Sandbox (#8)
* feat: add sandbox infrastructure — migration, types, and middleware Add database migration for sandbox support: - Add `is_sandbox` boolean column to company_settings - Update 4 enforcement trigger functions (journal entry immutability, journal entry line immutability, retention enforcement, document deletion blocking) to bypass checks for sandbox users - Add `cleanup_sandbox_user()` SECURITY DEFINER function that handles FK-safe deletion order (document_attachments → journal_entry_lines → journal_entries → supplier_invoices → auth.users cascade) - Add `cleanup_expired_sandbox_users()` function that loops over sandbox users older than N hours with per-user error handling Update TypeScript types: - Add `is_sandbox: boolean` to CompanySettings interface - Add `is_sandbox: false` to makeCompanySettings() test factory Update middleware: - Add `/sandbox` to public routes so the landing page is accessible without authentication Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: add sandbox landing page, seed API, cleanup cron, and banner Sandbox landing page (app/sandbox/page.tsx): - Client component matching the existing auth page aesthetic - Auth check: if logged in as real user, shows message to use incognito - Otherwise shows feature overview (invoices, transactions, bookkeeping, reports) with "Starta sandbox" button - On click: signInAnonymously() → POST /api/sandbox/seed → redirect - Uses window.location.href for full page load (ensures middleware picks up new session cookies) Seed API (app/api/sandbox/seed/route.ts): - POST handler gated to anonymous users only (403 for real users) - Idempotent: returns { seeded: false } if company_settings exists - Seeds ~40 rows: profile, company_settings (is_sandbox: true, onboarding_complete: true), chart of accounts (via RPC), fiscal period, 3 customers (Swedish business, EU business, individual), 4 invoices (paid/sent/overdue/draft), 4 invoice items, 2 posted journal entries with 5 lines, 8 transactions (3 categorized, 2 income, 3 uncategorized), 2 deadlines - Journal entries inserted directly (not via engine) to avoid event emission, using next_voucher_number() RPC Cleanup cron (app/api/sandbox/cleanup/cron/route.ts): - GET handler with CRON_SECRET Bearer token auth - Creates service role Supabase client - Calls cleanup_expired_sandbox_users RPC (24h default) Sandbox banner (components/dashboard/SandboxBanner.tsx): - Amber bar with dismiss button (client state, reappears on reload) - Text: "Sandlådemiljö — dina data raderas automatiskt efter 24 timmar" - "Skapa konto" link to /register Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat: integrate sandbox into dashboard — banner, nav, settings safeguards Dashboard layout (app/(dashboard)/layout.tsx): - Fetch is_sandbox from company_settings - Render SandboxBanner at top of page for sandbox users - Pass isSandbox prop to DashboardNav - Hide RecaptIdentify analytics for sandbox users Root page (app/page.tsx): - Same sandbox banner and isSandbox prop treatment as dashboard layout (root page has its own layout, not wrapped by (dashboard)/layout) DashboardNav (components/dashboard/DashboardNav.tsx): - Add optional isSandbox prop - Change logout button text to "Avsluta sandbox" when isSandbox - Redirect to /sandbox instead of /login on logout for sandbox users - Applied to both desktop sidebar and mobile drawer logout buttons Settings page (app/(dashboard)/settings/page.tsx): - Hide "Bank (PSD2)" tab entirely for sandbox users — prevents connecting real bank accounts from a temporary anonymous session - Hide "Radera konto" card for sandbox users — account auto-deletes via cron, and the delete flow requires email confirmation Vercel config (vercel.json): - Add sandbox cleanup cron at 04:00 UTC daily (/api/sandbox/cleanup/cron) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: remove audit trigger for non-existent tax_codes table Migration 018 referenced public.tax_codes which was never created (migration 012 is a placeholder). This caused failures when running migrations from scratch on a fresh database. