fix(entitlements): gate paid MCP tools (send_invoice/agi_submit/vat_declaration_submit) server-side (#846)
The HTTP routes call requireCapability at every paid chokepoint, but the MCP/agent path bypassed the paywall entirely: the three external-service tools stage operations whose commit calls the email / Skatteverket services directly, with no capability check. After the 2026-07-07 trial cutover a trial-connected non-payer using the gnubok MCP connector could still send invoice emails and file AGI/VAT. Close the gap with two layers, mirroring the existing TOOL_SCOPE_MAP gate: - Dispatch gate (mcp-server/server.ts): MCP_TOOL_CAPABILITY_MAP, checked right after the scope check, blocks a non-entitled company before any pending op is staged. Emits errorKind='capability_denied' telemetry. - Commit-time gate (commitPendingOperation): PAID_OPERATION_CAPABILITY_MAP, checked before the atomic claim. The real external-service chokepoint — applies to the MCP approve tool AND the UI approval path, and closes the trial-connected-token window (the grant has expired by commit time). A blocked op stays 'pending', so it is re-approvable once the company subscribes. Adds a transport-free capabilityBlockedError() helper (shared bilingual copy) and locks both maps with tests (maps, dispatch gate, commit gate). Only the three write/submit tools are gated; SKV read/local tools stay free per the statutory carve-out. No DB/migration change; self-hosted stays all-on. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
5df6199bd1
commit
db843a7a5b
@@ -60,6 +60,8 @@ import {
|
||||
type SkvSubmitResult,
|
||||
} from '@/lib/pending-operations/skatteverket-commit'
|
||||
import { getEmailService } from '@/lib/email/service'
|
||||
import { hasCapability, CAPABILITY_BLOCKED_MESSAGE_SV } from '@/lib/entitlements/has-capability'
|
||||
import { PAID_OPERATION_CAPABILITY_MAP } from '@/lib/entitlements/keys'
|
||||
import {
|
||||
generateInvoiceEmailHtml,
|
||||
generateInvoiceEmailText,
|
||||
@@ -3665,6 +3667,23 @@ async function commitPendingOperationInner(
|
||||
pendingOp: PendingOperation,
|
||||
opts: CommitOptions = {}
|
||||
): Promise<CommitResult> {
|
||||
// ── Capability gate (commit-time twin of the MCP dispatch gate). The actual
|
||||
// external-service call (email / Skatteverket submit) happens below, so
|
||||
// this is the true paid chokepoint — it also catches an op STAGED during
|
||||
// the trial then approved AFTER the grant expired, regardless of caller
|
||||
// (MCP approve tool or the UI approval path). Checked BEFORE the atomic
|
||||
// claim so a blocked op stays 'pending' and is re-approvable once the
|
||||
// company subscribes. Self-hosted short-circuits to all-on in hasCapability.
|
||||
const requiredCapability = PAID_OPERATION_CAPABILITY_MAP[pendingOp.operation_type]
|
||||
if (requiredCapability && !(await hasCapability(supabase, companyId, requiredCapability))) {
|
||||
return {
|
||||
status: 'failed',
|
||||
error: CAPABILITY_BLOCKED_MESSAGE_SV,
|
||||
http_status: 403,
|
||||
code: 'capability_blocked',
|
||||
}
|
||||
}
|
||||
|
||||
// ── Atomic claim: flip status pending → committing in a single conditional
|
||||
// update. If 0 rows are affected, another caller (auto-commit ↔ human
|
||||
// approval, or two parallel approvals) already claimed this op and we
|
||||
|
||||
Reference in New Issue
Block a user