Invoicing & account-security polish bundle (#550)
* feat: invoicing & account-security polish bundle Five independent improvements bundled to ship together: - BankID/password lockout fix: BankID-only users could enroll MFA and brick themselves (Supabase requires AAL2 to change password or unenroll MFA, and AAL2 needs a password sign-in). New app_metadata.has_password flag tracks this; middleware gates /mfa/enroll behind it, /account/set- password is the unlock path, SecuritySettings shows a banner, and /api/account/password is the single write path that flips the flag. Backfill script for existing users. - Swish invoice payment method: company_settings.swish + invoice_show_swish columns, validation in lib/api/schemas.ts (accepts 123XXXXXXX företag or 07XXXXXXXX mobile, strips whitespace/hyphens), rendered on invoice PDFs. - Send-reminders kill switch: per-company company_settings.send_invoice_ reminders toggle in PdfPrintSettings/Automatisering. Reminder processor also tightened: positive status allowlist (sent + overdue) so terminal statuses can never match; skip when customer already responded via reminder link; race-window re-check before send. - First-invoice logo prompt: one-shot dialog when creating the first invoice without a logo (issue #520). Self-limits via head-only count. - SIE export opening-balance fallback: route IB through getOpeningBalances so the compute_prior_opening_balances RPC supplies #IB after multi-year imports where opening_balance_entry_id is intentionally NULL. Previously #IB silently went to zero and #UB collapsed to current-period movements. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(account-polish): address PR review feedback - BankID-link path (extensions/general/tic/index.ts): read-merge-write app_metadata instead of passing { bankid_linked: true } alone. updateUserById REPLACES app_metadata wholesale, so the previous code would have wiped has_password for any user who later linked BankID, causing the set-password banner to (incorrectly) reappear and blocking the standard MFA enrollment button. The comment is now corrected. - Middleware (lib/supabase/middleware.ts): thread inner returnTo through the /mfa/enroll → /account/set-password redirect so the user lands on their original destination after the full chain completes, not on /. - safeReturnTo helper (lib/auth/safe-return-to.ts): replace the starts-with-/-but-not-// guard on mfa/enroll and set-password pages. The previous guard let /\evil.com and /@evil.com through. The new helper parses against a synthetic base origin and verifies it matches. - set-password page (app/(auth)/account/set-password/page.tsx): remove CLAUDE.md design system violations — bg-gradient-to-b on page bg, inline shadow-md style on the card, space-y-5, font-medium on the h1, rounded-xl on the card. Flat surface, hairline border, font-display h1 per the design tokens. - Swish dedup (lib/payments/swish.ts): extract normaliseSwish() and isValidSwish() helpers and use them in lib/api/schemas.ts, components/settings/BankDetailsForm.tsx, and the invoicing settings page. Single source of truth for the regex. - Password route (app/api/account/password/route.ts): emit a structured success log so the audit pipeline can detect password-set events, not just failures. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
2879f6ed17
commit
cc351158f8
@@ -0,0 +1,187 @@
|
||||
'use client'
|
||||
|
||||
import { useState, useEffect, Suspense } from 'react'
|
||||
import { useRouter, useSearchParams } from 'next/navigation'
|
||||
import { createClient } from '@/lib/supabase/client'
|
||||
import { Button } from '@/components/ui/button'
|
||||
import { Input } from '@/components/ui/input'
|
||||
import { Label } from '@/components/ui/label'
|
||||
import { useToast } from '@/components/ui/use-toast'
|
||||
import { Loader2, KeyRound } from 'lucide-react'
|
||||
import { userHasPassword } from '@/lib/auth/has-password'
|
||||
import { safeReturnTo } from '@/lib/auth/safe-return-to'
|
||||
|
||||
export default function SetPasswordPage() {
|
||||
return (
|
||||
<Suspense>
|
||||
<SetPasswordContent />
|
||||
</Suspense>
|
||||
)
|
||||
}
|
||||
|
||||
function SetPasswordContent() {
|
||||
const [password, setPassword] = useState('')
|
||||
const [confirmPassword, setConfirmPassword] = useState('')
|
||||
const [isLoading, setIsLoading] = useState(false)
|
||||
const { toast } = useToast()
|
||||
const router = useRouter()
|
||||
const searchParams = useSearchParams()
|
||||
const supabase = createClient()
|
||||
|
||||
const returnTo = safeReturnTo(searchParams.get('returnTo'), '/settings/account')
|
||||
|
||||
// Users who already have a password don't belong here — bounce them away.
|
||||
useEffect(() => {
|
||||
let cancelled = false
|
||||
;(async () => {
|
||||
const {
|
||||
data: { user },
|
||||
} = await supabase.auth.getUser()
|
||||
if (cancelled) return
|
||||
if (!user) {
|
||||
router.replace('/login')
|
||||
return
|
||||
}
|
||||
if (userHasPassword(user)) {
|
||||
router.replace(returnTo)
|
||||
}
|
||||
})()
|
||||
return () => {
|
||||
cancelled = true
|
||||
}
|
||||
// eslint-disable-next-line react-hooks/exhaustive-deps
|
||||
}, [])
|
||||
|
||||
const handleSetPassword = async (e: React.FormEvent<HTMLFormElement>) => {
|
||||
e.preventDefault()
|
||||
setIsLoading(true)
|
||||
|
||||
const strong =
|
||||
password.length >= 8 &&
|
||||
/[a-z]/.test(password) &&
|
||||
/[A-Z]/.test(password) &&
|
||||
/[0-9]/.test(password) &&
|
||||
/[^a-zA-Z0-9]/.test(password)
|
||||
|
||||
if (!strong) {
|
||||
toast({
|
||||
title: 'Lösenordet är för svagt',
|
||||
description:
|
||||
'Lösenordet måste vara minst 8 tecken och innehålla versaler, gemener, siffror och specialtecken.',
|
||||
variant: 'destructive',
|
||||
})
|
||||
setIsLoading(false)
|
||||
return
|
||||
}
|
||||
|
||||
if (password !== confirmPassword) {
|
||||
toast({
|
||||
title: 'Lösenorden matchar inte',
|
||||
description: 'Kontrollera att du skrev samma lösenord i båda fälten.',
|
||||
variant: 'destructive',
|
||||
})
|
||||
setIsLoading(false)
|
||||
return
|
||||
}
|
||||
|
||||
try {
|
||||
const res = await fetch('/api/account/password', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ password }),
|
||||
})
|
||||
|
||||
if (!res.ok) {
|
||||
const body = (await res.json().catch(() => ({}))) as { error?: string }
|
||||
toast({
|
||||
title: 'Kunde inte spara lösenord',
|
||||
description: body.error || 'Försök igen senare.',
|
||||
variant: 'destructive',
|
||||
})
|
||||
return
|
||||
}
|
||||
|
||||
toast({
|
||||
title: 'Lösenord sparat',
|
||||
description: 'Du kan nu aktivera tvåfaktorsautentisering.',
|
||||
})
|
||||
|
||||
router.push(returnTo)
|
||||
router.refresh()
|
||||
} catch {
|
||||
toast({
|
||||
title: 'Något gick fel',
|
||||
description: 'Försök igen senare.',
|
||||
variant: 'destructive',
|
||||
})
|
||||
} finally {
|
||||
setIsLoading(false)
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="min-h-screen flex flex-col items-center justify-center bg-background p-4">
|
||||
<div className="w-full max-w-sm animate-slide-up">
|
||||
<div className="text-center mb-10">
|
||||
<div className="flex justify-center mb-4">
|
||||
<div className="h-14 w-14 rounded-lg bg-secondary flex items-center justify-center">
|
||||
<KeyRound className="h-7 w-7 text-primary" />
|
||||
</div>
|
||||
</div>
|
||||
<h1 className="font-display text-3xl tracking-tight">
|
||||
Sätt ett lösenord
|
||||
</h1>
|
||||
<p className="text-muted-foreground text-sm mt-2">
|
||||
Du loggade in med BankID. För att aktivera tvåfaktorsautentisering
|
||||
eller logga in med e-post behöver du först sätta ett lösenord.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div className="rounded-lg border border-border bg-card p-6">
|
||||
<form onSubmit={handleSetPassword} className="space-y-4">
|
||||
<div className="space-y-2">
|
||||
<Label htmlFor="password">Lösenord</Label>
|
||||
<Input
|
||||
id="password"
|
||||
type="password"
|
||||
autoComplete="new-password"
|
||||
placeholder="Minst 8 tecken, Aa1!"
|
||||
value={password}
|
||||
onChange={(e) => setPassword(e.target.value)}
|
||||
required
|
||||
minLength={8}
|
||||
disabled={isLoading}
|
||||
className="h-11"
|
||||
/>
|
||||
</div>
|
||||
<div className="space-y-2">
|
||||
<Label htmlFor="confirm_password">Bekräfta lösenord</Label>
|
||||
<Input
|
||||
id="confirm_password"
|
||||
type="password"
|
||||
autoComplete="new-password"
|
||||
placeholder="Upprepa lösenordet"
|
||||
value={confirmPassword}
|
||||
onChange={(e) => setConfirmPassword(e.target.value)}
|
||||
required
|
||||
minLength={8}
|
||||
disabled={isLoading}
|
||||
className="h-11"
|
||||
/>
|
||||
</div>
|
||||
<Button type="submit" className="w-full h-11" disabled={isLoading}>
|
||||
{isLoading ? (
|
||||
<>
|
||||
<Loader2 className="mr-2 h-4 w-4 animate-spin" />
|
||||
Sparar...
|
||||
</>
|
||||
) : (
|
||||
'Spara lösenord'
|
||||
)}
|
||||
</Button>
|
||||
</form>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
)
|
||||
}
|
||||
@@ -1,6 +1,6 @@
|
||||
'use client'
|
||||
|
||||
import { useState, useRef, Suspense } from 'react'
|
||||
import { useState, useRef, useEffect, Suspense } from 'react'
|
||||
import { useRouter, useSearchParams } from 'next/navigation'
|
||||
import { createClient } from '@/lib/supabase/client'
|
||||
import { Button } from '@/components/ui/button'
|
||||
@@ -9,6 +9,8 @@ import { Label } from '@/components/ui/label'
|
||||
import { useToast } from '@/components/ui/use-toast'
|
||||
import { Loader2, ShieldCheck, Copy, Check, ArrowLeft } from 'lucide-react'
|
||||
import { getBranding } from '@/lib/branding/service'
|
||||
import { userHasPassword } from '@/lib/auth/has-password'
|
||||
import { safeReturnTo } from '@/lib/auth/safe-return-to'
|
||||
|
||||
export default function MfaEnrollPage() {
|
||||
return (
|
||||
@@ -32,8 +34,32 @@ function MfaEnrollContent() {
|
||||
const searchParams = useSearchParams()
|
||||
const supabase = createClient()
|
||||
|
||||
const rawReturnTo = searchParams.get('returnTo') || '/'
|
||||
const returnTo = rawReturnTo.startsWith('/') && !rawReturnTo.startsWith('//') ? rawReturnTo : '/'
|
||||
const returnTo = safeReturnTo(searchParams.get('returnTo'), '/')
|
||||
|
||||
// UX defense — middleware already blocks this route for BankID-only users
|
||||
// without a password, but a stale tab might land here too. Bounce them to
|
||||
// the set-password flow before they enroll a factor they cannot later
|
||||
// un-enroll without AAL2.