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: remove ALTER FUNCTION for 3 non-existent functions Removed search_path pinning for create_invoice_with_items, seed_asset_categories, and update_reconciliation_session_counts — none of these functions were ever created in any migration. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: remove ALTER for generate_invoice_number (created in later migration) The function is created in migration 20260306 with search_path already set, but migration 20260304 tried to ALTER it before it existed. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * Fixed redirect issue * Update app/api/sandbox/seed/route.ts Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com> * Update app/api/sandbox/seed/route.ts Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com> * Update app/sandbox/page.tsx Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com> * Fixed catch block issue --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
greptile-apps[bot]
parent
d696e0282b
commit
109f860e22
@@ -110,7 +110,4 @@ CREATE TRIGGER audit_company_settings
|
||||
AFTER INSERT OR UPDATE OR DELETE ON public.company_settings
|
||||
FOR EACH ROW EXECUTE FUNCTION public.write_audit_log();
|
||||
|
||||
-- tax_codes
|
||||
CREATE TRIGGER audit_tax_codes
|
||||
AFTER INSERT OR UPDATE OR DELETE ON public.tax_codes
|
||||
FOR EACH ROW EXECUTE FUNCTION public.write_audit_log();
|
||||
-- tax_codes trigger removed: table never created (migration 012 is a placeholder)
|
||||
|
||||
@@ -6,7 +6,7 @@ ALTER FUNCTION public.audit_log_immutable() SET search_path = public;
|
||||
ALTER FUNCTION public.block_document_deletion() SET search_path = public;
|
||||
ALTER FUNCTION public.calculate_retention_expiry() SET search_path = public;
|
||||
ALTER FUNCTION public.check_journal_entry_balance() SET search_path = public;
|
||||
ALTER FUNCTION public.create_invoice_with_items(p_invoice jsonb, p_items jsonb) SET search_path = public;
|
||||
-- create_invoice_with_items removed: function was never created
|
||||
ALTER FUNCTION public.detect_voucher_gaps(p_user_id uuid, p_fiscal_period_id uuid, p_series text) SET search_path = public;
|
||||
ALTER FUNCTION public.enforce_journal_entry_immutability() SET search_path = public;
|
||||
ALTER FUNCTION public.enforce_journal_entry_line_immutability() SET search_path = public;
|
||||
@@ -14,15 +14,15 @@ ALTER FUNCTION public.enforce_opening_balance_immutability() SET search_path = p
|
||||
ALTER FUNCTION public.enforce_period_lock() SET search_path = public;
|
||||
ALTER FUNCTION public.enforce_period_lock_documents() SET search_path = public;
|
||||
ALTER FUNCTION public.enforce_retention_journal_entries() SET search_path = public;
|
||||
ALTER FUNCTION public.generate_invoice_number(p_user_id uuid) SET search_path = public;
|
||||
-- generate_invoice_number removed: created in later migration (20260306) with search_path already set
|
||||
ALTER FUNCTION public.get_next_arrival_number(p_user_id uuid) SET search_path = public;
|
||||
ALTER FUNCTION public.get_unlinked_1930_lines(p_user_id uuid, p_date_from date, p_date_to date) SET search_path = public;
|
||||
ALTER FUNCTION public.handle_new_user() SET search_path = public;
|
||||
ALTER FUNCTION public.next_voucher_number(p_user_id uuid, p_fiscal_period_id uuid, p_series text) SET search_path = public;
|
||||
ALTER FUNCTION public.seed_asset_categories(p_user_id uuid) SET search_path = public;
