* fix(auth): resolve auth-link hosts from the brands table, drop NEXT_PUBLIC_WHITELABEL_DOMAINS Password reset, invite, email change and signup links now resolve the request host against brands.domain server-side. The env var was a second copy of that registry compiled into the browser; every new brand needed the row, the env var, the GoTrue allowlist and a redeploy, and two partners shipped with the env var stale, so their reset mails went out canonical-branded to the canonical host. - New POST /api/auth/password-reset: the login page no longer calls GoTrue directly, so the browser carries no domain list. - lib/domains/trusted-app-origin.ts is async and registry-backed; it also trusts this deployment's own VERCEL_URL / VERCEL_BRANCH_URL so previews keep sending links to themselves. - Signup shares the same resolver instead of following the raw host. - Docs and .env.example describe the single registry; GoTrue keeps the redirect allowlist as backstop (hosted: *.accounted.se wildcard). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NUNB7qjua8EUaJmZgfFscx * fix(auth): await the async origin resolver in the billing routes merged from main PR #2370 added resolveRequestAppOrigin callers in billing/checkout and billing/portal after this branch made the resolver async. Await them and move their tests from the removed env var to the brands mock; update the login source-assert test to the server-routed reset. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NUNB7qjua8EUaJmZgfFscx * fix(auth): refuse auth links on a failed brand lookup, keep local dev hosts, correct GoTrue allowlist docs Skeptic and CI findings on #2376, one pass: - A failed brands lookup now throws BrandLookupFailedError (TRANSIENT_ERROR, 503, retryable) instead of falling back to the canonical origin: a canonical link is the wrong-brand mail this PR removes. Password reset and email change answer 503 themselves; withRouteContext routes map the code. - A local canonical (dev) trusts other local hosts and ports on the same scheme, so lane servers on 3001-3003 confirm signups on themselves. - GoTrue matches the full redirect_to including the query and `*` stops at `.` and `/`: docs and decision line now prescribe https://*.accounted.se/auth/callback** and https://*.accounted.se/invite/**. - The Turnstile contract test asserts the server-routed reset forwards the captcha token (it still asserted the removed browser call). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NUNB7qjua8EUaJmZgfFscx --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
136 lines
5.4 KiB
TypeScript
136 lines
5.4 KiB
TypeScript
import { NextResponse } from 'next/server'
|
|
import { z } from 'zod'
|
|
import { createClient } from '@/lib/supabase/server'
|
|
import { validateBody } from '@/lib/api/validate'
|
|
import {
|
|
evaluateBrandSignupGate,
|
|
readInviteTokenFromCookieHeader,
|
|
} from '@/lib/auth/brand-signup-gate'
|
|
import { safeReturnTo } from '@/lib/auth/safe-return-to'
|
|
import { resolveTrustedAppOrigin } from '@/lib/domains/trusted-app-origin'
|
|
import { getErrorMessage } from '@/lib/errors/get-error-message'
|
|
import { createLogger } from '@/lib/logger'
|
|
|
|
const log = createLogger('auth-signup')
|
|
|
|
/**
|
|
* POST /api/auth/signup: email+password signup, moved server-side so the
|
|
* invite-only brand-domain gate (lib/auth/brand-signup-gate.ts) cannot be
|
|
* bypassed. The register page used to call supabase.auth.signUp straight
|
|
* from the browser; that call never touched Next.js, so any host-based
|
|
* gating there would have been cosmetic. This route is now the only
|
|
* email-signup path on every host: on canonical and open-brand hosts the
|
|
* behavior is byte-identical to the old direct call (same GoTrue request,
|
|
* same captcha, same emailRedirectTo shape), on invite-only brand hosts it
|
|
* refuses with signup_not_allowed unless the email is allowlisted or a
|
|
* valid invite cookie rides along.
|
|
*
|
|
* Anonymous by design: there is no session to authenticate at signup time,
|
|
* so no withRouteContext / requireAuth. Abuse is bounded the same way the
|
|
* direct GoTrue call was: the forwarded Turnstile token (verified by
|
|
* GoTrue) plus GoTrue's own signup rate limits.
