Files
accounted/app/api/company/check-org-number/route.ts
T
Mattsson 3e42fc6f32 Feat/voucher docs (#664)
* feat: implement inbox document picker and linking functionality

* feat: implement self-billing invoice functionality

- Added support for registering self-billed invoices received from customers.
- Updated the invoice schema to include fields for self-billing metadata such as `is_self_billed`, `external_invoice_number`, `self_billing_agreement_ref`, and `received_date`.
- Created API route for handling self-billed invoice submissions, including validation and error handling.
- Implemented database migrations to add necessary columns and constraints for self-billing invoices.
- Developed tests to ensure correct behavior of self-billing invoice creation and validation rules.
- Updated Swedish localization files to include new terms related to self-billing.

* feat: enforce SIE import requirement for non-Fortnox providers in migration process

* feat: streamline invoice processing and enhance error logging across APIs
2026-06-04 13:14:57 +02:00

62 lines
2.5 KiB
TypeScript

import { NextResponse } from 'next/server'
import { requireAuth } from '@/lib/auth/require-auth'
import { normalizeOrgNumber } from '@/lib/company-lookup/normalize-org-number'
/**
* GET /api/company/check-org-number?org_number=XXXXXXXXXX
*
* Returns `{ data: { exists: boolean, companies: { id, name }[] } }` for the
* companies the CURRENT USER already has with the given organisation number —
* scoped to their own account only.
*
* Org-number reuse across the platform is intentionally allowed (see
* lib/company/actions.ts), so this is a soft, account-scoped warning, NOT a
* uniqueness gate. It uses the normal authenticated client on purpose: the
* `companies` SELECT RLS policy limits results to companies the caller is a
* member of (id IN user_company_ids()), so it can never reveal another user's
* companies and can't be used to enumerate org numbers platform-wide.
*
* Normalizes input with the same rule as the create action so a 12-digit form
* still matches a stored 10-digit canonical. Returns no matches for malformed
* input — the create action rejects that separately as `org_number_invalid`.
*/
export async function GET(request: Request) {
// requireAuth() (not a raw getUser()) so MFA AAL2 is enforced on hosted before
// we run the account-scoped lookup. The returned client carries the caller's
// RLS context, which is what scopes the companies SELECT below.
const { supabase, error: authError } = await requireAuth()
if (authError) return authError
const url = new URL(request.url)
const raw = url.searchParams.get('org_number') ?? ''
if (!raw) {
return NextResponse.json({ error: 'org_number is required' }, { status: 400 })
}
const canonical = normalizeOrgNumber(raw)
if (!canonical) {
// Malformed input is not a duplicate of anything by definition.
return NextResponse.json({ data: { exists: false, companies: [] } })
}
// RLS scopes this SELECT to the caller's own memberships (companies_select:
// id IN user_company_ids()), so the result is inherently account-scoped.
const { data, error } = await supabase
.from('companies')
.select('id, name')
.eq('org_number', canonical)
.is('archived_at', null)
if (error) {
return NextResponse.json({ error: error.message }, { status: 500 })
}
const companies = (data ?? []).map((c: { id: string; name: string }) => ({
id: c.id,
name: c.name,
}))
return NextResponse.json({
data: { exists: companies.length > 0, companies },
})
}