|
||||
-- seed_asset_categories removed: function was never created
|
||||
ALTER FUNCTION public.seed_chart_of_accounts(p_user_id uuid, p_entity_type text) SET search_path = public;
|
||||
ALTER FUNCTION public.set_committed_at() SET search_path = public;
|
||||
ALTER FUNCTION public.update_overdue_supplier_invoices() SET search_path = public;
|
||||
ALTER FUNCTION public.update_reconciliation_session_counts() SET search_path = public;
|
||||
-- update_reconciliation_session_counts removed: function was never created
|
||||
ALTER FUNCTION public.update_updated_at_column() SET search_path = public;
|
||||
ALTER FUNCTION public.write_audit_log() SET search_path = public;
|
||||
|
||||
@@ -0,0 +1,289 @@
|
||||
-- Sandbox support: is_sandbox column, enforcement trigger bypasses, cleanup functions
|
||||
|
||||
-- =============================================================================
|
||||
-- 1a. Add is_sandbox column to company_settings
|
||||
-- =============================================================================
|
||||
|
||||
ALTER TABLE public.company_settings
|
||||
ADD COLUMN is_sandbox boolean NOT NULL DEFAULT false;
|
||||
|
||||
CREATE INDEX idx_company_settings_sandbox
|
||||
ON public.company_settings (is_sandbox)
|
||||
WHERE is_sandbox = true;
|
||||
|
||||
-- =============================================================================
|
||||
-- 1b. Update enforcement triggers to skip for sandbox users
|
||||
-- =============================================================================
|
||||
|
||||
-- enforce_journal_entry_immutability — add sandbox bypass
|
||||
CREATE OR REPLACE FUNCTION public.enforce_journal_entry_immutability()
|
||||
RETURNS trigger
|
||||
LANGUAGE plpgsql
|
||||
SET search_path = public
|
||||
AS $$
|
||||
BEGIN
|
||||
-- Skip enforcement for sandbox users
|
||||
IF EXISTS (
|
||||
SELECT 1 FROM public.company_settings
|
||||
WHERE user_id = COALESCE(OLD.user_id, NEW.user_id) AND is_sandbox = true
|
||||
) THEN
|
||||
IF TG_OP = 'DELETE' THEN
|
||||
RETURN OLD;
|
||||
END IF;
|
||||
RETURN NEW;
|
||||
END IF;
|
||||
|
||||
IF TG_OP = 'DELETE' THEN
|
||||
-- Allow deleting drafts
|
||||
IF OLD.status = 'draft' THEN
|
||||
RETURN OLD;
|
||||
END IF;
|
||||
RAISE EXCEPTION 'Cannot delete a % journal entry (id: %)', OLD.status, OLD.id;
|
||||
END IF;
|
||||
|
||||
-- TG_OP = 'UPDATE'
|
||||
-- Allow: draft → draft (editing a draft)
|
||||
IF OLD.status = 'draft' AND NEW.status = 'draft' THEN
|
||||
RETURN NEW;
|
||||
END IF;
|
||||
|
||||
-- Allow: draft → posted (committing)
|
||||
IF OLD.status = 'draft' AND NEW.status = 'posted' THEN
|
||||
RETURN NEW;
|
||||
END IF;
|
||||
|
||||
-- Allow: posted → reversed (storno reversal)
|
||||
IF OLD.status = 'posted' AND NEW.status = 'reversed' THEN
|
||||
-- Only allow setting reversed_by_id during this transition
|
||||
IF NEW.description != OLD.description
|
||||
OR NEW.entry_date != OLD.entry_date
|
||||
OR NEW.fiscal_period_id != OLD.fiscal_period_id
|
||||
OR NEW.voucher_number != OLD.voucher_number THEN
|
||||
RAISE EXCEPTION 'Cannot modify fields of a posted entry during reversal (id: %)', OLD.id;
|
||||
END IF;
|
||||
RETURN NEW;
|
||||
END IF;
|
||||
|
||||
-- Block all other transitions
|
||||
RAISE EXCEPTION 'Cannot modify a % journal entry (id: %). Committed entries are immutable per Bokföringslagen.',
|
||||
OLD.status, OLD.id;
|
||||
END;
|
||||
$$;
|
||||
|
||||
-- enforce_journal_entry_line_immutability — add sandbox bypass
|
||||
CREATE OR REPLACE FUNCTION public.enforce_journal_entry_line_immutability()
|
||||
RETURNS trigger
|
||||
LANGUAGE plpgsql
|
||||
SET search_path = public
|
||||
AS $$
|
||||
DECLARE
|
||||
v_status text;
|
||||
v_user_id uuid;
|
||||
BEGIN
|
||||