|
||||
useEffect(() => {
|
||||
let cancelled = false
|
||||
;(async () => {
|
||||
const {
|
||||
data: { user },
|
||||
} = await supabase.auth.getUser()
|
||||
if (cancelled || !user) return
|
||||
if (!userHasPassword(user)) {
|
||||
router.replace(
|
||||
`/account/set-password?returnTo=${encodeURIComponent(
|
||||
`/mfa/enroll?returnTo=${encodeURIComponent(returnTo)}`,
|
||||
)}`,
|
||||
)
|
||||
}
|
||||
})()
|
||||
return () => {
|
||||
cancelled = true
|
||||
}
|
||||
// eslint-disable-next-line react-hooks/exhaustive-deps
|
||||
}, [])
|
||||
|
||||
const handleEnroll = async () => {
|
||||
setIsEnrolling(true)
|
||||
|
||||
@@ -2,7 +2,6 @@
|
||||
|
||||
import { useState } from 'react'
|
||||
import { useRouter } from 'next/navigation'
|
||||
import { createClient } from '@/lib/supabase/client'
|
||||
import { Button } from '@/components/ui/button'
|
||||
import { Input } from '@/components/ui/input'
|
||||
import { Label } from '@/components/ui/label'
|
||||
@@ -15,7 +14,6 @@ export default function ResetPasswordPage() {
|
||||
const [isLoading, setIsLoading] = useState(false)
|
||||
const { toast } = useToast()
|
||||
const router = useRouter()
|
||||
const supabase = createClient()
|
||||
|
||||
const handleResetPassword = async (e: React.FormEvent<HTMLFormElement>) => {
|
||||
e.preventDefault()
|
||||
@@ -48,12 +46,22 @@ export default function ResetPasswordPage() {
|
||||
}
|
||||
|
||||
try {
|
||||
const { error } = await supabase.auth.updateUser({ password })
|
||||
// Routed through the API so the has_password flag flips in lock-step
|
||||
// with the password update. This is the unlock path for BankID-only
|
||||
// users who enrolled MFA and got locked out — the recovery session
|
||||
// bypasses AAL2, the API flips has_password, and the lockout banner
|
||||
// disappears the next time they log in.
|
||||
const res = await fetch('/api/account/password', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ password }),
|
||||
})
|
||||
|
||||
if (error) {
|
||||
if (!res.ok) {
|
||||
const body = (await res.json().catch(() => ({}))) as { error?: string }
|
||||
toast({
|
||||
title: 'Kunde inte uppdatera lösenord',
|
||||
description: error.message,
|
||||
description: body.error || 'Försök igen senare.',
|
||||
variant: 'destructive',
|
||||
})
|
||||
return
|
||||
|
||||
@@ -27,6 +27,7 @@ import { getErrorMessage } from '@/lib/errors/get-error-message'
|
||||
import { useUnsavedChanges } from '@/lib/hooks/use-unsaved-changes'
|
||||
import CustomerForm from '@/components/customers/CustomerForm'
|
||||
import { BankDetailsSetupDialog } from '@/components/invoices/BankDetailsSetupDialog'
|
||||
import { FirstInvoiceLogoPrompt } from '@/components/invoices/FirstInvoiceLogoPrompt'
|
||||
import { useCompany } from '@/contexts/CompanyContext'
|
||||
import type { Customer, Currency, CreateInvoiceInput, CreateCustomerInput, InvoiceDocumentType } from '@/types'
|
||||
|
||||
@@ -85,6 +86,12 @@ export default function NewInvoicePage() {
|
||||
const [accountingMethod, setAccountingMethod] = useState<'accrual' | 'cash'>('accrual')
|
||||
const [oreRounding, setOreRounding] = useState<boolean>(true)
|
||||
const [numberPreview, setNumberPreview] = useState<string | null>(null)
|
||||
const [logoUrl, setLogoUrl] = useState<string | null>(null)
|
||||
// True only when the user had zero invoices when this page loaded. The
|
||||
// post-create flow uses this to offer a one-shot "upload a logo?" prompt
|
||||
// — issue #520. Self-limits: once count > 0 it stays false.
|
||||
const [hadZeroInvoices, setHadZeroInvoices] = useState<boolean | null>(null)
|
||||
const [showLogoPrompt, setShowLogoPrompt] = useState(false)
|
||||
const pendingCustomerRef = useRef<Customer | null>(null)
|
||||
|
||||
const {
|
||||
@@ -144,7 +151,7 @@ export default function NewInvoicePage() {
|
||||
if (!company?.id) return
|
||||
const { data } = await supabase
|
||||
.from('company_settings')
|
||||
.select('invoice_default_notes, clearing_number, account_number, bankgiro, accounting_method, ore_rounding')
|
||||
.select('invoice_default_notes, clearing_number, account_number, bankgiro, accounting_method, ore_rounding, logo_url')
|
||||
.eq('company_id', company.id)
|
||||
.single()
|
||||
if (data?.invoice_default_notes) {
|
||||
@@ -160,8 +167,29 @@ export default function NewInvoicePage() {
|
||||
if (typeof data?.ore_rounding === 'boolean') {
|
||||
setOreRounding(data.ore_rounding)
|
||||
}
|
||||
setLogoUrl(data?.logo_url ?? null)
|
||||
}
|
||||
|
||||
// First-invoice detection (issue #520): captured at page load so the
|
||||
// post-create flow can offer the logo prompt for genuinely first-time
|
||||
// invoices only. head:true keeps it cheap — no rows pulled.
|
||||
useEffect(() => {
|
||||
if (!company?.id) return
|
||||
let cancelled = false
|
||||
;(async () => {
|
||||
const { count } = await supabase
|
||||
.from('invoices')
|
||||
.select('id', { count: 'exact', head: true })
|
||||
.eq('company_id', company.id)
|
||||
if (!cancelled) setHadZeroInvoices(count === 0 || count === null)
|
||||
})()
|
||||
return () => {
|
||||
cancelled = true
|
||||
}
|
||||
// supabase is a stable reference from createClient() at top of component
|
||||
// eslint-disable-next-line react-hooks/exhaustive-deps
|
||||
}, [company?.id])
|
||||
|
||||
// Preview the next invoice number so the user can catch a mis-set
|
||||
// sequence/prefix before committing. The actual allocator still runs
|
||||
// atomically at create time; this is read-only.
|
||||
@@ -319,6 +347,16 @@ export default function NewInvoicePage() {
|
||||
}
|
||||
}
|
||||
|
||||
function handleLogoPromptClose() {
|
||||
setShowLogoPrompt(false)
|
||||
// Resume the post-create flow that was deferred by the logo prompt.
|
||||
if (selectedCustomer?.email && createdInvoiceId) {
|
||||
setShowSendPrompt(true)
|
||||
} else if (createdInvoiceId) {
|
||||
router.push(`/invoices/${createdInvoiceId}`)
|
||||
}
|
||||
}
|
||||
|
||||
async function handleConfirm() {
|
||||
if (!pendingData) return
|
||||
setIsSubmitting(true)
|
||||
@@ -343,10 +381,15 @@ export default function NewInvoicePage() {
|
||||
})
|
||||
|
||||
setShowReview(false)
|
||||
setCreatedInvoiceId(result.data.id)
|
||||
|
||||
// If customer has email, offer to send immediately
|
||||
if (selectedCustomer?.email) {
|
||||
setCreatedInvoiceId(result.data.id)
|
||||
// First-invoice-only logo prompt (issue #520) takes priority over the
|
||||
// send-now dialog so a fresh upload makes it onto the just-sent PDF
|
||||
// (pdf-template reads logo_url live from company_settings). Once the
|
||||
// prompt closes, handleLogoPromptClose resumes the regular flow.
