* fix(security): tenant guard on the GL-line read RPCs (PR #624 follow-up) get_unlinked_gl_lines and get_account_gl_lines_for_matching are SECURITY DEFINER and EXECUTE-able by anon/authenticated, so any authenticated (or anonymous) caller could invoke them directly over /rest/v1/rpc with another company's id and read its general-ledger lines — a cross-tenant read that bypasses the API routes' requireCompanyId() guard. Confirmed against the DB: anon and authenticated both hold EXECUTE, and SECURITY DEFINER sidesteps RLS. Add an in-function guard constraining anon/authenticated callers to their own companies (the same boundary user_company_ids()/RLS enforces). Trusted callers are untouched — service_role (the enable-banking reconciliation cron) and direct / superuser access (migrations, the pg-real harness) are not anon/authenticated, so the predicate is a no-op and behaviour is unchanged. A foreign company id now yields zero rows, not data. Scope: hardens the two READ RPCs that expose ledger data. The remaining company-scoped SECURITY DEFINER RPCs are writes / sequence generators with their own internal authorization; a broader audit of that set is tracked separately. pg-real coverage: a company-B member probing company A gets zero rows from both RPCs, while a company-A member and direct/superuser access still see the data. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(security): revoke EXECUTE from PUBLIC/anon on the GL-line read RPCs Defense-in-depth follow-up to the tenant guard. The guard already returns zero rows to an anon/authenticated caller probing another company; this additionally strips the EXECUTE privilege so an unauthenticated (anon) caller cannot invoke the financial-ledger RPCs at all. Supabase grants EXECUTE to PUBLIC as well as to anon, and anon is a member of PUBLIC — revoking only anon is insufficient, so revoke both, then keep the two legitimate callers: authenticated (the API routes call via the user's session; the in-function guard scopes them to their own companies) and service_role (the enable-banking reconciliation cron). Verified on the DB: anon EXECUTE = false, authenticated/service_role = true. Adds an anon-role pg test asserting the call is rejected at the privilege layer. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(security): read JWT role from claims object in the GL-line RPC guard The 20260611120000 guard used auth.role() to detect the caller's role, but auth.role() reads the individual request.jwt.claim.role GUC first and only some installs fall back to the claims object. PostgREST sets the claims OBJECT (the individual claim.* GUCs are deprecated), and the pg-real harness sets request.jwt.claims (+ claim.sub for auth.uid()) but NOT claim.role — so on an auth.role() without the object fallback it returns NULL and the guard's NOT IN ('anon','authenticated') branch was TRUE, skipping the membership check. A pg-real test caught it: an authenticated non-member could still read another company's GL lines (the guard failed open in that environment). Read the role straight from request.jwt.claims (exactly what auth.role() itself falls back to), so the guard enforces in every environment regardless of which JWT-claim GUCs are populated. Verified on the DB: an authenticated non-member evaluates both guard branches false → row excluded. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
114 lines
4.7 KiB
TypeScript
114 lines
4.7 KiB
TypeScript
/**
|
|
* pg-real test for the GL-line read-RPC tenant guard
|
|
* (20260611120000_gl_lines_rpc_tenant_guard.sql).
|
|
*
|
|
* get_unlinked_gl_lines and get_account_gl_lines_for_matching are SECURITY
|
|
* DEFINER and EXECUTE-able by anon/authenticated, so without the guard any
|
|
* authenticated user could call them directly with another company's id and read
|
|
* its general ledger. The guard enforces membership for anon/authenticated while
|
|
* leaving service_role and direct/superuser access (this harness, migrations,
|
|
* the reconciliation cron) untouched.