-- Get the parent entry status and user_id
|
||||
SELECT status, user_id INTO v_status, v_user_id
|
||||
FROM public.journal_entries
|
||||
WHERE id = COALESCE(OLD.journal_entry_id, NEW.journal_entry_id);
|
||||
|
||||
-- Skip enforcement for sandbox users
|
||||
IF EXISTS (
|
||||
SELECT 1 FROM public.company_settings
|
||||
WHERE user_id = v_user_id AND is_sandbox = true
|
||||
) THEN
|
||||
IF TG_OP = 'DELETE' THEN
|
||||
RETURN OLD;
|
||||
END IF;
|
||||
RETURN NEW;
|
||||
END IF;
|
||||
|
||||
-- Allow modifications to lines of draft entries
|
||||
IF v_status = 'draft' THEN
|
||||
IF TG_OP = 'DELETE' THEN
|
||||
RETURN OLD;
|
||||
END IF;
|
||||
RETURN NEW;
|
||||
END IF;
|
||||
|
||||
-- Block modifications to lines of posted/reversed entries
|
||||
RAISE EXCEPTION 'Cannot % lines of a % journal entry. Committed entries are immutable per Bokföringslagen.',
|
||||
TG_OP, v_status;
|
||||
END;
|
||||
$$;
|
||||
|
||||
-- enforce_retention_journal_entries — add sandbox bypass (SECURITY DEFINER)
|
||||
CREATE OR REPLACE FUNCTION public.enforce_retention_journal_entries()
|
||||
RETURNS trigger
|
||||
LANGUAGE plpgsql
|
||||
SECURITY DEFINER
|
||||
SET search_path = public
|
||||
AS $$
|
||||
DECLARE
|
||||
v_retention_expires date;
|
||||
BEGIN
|
||||
-- Skip enforcement for sandbox users
|
||||
IF EXISTS (
|
||||
SELECT 1 FROM public.company_settings
|
||||
WHERE user_id = OLD.user_id AND is_sandbox = true
|
||||
) THEN
|
||||
RETURN OLD;
|
||||
END IF;
|
||||
|
||||
SELECT fp.retention_expires_at INTO v_retention_expires
|
||||
FROM public.fiscal_periods fp
|
||||
WHERE fp.id = OLD.fiscal_period_id;
|
||||
|
||||
IF v_retention_expires IS NOT NULL AND v_retention_expires > CURRENT_DATE THEN
|
||||
INSERT INTO public.audit_log (user_id, action, table_name, record_id, description)
|
||||
VALUES (OLD.user_id, 'RETENTION_BLOCK', 'journal_entries', OLD.id,
|
||||
'Attempted deletion within retention period (expires ' || v_retention_expires || ')');
|
||||
|
||||
RAISE EXCEPTION 'Cannot delete journal entry within 7-year retention period (expires %)',
|
||||
v_retention_expires;
|
||||
END IF;
|
||||
|
||||
RETURN OLD;
|
||||
END;
|
||||
$$;
|
||||
|
||||
-- block_document_deletion — add sandbox bypass (SECURITY DEFINER)
|
||||
CREATE OR REPLACE FUNCTION public.block_document_deletion()
|
||||
RETURNS trigger
|
||||
LANGUAGE plpgsql
|
||||
SECURITY DEFINER
|
||||
SET search_path = public
|
||||
AS $$
|
||||
DECLARE
|
||||
v_entry_status text;
|
||||
v_retention_expires date;
|
||||
BEGIN
|
||||
-- Skip enforcement for sandbox users
|
||||
IF EXISTS (
|
||||
SELECT 1 FROM public.company_settings
|
||||
WHERE user_id = OLD.user_id AND is_sandbox = true
|
||||
) THEN
|
||||
RETURN OLD;
|
||||
END IF;
|
||||
|
||||
-- Check if linked to a committed journal entry
|
||||
IF OLD.journal_entry_id IS NOT NULL THEN
|
||||
SELECT je.status INTO v_entry_status
|
||||
FROM public.journal_entries je
|
||||
WHERE je.id = OLD.journal_entry_id;
|
||||
|
||||
IF v_entry_status IN ('posted', 'reversed') THEN
|
||||
-- Log the blocked attempt
|
||||
INSERT INTO public.audit_log (user_id, action, table_name, record_id, description)
|
||||
VALUES (OLD.user_id, 'DOCUMENT_DELETE_BLOCKED', 'document_attachments', OLD.id,
|
||||
'Attempted deletion of document linked to ' || v_entry_status || ' journal entry ' || OLD.journal_entry_id);
|
||||
|
||||
RAISE EXCEPTION 'Cannot delete document linked to a % journal entry (Bokföringslagen)',
|
||||
v_entry_status;
|
||||
END IF;
|
||||
END IF;
|
||||
|
||||
-- Check retention window
|
||||
IF OLD.journal_entry_id IS NOT NULL THEN
|
||||
SELECT fp.retention_expires_at INTO v_retention_expires
|
||||
FROM public.journal_entries je
|
||||
JOIN public.fiscal_periods fp ON fp.id = je.fiscal_period_id