|
||||
if (hadZeroInvoices === true && !logoUrl) {
|
||||
setShowLogoPrompt(true)
|
||||
} else if (selectedCustomer?.email) {
|
||||
setShowSendPrompt(true)
|
||||
} else {
|
||||
router.push(`/invoices/${result.data.id}`)
|
||||
@@ -932,6 +975,14 @@ export default function NewInvoicePage() {
|
||||
onComplete={handleBankSetupComplete}
|
||||
/>
|
||||
|
||||
{/* First-invoice logo prompt (issue #520) */}
|
||||
<FirstInvoiceLogoPrompt
|
||||
open={showLogoPrompt}
|
||||
onClose={handleLogoPromptClose}
|
||||
logoUrl={logoUrl}
|
||||
onLogoUpdate={(url) => setLogoUrl(url)}
|
||||
/>
|
||||
|
||||
{/* Send now prompt dialog */}
|
||||
<Dialog open={showSendPrompt} onOpenChange={(open) => {
|
||||
if (!open && createdInvoiceId) {
|
||||
|
||||
@@ -7,6 +7,7 @@ import { SettingsFormWrapper } from '@/components/settings/SettingsFormWrapper'
|
||||
import { SettingsLoadingSkeleton } from '@/components/settings/SettingsLoadingSkeleton'
|
||||
import { useSettings } from '@/components/settings/useSettings'
|
||||
import { useToast } from '@/components/ui/use-toast'
|
||||
import { normaliseSwish } from '@/lib/payments/swish'
|
||||
import type { CompanySettings } from '@/types'
|
||||
|
||||
export default function InvoicingSettingsPage() {
|
||||
@@ -31,6 +32,7 @@ export default function InvoicingSettingsPage() {
|
||||
clearing_number: formData.get('clearing_number') as string,
|
||||
account_number: formData.get('account_number') as string,
|
||||
bankgiro: (formData.get('bankgiro') as string) || null,
|
||||
swish: normaliseSwish(formData.get('swish') as string) || null,
|
||||
invoice_prefix: (formData.get('invoice_prefix') as string) || null,
|
||||
next_invoice_number: parseInt(formData.get('next_invoice_number') as string) || 1,
|
||||
invoice_default_days: parseInt(formData.get('invoice_default_days') as string) || 30,
|
||||
|
||||
@@ -0,0 +1,147 @@
|
||||
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
||||
import { createMockRequest, parseJsonResponse } from '@/tests/helpers'
|
||||
|
||||
vi.mock('@/lib/supabase/server', () => ({
|
||||
createClient: vi.fn(),
|
||||
createServiceClient: vi.fn(),
|
||||
}))
|
||||
|
||||
import { createClient, createServiceClient } from '@/lib/supabase/server'
|
||||
import { POST } from '../route'
|
||||
|
||||
const mockCreateClient = vi.mocked(createClient)
|
||||
const mockCreateServiceClient = vi.mocked(createServiceClient)
|
||||
|
||||
function mockUserClient(opts: {
|
||||
user: { id: string } | null
|
||||
updateUserError?: { message: string; status?: number; code?: string } | null
|
||||
}) {
|
||||
const updateUser = vi.fn().mockResolvedValue({
|
||||
data: {},
|
||||
error: opts.updateUserError ?? null,
|
||||
})
|
||||
|
||||
mockCreateClient.mockResolvedValue({
|
||||
auth: {
|
||||
getUser: vi.fn().mockResolvedValue({ data: { user: opts.user } }),
|
||||
updateUser,
|
||||
},
|
||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
||||
} as any)
|
||||
|
||||
return { updateUser }
|
||||
}
|
||||
|
||||
function mockService(opts: {
|
||||
priorAppMetadata?: Record<string, unknown>
|
||||
updateUserByIdError?: Error | null
|
||||
}) {
|
||||
const updateUserById = opts.updateUserByIdError
|
||||
? vi.fn().mockRejectedValue(opts.updateUserByIdError)
|
||||
: vi.fn().mockResolvedValue({ data: {}, error: null })
|
||||
|
||||
const getUserById = vi.fn().mockResolvedValue({
|
||||
data: { user: { app_metadata: opts.priorAppMetadata ?? {} } },
|
||||
})
|
||||
|
||||
mockCreateServiceClient.mockReturnValue({
|
||||
auth: { admin: { getUserById, updateUserById } },
|
||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
||||
} as any)
|
||||
|
||||
return { getUserById, updateUserById }
|
||||
}
|
||||
|
||||
const STRONG_PASSWORD = 'StrongP@ssword1'
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks()
|
||||
})
|
||||
|
||||
describe('POST /api/account/password', () => {
|
||||
it('returns 401 when unauthenticated', async () => {
|
||||
mockUserClient({ user: null })
|
||||
mockService({})
|
||||
|
||||
const req = createMockRequest('/api/account/password', {
|
||||
method: 'POST',
|
||||
body: { password: STRONG_PASSWORD },
|
||||
})
|
||||
const { status } = await parseJsonResponse(await POST(req))
|
||||
expect(status).toBe(401)
|
||||
})
|
||||
|
||||
it('returns 400 when password is too weak', async () => {
|
||||
mockUserClient({ user: { id: 'user-1' } })
|
||||
mockService({})
|
||||
|
||||
const req = createMockRequest('/api/account/password', {
|
||||
method: 'POST',
|
||||
body: { password: 'weak' },
|
||||
})
|
||||
const { status } = await parseJsonResponse(await POST(req))
|
||||
expect(status).toBe(400)
|
||||
})
|
||||
|
||||
it('returns 400 when Supabase rejects the password update', async () => {
|
||||
const { updateUser } = mockUserClient({
|
||||
user: { id: 'user-1' },
|
||||
updateUserError: { message: 'Password too similar to old', status: 400 },
|
||||
})
|
||||
const { updateUserById } = mockService({})
|
||||
|
||||
const req = createMockRequest('/api/account/password', {
|
||||
method: 'POST',
|
||||
body: { password: STRONG_PASSWORD },
|
||||
})
|
||||
const { status, body } = await parseJsonResponse<{ error?: string }>(
|
||||
await POST(req),
|
||||
)
|
||||
expect(status).toBe(400)
|
||||
expect(body.error).toContain('Password too similar')
|
||||
expect(updateUser).toHaveBeenCalledWith({ password: STRONG_PASSWORD })
|
||||
// Flag should NOT be flipped on a failed password update
|
||||
expect(updateUserById).not.toHaveBeenCalled()
|
||||
})
|
||||
|
||||
it('flips app_metadata.has_password to true on success and preserves siblings', async () => {
|
||||
const { updateUser } = mockUserClient({ user: { id: 'user-1' } })
|
||||
const { getUserById, updateUserById } = mockService({
|
||||
priorAppMetadata: { bankid_linked: true, provider: 'email' },
|
||||
})
|
||||
|
||||
const req = createMockRequest('/api/account/password', {
|
||||
method: 'POST',
|
||||
body: { password: STRONG_PASSWORD },
|
||||
})
|
||||
const { status, body } = await parseJsonResponse<{ data?: { ok: boolean } }>(
|
||||
await POST(req),
|
||||
)
|
||||
expect(status).toBe(200)
|
||||
expect(body.data?.ok).toBe(true)
|
||||
expect(updateUser).toHaveBeenCalledWith({ password: STRONG_PASSWORD })
|
||||
expect(getUserById).toHaveBeenCalledWith('user-1')
|
||||
expect(updateUserById).toHaveBeenCalledWith('user-1', {
|
||||
app_metadata: {
|
||||
bankid_linked: true,
|
||||
provider: 'email',
|
||||
has_password: true,
|
||||
},
|
||||
})
|
||||
})
|
||||
|
||||
it('still returns success when the flag flip fails (password is set; logged)', async () => {
|
||||
mockUserClient({ user: { id: 'user-1' } })
|
||||
mockService({ updateUserByIdError: new Error('admin down') })
|
||||
|
||||
const req = createMockRequest('/api/account/password', {
|
||||
method: 'POST',
|
||||
body: { password: STRONG_PASSWORD },
|
||||
})
|
||||
const { status, body } = await parseJsonResponse<{ data?: { ok: boolean } }>(
|
||||
await POST(req),
|
||||
)
|
||||
expect(status).toBe(200)
|
||||
expect(body.data?.ok).toBe(true)
|
||||
})
|
||||
})
|
||||
@@ -0,0 +1,93 @@
|
||||
import { createClient, createServiceClient } from '@/lib/supabase/server'
|
||||
import { NextResponse } from 'next/server'
|
||||
import { z } from 'zod'
|
||||
import { validateBody } from '@/lib/api/validate'
|
||||
import { createLogger } from '@/lib/logger'
|
||||
|
||||
const log = createLogger('api/account/password')
|
||||
|
||||
const SetPasswordSchema = z.object({
|
||||
password: z
|
||||
.string()
|
||||
.min(8, 'Lösenordet måste vara minst 8 tecken')
|
||||
.refine(
|
||||
(v) =>
|
||||
/[a-z]/.test(v) &&
|
||||
/[A-Z]/.test(v) &&
|
||||
/[0-9]/.test(v) &&
|
||||
/[^a-zA-Z0-9]/.test(v),
|
||||
'Lösenordet måste innehålla versaler, gemener, siffror och specialtecken',
|
||||
),
|
||||
})
|
||||
|
||||
/**
|
||||
* POST /api/account/password
|
||||
*
|
||||
* Server-routed password set/change. Wraps `supabase.auth.updateUser({ password })`
|
||||
* on the user's own session, then flips `app_metadata.has_password = true` via the
|
||||
* service client (clients can't write app_metadata).
|
||||
*
|
||||
* This route is the single write path for setting a password. SecuritySettings,
|
||||
* the reset-password page, and the new /account/set-password page all funnel
|
||||
* through here so the flag stays in sync — see lib/auth/has-password.ts.
|
||||
*
|
||||
* If the password update succeeds but the flag write fails, we log and still
|
||||
* return success: the user has a working password and the banner will show one
|
||||
* more time, but a retry will re-flip the flag.
|
||||
*/
|
||||
export async function POST(request: Request) {
|
||||
const supabase = await createClient()
|
||||
|
||||
const {
|
||||
data: { user },
|
||||
} = await supabase.auth.getUser()
|
||||
if (!user) {
|
||||
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
|
||||
}
|
||||
|
||||
const result = await validateBody(request, SetPasswordSchema)
|
||||
if (!result.success) return result.response
|
||||
const { password } = result.data
|
||||
|
||||
const { error: updateError } = await supabase.auth.updateUser({ password })
|
||||
if (updateError) {
|
||||
log.warn('updateUser({password}) failed', {
|
||||
userId: user.id,
|
||||
code: (updateError as { code?: string }).code,
|
||||
status: updateError.status,
|
||||
})
|
||||
return NextResponse.json(
|
||||
{
|
||||
error:
|
||||
updateError.message ||
|
||||
'Kunde inte uppdatera lösenord. Försök igen.',
|
||||
},
|
||||
{ status: 400 },
|
||||
)
|
||||
}
|
||||
|
||||
// Read-merge-write so we don't wipe sibling app_metadata keys.
|
||||
// updateUserById replaces app_metadata wholesale (see lib/auth/has-password.ts
|
||||
// and the comment in app/api/account/delete/route.ts).
|
||||
const service = createServiceClient()
|
||||
let flagWriteOk = false
|
||||
try {
|
||||
const { data: u } = await service.auth.admin.getUserById(user.id)
|
||||
const prior = u?.user?.app_metadata ?? {}
|
||||
await service.auth.admin.updateUserById(user.id, {
|
||||
app_metadata: { ...prior, has_password: true },
|
||||
})
|
||||
flagWriteOk = true
|
||||
} catch (err) {
|
||||
log.error('failed to flip has_password flag after successful password set', {
|
||||
userId: user.id,
|
||||
err,
|
||||
})
|
||||
// Don't surface the failure: the user has a working password. The
|
||||
// banner will show once more and a retry will succeed.
|
||||
}
|
||||
|
||||
log.info('password set', { userId: user.id, flagWriteOk })
|
||||
|
||||
return NextResponse.json({ data: { ok: true } })
|
||||
}
|
||||
@@ -0,0 +1,67 @@
|
||||
'use client'
|
||||
|
||||
import {
|
||||
Dialog,
|
||||
DialogContent,
|
||||
DialogHeader,
|
||||
DialogTitle,
|
||||
DialogDescription,
|
||||
DialogFooter,
|
||||
} from '@/components/ui/dialog'
|
||||
import { Button } from '@/components/ui/button'
|
||||
import { LogoUpload } from '@/components/settings/LogoUpload'
|
||||
|
||||
interface FirstInvoiceLogoPromptProps {
|
||||
open: boolean
|
||||
onClose: () => void
|
||||
logoUrl: string | null
|
||||
onLogoUpdate: (url: string | null) => void
|
||||
}
|
||||
|
||||
/**
|
||||
* One-shot dialog offered after the user creates their first invoice and has
|
||||
* no logo on file. Reuses the same LogoUpload control as settings, so the
|
||||
* upload, MIME validation, and preview are identical to the canonical flow.
|
||||
*
|
||||
* The PDF reads logo_url live at render time, so uploading now still applies
|
||||
* to the just-created invoice when it is later previewed or sent.
|
||||
*/
|
||||
export function FirstInvoiceLogoPrompt({
|
||||
open,
|
||||
onClose,
|
||||
logoUrl,
|
||||
onLogoUpdate,
|
||||
}: FirstInvoiceLogoPromptProps) {
|
||||
return (
|
||||
<Dialog open={open} onOpenChange={(o) => !o && onClose()}>
|
||||
<DialogContent className="sm:max-w-md">
|
||||
<DialogHeader>
|
||||
<DialogTitle className="font-display text-xl tracking-tight">
|
||||
Lägg till en logotyp?
|
||||
</DialogTitle>
|
||||
<DialogDescription>
|
||||
Din första faktura är skapad. Vill du ladda upp en logotyp som
|
||||
visas i sidhuvudet? Du kan ändra den senare i{' '}
|
||||
<a
|
||||
href="/settings/company"
|
||||
className="underline underline-offset-2 hover:text-foreground"
|
||||
>
|
||||
Inställningar
|
||||
</a>
|
||||
.
