fix(entitlements): close paywall leaks on interactive bank, SKV, and email routes (#910)

* fix(entitlements): close paywall leaks on interactive bank, SKV, and email routes

The capability gate covered crons, MCP tools, and invoice send, but four
interactive server paths still bypassed it ahead of the 2026-07-07 trial
cutover:

- enable-banking POST /connect and /sync (bank_sync)
- skatteverket authorize/validate/draft/lock/submit/spara/las/kontrollera/
  skattekonto-sync (skatteverket); unlock and all reads stay free, and the
  AGI/VAT file download path remains ungated per the manual-filing decision
- salary payslip email send (email_send)
- recurring-invoice auto-send (email_send); the invoice is still created,
  only the email is withheld (freeze-and-retain)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* test(entitlements): pin unlock routes as paywall-free recovery paths

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-07-06 22:20:26 +02:00
committed by GitHub
co-authored by Claude Opus 4.7
parent 573feea890
commit 7f24ede6c0
9 changed files with 191 additions and 0 deletions
@@ -21,6 +21,8 @@ import { renderToBuffer } from '@react-pdf/renderer'
import { InvoicePDF } from '@/lib/invoices/pdf-template'
import { prepareInvoicePdfRender, buildSwishQrDataUrl } from '@/lib/invoices/pdf-render-helpers'
import { getEmailService } from '@/lib/email/service'
import { hasCapability } from '@/lib/entitlements/has-capability'
import { CAPABILITY } from '@/lib/entitlements/keys'
import {
generateInvoiceEmailHtml,
generateInvoiceEmailText,
@@ -361,6 +363,16 @@ async function sendInvoiceFromSchedule(
})
return false
}
// Paywall: email sending is a paid capability. The invoice itself is still
// created (bookkeeping stays free); it just isn't emailed, and the schedule
// surfaces the standard manual-send warning (freeze-and-retain).
if (!(await hasCapability(supabase, companyId, CAPABILITY.email_send))) {
log.warn('company lacks email_send capability; recurring schedule cannot auto-send', {
invoiceId: invoice.id,
companyId,
})
return false
}
if (!invoice.customer.email) {
log.warn('customer has no email; recurring schedule cannot auto-send', {
invoiceId: invoice.id,