fix(import): refuse a Bokio connection that opens a different company (#1315)

A Bokio integration token is scoped to one Bokio company and the company id is typed in by hand, so credentials for the user's other company imported that company's customers, suppliers and invoices with no error at all. Probe /companies/{id} before storing, mirroring the Bjorn Lunden /details probe, and refuse on a confident org-number mismatch.

Also surface the inbox mail body when nothing was attached: it was captured in email_body_text and never read back, which made Gmail's forwarding-confirmation mail unreadable and the forward impossible to complete.
This commit is contained in:
Jakob Wennberg
2026-07-30 19:07:40 +02:00
committed by GitHub
parent 27ae59040e
commit 0f1c7c9365
9 changed files with 311 additions and 5 deletions
+11
View File
@@ -1813,6 +1813,17 @@ const PROVIDER_MIGRATION: Record<string, StructuredErrorEntry> = {
message_en:
'The provider rejected the credentials. Check that the account ID and application token are correct and try again.',
},
PROVIDER_COMPANY_MISMATCH: {
// 422, same reasoning as PROVIDER_TOKEN_INVALID: the credentials are valid,
// but they open a DIFFERENT legal entity than the one being imported into.
// Importing anyway mixes another company's ledger into this one, which is
// both a bookkeeping and a data-protection problem: refuse at the boundary.
httpStatus: 422,
message_sv:
'Uppgifterna gäller ett annat företag än det du importerar till. Kontrollera att du valt rätt företag hos leverantören och försök igen.',
message_en:
'These credentials belong to a different company than the one you are importing into. Check that you picked the right company at the provider and try again.',
},
PROVIDER_PREVIEW_FAILED: {
httpStatus: 500,
message_sv: 'Förhandsgranskningen från leverantören misslyckades.',