|
||||
</DialogDescription>
|
||||
</DialogHeader>
|
||||
|
||||
<div className="py-2">
|
||||
<LogoUpload logoUrl={logoUrl} onUpdate={onLogoUpdate} />
|
||||
</div>
|
||||
|
||||
<DialogFooter>
|
||||
<Button variant={logoUrl ? 'default' : 'ghost'} onClick={onClose}>
|
||||
{logoUrl ? 'Klar' : 'Hoppa över'}
|
||||
</Button>
|
||||
</DialogFooter>
|
||||
</DialogContent>
|
||||
</Dialog>
|
||||
)
|
||||
}
|
||||
@@ -5,6 +5,7 @@ import { Input } from '@/components/ui/input'
|
||||
import { Label } from '@/components/ui/label'
|
||||
import { BankNameCombobox } from '@/components/settings/BankNameCombobox'
|
||||
import { validateBankgiroNumber, formatBankgiroNumber } from '@/lib/bankgiro/luhn'
|
||||
import { normaliseSwish, isValidSwish } from '@/lib/payments/swish'
|
||||
import { ENABLED_EXTENSION_IDS } from '@/lib/extensions/_generated/enabled-extensions'
|
||||
import type { CompanySettings } from '@/types'
|
||||
|
||||
@@ -16,6 +17,7 @@ export function BankDetailsForm({ settings }: BankDetailsFormProps) {
|
||||
const [bankgiroError, setBankgiroError] = useState<string | null>(null)
|
||||
const [clearingError, setClearingError] = useState<string | null>(null)
|
||||
const [accountNumberError, setAccountNumberError] = useState<string | null>(null)
|
||||
const [swishError, setSwishError] = useState<string | null>(null)
|
||||
const hasBankingExtension = ENABLED_EXTENSION_IDS.has('enable-banking')
|
||||
|
||||
return (
|
||||
@@ -77,25 +79,48 @@ export function BankDetailsForm({ settings }: BankDetailsFormProps) {
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="max-w-xs space-y-2">
|
||||
<Label htmlFor="bankgiro">Bankgiro</Label>
|
||||
<Input
|
||||
id="bankgiro"
|
||||
name="bankgiro"
|
||||
placeholder="XXX-XXXX"
|
||||
defaultValue={settings.bankgiro || ''}
|
||||
onBlur={(e) => {
|
||||
const val = e.target.value.trim()
|
||||
if (!val) { setBankgiroError(null); return }
|
||||
if (validateBankgiroNumber(val)) {
|
||||
e.target.value = formatBankgiroNumber(val)
|
||||
setBankgiroError(null)
|
||||
} else {
|
||||
setBankgiroError('Ogiltigt bankgironummer')
|
||||
}
|
||||
}}
|
||||
/>
|
||||
{bankgiroError && <p className="text-xs text-destructive">{bankgiroError}</p>}
|
||||
<div className="grid grid-cols-1 sm:grid-cols-2 gap-4">
|
||||
<div className="space-y-2">
|
||||
<Label htmlFor="bankgiro">Bankgiro</Label>
|
||||
<Input
|
||||
id="bankgiro"
|
||||
name="bankgiro"
|
||||
placeholder="XXX-XXXX"
|
||||
defaultValue={settings.bankgiro || ''}
|
||||
onBlur={(e) => {
|
||||
const val = e.target.value.trim()
|
||||
if (!val) { setBankgiroError(null); return }
|
||||
if (validateBankgiroNumber(val)) {
|
||||
e.target.value = formatBankgiroNumber(val)
|
||||
setBankgiroError(null)
|
||||
} else {
|
||||
setBankgiroError('Ogiltigt bankgironummer')
|
||||
}
|
||||
}}
|
||||
/>
|
||||
{bankgiroError && <p className="text-xs text-destructive">{bankgiroError}</p>}
|
||||
</div>
|
||||
|
||||
<div className="space-y-2">
|
||||
<Label htmlFor="swish">Swish</Label>
|
||||
<Input
|
||||
id="swish"
|
||||
name="swish"
|
||||
placeholder="123 XXX XX XX eller 07X XXX XX XX"
|
||||
defaultValue={settings.swish || ''}
|
||||
onBlur={(e) => {
|
||||
const val = normaliseSwish(e.target.value)
|
||||
if (!val) { setSwishError(null); e.target.value = ''; return }
|
||||
if (isValidSwish(val)) {
|
||||
e.target.value = val
|
||||
setSwishError(null)
|
||||
} else {
|
||||
setSwishError('Ogiltigt Swish-nummer (företagsnummer 123XXXXXXX eller mobilnummer 07XXXXXXXX)')
|
||||
}
|
||||
}}
|
||||
/>
|
||||
{swishError && <p className="text-xs text-destructive">{swishError}</p>}
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
)
|
||||
@@ -107,6 +132,7 @@ export function validateBankFields(formData: FormData): { field: string; message
|
||||
const clearing = (formData.get('clearing_number') as string || '').trim()
|
||||
const account = (formData.get('account_number') as string || '').trim()
|
||||
const bankgiro = (formData.get('bankgiro') as string || '').trim()
|
||||
const swish = normaliseSwish(formData.get('swish') as string)
|
||||
|
||||
if (clearing && !/^\d{4,5}$/.test(clearing)) {
|
||||
errors.push({ field: 'clearing_number', message: 'Clearingnummer måste vara 4-5 siffror' })
|
||||
@@ -117,5 +143,8 @@ export function validateBankFields(formData: FormData): { field: string; message
|
||||
if (bankgiro && !validateBankgiroNumber(bankgiro)) {
|
||||
errors.push({ field: 'bankgiro', message: 'Ogiltigt bankgironummer' })
|
||||
}
|
||||
if (swish && !isValidSwish(swish)) {
|
||||
errors.push({ field: 'swish', message: 'Ogiltigt Swish-nummer (företagsnummer 123XXXXXXX eller mobilnummer 07XXXXXXXX)' })
|
||||
}
|
||||
return errors
|
||||
}
|
||||
|
||||
@@ -110,6 +110,17 @@ export function PdfPrintSettings({ settings, onUpdate }: PdfPrintSettingsProps)
|
||||
/>
|
||||
</div>
|
||||
|
||||
<div className="flex items-center justify-between">
|
||||
<div>
|
||||
<Label>Visa Swish</Label>
|
||||
<p className="text-xs text-muted-foreground">Visa Swish-nummer på fakturautskrift</p>
|
||||
</div>
|
||||
<Switch
|
||||
checked={settings.invoice_show_swish ?? true}
|
||||
onCheckedChange={(v) => saveToggle('invoice_show_swish', v)}
|
||||
/>
|
||||
</div>
|
||||
|
||||
<div className="flex items-center justify-between">
|
||||
<div>
|
||||
<Label>Visa logga</Label>
|
||||
@@ -190,6 +201,25 @@ export function PdfPrintSettings({ settings, onUpdate }: PdfPrintSettingsProps)
|
||||
/>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="pt-6 space-y-4">
|
||||
<h2 className="text-sm font-medium uppercase tracking-wider text-muted-foreground">
|
||||
Automatisering
|
||||
</h2>
|
||||
|
||||
<div className="flex items-center justify-between">
|
||||
<div>
|
||||
<Label>Skicka automatiska påminnelser</Label>
|
||||
<p className="text-xs text-muted-foreground">
|
||||
Skicka påminnelser till kunder för försenade fakturor enligt din inställning för påminnelseintervall.
|
||||
</p>
|
||||
</div>
|
||||
<Switch
|
||||
checked={settings.send_invoice_reminders ?? true}
|
||||
onCheckedChange={(v) => saveToggle('send_invoice_reminders', v)}
|
||||
/>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
)
|
||||
}
|
||||
|
||||
@@ -12,6 +12,7 @@ import { Loader2, ShieldCheck, ShieldOff, KeyRound } from 'lucide-react'
|
||||
import { isMfaRequired } from '@/lib/auth/mfa'
|
||||
import { isBankIdEnabled } from '@/lib/auth/bankid'
|
||||
import { BankIdSettings } from '@/components/settings/BankIdSettings'
|
||||
import { userHasPassword } from '@/lib/auth/has-password'
|
||||
|
||||
const isSelfHosted = process.env.NEXT_PUBLIC_SELF_HOSTED === 'true'
|
||||
const mfaRequired = isMfaRequired()
|
||||
@@ -25,19 +26,24 @@ export function SecuritySettings() {
|
||||
const [isLoadingMfa, setIsLoadingMfa] = useState(true)
|
||||
const [isUnenrolling, setIsUnenrolling] = useState(false)
|
||||
const [mfaFactorId, setMfaFactorId] = useState<string | null>(null)
|
||||
const [hasPassword, setHasPassword] = useState<boolean | null>(null)
|
||||
const { toast } = useToast()
|
||||
const router = useRouter()
|
||||
const supabase = createClient()
|
||||
|
||||
useEffect(() => {
|
||||
async function loadMfaStatus() {
|
||||
const { data } = await supabase.auth.mfa.listFactors()
|
||||
const verifiedFactor = data?.totp?.find(f => f.status === 'verified')
|
||||
async function loadStatus() {
|
||||
const [{ data: factors }, { data: userData }] = await Promise.all([
|
||||
supabase.auth.mfa.listFactors(),
|
||||
supabase.auth.getUser(),
|
||||
])
|
||||
const verifiedFactor = factors?.totp?.find(f => f.status === 'verified')
|
||||
setHasMfa(!!verifiedFactor)
|
||||
setMfaFactorId(verifiedFactor?.id ?? null)
|
||||
setHasPassword(userData?.user ? userHasPassword(userData.user) : null)
|
||||
setIsLoadingMfa(false)
|
||||
}
|
||||
loadMfaStatus()
|
||||
loadStatus()
|
||||
// eslint-disable-next-line react-hooks/exhaustive-deps
|
||||
}, [])
|
||||
|
||||
@@ -72,12 +78,17 @@ export function SecuritySettings() {
|
||||
}
|
||||
|
||||
try {
|
||||
const { error } = await supabase.auth.updateUser({ password: newPassword })
|
||||
const res = await fetch('/api/account/password', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ password: newPassword }),
|
||||
})
|
||||
|
||||
if (error) {
|
||||
if (!res.ok) {
|
||||
const body = (await res.json().catch(() => ({}))) as { error?: string }
|
||||
toast({
|
||||
title: 'Kunde inte uppdatera lösenord',
|
||||
description: error.message,
|
||||
description: body.error || 'Försök igen senare.',
|
||||
variant: 'destructive',
|
||||
})
|
||||
return
|
||||
@@ -89,6 +100,7 @@ export function SecuritySettings() {
|
||||
})
|
||||
setNewPassword('')
|
||||
setConfirmPassword('')
|
||||
setHasPassword(true)
|
||||
} catch {
|
||||
toast({
|
||||
title: 'Något gick fel',
|
||||
@@ -136,7 +148,36 @@ export function SecuritySettings() {
|
||||
return (
|
||||
<div className="space-y-6">
|
||||
{bankIdEnabled && <BankIdSettings />}
|
||||
{/* Change password */}
|
||||
|
||||
{/* BankID-only users with no password — banner above everything else */}
|
||||
{hasPassword === false && (
|
||||
<Card>
|
||||
<CardHeader>
|
||||
<CardTitle className="flex items-center gap-2 text-base">
|
||||
<KeyRound className="h-4 w-4" />
|
||||
Sätt ett lösenord
|
||||
</CardTitle>
|
||||
<CardDescription>
|
||||
Du loggade in med BankID och har inget lösenord ännu. Sätt ett
|
||||
lösenord för att kunna aktivera 2FA eller logga in när BankID
|
||||
inte är tillgängligt.
