feat(invoices): per-recipient email delivery outcomes (#1384)

* feat(invoices): per-recipient email delivery outcomes

Resend delivery webhooks identify affected addresses in data.to, so one
message with CC recipients can carry independent To/CC outcomes instead
of masking the failing address into the aggregate reason text.

- new apply_invoice_delivery_provider_event RPC merges each reported
  recipient onto its immutable To/CC position with the same rank and
  timestamp ordering as the aggregate status (retry and out-of-order safe)
- recipient map is PII-free: keyed to:N / cc:N, BCC and unmatched
  recipients are never represented, and the map is cleared on PII redaction
- delivery summaries, API route and MCP tool expose the sanitized map;
  the route re-sanitizes as defense in depth
- UI shows a per-recipient status list under the aggregate outcome

The prod ops check in issue #1350 (webhook registered in Resend and
RESEND_DELIVERY_WEBHOOK_SECRET set in Vercel) cannot be verified from the
repo and remains a follow-up.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(invoices): commit provider event before cross-context read

The BCC-leak test applied the event inside the rollback-scoped service
role helper and then asserted through a separate member context, so the
applied status was rolled back before the read. Use the committing
runAsServiceRole helper for the apply, matching how the summary read is
performed in its own context.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-08-03 17:56:37 +02:00
committed by GitHub
co-authored by Claude Fable 5
parent bb1eddcccf
commit cd7d7f52b9
16 changed files with 1115 additions and 24 deletions
+18 -3
View File
@@ -1048,9 +1048,9 @@ export type InvoiceDeliveryStatus = 'preparing' | 'pending' | 'sent' | 'failed'
/**
* Delivery outcome reported by the email provider after the send itself
* succeeded. Reported per message, never per recipient: a message with several
* recipients gets one outcome, and the reason text names the address that
* failed. `null` means no report has arrived yet.
* succeeded. The delivery keeps an aggregate outcome and, when the provider
* identifies affected recipients, outcomes keyed by stable To/CC positions.
* `null` means no report has arrived yet.
*/
export type InvoiceDeliveryProviderStatus =
| 'delayed'
@@ -1060,6 +1060,20 @@ export type InvoiceDeliveryProviderStatus =
| 'failed'
| 'suppressed'
export interface InvoiceDeliveryRecipientStatus {
status: InvoiceDeliveryProviderStatus
status_at: string
}
/**
* PII-free recipient references. `to:1` is the first immutable To address and
* `cc:1` the first immutable CC address. BCC recipients are never exposed.
*/
export type InvoiceDeliveryRecipientStatuses = Partial<Record<
`to:${number}` | `cc:${number}`,
InvoiceDeliveryRecipientStatus
>>
export interface InvoiceDelivery {
id: string
company_id: string
@@ -1080,6 +1094,7 @@ export interface InvoiceDelivery {
provider_status: InvoiceDeliveryProviderStatus | null
provider_status_at: string | null
provider_status_detail: string | null
provider_recipient_statuses: InvoiceDeliveryRecipientStatuses
error_code: string | null
document_attachment_id: string | null
attachment_filename: string | null