|
|
*/
|
|
|
|
const SignupSchema = z.object({
|
|
email: z.string().trim().toLowerCase().max(320).pipe(z.string().email()),
|
|
password: z.string().min(8).max(256),
|
|
captchaToken: z.string().max(4096).nullish(),
|
|
/** Post-signup resume path (MCP OAuth consent); same-origin enforced. */
|
|
next: z.string().max(2048).nullish(),
|
|
})
|
|
|
|
export async function POST(request: Request) {
|
|
const validation = await validateBody(request, SignupSchema)
|
|
if (!validation.success) return validation.response
|
|
const { email, password, captchaToken } = validation.data
|
|
|
|
const host =
|
|
request.headers.get('x-forwarded-host') ?? request.headers.get('host') ?? ''
|
|
|
|
// The invite cookie is set by /invite/[token] before it redirects to
|
|
// /register, so an invitee's signup carries it automatically.
|
|
const inviteToken = readInviteTokenFromCookieHeader(request.headers.get('cookie'))
|
|
|
|
const gate = await evaluateBrandSignupGate({ host, email, inviteToken })
|
|
if (!gate.allowed && 'lookupFailed' in gate) {
|
|
// Transient brands-table error: fail safe, do not create the account.
|
|
// 503 tells the client to retry rather than the misleading "not allowed".
|
|
return NextResponse.json(
|
|
{
|
|
error: {
|
|
code: 'brand_lookup_failed',
|
|
message: 'Tillfälligt fel. Försök igen om en stund.',
|
|
message_en: 'Temporary error. Please try again shortly.',
|
|
},
|
|
},
|
|
{ status: 503 },
|
|
)
|
|
}
|
|
if (!gate.allowed) {
|
|
return NextResponse.json(
|
|
{
|
|
error: {
|
|
code: 'signup_not_allowed',
|
|
// Brand-neutral copy: the interstitial on the register page owns
|
|
// the user-facing story; this message is the API-level fallback.
|
|
message: 'Registrering på den här domänen kräver inbjudan.',
|
|
message_en: 'Signing up on this domain requires an invitation.',
|
|
},
|
|
},
|
|
{ status: 403 },
|
|
)
|
|
}
|
|
|
|
// Confirmation links must land back on the ORIGINATING host (WL-05 brand
|
|
// mail resolves its brand from this URL). The host is resolved through the
|
|
// same registry as every other auth link (canonical, this deployment's
|
|
// own Vercel hosts, or a registered brand domain); anything else falls
|
|
// back to the canonical origin rather than following the raw header.
|
|
const confirmationCallback = new URL(
|
|
'/auth/callback',
|
|
await resolveTrustedAppOrigin(host),
|
|
)
|
|
const nextPath = safeReturnTo(validation.data.next ?? null, '/')
|
|
if (nextPath !== '/') confirmationCallback.searchParams.set('next', nextPath)
|
|
|
|
const supabase = await createClient()
|
|
const { data, error } = await supabase.auth.signUp({
|
|
email,
|
|
password,
|
|
options: {
|
|
emailRedirectTo: confirmationCallback.toString(),
|
|
...(captchaToken ? { captchaToken } : {}),
|
|
},
|
|
})
|
|
|
|
if (error) {
|
|
log.warn('signUp rejected', { status: error.status, code: error.code })
|
|
// The register page feeds this envelope to classifyAuthError, which
|
|
// keys on the GoTrue code (and the HTTP status); the display message is
|
|
// localized through getErrorMessage like every other auth surface.
|
|
return NextResponse.json(
|
|
{
|
|
error: {
|
|
code: error.code ?? 'auth_error',
|
|
message: getErrorMessage(error, { context: 'auth', locale: 'sv' }),
|
|
message_en: getErrorMessage(error, { context: 'auth', locale: 'en' }),
|
|
},
|
|
},
|
|
{ status: error.status && error.status >= 400 ? error.status : 400 },
|
|
)
|
|
}
|
|
|
|
// Supabase obfuscates duplicate signups (anti-enumeration): a confirmed
|
|
// existing email returns a user with identities: [] and sends no mail.
|
|
// Surface that as a distinct status so the page can skip the misleading
|
|
// "check your email" screen; the information is the same the browser call
|
|
// exposed, so nothing new leaks.
|
|
const status = data.session
|
|
? 'session'
|
|
: data.user && (data.user.identities?.length ?? 0) === 0
|
|
? 'duplicate'
|
|
: 'confirmation_sent'
|
|
|
|
return NextResponse.json({ data: { status } })
|
|
}
|