feat(billing): multi-user paywall: multi_user capability, 20-day grace, owner-only dormancy (#2099)

* feat(billing): multi-user seat gate: multi_user capability, 20-day grace, owner-only dormancy

Multiple people in one company becomes a paid capability (multi_user, the
eighth PAID key). Derived at access time from capability_grants, no status
column, no enforcement cron:

- entitled: active grant (trial/stripe/team/manual/comp), everyone works
- grace: newest grant expired < 20 days ago; countdown banner for everyone
  in companies with > 1 user; invites still allowed
- frozen: only role=owner resolves; other memberships go dormant (rows
  untouched, paying reactivates instantly); invites 403 with paid-plan upsell

Enforcement: new resolve_active_company_gated RPC (zero-arg RPC and RLS twin
untouched: they also run on self-hosts, where the gate never bites), gated
query fallback for service-role/API-key paths, setActiveCompany guard, MCP
company-access check, invite route. Middleware routes all-frozen users to a
new /paused page; the switcher greys locked companies.

Migration 20260901081417 (applied to staging): trial trigger seeds
multi_user, backfills for mid-trial companies, active Stripe subs, team
agreements, and a grandfather grant (expires now, i.e. grace = deploy + 20
days) for existing unpaid multi-member companies. Daily cron mails owners at
grace start and last day. Strings in sv+en; pg-real + unit tests included.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L4tNt8wRG3a5iuU1JE2pnP

* fix(billing): multi-user seat gate hardening from skeptic review

- Stripe cancel now EXPIRES the multi_user stripe grant instead of deleting
  it: the 20-day grace window hangs on an expired row, so a deleted one
  froze churned payers' staff instantly with no banner and no mail. Other
  stripe grants keep the freeze-and-retain delete.
- New SECURITY DEFINER company_multi_user_state() RPC (migration
  20260901083726, applied to staging) and RPC-first getMultiUserState:
  capability_grants RLS hides team-scoped rows from non-team users, so
  user-client reads misread byra-covered companies as frozen (switch
  refusal, wrong switcher locks).
- Byra-kind teams get a standing team-scoped multi_user grant (backfill +
  teams trigger): byra client companies have no company-scoped trial by
  design, so a grantless byra team would freeze every consultant and
  client user.
- Comped/manual companies with active PAID-key grants extend to multi_user
  (a comped company must not read as paying while locking out user two).
- /api/v1 gets the same dormancy gate as MCP (frozen non-owner -> 403).
- PGRST202 on resolution fails OPEN (pre-migration DB has zero multi_user
  rows; the gated fallback would have frozen every non-owner mid-deploy).
- Grace cron: covers team-scoped lapses (byra agreement ending) and skips
  the start mail for the hand-mailed grandfather cohort.
- Tests updated/added across all touched surfaces; pg tests for the new
  RPC and byra trigger; trial-suppression pg test extended to 8 keys.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L4tNt8wRG3a5iuU1JE2pnP

* fix(billing): decouple seat-gate env check and fail open on gate read throws

CI round 1 on #2099:
- isMultiUserEnforced no longer imports has-capability: several route test
  suites partially mock that module and the vitest mock guard threw from
  inside the v1 seat gate, turning expected 4xx responses into 500s.
  multi_user is never a connector capability, so the bypass reduces to the
  same env reads, now inlined.
- getMultiUserState wraps its resolution in a fail-open try/catch: a client
  without .rpc or a thrown network error must never lock users out.
- no-phantom-columns ceiling 391 -> 393 with reasons: the seat gate's .or()
  scope filter (server-resolved UUIDs) and the Stripe cancel expiry update's
  timestamp .or(); all columns in both strings are literals.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L4tNt8wRG3a5iuU1JE2pnP

* fix(billing): membership-guard the multi-user entitlement RPCs (Superagent P3)

company_multi_user_ok and company_multi_user_state are SECURITY DEFINER and
were granted to authenticated with a caller-supplied company UUID: any
logged-in user could probe an arbitrary company's billing state and grace
deadline across tenants. Migration 20260901091752 (applied to staging)
requires an auth.uid() membership in the target company when a JWT is
present, keeps service-role/definer contexts unrestricted, and clamps the
grace window to [0, 20] days. pg tests: stranger gets false/NULL, member
reads normally, oversized p_grace_days cannot widen the probe.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L4tNt8wRG3a5iuU1JE2pnP

