feat(billing): multi-user paywall: multi_user capability, 20-day grace, owner-only dormancy (#2099)
* feat(billing): multi-user seat gate: multi_user capability, 20-day grace, owner-only dormancy Multiple people in one company becomes a paid capability (multi_user, the eighth PAID key). Derived at access time from capability_grants, no status column, no enforcement cron: - entitled: active grant (trial/stripe/team/manual/comp), everyone works - grace: newest grant expired < 20 days ago; countdown banner for everyone in companies with > 1 user; invites still allowed - frozen: only role=owner resolves; other memberships go dormant (rows untouched, paying reactivates instantly); invites 403 with paid-plan upsell Enforcement: new resolve_active_company_gated RPC (zero-arg RPC and RLS twin untouched: they also run on self-hosts, where the gate never bites), gated query fallback for service-role/API-key paths, setActiveCompany guard, MCP company-access check, invite route. Middleware routes all-frozen users to a new /paused page; the switcher greys locked companies. Migration 20260901081417 (applied to staging): trial trigger seeds multi_user, backfills for mid-trial companies, active Stripe subs, team agreements, and a grandfather grant (expires now, i.e. grace = deploy + 20 days) for existing unpaid multi-member companies. Daily cron mails owners at grace start and last day. Strings in sv+en; pg-real + unit tests included. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L4tNt8wRG3a5iuU1JE2pnP * fix(billing): multi-user seat gate hardening from skeptic review - Stripe cancel now EXPIRES the multi_user stripe grant instead of deleting it: the 20-day grace window hangs on an expired row, so a deleted one froze churned payers' staff instantly with no banner and no mail. Other stripe grants keep the freeze-and-retain delete. - New SECURITY DEFINER company_multi_user_state() RPC (migration 20260901083726, applied to staging) and RPC-first getMultiUserState: capability_grants RLS hides team-scoped rows from non-team users, so user-client reads misread byra-covered companies as frozen (switch refusal, wrong switcher locks). - Byra-kind teams get a standing team-scoped multi_user grant (backfill + teams trigger): byra client companies have no company-scoped trial by design, so a grantless byra team would freeze every consultant and client user. - Comped/manual companies with active PAID-key grants extend to multi_user (a comped company must not read as paying while locking out user two). - /api/v1 gets the same dormancy gate as MCP (frozen non-owner -> 403). - PGRST202 on resolution fails OPEN (pre-migration DB has zero multi_user rows; the gated fallback would have frozen every non-owner mid-deploy). - Grace cron: covers team-scoped lapses (byra agreement ending) and skips the start mail for the hand-mailed grandfather cohort. - Tests updated/added across all touched surfaces; pg tests for the new RPC and byra trigger; trial-suppression pg test extended to 8 keys. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L4tNt8wRG3a5iuU1JE2pnP * fix(billing): decouple seat-gate env check and fail open on gate read throws CI round 1 on #2099: - isMultiUserEnforced no longer imports has-capability: several route test suites partially mock that module and the vitest mock guard threw from inside the v1 seat gate, turning expected 4xx responses into 500s. multi_user is never a connector capability, so the bypass reduces to the same env reads, now inlined. - getMultiUserState wraps its resolution in a fail-open try/catch: a client without .rpc or a thrown network error must never lock users out. - no-phantom-columns ceiling 391 -> 393 with reasons: the seat gate's .or() scope filter (server-resolved UUIDs) and the Stripe cancel expiry update's timestamp .or(); all columns in both strings are literals. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L4tNt8wRG3a5iuU1JE2pnP * fix(billing): membership-guard the multi-user entitlement RPCs (Superagent P3) company_multi_user_ok and company_multi_user_state are SECURITY DEFINER and were granted to authenticated with a caller-supplied company UUID: any logged-in user could probe an arbitrary company's billing state and grace deadline across tenants. Migration 20260901091752 (applied to staging) requires an auth.uid() membership in the target company when a JWT is present, keeps service-role/definer contexts unrestricted, and clamps the grace window to [0, 20] days. pg tests: stranger gets false/NULL, member reads normally, oversized p_grace_days cannot widen the probe. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L4tNt8wRG3a5iuU1JE2pnP --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
ca12b1855e
commit
aabddb592f
@@ -36,6 +36,19 @@ vi.mock('@supabase/supabase-js', async () => {
|
||||
}
|
||||
})
|
||||
|
||||
// Multi-user seat gate: mocked so the membership stub stays single-purpose;
|
||||
// the gate's own logic is covered in lib/entitlements/__tests__/multi-user.test.ts.
