillo Date: Wed, 16 Sep 2026 21:23:25 -0500 Subject: [PATCH 3/5] Create allowedUsers.ts List of allowed users --- api/allowedUsers.ts | 1 + 1 file changed, 1 insertion(+) create mode 100644 api/allowedUsers.ts diff --git a/api/allowedUsers.ts b/api/allowedUsers.ts new file mode 100644 index 00000000..c49e9c70 --- /dev/null +++ b/api/allowedUsers.ts @@ -0,0 +1 @@ +export const allowedUsers = ["mriscoc", "otroUsuario"]; From ffcfd5a53479328ea1eac815a294d7b1686cac6f Mon Sep 17 00:00:00 2001 From: Miguel Risco-Castillo Date: Wed, 16 Sep 2026 21:34:34 -0500 Subject: [PATCH 4/5] Update index.ts for use allowedUsers.ts Accepts a list of valid users registered in allowedUsers.ts --- api/index.ts | 23 ++++++++++++----------- 1 file changed, 12 insertions(+), 11 deletions(-) diff --git a/api/index.ts b/api/index.ts index fcee5cda..61a7e2a8 100644 --- a/api/index.ts +++ b/api/index.ts @@ -9,6 +9,7 @@ import { GithubApiService } from "../src/Services/GithubApiService.ts"; import { ServiceError } from "../src/Types/index.ts"; import { ErrorPage } from "../src/pages/Error.ts"; import { cacheProvider } from "../src/config/cache.ts"; +import { allowedUsers } from "../src/config/allowedUsers.ts"; const serviceProvider = new GithubApiService(); const client = new GithubRepositoryService(serviceProvider).repository; @@ -40,17 +41,17 @@ async function app(req: Request): Promise { const params = parseParams(req); const username = params.get("username"); - // 🔒 Validación de usuario permitido - const allowedUser = "mriscoc"; - if (username !== allowedUser) { - return new Response("Usuario no autorizado", { - status: 403, - headers: new Headers({ - "Content-Type": "text/plain", - "Cache-Control": cacheControlHeader, - }), - }); - } +// 🔒 Allowed users validation +if (username !== null && !allowedUsers.includes(username)) { + return new Response("Unauthorized user", { + status: 403, + headers: new Headers({ + "Content-Type": "text/plain", + "Cache-Control": cacheControlHeader, + }), + }); +} + const row = params.getNumberValue("row", CONSTANTS.DEFAULT_MAX_ROW); const column = params.getNumberValue("column", CONSTANTS.DEFAULT_MAX_COLUMN); From f0a97615c4e2d967943d4f5c968e3bbbbb4ce29e Mon Sep 17 00:00:00 2001 From: Miguel Risco-Castillo Date: Wed, 16 Sep 2026 21:36:25 -0500 Subject: [PATCH 5/5] Update index.ts --- api/index.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/api/index.ts b/api/index.ts index 61a7e2a8..140571ee 100644 --- a/api/index.ts +++ b/api/index.ts @@ -9,7 +9,7 @@ import { GithubApiService } from "../src/Services/GithubApiService.ts"; import { ServiceError } from "../src/Types/index.ts"; import { ErrorPage } from "../src/pages/Error.ts"; import { cacheProvider } from "../src/config/cache.ts"; -import { allowedUsers } from "../src/config/allowedUsers.ts"; +import { allowedUsers } from "./allowedUsers.ts"; const serviceProvider = new GithubApiService(); const client = new GithubRepositoryService(serviceProvider).repository;