* feat: add option to exclude year-end closing entries in SIE export and related reports * delete docs * fix: allow Chrome's PDF viewer in verifikat document preview The /api/documents/:id/inline route shipped with `object-src 'none'` in its CSP, which blocked Chrome's built-in PDF viewer (it renders inline PDFs via an internal <embed>). Users on Chrome saw "Det här innehållet har blockerats" when expanding a PDF attachment in the bookkeeping view; Firefox (PDF.js) and Edge (own viewer) were unaffected, and JPGs worked because <img> isn't subject to object-src. Drops the CSP for this route to the minimum needed for embeddability: `frame-ancestors 'self'`. X-Content-Type-Options: nosniff plus the fixed Content-Type from the handler already block MIME confusion; X-Frame-Options: SAMEORIGIN + frame-ancestors still block clickjacking. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * feat(auth): add webmail deep link to email confirmation screens Mirrors Stripe's signup UX: after asking the user to verify their email, detect their webmail provider from the domain and show a button that opens the inbox in a new tab. Gmail gets a from:<sender> search pre-populated; Outlook/Yahoo/iCloud/Proton open the inbox directly. Unknown / custom domains fall back to the existing copy. Sender address is configurable via NEXT_PUBLIC_BRANDING_AUTH_EMAIL_FROM (default noreply@gnubok.se) so white-label installs can match their Supabase Auth SMTP config. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(auth): unblock first-time password set for BankID users with MFA Supabase rejects updateUser({password}) and mfa.unenroll with "AAL2 session is required" whenever a TOTP factor is enrolled. BankID magic-link logins produce AAL1, and middleware skips MFA enforcement for bankid_linked users, so they had no path to AAL2 — leaving them unable to set a backup password or disable MFA without going through the email-recovery escape hatch. - /api/account/password: branch on app_metadata.has_password. First-time set writes via service.auth.admin.updateUserById (no existing credential to protect, AAL2 guard does not apply). Change-password keeps the user-session updateUser so AAL2 still fires for credential rotation. - /mfa/verify: accept a safeReturnTo query param and route there after successful verify, so step-up flows can land back where they came from. - SecuritySettings: detect the AAL2 error from both change-password and mfa.unenroll and redirect through /mfa/verify?returnTo=/settings/account instead of toasting a dead-end error. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * Add tests and rounding utility for öre precision in bokslut calculations - Implemented `roundOre` function for rounding SEK amounts to two decimal places, ensuring consistent monetary calculations. - Introduced `ORE_TOLERANCE` constant for comparing rounded amounts, facilitating invariant checks in financial entries. - Created comprehensive tests for `roundOre`, covering typical cases, edge cases, and idempotency. - Added year-end invariants tests to verify database-level guarantees for closing entries, ensuring they balance to the öre and reject discrepancies. - Developed end-to-end tests for the dispositions chain, validating the correctness of calculations across various scenarios. * fix: update PDF rendering to remove Swish QR code generation and set default to disable Swish visibility * fix: enhance security by rejecting data URIs in safeReturnTo function tests * fix: improve rounding logic in roundOre function and add customer_type migration * fix: add customer_type column to customers and enforce CHECK constraint --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
124 lines
4.1 KiB
TypeScript
124 lines
4.1 KiB
TypeScript
import { createClient, createServiceClient } from '@/lib/supabase/server'
|
|
import { NextResponse } from 'next/server'
|
|
import { z } from 'zod'
|
|
import { validateBody } from '@/lib/api/validate'
|
|
import { createLogger } from '@/lib/logger'
|
|
|
|
const log = createLogger('api/account/password')
|
|
|
|
const SetPasswordSchema = z.object({
|
|
password: z
|
|
.string()
|
|
.min(8, 'Lösenordet måste vara minst 8 tecken')
|
|
.refine(
|
|
(v) =>
|
|
/[a-z]/.test(v) &&
|
|
/[A-Z]/.test(v) &&
|
|
/[0-9]/.test(v) &&
|
|
/[^a-zA-Z0-9]/.test(v),
|
|
'Lösenordet måste innehålla versaler, gemener, siffror och specialtecken',
|
|
),
|
|
})
|
|
|
|
/**
|
|
* POST /api/account/password
|
|
*
|
|
* Server-routed password set/change, then flips `app_metadata.has_password =
|
|
* true` via the service client (clients can't write app_metadata).