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-09-01 11:29:12 +02:00
committed by GitHub
co-authored by Claude Fable 5
parent ca12b1855e
commit aabddb592f
44 changed files with 2573 additions and 49 deletions
+80
View File
@@ -36,6 +36,19 @@ vi.mock('@supabase/supabase-js', async () => {
}
})
// Multi-user seat gate: mocked so the membership stub stays single-purpose;
// the gate's own logic is covered in lib/entitlements/__tests__/multi-user.test.ts.
const getMultiUserStateMock = vi.hoisted(() => vi.fn())
vi.mock('@/lib/entitlements/multi-user', async () => {
const actual = await vi.importActual<typeof import('@/lib/entitlements/multi-user')>(
'@/lib/entitlements/multi-user',
)
return {
...actual,
getMultiUserState: (...args: unknown[]) => getMultiUserStateMock(...args),
}
})
vi.mock('@/lib/api/idempotency', async () => {
const actual = await vi.importActual<typeof import('@/lib/api/idempotency')>(
'@/lib/api/idempotency',
@@ -102,6 +115,7 @@ function companyParams(companyId: string) {
beforeEach(() => {
vi.clearAllMocks()
mockServiceClient.mockReturnValue(makeSupabaseStub(null))
getMultiUserStateMock.mockResolvedValue({ state: 'entitled', graceEndsAt: null })
})
describe('withApiV1: auth', () => {
@@ -277,6 +291,72 @@ describe('withApiV1: company membership', () => {
const body = await res.json()
expect(body.data.companyId).toBe('company-1')
})
it('refuses a NON-OWNER membership in a frozen company with 403 (multi-user seat gate)', async () => {
mockValidate.mockResolvedValue({
userId: 'user-1',
companyId: 'company-1',
scopes: ['companies:read'],
mode: 'live',
})
mockServiceClient.mockReturnValue(makeSupabaseStub({ company_id: 'company-1', role: 'admin' }))
getMultiUserStateMock.mockResolvedValue({ state: 'frozen', graceEndsAt: null })
const handler = withApiV1<{ params: Promise<{ companyId: string }> }>(
'companies.get',
async (_req, ctx) => ok({ ok: true }, { requestId: ctx.requestId }),
{ requireScope: 'companies:read' },
)
const res = await handler(
makeRequest('https://x.test/api/v1/companies/company-1', {
headers: { Authorization: 'Bearer gnubok_sk_x' },
}),
companyParams('company-1'),
)
expect(res.status).toBe(403)
const body = await res.json()
expect(body.error.code).toBe('FORBIDDEN')
expect(body.error.details.capability).toBe('multi_user')
})
it('OWNERS pass the seat gate without a state read; grace passes for non-owners', async () => {
mockValidate.mockResolvedValue({
userId: 'user-1',
companyId: 'company-1',
scopes: ['companies:read'],
mode: 'live',
})
mockServiceClient.mockReturnValue(makeSupabaseStub({ company_id: 'company-1', role: 'owner' }))
getMultiUserStateMock.mockResolvedValue({ state: 'frozen', graceEndsAt: null })
const handler = withApiV1<{ params: Promise<{ companyId: string }> }>(
'companies.get',
async (_req, ctx) => ok({ ok: true }, { requestId: ctx.requestId }),
{ requireScope: 'companies:read' },
)
const ownerRes = await handler(
makeRequest('https://x.test/api/v1/companies/company-1', {
headers: { Authorization: 'Bearer gnubok_sk_x' },
}),
companyParams('company-1'),
)
expect(ownerRes.status).toBe(200)
expect(getMultiUserStateMock).not.toHaveBeenCalled()
mockServiceClient.mockReturnValue(makeSupabaseStub({ company_id: 'company-1', role: 'member' }))
getMultiUserStateMock.mockResolvedValue({
state: 'grace',
graceEndsAt: new Date(Date.now() + 5 * 86_400_000).toISOString(),
})
const graceRes = await handler(
makeRequest('https://x.test/api/v1/companies/company-1', {
headers: { Authorization: 'Bearer gnubok_sk_x' },
}),
companyParams('company-1'),
)
expect(graceRes.status).toBe(200)
})
})
describe('withApiV1: static (non-dynamic) route params', () => {
+23
View File
@@ -58,6 +58,7 @@ import { runWithActor } from '@/lib/bookkeeping/actor-context-node'
// idempotent (guarded by a module-level boolean).
ensureInitialized()
import { resolveRequiredScope } from '@/lib/auth/scopes'
import { getMultiUserState, isMembershipDormant } from '@/lib/entitlements/multi-user'
import { getEndpointByConcretePath } from './registry'
import {
checkIdempotencyKey,
@@ -412,6 +413,28 @@ export function withApiV1<P extends DynamicParams = { params: Promise<Record<str
details: { companyId },
})
}
// Multi-user seat gate: the API-key surface is a chokepoint like the
// cookie routes and MCP. A non-owner membership in a frozen company
// (multi_user lapsed past its 20-day grace) is refused here so an old
// key cannot keep working the books after the freeze. Owners pass
// without the extra read; the service client sees team-scoped grants.
if ((membership as { role?: string }).role !== 'owner') {
const access = await getMultiUserState(supabase, companyId)
if (isMembershipDormant((membership as { role: string }).role, access.state)) {
userLog.warn('multi-user seat gate refused frozen membership', { companyId, ...forensic })
return await v1ErrorResponseFromCode('FORBIDDEN', userLog, {
requestId,
status: 403,
reason: 'multi_user_frozen',
details: {
companyId,
capability: 'multi_user',
message: 'Company is paused for this account: multiple users require a paid plan. Ask the company owner to upgrade.',
},
})
}
}
}
// 6. Idempotency. Mandatory for state-changing methods when the route