|
||||
</CardDescription>
|
||||
</CardHeader>
|
||||
<CardContent>
|
||||
<Button
|
||||
onClick={() =>
|
||||
router.push('/account/set-password?returnTo=/settings/account')
|
||||
}
|
||||
>
|
||||
Sätt lösenord
|
||||
</Button>
|
||||
</CardContent>
|
||||
</Card>
|
||||
)}
|
||||
|
||||
{/* Change password — hidden when the user has no password (the banner
|
||||
above handles the set-initial-password flow). */}
|
||||
{hasPassword !== false && (
|
||||
<Card>
|
||||
<CardHeader>
|
||||
<CardTitle className="flex items-center gap-2">
|
||||
@@ -190,6 +231,7 @@ export function SecuritySettings() {
|
||||
</form>
|
||||
</CardContent>
|
||||
</Card>
|
||||
)}
|
||||
|
||||
{/* MFA — hidden for self-hosted */}
|
||||
{!isSelfHosted && (
|
||||
@@ -257,12 +299,24 @@ export function SecuritySettings() {
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
<Button
|
||||
onClick={() => router.push(`/mfa/enroll?returnTo=${encodeURIComponent('/settings/account')}`)}
|
||||
>
|
||||
<ShieldCheck className="mr-2 h-4 w-4" />
|
||||
Aktivera 2FA
|
||||
</Button>
|
||||
{hasPassword === false ? (
|
||||
<Button
|
||||
onClick={() =>
|
||||
router.push(
|
||||
'/account/set-password?returnTo=/mfa/enroll',
|
||||
)
|
||||
}
|
||||
>
|
||||
Sätt ett lösenord först
|
||||
</Button>
|
||||
) : (
|
||||
<Button
|
||||
onClick={() => router.push(`/mfa/enroll?returnTo=${encodeURIComponent('/settings/account')}`)}
|
||||
>
|
||||
<ShieldCheck className="mr-2 h-4 w-4" />
|
||||
Aktivera 2FA
|
||||
</Button>
|
||||
)}
|
||||
</div>
|
||||
)}
|
||||
</CardContent>
|
||||
|
||||
@@ -159,7 +159,9 @@ describe('POST /bankid/complete', () => {
|
||||
)
|
||||
expect(admin.updateUserById).toHaveBeenCalledWith(
|
||||
'new-user-uuid',
|
||||
expect.objectContaining({ app_metadata: { bankid_linked: true } })
|
||||
expect.objectContaining({
|
||||
app_metadata: { bankid_linked: true, has_password: false },
|
||||
})
|
||||
)
|
||||
})
|
||||
})
|
||||
|
||||
@@ -756,9 +756,12 @@ export const ticExtension: Extension = {
|
||||
|
||||
const userId = newUser.user.id
|
||||
|
||||
// Mark user as BankID-linked (skips TOTP MFA)
|
||||
// Mark user as BankID-linked (skips TOTP MFA) and record that they
|
||||
// do not have a password yet — the BankID signup gave them a random
|
||||
// server-side password they will never see. This flag gates MFA
|
||||
// enrollment (see lib/auth/has-password.ts).
|
||||
await supabase.auth.admin.updateUserById(userId, {
|
||||
app_metadata: { bankid_linked: true },
|
||||
app_metadata: { bankid_linked: true, has_password: false },
|
||||
})
|
||||
|
||||
// Store BankID identity
|
||||
@@ -911,9 +914,15 @@ export const ticExtension: Extension = {
|
||||
)
|
||||
}
|
||||
|
||||
// Mark user as BankID-linked (skips TOTP MFA)
|
||||
// Read-merge-write: updateUserById REPLACES app_metadata wholesale
|
||||
// (see app/api/account/password/route.ts). Passing just
|
||||
// { bankid_linked: true } would wipe has_password for users who
|
||||
// already set one — they'd then be incorrectly shown the
|
||||
// set-password banner on their next session.
|
||||
const { data: priorUser } = await supabase.auth.admin.getUserById(ctx.userId)
|
||||
const priorMeta = priorUser?.user?.app_metadata ?? {}
|
||||
await supabase.auth.admin.updateUserById(ctx.userId, {
|
||||
app_metadata: { bankid_linked: true },
|
||||
app_metadata: { ...priorMeta, bankid_linked: true },
|
||||
})
|
||||
|
||||
return NextResponse.json({ data: { linked: true } })
|
||||
|
||||
@@ -1129,6 +1129,48 @@ describe('UpdateSettingsSchema', () => {
|
||||
const result = UpdateSettingsSchema.safeParse({ invoice_default_days: 30.5 })
|
||||
expect(result.success).toBe(false)
|
||||
})
|
||||
|
||||
describe('swish', () => {
|
||||
it('accepts a Swish-företag number (123XXXXXXX)', () => {
|
||||
const result = UpdateSettingsSchema.safeParse({ swish: '1234567890' })
|
||||
expect(result.success).toBe(true)
|
||||
if (result.success) expect(result.data.swish).toBe('1234567890')
|
||||
})
|
||||
|
||||
it('accepts a Swedish mobile number (07XXXXXXXX)', () => {
|
||||
const result = UpdateSettingsSchema.safeParse({ swish: '0701234567' })
|
||||
expect(result.success).toBe(true)
|
||||
if (result.success) expect(result.data.swish).toBe('0701234567')
|
||||
})
|
||||
|
||||
it('strips whitespace and hyphens before validating', () => {
|
||||
const result = UpdateSettingsSchema.safeParse({ swish: '123 456 78 90' })
|
||||
expect(result.success).toBe(true)
|
||||
if (result.success) expect(result.data.swish).toBe('1234567890')
|
||||
})
|
||||
|
||||
it('rejects a non-Swish-företag, non-mobile number', () => {
|
||||
const result = UpdateSettingsSchema.safeParse({ swish: '0123456789' })
|
||||
expect(result.success).toBe(false)
|
||||
})
|
||||
|
||||
it('accepts empty string for clearing the value', () => {
|
||||
const result = UpdateSettingsSchema.safeParse({ swish: '' })
|
||||
expect(result.success).toBe(true)
|
||||
})
|
||||
|
||||
it('accepts invoice_show_swish toggle', () => {
|
||||
const result = UpdateSettingsSchema.safeParse({ invoice_show_swish: false })
|
||||
expect(result.success).toBe(true)
|
||||
})
|
||||
})
|
||||
|
||||
describe('send_invoice_reminders', () => {
|
||||
it('accepts the kill-switch toggle', () => {
|
||||
const result = UpdateSettingsSchema.safeParse({ send_invoice_reminders: false })
|
||||
expect(result.success).toBe(true)
|
||||
})
|
||||
})
|
||||
})
|
||||
|
||||
// ============================================================
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
import { z } from 'zod'
|
||||
import { normaliseSwish, isValidSwish } from '@/lib/payments/swish'
|
||||
|
||||
// ============================================================
|
||||
// Shared primitives
|
||||
@@ -481,6 +482,16 @@ export const UpdateSettingsSchema = z.object({
|
||||
account_number: z.string().regex(/^\d{6,12}$/, 'Kontonummer måste vara 6-12 siffror').optional().or(z.literal('')),
|
||||
bankgiro: z.string().regex(/^(\d{3,4}-\d{4}|\d{7,8})$/, 'Ogiltigt bankgironummer (7-8 siffror)').nullable().optional().or(z.literal('')),
|
||||
plusgiro: z.string().regex(/^\d{1,7}-\d{1}$/, 'Ogiltigt plusgironummer').nullable().optional().or(z.literal('')),
|
||||
swish: z.string()
|
||||
.transform(normaliseSwish)
|
||||
.pipe(
|
||||
z.string().refine(
|
||||
isValidSwish,
|
||||
'Ogiltigt Swish-nummer (företagsnummer 123XXXXXXX eller mobilnummer 07XXXXXXXX)',
|
||||
),
|
||||
)
|
||||
.nullable()
|
||||
.optional(),
|
||||
iban: z.string().optional(),
|
||||
bic: z.string().optional(),
|
||||
accounting_method: AccountingMethodSchema.optional(),
|
||||
@@ -503,11 +514,14 @@ export const UpdateSettingsSchema = z.object({
|
||||
invoice_show_ocr: z.boolean().optional(),
|
||||
invoice_show_bankgiro: z.boolean().optional(),
|
||||
invoice_show_plusgiro: z.boolean().optional(),
|
||||
invoice_show_swish: z.boolean().optional(),
|
||||
invoice_show_logo: z.boolean().optional(),
|
||||
invoice_show_company_name: z.boolean().optional(),
|
||||
invoice_company_name_position: z.enum(['header', 'footer']).optional(),
|
||||
invoice_late_fee_text: z.string().nullable().optional(),
|
||||
invoice_credit_terms_text: z.string().nullable().optional(),
|
||||
// Automation
|
||||
send_invoice_reminders: z.boolean().optional(),
|
||||
// AI agent flow
|
||||
ai_flow_enabled: z.boolean().optional(),
|
||||
// Salary payment file
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
import { describe, it, expect } from 'vitest'
|
||||
import { userHasPassword } from '../has-password'
|
||||
|
||||
describe('userHasPassword', () => {
|
||||
it('returns true when has_password === true', () => {
|
||||
expect(userHasPassword({ app_metadata: { has_password: true } })).toBe(true)
|
||||
})
|
||||
|
||||
it('returns false when has_password === false', () => {
|
||||
expect(userHasPassword({ app_metadata: { has_password: false } })).toBe(false)
|
||||
})
|
||||
|
||||
it('returns false when flag is missing but bankid_linked === true', () => {
|
||||
expect(userHasPassword({ app_metadata: { bankid_linked: true } })).toBe(false)
|
||||
})
|
||||
|
||||
it('returns true when flag is missing and bankid_linked is not true (legacy email/password user)', () => {
|
||||
expect(userHasPassword({ app_metadata: {} })).toBe(true)
|
||||
expect(userHasPassword({ app_metadata: { bankid_linked: false } })).toBe(true)
|
||||
})
|
||||
|
||||
it('returns true when app_metadata is missing entirely', () => {
|
||||
expect(userHasPassword({ app_metadata: undefined as unknown as Record<string, unknown> })).toBe(true)
|
||||
})
|
||||
|
||||
it('prefers explicit has_password over bankid_linked (BankID user who later set a password)', () => {
|
||||
expect(
|
||||
userHasPassword({ app_metadata: { bankid_linked: true, has_password: true } }),
|
||||
).toBe(true)
|
||||
})
|
||||
})
|
||||
@@ -0,0 +1,42 @@
|
||||
import { describe, it, expect } from 'vitest'
|
||||
import { safeReturnTo } from '../safe-return-to'
|
||||
|
||||
describe('safeReturnTo', () => {
|
||||
it('returns the value when it is a same-origin relative path', () => {
|
||||
expect(safeReturnTo('/settings/account', '/')).toBe('/settings/account')
|
||||
expect(safeReturnTo('/invoices/new', '/')).toBe('/invoices/new')
|
||||
})
|
||||
|
||||
it('preserves search and hash', () => {
|
||||
expect(safeReturnTo('/invoices?status=overdue', '/')).toBe('/invoices?status=overdue')
|
||||
expect(safeReturnTo('/settings/account#mfa', '/')).toBe('/settings/account#mfa')
|
||||
})
|
||||
|
||||
it('returns the fallback for missing or empty values', () => {
|
||||
expect(safeReturnTo(null, '/home')).toBe('/home')
|
||||
expect(safeReturnTo(undefined, '/home')).toBe('/home')
|
||||
expect(safeReturnTo('', '/home')).toBe('/home')
|
||||
})
|
||||
|
||||
it('rejects absolute URLs', () => {
|
||||
expect(safeReturnTo('https://evil.com/path', '/')).toBe('/')
|
||||
expect(safeReturnTo('http://evil.com', '/')).toBe('/')
|
||||
})
|
||||
|
||||
it('rejects protocol-relative URLs', () => {
|
||||
expect(safeReturnTo('//evil.com/path', '/')).toBe('/')
|
||||
})
|
||||
|
||||
it('rejects the /\\evil.com browser-quirk form', () => {
|
||||
expect(safeReturnTo('/\\evil.com', '/')).toBe('/')
|
||||
})
|
||||
|
||||
it('rejects the /@user@host form some clients resolve off-origin', () => {
|
||||
expect(safeReturnTo('/@evil.com', '/')).toBe('/')
|
||||
})
|
||||
|
||||
it('rejects values that do not start with /', () => {
|
||||
expect(safeReturnTo('settings', '/')).toBe('/')
|
||||
expect(safeReturnTo('javascript:alert(1)', '/')).toBe('/')
|
||||
})
|
||||
})
|
||||
@@ -0,0 +1,20 @@
|
||||
import type { User } from '@supabase/supabase-js'
|
||||
|
||||
/**
|
||||
* True iff the user has set a password they actually know.