|
|
*
|
|
* Two paths depending on whether the user already has a real password:
|
|
*
|
|
* - First-time set (`app_metadata.has_password !== true`): write via the
|
|
* admin API. BankID-only users — and legacy users whose `has_password`
|
|
* flag was set to false by the backfill — sit at AAL1 with a TOTP factor
|
|
* enrolled, and `updateUser` on the user session would be rejected with
|
|
* "AAL2 session is required to update email or password when MFA is
|
|
* enabled". Setting an initial password has no existing credential to
|
|
* protect, so bypassing AAL2 is safe.
|
|
*
|
|
* - Change-password (`app_metadata.has_password === true`): write via the
|
|
* user session so Supabase's AAL2 guard still fires. A stolen AAL1
|
|
* cookie must not be able to rotate a known password.
|
|
*
|
|
* This route is the single write path for setting a password. SecuritySettings,
|
|
* the reset-password page, and the /account/set-password page all funnel
|
|
* through here so the flag stays in sync — see lib/auth/has-password.ts.
|
|
*
|
|
* If the password update succeeds but the flag write fails, we log and still
|
|
* return success: the user has a working password and the banner will show one
|
|
* more time, but a retry will re-flip the flag.
|
|
*/
|
|
export async function POST(request: Request) {
|
|
const supabase = await createClient()
|
|
|
|
const {
|
|
data: { user },
|
|
} = await supabase.auth.getUser()
|
|
if (!user) {
|
|
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
|
|
}
|
|
|
|
const result = await validateBody(request, SetPasswordSchema)
|
|
if (!result.success) return result.response
|
|
const { password } = result.data
|
|
|
|
const isFirstTimeSet = user.app_metadata?.has_password !== true
|
|
const service = createServiceClient()
|
|
|
|
let updateError:
|
|
| { message?: string; status?: number; code?: string }
|
|
| null
|
|
| undefined = null
|
|
|
|
if (isFirstTimeSet) {
|
|
const { error } = await service.auth.admin.updateUserById(user.id, {
|
|
password,
|
|
})
|
|
updateError = error
|
|
} else {
|
|
const { error } = await supabase.auth.updateUser({ password })
|
|
updateError = error
|
|
}
|
|
|
|
if (updateError) {
|
|
log.warn('password update failed', {
|
|
userId: user.id,
|
|
isFirstTimeSet,
|
|
code: updateError.code,
|
|
status: updateError.status,
|
|
})
|
|
return NextResponse.json(
|
|
{
|
|
error:
|
|
updateError.message ||
|
|
'Kunde inte uppdatera lösenord. Försök igen.',
|
|
},
|
|
{ status: 400 },
|
|
)
|
|
}
|
|
|
|
// Read-merge-write so we don't wipe sibling app_metadata keys.
|
|
// updateUserById replaces app_metadata wholesale (see lib/auth/has-password.ts
|
|
// and the comment in app/api/account/delete/route.ts).
|
|
let flagWriteOk = false
|
|
try {
|
|
const { data: u } = await service.auth.admin.getUserById(user.id)
|
|
const prior = u?.user?.app_metadata ?? {}
|
|
await service.auth.admin.updateUserById(user.id, {
|
|
app_metadata: { ...prior, has_password: true },
|
|
})
|
|
flagWriteOk = true
|
|
} catch (err) {
|
|
log.error('failed to flip has_password flag after successful password set', {
|
|
userId: user.id,
|
|
err,
|
|
})
|
|
// Don't surface the failure: the user has a working password. The
|
|
// banner will show once more and a retry will succeed.
|
|
}
|
|
|
|
log.info('password set', { userId: user.id, isFirstTimeSet, flagWriteOk })
|
|
|
|
return NextResponse.json({ data: { ok: true } })
|
|
}
|