Close the second leak path: /api/hero-prop bypassed the snapshot gate

The landing hero reads the snapshot from Redis DIRECTLY via heroPropService,
so it never passed through routes/snapshot.js and was still serving model_odds,
ev_pct, value and takeable to anonymous visitors after the first fix. Same
strip, same tier resolution, same private-cache rule for authenticated callers;
the Next proxy now forwards the bearer token.

PRODUCT CONSEQUENCE, FLAGGED RATHER THAN BURIED: the landing hero is served to
anonymous visitors, so it now renders BOOK and FAIR with the model leg LOCKED
instead of the full triplet it showed this morning. That follows the stated
free-tier rule exactly, but it does trade a strong marketing moment (VALUE
+21.1% VS FAIR on the shop window) for consistency of the gate. Reversing is
one line — add 'model_price' to the free tier in src/config/tiers.js, or
special-case the hero route — and is a product call, not a correctness one.

Tests 3557 passed / 291 suites, web build exit 0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VCNgGSt5qvcLxaeQqa7Zpj
This commit is contained in:
Kev
2026-07-20 19:52:00 -04:00
parent fbcb00b7b1
commit aaa41134d4
4 changed files with 23 additions and 5 deletions
+1 -1
View File
File diff suppressed because one or more lines are too long
+2 -2
View File
@@ -12,11 +12,11 @@ const BACKEND_URL = process.env.BACKEND_URL || 'http://localhost:3000';
* { available: false } so the card HIDES; there is NO hand-written fallback
* (the old static Jokic card is gone).
*/
export async function GET() {
export async function GET(req: Request) {
try {
const upstream = await fetch(`${BACKEND_URL}/api/hero-prop`, {
method: 'GET',
headers: { Accept: 'application/json' },
headers: { Accept: 'application/json', ...(req.headers.get('authorization') ? { Authorization: req.headers.get('authorization')! } : {}) },
cache: 'no-store',
});
const data = await upstream.json().catch(() => ({ available: false }));