|
||||
*
|
||||
* Source of truth: `app_metadata.has_password` (server-only, set by us — clients
|
||||
* cannot fake it through `updateUser`).
|
||||
*
|
||||
* - BankID signup writes `has_password: false` (they got a random server-side
|
||||
* password they will never see).
|
||||
* - Email/password signup doesn't set the flag — we infer `true` because the
|
||||
* user supplied a password to reach signUp at all.
|
||||
* - The flag flips to `true` after a successful POST /api/account/password.
|
||||
*/
|
||||
export function userHasPassword(user: Pick<User, 'app_metadata'>): boolean {
|
||||
const meta = user.app_metadata ?? {}
|
||||
if (meta.has_password === true) return true
|
||||
if (meta.has_password === false) return false
|
||||
return meta.bankid_linked !== true
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
/**
|
||||
* Validate that a returnTo query param is a same-origin relative path.
|
||||
*
|
||||
* The previous guard only rejected protocol-relative URLs (`//evil.com`),
|
||||
* but `/\evil.com`, `/?@evil.com`, and various other forms can still
|
||||
* redirect off-origin in some browsers. Parse with a real URL and verify
|
||||
* the origin matches.
|
||||
*
|
||||
* Returns the normalised path-with-search-and-hash on success, or the
|
||||
* provided `fallback` if `value` is missing, malformed, or off-origin.
|
||||
*/
|
||||
export function safeReturnTo(value: string | null | undefined, fallback: string): string {
|
||||
if (!value) return fallback
|
||||
if (!value.startsWith('/')) return fallback
|
||||
// Reject protocol-relative and the two known browser-quirk forms.
|
||||
if (value.startsWith('//') || value.startsWith('/\\') || value.startsWith('/@')) {
|
||||
return fallback
|
||||
}
|
||||
try {
|
||||
const base = 'https://gnubok.invalid'
|
||||
const parsed = new URL(value, base)
|
||||
if (parsed.origin !== base) return fallback
|
||||
return parsed.pathname + parsed.search + parsed.hash
|
||||
} catch {
|
||||
return fallback
|
||||
}
|
||||
}
|
||||
@@ -91,11 +91,11 @@ describe('processOverdueReminders — credit-note filter', () => {
|
||||
expect(isCall?.args[1]).toBeNull()
|
||||
})
|
||||
|
||||
it('combines the credit-note filter with status=sent and due_date cutoff', async () => {
|
||||
it('combines the credit-note filter with status allowlist and due_date cutoff', async () => {
|
||||
await processOverdueReminders()
|
||||
|
||||
const eqStatus = chainCalls.find(
|
||||
(c) => c.method === 'eq' && c.args[0] === 'status',
|
||||
const inStatus = chainCalls.find(
|
||||
(c) => c.method === 'in' && c.args[0] === 'status',
|
||||
)
|
||||
const isCreditedNull = chainCalls.find(
|
||||
(c) => c.method === 'is' && c.args[0] === 'credited_invoice_id',
|
||||
@@ -104,8 +104,36 @@ describe('processOverdueReminders — credit-note filter', () => {
|
||||
(c) => c.method === 'lte' && c.args[0] === 'due_date',
|
||||
)
|
||||
|
||||
expect(eqStatus?.args[1]).toBe('sent')
|
||||
expect(inStatus?.args[1]).toEqual(['sent', 'overdue'])
|
||||
expect(isCreditedNull?.args[1]).toBeNull()
|
||||
expect(lteDueDate).toBeDefined()
|
||||
})
|
||||
|
||||
it('uses a positive allowlist (sent + overdue) so paid / partially_paid / cancelled / credited can never match', async () => {
|
||||
await processOverdueReminders()
|
||||
|
||||
const inStatus = chainCalls.find(
|
||||
(c) => c.method === 'in' && c.args[0] === 'status',
|
||||
)
|
||||
expect(inStatus?.args[1]).toEqual(['sent', 'overdue'])
|
||||
|
||||
// Defense in depth: ensure no .eq('status', terminal) somehow snuck in.
|
||||
const eqTerminal = chainCalls.find(
|
||||
(c) =>
|
||||
c.method === 'eq' &&
|
||||
c.args[0] === 'status' &&
|
||||
['paid', 'partially_paid', 'cancelled', 'credited'].includes(
|
||||
c.args[1] as string,
|
||||
),
|
||||
)
|
||||
expect(eqTerminal).toBeUndefined()
|
||||
})
|
||||
|
||||
it('includes overdue in the allowlist so level-2 and level-3 reminders re-fire after the first reminder flips status', async () => {
|
||||
await processOverdueReminders()
|
||||
const inStatus = chainCalls.find(
|
||||
(c) => c.method === 'in' && c.args[0] === 'status',
|
||||
)
|
||||
expect(inStatus?.args[1]).toContain('overdue')
|
||||
})
|
||||
})
|
||||
|
||||
@@ -609,6 +609,12 @@ export function InvoicePDF({ invoice, customer, items, company, originalInvoiceN
|
||||
<Text style={styles.paymentValue}>{company.plusgiro}</Text>
|
||||
</View>
|
||||
)}
|
||||
{company.swish && (company.invoice_show_swish ?? true) && (
|
||||
<View style={styles.paymentRow}>
|
||||
<Text style={styles.paymentLabel}>Swish:</Text>
|
||||
<Text style={styles.paymentValue}>{company.swish}</Text>
|
||||
</View>
|
||||
)}
|
||||
{company.iban && (
|
||||
<View style={styles.paymentRow}>
|
||||
<Text style={styles.paymentLabel}>IBAN:</Text>
|
||||
|
||||
@@ -136,13 +136,16 @@ export async function processOverdueReminders(): Promise<ProcessRemindersResult>
|
||||
const cutoffDate = new Date()
|
||||
cutoffDate.setDate(cutoffDate.getDate() - minOverdueDays)
|
||||
|
||||
// Positive allowlist — inherently excludes 'paid', 'partially_paid', 'cancelled', 'credited'.
|
||||
// Including 'overdue' ensures level-2 / level-3 reminders re-fire after the first reminder
|
||||
// flips status to 'overdue' (see status update below).
|
||||
const { data: overdueInvoices, error: invoiceError } = await supabase
|
||||
.from('invoices')
|
||||
.select(`
|
||||
*,
|
||||
customer:customers(*)
|
||||
`)
|
||||
.eq('status', 'sent')
|
||||
.in('status', ['sent', 'overdue'])
|
||||
.is('credited_invoice_id', null)
|
||||
.lte('due_date', cutoffDate.toISOString().split('T')[0])
|
||||
.order('due_date', { ascending: true })
|
||||
@@ -172,9 +175,21 @@ export async function processOverdueReminders(): Promise<ProcessRemindersResult>
|
||||
// Get existing reminders for this invoice
|
||||
const { data: existingReminders } = await supabase
|
||||
.from('invoice_reminders')
|
||||
.select('reminder_level')
|
||||
.select('reminder_level, response_type')
|
||||
.eq('invoice_id', invoice.id)
|
||||
|
||||
// Skip if customer already responded (marked paid OR disputed) — they've
|
||||
// told us they don't want another reminder. The business owner still needs
|
||||
// to record the actual payment (mark-paid / match-invoice) to flip status
|
||||
// and post the journal entry; we don't do that here because the customer
|
||||
// action is unauthenticated and posting a JE without a verified payment
|
||||
// would put the books out of sync.
|
||||
const customerResponded = existingReminders?.some(r => r.response_type !== null)
|
||||
if (customerResponded) {
|
||||
log.info(`Skipping invoice ${invoice.invoice_number}: customer already responded via reminder link`)
|
||||
continue
|
||||
}
|
||||
|
||||
const existingLevels = existingReminders?.map(r => r.reminder_level) || []
|
||||
const daysOverdue = calculateDaysOverdue(invoice.due_date)
|
||||
const reminderLevel = determineReminderLevel(daysOverdue, existingLevels)
|
||||
@@ -205,6 +220,26 @@ export async function processOverdueReminders(): Promise<ProcessRemindersResult>
|
||||
continue
|
||||
}
|
||||
|
||||
// Per-company kill switch (settings → Fakturering → "Skicka automatiska påminnelser")
|
||||
if (company.send_invoice_reminders === false) {
|
||||
log.info(`Skipping invoice ${invoice.invoice_number}: automatic reminders disabled for company ${invoice.company_id}`)
|
||||
continue
|
||||
}
|
||||
|
||||
// Race-window guard — re-check invoice status immediately before sending.
|
||||
// The cron runs at 08:00; a payment match arriving during the run shouldn't
|
||||
// produce a reminder for an already-paid invoice.