|
||||
const getMultiUserStateMock = vi.hoisted(() => vi.fn())
|
||||
vi.mock('@/lib/entitlements/multi-user', async () => {
|
||||
const actual = await vi.importActual<typeof import('@/lib/entitlements/multi-user')>(
|
||||
'@/lib/entitlements/multi-user',
|
||||
)
|
||||
return {
|
||||
...actual,
|
||||
getMultiUserState: (...args: unknown[]) => getMultiUserStateMock(...args),
|
||||
}
|
||||
})
|
||||
|
||||
vi.mock('@/lib/api/idempotency', async () => {
|
||||
const actual = await vi.importActual<typeof import('@/lib/api/idempotency')>(
|
||||
'@/lib/api/idempotency',
|
||||
@@ -102,6 +115,7 @@ function companyParams(companyId: string) {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks()
|
||||
mockServiceClient.mockReturnValue(makeSupabaseStub(null))
|
||||
getMultiUserStateMock.mockResolvedValue({ state: 'entitled', graceEndsAt: null })
|
||||
})
|
||||
|
||||
describe('withApiV1: auth', () => {
|
||||
@@ -277,6 +291,72 @@ describe('withApiV1: company membership', () => {
|
||||
const body = await res.json()
|
||||
expect(body.data.companyId).toBe('company-1')
|
||||
})
|
||||
|
||||
it('refuses a NON-OWNER membership in a frozen company with 403 (multi-user seat gate)', async () => {
|
||||
mockValidate.mockResolvedValue({
|
||||
userId: 'user-1',
|
||||
companyId: 'company-1',
|
||||
scopes: ['companies:read'],
|
||||
mode: 'live',
|
||||
})
|
||||
mockServiceClient.mockReturnValue(makeSupabaseStub({ company_id: 'company-1', role: 'admin' }))
|
||||
getMultiUserStateMock.mockResolvedValue({ state: 'frozen', graceEndsAt: null })
|
||||
|
||||
const handler = withApiV1<{ params: Promise<{ companyId: string }> }>(
|
||||
'companies.get',
|
||||
async (_req, ctx) => ok({ ok: true }, { requestId: ctx.requestId }),
|
||||
{ requireScope: 'companies:read' },
|
||||
)
|
||||
|
||||
const res = await handler(
|
||||
makeRequest('https://x.test/api/v1/companies/company-1', {
|
||||
headers: { Authorization: 'Bearer gnubok_sk_x' },
|
||||
}),
|
||||
companyParams('company-1'),
|
||||
)
|
||||
expect(res.status).toBe(403)
|
||||
const body = await res.json()
|
||||
expect(body.error.code).toBe('FORBIDDEN')
|
||||
expect(body.error.details.capability).toBe('multi_user')
|
||||
})
|
||||
|
||||
it('OWNERS pass the seat gate without a state read; grace passes for non-owners', async () => {
|
||||
mockValidate.mockResolvedValue({
|
||||
userId: 'user-1',
|
||||
companyId: 'company-1',
|
||||
scopes: ['companies:read'],
|
||||
mode: 'live',
|
||||
})
|
||||
mockServiceClient.mockReturnValue(makeSupabaseStub({ company_id: 'company-1', role: 'owner' }))
|
||||
getMultiUserStateMock.mockResolvedValue({ state: 'frozen', graceEndsAt: null })
|
||||
|
||||
const handler = withApiV1<{ params: Promise<{ companyId: string }> }>(
|
||||
'companies.get',
|
||||
async (_req, ctx) => ok({ ok: true }, { requestId: ctx.requestId }),
|
||||
{ requireScope: 'companies:read' },
|
||||
)
|
||||
const ownerRes = await handler(
|
||||
makeRequest('https://x.test/api/v1/companies/company-1', {
|
||||
headers: { Authorization: 'Bearer gnubok_sk_x' },
|
||||
}),
|
||||
companyParams('company-1'),
|
||||
)
|
||||
expect(ownerRes.status).toBe(200)
|
||||
expect(getMultiUserStateMock).not.toHaveBeenCalled()
|
||||
|
||||
mockServiceClient.mockReturnValue(makeSupabaseStub({ company_id: 'company-1', role: 'member' }))
|
||||
getMultiUserStateMock.mockResolvedValue({
|
||||
state: 'grace',
|
||||
graceEndsAt: new Date(Date.now() + 5 * 86_400_000).toISOString(),
|
||||
})
|
||||
const graceRes = await handler(
|
||||
makeRequest('https://x.test/api/v1/companies/company-1', {
|
||||
headers: { Authorization: 'Bearer gnubok_sk_x' },
|
||||
}),
|
||||
companyParams('company-1'),
|
||||
)
|
||||
expect(graceRes.status).toBe(200)
|
||||
})
|
||||
})
|
||||
|
||||
describe('withApiV1: static (non-dynamic) route params', () => {
|
||||
|
||||
@@ -58,6 +58,7 @@ import { runWithActor } from '@/lib/bookkeeping/actor-context-node'
|
||||
// idempotent (guarded by a module-level boolean).
|
||||
ensureInitialized()
|
||||
import { resolveRequiredScope } from '@/lib/auth/scopes'
|
||||
import { getMultiUserState, isMembershipDormant } from '@/lib/entitlements/multi-user'
|
||||
import { getEndpointByConcretePath } from './registry'
|
||||
import {
|
||||
checkIdempotencyKey,
|
||||
@@ -412,6 +413,28 @@ export function withApiV1<P extends DynamicParams = { params: Promise<Record<str
|
||||
details: { companyId },
|
||||
})
|
||||
}
|
||||
|
||||
// Multi-user seat gate: the API-key surface is a chokepoint like the
|
||||
// cookie routes and MCP. A non-owner membership in a frozen company
|
||||
// (multi_user lapsed past its 20-day grace) is refused here so an old
|
||||
// key cannot keep working the books after the freeze. Owners pass
|
||||
// without the extra read; the service client sees team-scoped grants.
|
||||
if ((membership as { role?: string }).role !== 'owner') {
|
||||
const access = await getMultiUserState(supabase, companyId)
|
||||
if (isMembershipDormant((membership as { role: string }).role, access.state)) {
|
||||
userLog.warn('multi-user seat gate refused frozen membership', { companyId, ...forensic })
|
||||
return await v1ErrorResponseFromCode('FORBIDDEN', userLog, {
|
||||
requestId,
|
||||
status: 403,
|
||||
reason: 'multi_user_frozen',
|
||||
details: {
|
||||
companyId,
|
||||
capability: 'multi_user',
|
||||
message: 'Company is paused for this account: multiple users require a paid plan. Ask the company owner to upgrade.',
|
||||
},
|
||||
})
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// 6. Idempotency. Mandatory for state-changing methods when the route
|
||||
|
||||
Reference in New Issue
Block a user