|
||||
WHERE je.id = OLD.journal_entry_id;
|
||||
|
||||
IF v_retention_expires IS NOT NULL AND v_retention_expires > CURRENT_DATE THEN
|
||||
INSERT INTO public.audit_log (user_id, action, table_name, record_id, description)
|
||||
VALUES (OLD.user_id, 'RETENTION_BLOCK', 'document_attachments', OLD.id,
|
||||
'Attempted deletion within retention period (expires ' || v_retention_expires || ')');
|
||||
|
||||
RAISE EXCEPTION 'Cannot delete document within 7-year retention period (expires %)',
|
||||
v_retention_expires;
|
||||
END IF;
|
||||
END IF;
|
||||
|
||||
RETURN OLD;
|
||||
END;
|
||||
$$;
|
||||
|
||||
-- =============================================================================
|
||||
-- 1c. cleanup_sandbox_user(p_user_id uuid)
|
||||
-- =============================================================================
|
||||
|
||||
CREATE OR REPLACE FUNCTION public.cleanup_sandbox_user(p_user_id uuid)
|
||||
RETURNS integer
|
||||
LANGUAGE plpgsql
|
||||
SECURITY DEFINER
|
||||
SET search_path = public
|
||||
AS $$
|
||||
DECLARE
|
||||
v_is_sandbox boolean;
|
||||
v_deleted integer := 0;
|
||||
BEGIN
|
||||
-- Verify this is a sandbox user
|
||||
SELECT is_sandbox INTO v_is_sandbox
|
||||
FROM public.company_settings
|
||||
WHERE user_id = p_user_id;
|
||||
|
||||
IF v_is_sandbox IS NOT TRUE THEN
|
||||
RAISE EXCEPTION 'User % is not a sandbox user', p_user_id;
|
||||
END IF;
|
||||
|
||||
-- Clear RESTRICT FKs on document_attachments
|
||||
UPDATE public.document_attachments
|
||||
SET journal_entry_id = NULL, journal_entry_line_id = NULL
|
||||
WHERE user_id = p_user_id;
|
||||
|
||||
DELETE FROM public.document_attachments WHERE user_id = p_user_id;
|
||||
|
||||
-- Delete journal entry lines (child of journal_entries)
|
||||
DELETE FROM public.journal_entry_lines
|
||||
WHERE journal_entry_id IN (
|
||||
SELECT id FROM public.journal_entries WHERE user_id = p_user_id
|
||||
);
|
||||
|
||||
-- Delete journal entries (triggers bypass for sandbox)
|
||||
DELETE FROM public.journal_entries WHERE user_id = p_user_id;
|
||||
|
||||
-- Delete supplier invoices before suppliers cascade
|
||||
DELETE FROM public.supplier_invoices WHERE user_id = p_user_id;
|
||||
|
||||
-- Delete from auth.users — cascades everything else
|
||||
DELETE FROM auth.users WHERE id = p_user_id;
|
||||
GET DIAGNOSTICS v_deleted = ROW_COUNT;
|
||||
|
||||
RETURN v_deleted;
|
||||
END;
|
||||
$$;
|
||||
|
||||
-- =============================================================================
|
||||
-- 1d. cleanup_expired_sandbox_users(p_max_age_hours int)
|
||||
-- =============================================================================
|
||||
|
||||
CREATE OR REPLACE FUNCTION public.cleanup_expired_sandbox_users(p_max_age_hours int DEFAULT 24)
|
||||
RETURNS integer
|
||||
LANGUAGE plpgsql
|
||||
SECURITY DEFINER
|
||||
SET search_path = public
|
||||
AS $$
|
||||
DECLARE
|
||||
v_user_id uuid;
|
||||
v_total integer := 0;
|
||||
BEGIN
|
||||
FOR v_user_id IN
|
||||
SELECT cs.user_id
|
||||
FROM public.company_settings cs
|
||||
WHERE cs.is_sandbox = true
|
||||
AND cs.created_at < now() - interval '1 hour' * p_max_age_hours
|
||||
LOOP
|
||||
BEGIN
|
||||
PERFORM public.cleanup_sandbox_user(v_user_id);
|
||||
v_total := v_total + 1;
|
||||
EXCEPTION WHEN OTHERS THEN
|
||||
RAISE WARNING 'Failed to clean up sandbox user %: %', v_user_id, SQLERRM;
|
||||
END;
|
||||
END LOOP;
|
||||
|
||||
RETURN v_total;
|
||||
END;
|
||||
$$;
|
||||
|
||||
-- Grant execute to service_role
|
||||
GRANT EXECUTE ON FUNCTION public.cleanup_sandbox_user(uuid) TO service_role;
|
||||
GRANT EXECUTE ON FUNCTION public.cleanup_expired_sandbox_users(int) TO service_role;
|
||||
Reference in New Issue
Block a user