|
||||
const { data: currentInvoice } = await supabase
|
||||
.from('invoices')
|
||||
.select('status')
|
||||
.eq('id', invoice.id)
|
||||
.single()
|
||||
|
||||
if (!currentInvoice || !['sent', 'overdue'].includes(currentInvoice.status as string)) {
|
||||
log.info(`Skipping invoice ${invoice.invoice_number}: status changed to ${currentInvoice?.status ?? 'unknown'} mid-run`)
|
||||
continue
|
||||
}
|
||||
|
||||
// Create reminder record first (to get action token)
|
||||
const { data: reminderRecord, error: reminderError } = await supabase
|
||||
.from('invoice_reminders')
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
import { describe, it, expect } from 'vitest'
|
||||
import { normaliseSwish, isValidSwish } from '../swish'
|
||||
|
||||
describe('normaliseSwish', () => {
|
||||
it('strips whitespace and hyphens', () => {
|
||||
expect(normaliseSwish('123 456 78 90')).toBe('1234567890')
|
||||
expect(normaliseSwish('070-123 45 67')).toBe('0701234567')
|
||||
expect(normaliseSwish(' 1234567890 ')).toBe('1234567890')
|
||||
})
|
||||
|
||||
it('returns empty string for null/undefined/empty', () => {
|
||||
expect(normaliseSwish(null)).toBe('')
|
||||
expect(normaliseSwish(undefined)).toBe('')
|
||||
expect(normaliseSwish('')).toBe('')
|
||||
})
|
||||
})
|
||||
|
||||
describe('isValidSwish', () => {
|
||||
it('accepts Swish Företag numbers (123XXXXXXX)', () => {
|
||||
expect(isValidSwish('1234567890')).toBe(true)
|
||||
expect(isValidSwish('1230000000')).toBe(true)
|
||||
})
|
||||
|
||||
it('accepts Swedish mobile numbers (07XXXXXXXX)', () => {
|
||||
expect(isValidSwish('0701234567')).toBe(true)
|
||||
expect(isValidSwish('0700000000')).toBe(true)
|
||||
})
|
||||
|
||||
it('accepts empty string for clearing the field', () => {
|
||||
expect(isValidSwish('')).toBe(true)
|
||||
})
|
||||
|
||||
it('rejects non-conforming numbers', () => {
|
||||
expect(isValidSwish('0123456789')).toBe(false)
|
||||
expect(isValidSwish('1239')).toBe(false)
|
||||
expect(isValidSwish('12345678901')).toBe(false)
|
||||
expect(isValidSwish('123abc4567')).toBe(false)
|
||||
})
|
||||
})
|
||||
@@ -0,0 +1,23 @@
|
||||
/**
|
||||
* Swish number normalisation + validation.
|
||||
*
|
||||
* Two accepted shapes:
|
||||
* - Swish Företag: `123XXXXXXX` (10 digits starting with `123`)
|
||||
* - Swedish mobile: `07XXXXXXXX` (10 digits starting with `07`)
|
||||
*
|
||||
* Whitespace and hyphens are stripped before validation so users can paste
|
||||
* formatted numbers (`123 456 78 90` or `070-123 45 67`) and have them
|
||||
* canonicalised.
|
||||
*/
|
||||
|
||||
const SWISH_FORETAG = /^123\d{7}$/
|
||||
const SWEDISH_MOBILE = /^07\d{8}$/
|
||||
|
||||
export function normaliseSwish(value: string | null | undefined): string {
|
||||
if (!value) return ''
|
||||
return value.replace(/[\s-]/g, '')
|
||||
}
|
||||
|
||||
export function isValidSwish(normalised: string): boolean {
|
||||
return normalised === '' || SWISH_FORETAG.test(normalised) || SWEDISH_MOBILE.test(normalised)
|
||||
}
|
||||
@@ -20,6 +20,10 @@ function makeBuilder() {
|
||||
function makeClient() {
|
||||
return {
|
||||
from: vi.fn().mockImplementation(() => makeBuilder()),
|
||||
// `rpc` drains the same queue so tests can intersperse RPC + table fetches.
|
||||
// SIE export calls `compute_prior_opening_balances` via getOpeningBalances
|
||||
// whenever `opening_balance_entry_id` is null (the multi-year-import path).
|
||||
rpc: vi.fn().mockImplementation(async () => results[resultIdx++] ?? { data: null, error: null }),
|
||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
||||
} as any
|
||||
}
|
||||
@@ -67,6 +71,8 @@ describe('generateSIEExport', () => {
|
||||
{ data: [], error: null },
|
||||
// 5: projects (empty)
|
||||
{ data: [], error: null },
|
||||
// 6: compute_prior_opening_balances RPC (empty — no IB)
|
||||
{ data: [], error: null },
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
@@ -90,6 +96,7 @@ describe('generateSIEExport', () => {
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null }, // RPC fallback
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', {
|
||||
@@ -114,6 +121,7 @@ describe('generateSIEExport', () => {
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null }, // RPC fallback
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
@@ -150,6 +158,7 @@ describe('generateSIEExport', () => {
|
||||
},
|
||||
{ data: [], error: null }, // cost_centers
|
||||
{ data: [], error: null }, // projects
|
||||
{ data: [], error: null }, // RPC fallback
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
@@ -180,6 +189,7 @@ describe('generateSIEExport', () => {
|
||||
],
|
||||
error: null,
|
||||
},
|
||||
{ data: [], error: null }, // RPC fallback
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
@@ -214,6 +224,7 @@ describe('generateSIEExport', () => {
|
||||
},
|
||||
{ data: [{ code: 'CC1', name: 'Avdelning 1', is_active: true }], error: null },
|
||||
{ data: [{ code: 'P001', name: 'Projekt Alpha', is_active: true }], error: null },
|
||||
{ data: [], error: null }, // RPC fallback
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
@@ -247,6 +258,7 @@ describe('generateSIEExport', () => {
|
||||
},
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null }, // RPC fallback
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
@@ -283,6 +295,7 @@ describe('generateSIEExport', () => {
|
||||
},
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null }, // RPC fallback
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
@@ -298,6 +311,7 @@ describe('generateSIEExport', () => {
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null }, // RPC fallback
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
@@ -321,6 +335,7 @@ describe('generateSIEExport', () => {
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null }, // RPC fallback
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
@@ -337,6 +352,7 @@ describe('generateSIEExport', () => {
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null },
|
||||
{ data: [], error: null }, // RPC fallback
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
@@ -344,4 +360,67 @@ describe('generateSIEExport', () => {
|
||||
expect(output).not.toContain('#DIM')
|
||||
expect(output).not.toContain('#OBJEKT')
|
||||
})
|
||||
|
||||
it('emits #IB from compute_prior_opening_balances RPC fallback when opening_balance_entry_id is null', async () => {
|
||||
// Reproduces the user-reported bug: after a multi-year SIE import the
|
||||
// continuation-import guard intentionally leaves opening_balance_entry_id
|
||||
// NULL, and previously the SIE export silently produced zero #IB records,
|
||||
// collapsing #UB to current-period movements only. The fix wires SIE
|
||||
// export to getOpeningBalances() so the RPC backs up the missing link.
|
||||
results = [
|
||||
// period — note: no opening_balance_entry_id, so getOpeningBalances
|
||||
// falls through to the RPC path
|
||||
{ data: { id: 'period-1', period_start: '2024-01-01', period_end: '2024-12-31', opening_balance_entry_id: null }, error: null },
|
||||
{ data: null, error: null }, // prevPeriod
|
||||
{ data: [], error: null }, // accounts
|
||||
{ data: [], error: null }, // journal_entries (no movements this period)
|
||||
{ data: [], error: null }, // cost_centers
|
||||
{ data: [], error: null }, // projects
|
||||
// RPC fallback returns prior IBs derived from historical journal lines
|
||||
{
|
||||
data: [
|
||||
{ account_number: '1930', debit: 50000, credit: 0 },
|
||||
{ account_number: '2440', debit: 0, credit: 50000 },
|
||||
],
|
||||
error: null,
|
||||
},
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
|
||||
expect(output).toContain('#IB 0 1930 50000.00')
|
||||
expect(output).toContain('#IB 0 2440 -50000.00')
|
||||
// UB = IB + period movements (zero this period), so #UB mirrors #IB
|
||||
expect(output).toContain('#UB 0 1930 50000.00')
|
||||
expect(output).toContain('#UB 0 2440 -50000.00')
|
||||
})
|
||||
|
||||
it('reads #IB from explicit opening_balance_entry_id when set', async () => {
|
||||
// When opening_balance_entry_id is set, getOpeningBalances uses the
|
||||
// journal_entry_lines path (fetchAllRows) instead of the RPC, so the
|
||||
// queue here serves the line rows rather than RPC rows.
|
||||
results = [
|
||||
{ data: { id: 'period-1', period_start: '2024-01-01', period_end: '2024-12-31', opening_balance_entry_id: 'ob-entry-1' }, error: null },
|
||||
{ data: null, error: null }, // prevPeriod
|
||||
{ data: [], error: null }, // accounts
|
||||
{ data: [], error: null }, // journal_entries
|
||||
{ data: [], error: null }, // cost_centers
|
||||
{ data: [], error: null }, // projects
|
||||
// fetchAllRows page 1 — explicit OB entry lines
|
||||
{
|
||||
data: [
|
||||
{ account_number: '1930', debit_amount: 12000, credit_amount: 0 },
|
||||
{ account_number: '2440', debit_amount: 0, credit_amount: 12000 },
|
||||
],
|
||||
error: null,
|
||||
},
|
||||
]
|
||||
|
||||
const output = await generateSIEExport(supabase, 'company-1', baseOptions)
|
||||
|
||||
expect(output).toContain('#IB 0 1930 12000.00')
|
||||
expect(output).toContain('#IB 0 2440 -12000.00')
|
||||
expect(output).toContain('#UB 0 1930 12000.00')
|
||||
expect(output).toContain('#UB 0 2440 -12000.00')
|
||||
})
|
||||
})
|
||||
|
||||
+16
-19
@@ -1,6 +1,7 @@
|
||||
import type { SupabaseClient } from '@supabase/supabase-js'
|
||||
import { fetchAllRows } from '@/lib/supabase/fetch-all'
|
||||
import { getBranding } from '@/lib/branding/service'
|
||||
import { getOpeningBalances } from './opening-balances'
|
||||
import type { SIEExportOptions, JournalEntry, JournalEntryLine, BASAccount } from '@/types'
|
||||
|
||||
function sanitizeProgramName(str: string): string {
|
||||
@@ -136,27 +137,23 @@ export async function generateSIEExport(
|
||||
}
|
||||
|
||||
// === Opening balances (IB) ===
|
||||
// Collect IB per account for UB calculation (UB = IB + movements)
|
||||
// Routes through getOpeningBalances() so we get the same fallback as trial
|
||||
// balance / balance sheet: when opening_balance_entry_id is NULL — which is
|
||||
// expected after continuation SIE imports (sie-import.ts skips creating an
|
||||
// IB entry once prior posted activity exists) — the compute_prior_opening_
|
||||
// balances RPC derives IB from earlier journal lines instead of silently
|
||||
// emitting zero #IB records and producing wrong #UB values.
