Files
worldmonitor/api/hackernews.js
Elie Habib f7119b9ed6 Harden CORS, XSS, and input validation across all API endpoints and components
- Add CORS origin allowlist (api/_cors.js) replacing Access-Control-Allow-Origin: *
- Add isDisallowedOrigin guard to all API endpoints (acled, cloudflare-outages, finnhub, fred-data, hackernews, wingbits)
- Gut debug-env endpoint to return 404
- Tighten sanitizeUrl() with escapeAttr output and strict relative URL validation
- Add sanitizeUrl() adoption in CountryIntelModal, InsightsPanel, PredictionPanel, RegulationPanel, TechEventsPanel
- Comprehensive escapeHtml() hardening in MapPopup (cables, flights, vessels, clusters)
- Bound HackerNews concurrent fetches (MAX_CONCURRENCY=10), validate story type and limit params
- Add wingbits cache eviction (MAX_LOCAL_CACHE_ENTRIES=2000, sweep on TTL + LRU)
- Fix arxiv http→https, og-story parseInt safety with Number.isFinite + clamping
2026-02-11 14:35:07 +04:00

93 lines
2.9 KiB
JavaScript

export const config = { runtime: 'edge' };
// Fetch Hacker News front page stories
// Uses official HackerNews Firebase API
const ALLOWED_STORY_TYPES = new Set(['top', 'new', 'best', 'ask', 'show', 'job']);
const DEFAULT_LIMIT = 30;
const MAX_LIMIT = 60;
const MAX_CONCURRENCY = 10;
function parseLimit(rawLimit) {
const parsed = Number.parseInt(rawLimit || '', 10);
if (!Number.isFinite(parsed)) return DEFAULT_LIMIT;
return Math.max(1, Math.min(MAX_LIMIT, parsed));
}
export default async function handler(request) {
try {
const { searchParams } = new URL(request.url);
const requestedType = searchParams.get('type') || 'top';
const storyType = ALLOWED_STORY_TYPES.has(requestedType) ? requestedType : 'top';
const limit = parseLimit(searchParams.get('limit'));
// HackerNews official Firebase API
const storiesUrl = `https://hacker-news.firebaseio.com/v0/${storyType}stories.json`;
// Fetch story IDs
const storiesResponse = await fetch(storiesUrl, {
signal: AbortSignal.timeout(10000),
});
if (!storiesResponse.ok) {
throw new Error(`HackerNews API returned ${storiesResponse.status}`);
}
const storyIds = await storiesResponse.json();
if (!Array.isArray(storyIds)) {
throw new Error('HackerNews API returned unexpected payload');
}
const limitedIds = storyIds.slice(0, limit);
// Fetch story details in bounded batches to avoid unbounded fan-out.
const stories = [];
for (let i = 0; i < limitedIds.length; i += MAX_CONCURRENCY) {
const batchIds = limitedIds.slice(i, i + MAX_CONCURRENCY);
const storyPromises = batchIds.map(async (id) => {
const storyUrl = `https://hacker-news.firebaseio.com/v0/item/${id}.json`;
try {
const response = await fetch(storyUrl, {
signal: AbortSignal.timeout(5000),
});
if (response.ok) {
return await response.json();
}
return null;
} catch (error) {
console.error(`Failed to fetch story ${id}:`, error);
return null;
}
});
const batchResults = await Promise.all(storyPromises);
stories.push(...batchResults.filter((story) => story !== null));
}
return new Response(JSON.stringify({
type: storyType,
stories: stories,
total: stories.length,
timestamp: new Date().toISOString()
}), {
status: 200,
headers: {
'Content-Type': 'application/json',
'Access-Control-Allow-Origin': '*',
'Cache-Control': 'public, max-age=300', // 5 min cache
},
});
} catch (error) {
return new Response(
JSON.stringify({
error: 'Failed to fetch Hacker News data',
message: error.message
}),
{
status: 500,
headers: {
'Content-Type': 'application/json',
'Access-Control-Allow-Origin': '*'
},
}
);
}
}