|
||||
const openingBalancesByAccount = new Map<string, number>()
|
||||
const { balances: obBalances } = await getOpeningBalances(supabase, companyId, {
|
||||
period_start: period.period_start,
|
||||
opening_balance_entry_id: period.opening_balance_entry_id ?? null,
|
||||
})
|
||||
|
||||
if (period.opening_balance_entry_id) {
|
||||
const { data: obEntry } = await supabase
|
||||
.from('journal_entries')
|
||||
.select('*, lines:journal_entry_lines(*)')
|
||||
.eq('id', period.opening_balance_entry_id)
|
||||
.eq('company_id', companyId)
|
||||
.single()
|
||||
|
||||
if (obEntry?.lines) {
|
||||
for (const line of (obEntry.lines as JournalEntryLine[])) {
|
||||
const amount = (Number(line.debit_amount) || 0) - (Number(line.credit_amount) || 0)
|
||||
lines.push(`#IB 0 ${line.account_number} ${formatAmount(amount)}`)
|
||||
openingBalancesByAccount.set(
|
||||
line.account_number,
|
||||
(openingBalancesByAccount.get(line.account_number) || 0) + amount
|
||||
)
|
||||
}
|
||||
}
|
||||
for (const [accountNumber, { debit, credit }] of obBalances) {
|
||||
const amount = Math.round(((Number(debit) || 0) - (Number(credit) || 0)) * 100) / 100
|
||||
if (amount === 0) continue
|
||||
lines.push(`#IB 0 ${accountNumber} ${formatAmount(amount)}`)
|
||||
openingBalancesByAccount.set(accountNumber, amount)
|
||||
}
|
||||
|
||||
// === Journal entries (VER + TRANS) ===
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
import { createServerClient } from '@supabase/ssr'
|
||||
import { NextResponse, type NextRequest } from 'next/server'
|
||||
import { shouldEnforceMfa } from '@/lib/auth/mfa'
|
||||
import { userHasPassword } from '@/lib/auth/has-password'
|
||||
|
||||
export async function updateSession(request: NextRequest) {
|
||||
let supabaseResponse = NextResponse.next({
|
||||
@@ -89,11 +90,40 @@ export async function updateSession(request: NextRequest) {
|
||||
return NextResponse.redirect(url)
|
||||
}
|
||||
|
||||
// MFA pages — accessible to authenticated users (AAL1+), skip MFA enforcement
|
||||
// /mfa/enroll: gate behind has-password. BankID-only users who reach this
|
||||
// page can lock themselves out — Supabase requires AAL2 to change password
|
||||
// or unenroll MFA, and AAL2 needs a prior password sign-in. Force them to
|
||||
// set a password first. The /account/set-password page does that and routes
|
||||
// back here via ?returnTo. Thread the inner returnTo through so the user
|
||||
// ends up on their original destination after the full chain completes.
|
||||
if (pathname.startsWith('/mfa/enroll')) {
|
||||
if (!userHasPassword(user)) {
|
||||
const innerReturnTo = request.nextUrl.searchParams.get('returnTo')
|
||||
const mfaTarget = `/mfa/enroll${
|
||||
innerReturnTo ? `?returnTo=${encodeURIComponent(innerReturnTo)}` : ''
|
||||
}`
|
||||
return NextResponse.redirect(
|
||||
new URL(
|
||||
`/account/set-password?returnTo=${encodeURIComponent(mfaTarget)}`,
|
||||
request.url,
|
||||
),
|
||||
)
|
||||
}
|
||||
return supabaseResponse
|
||||
}
|
||||
|
||||
// Other MFA pages — accessible to authenticated users (AAL1+), skip MFA enforcement
|
||||
if (pathname.startsWith('/mfa/')) {
|
||||
return supabaseResponse
|
||||
}
|
||||
|
||||
// /account/set-password is the escape hatch from the BankID/MFA lockout
|
||||
// and must be reachable even when the user has no company yet (e.g. mid-
|
||||
// onboarding) and is at AAL1.
|
||||
if (pathname.startsWith('/account/set-password')) {
|
||||
return supabaseResponse
|
||||
}
|
||||
|
||||
// MFA enforcement (application-side only, not RLS)
|
||||
if (shouldEnforceMfa(user)) {
|
||||
const { data: aal } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel()
|
||||
|
||||
@@ -0,0 +1,105 @@
|
||||
#!/usr/bin/env npx tsx
|
||||
/**
|
||||
* Backfill auth.users.app_metadata.has_password for the BankID-MFA lockout fix.
|
||||
*
|
||||
* - BankID-linked users (app_metadata.bankid_linked === true) with the flag
|
||||
* unset → set has_password = false. Banner in SecuritySettings will then
|
||||
* guide them through /account/set-password before MFA enroll is unlocked.
|
||||
*
|
||||
* - All other users with the flag unset (legacy email/password signups) →
|
||||
* set has_password = true. They have a real password.
|
||||
*
|
||||
* - Anyone with the flag already set is left alone — fully idempotent.
|
||||
*
|
||||
* Usage:
|
||||
* npx tsx scripts/backfill-has-password.ts # apply
|
||||
* npx tsx scripts/backfill-has-password.ts --dry-run # report only
|
||||
*/
|
||||
|
||||
import { config } from 'dotenv'
|
||||
config({ path: '.env.local' })
|
||||
import { createClient } from '@supabase/supabase-js'
|
||||
|
||||
const DRY_RUN = process.argv.includes('--dry-run')
|
||||
|
||||
const supabaseUrl = process.env.NEXT_PUBLIC_SUPABASE_URL
|
||||
const serviceRoleKey = process.env.SUPABASE_SERVICE_ROLE_KEY
|
||||
|
||||
if (!supabaseUrl || !serviceRoleKey) {
|
||||
console.error(
|
||||
'Missing NEXT_PUBLIC_SUPABASE_URL or SUPABASE_SERVICE_ROLE_KEY in .env.local',
|
||||
)
|
||||
process.exit(1)
|
||||
}
|
||||
|
||||
const supabase = createClient(supabaseUrl, serviceRoleKey)
|
||||
|
||||
async function main() {
|
||||
let page = 1
|
||||
const perPage = 200
|
||||
let totalScanned = 0
|
||||
let setFalse = 0
|
||||
let setTrue = 0
|
||||
let skipped = 0
|
||||
|
||||
for (;;) {
|
||||
const { data, error } = await supabase.auth.admin.listUsers({
|
||||
page,
|
||||
perPage,
|
||||
})
|
||||
if (error) {
|
||||
console.error('listUsers failed', error)
|
||||
process.exit(1)
|
||||
}
|
||||
if (!data.users || data.users.length === 0) break
|
||||
|
||||
for (const user of data.users) {
|
||||
totalScanned++
|
||||
const meta = (user.app_metadata ?? {}) as Record<string, unknown>
|
||||
const flagAlreadySet =
|
||||
meta.has_password === true || meta.has_password === false
|
||||
|
||||
if (flagAlreadySet) {
|
||||
skipped++
|
||||
continue
|
||||
}
|
||||
|
||||
const isBankIdLinked = meta.bankid_linked === true
|
||||
const nextValue = isBankIdLinked ? false : true
|
||||
|
||||
if (DRY_RUN) {
|
||||
if (nextValue) setTrue++
|
||||
else setFalse++
|
||||
continue
|
||||
}
|
||||
|
||||
const merged = { ...meta, has_password: nextValue }
|
||||
const { error: updateError } = await supabase.auth.admin.updateUserById(
|
||||
user.id,
|
||||
{ app_metadata: merged },
|
||||
)
|
||||
if (updateError) {
|
||||
console.error(`failed to update user ${user.id}`, updateError)
|
||||
continue
|
||||
}
|
||||
if (nextValue) setTrue++
|
||||
else setFalse++
|
||||
}
|
||||
|
||||
if (data.users.length < perPage) break
|
||||
page++
|
||||
}
|
||||
|
||||
console.log(JSON.stringify({
|
||||
mode: DRY_RUN ? 'dry-run' : 'apply',
|
||||
scanned: totalScanned,
|
||||
set_true: setTrue,
|
||||
set_false: setFalse,
|
||||
skipped_already_set: skipped,
|
||||
}, null, 2))
|
||||
}
|
||||
|
||||
main().catch((err) => {
|
||||
console.error(err)
|
||||
process.exit(1)
|
||||
})
|
||||
@@ -0,0 +1,11 @@
|
||||
-- Add Swish as an invoice payment method.
|
||||
-- Mirrors invoice_show_bankgiro / invoice_show_plusgiro from 20260401200000.
|
||||
-- swish accepts either a Swish-företag/handel number (1230000000–1239999999)
|
||||
-- or a Swedish mobile (07X). Validation is enforced in lib/api/schemas.ts;
|
||||
-- the column is plain text so historical/unusual values remain accepted.
|
||||
|
||||
ALTER TABLE public.company_settings
|
||||
ADD COLUMN IF NOT EXISTS swish text,
|
||||
ADD COLUMN IF NOT EXISTS invoice_show_swish boolean DEFAULT true;
|
||||
|
||||
NOTIFY pgrst, 'reload schema';
|
||||
@@ -0,0 +1,9 @@
|
||||
-- Per-company kill switch for automated invoice reminder emails.
|
||||
-- Default true preserves current behavior. When false, the daily
|
||||
-- /api/invoices/reminders/cron run skips this company entirely
|
||||
-- (see lib/invoices/reminder-processor.ts).
|
||||
|
||||
ALTER TABLE public.company_settings
|
||||
ADD COLUMN IF NOT EXISTS send_invoice_reminders boolean DEFAULT true;
|
||||
|
||||
NOTIFY pgrst, 'reload schema';
|
||||
@@ -522,6 +522,7 @@ export function makeCompanySettings(
|
||||
account_number: null,
|
||||
bankgiro: null,
|
||||
plusgiro: null,
|
||||
swish: null,
|
||||
iban: null,
|
||||
bic: null,
|
||||
accounting_method: 'accrual',
|
||||
@@ -537,11 +538,13 @@ export function makeCompanySettings(
|
||||
invoice_show_ocr: true,
|
||||
invoice_show_bankgiro: true,
|
||||
invoice_show_plusgiro: true,
|
||||
invoice_show_swish: true,
|
||||
invoice_show_logo: true,
|
||||
invoice_show_company_name: true,
|
||||
invoice_company_name_position: 'header',
|
||||
invoice_late_fee_text: null,
|
||||
invoice_credit_terms_text: null,
|
||||
send_invoice_reminders: true,
|
||||
logo_url: null,
|
||||
onboarding_step: 6,
|
||||
onboarding_complete: true,
|
||||
|
||||
@@ -220,6 +220,7 @@ export interface CompanySettings {
|
||||
account_number: string | null
|
||||
bankgiro: string | null
|
||||
plusgiro: string | null
|
||||
swish: string | null
|
||||
iban: string | null
|
||||
bic: string | null
|
||||
|
||||
@@ -245,12 +246,16 @@ export interface CompanySettings {
|
||||
invoice_show_ocr: boolean
|
||||
invoice_show_bankgiro: boolean
|
||||
invoice_show_plusgiro: boolean
|
||||
invoice_show_swish: boolean
|
||||
invoice_show_logo: boolean
|
||||
invoice_show_company_name: boolean
|
||||
invoice_company_name_position: 'header' | 'footer'
|
||||
invoice_late_fee_text: string | null
|
||||
invoice_credit_terms_text: string | null
|
||||
|
||||
// Automation
|
||||
send_invoice_reminders: boolean
|
||||
|
||||
// Logo
|
||||
logo_url: string | null
|
||||
|
||||
|
||||
Reference in New Issue
Block a user