|
|
*/
|
|
import { describe, it, expect } from 'vitest'
|
|
import { randomUUID } from 'node:crypto'
|
|
import { getPool, withUserContext } from './setup'
|
|
import { seedCompany } from './fixtures'
|
|
|
|
async function insertPostedJournalEntry(params: {
|
|
userId: string
|
|
companyId: string
|
|
fiscalPeriodId: string
|
|
entryDate: string
|
|
voucherNumber: number
|
|
amount?: number
|
|
}): Promise<string> {
|
|
const id = randomUUID()
|
|
const amount = params.amount ?? 1500
|
|
await getPool().query(
|
|
`INSERT INTO public.journal_entries
|
|
(id, user_id, company_id, fiscal_period_id, voucher_number, voucher_series,
|
|
entry_date, description, source_type, status)
|
|
VALUES ($1, $2, $3, $4, $5, 'A', $6, 'Bank tx', 'bank_transaction', 'posted')`,
|
|
[id, params.userId, params.companyId, params.fiscalPeriodId, params.voucherNumber, params.entryDate],
|
|
)
|
|
await getPool().query(
|
|
`INSERT INTO public.journal_entry_lines
|
|
(journal_entry_id, account_number, debit_amount, credit_amount)
|
|
VALUES ($1, '1930', $2, 0),
|
|
($1, '2091', 0, $2)`,
|
|
[id, amount],
|
|
)
|
|
return id
|
|
}
|
|
|
|
const UNLINKED = `SELECT journal_entry_id FROM public.get_unlinked_gl_lines($1)`
|
|
const MATCHING = `SELECT journal_entry_id FROM public.get_account_gl_lines_for_matching($1, '1930', NULL, NULL, true)`
|
|
|
|
describe('GL-line read RPCs — tenant-isolation guard', () => {
|
|
it('lets a member read its own company but blocks an authenticated non-member', async () => {
|
|
const a = await seedCompany() // userA is owner-member of companyA
|
|
const b = await seedCompany() // userB belongs to companyB only
|
|
const entryA = await insertPostedJournalEntry({
|
|
userId: a.userId,
|
|
companyId: a.companyId,
|
|
fiscalPeriodId: a.fiscalPeriodId,
|
|
entryDate: '2026-03-15',
|
|
voucherNumber: 1,
|
|
})
|
|
|
|
// Direct / superuser connection (no JWT role) — the trusted bypass that this
|
|
// harness, migrations and the service-role cron rely on. Data is visible.
|
|
const bare = await getPool().query(UNLINKED, [a.companyId])
|
|
expect(bare.rows.map((r) => r.journal_entry_id)).toContain(entryA)
|
|
|
|
// A member of company A sees A's line through both RPCs.
|
|
await withUserContext(a.userId, async (client) => {
|
|
const u = await client.query(UNLINKED, [a.companyId])
|
|
expect(u.rows.map((r) => r.journal_entry_id)).toContain(entryA)
|
|
const m = await client.query(MATCHING, [a.companyId])
|
|
expect(m.rows.map((r) => r.journal_entry_id)).toContain(entryA)
|
|
})
|
|
|
|
// A member of company B probing company A gets nothing — the cross-tenant
|
|
// read that SECURITY DEFINER + anon/authenticated EXECUTE used to allow.
|
|
await withUserContext(b.userId, async (client) => {
|
|
const u = await client.query(UNLINKED, [a.companyId])
|
|
expect(u.rows).toHaveLength(0)
|
|
const m = await client.query(MATCHING, [a.companyId])
|
|
expect(m.rows).toHaveLength(0)
|
|
})
|
|
})
|
|
|
|
it('rejects an anon (unauthenticated) caller outright — EXECUTE revoked from anon + PUBLIC', async () => {
|
|
const a = await seedCompany()
|
|
await insertPostedJournalEntry({
|
|
userId: a.userId,
|
|
companyId: a.companyId,
|
|
fiscalPeriodId: a.fiscalPeriodId,
|
|
entryDate: '2026-03-15',
|
|
voucherNumber: 1,
|
|
})
|
|
|
|
// Each probe runs in its own transaction: a permission-denied error aborts
|
|
// the transaction, so the two can't share one. anon has no EXECUTE (revoked
|
|
// from its own grant AND from PUBLIC, of which anon is a member), so the call
|
|
// is rejected at the privilege layer — defense in depth on top of the
|
|
// in-function tenant guard.
|
|
const callAsAnon = async (sql: string): Promise<void> => {
|
|
const client = await getPool().connect()
|
|
try {
|
|
await client.query('BEGIN')
|
|
await client.query(`SELECT set_config('request.jwt.claims', '{"role":"anon"}', true)`)
|
|
await client.query('SET LOCAL ROLE anon')
|
|
await client.query(sql, [a.companyId])
|
|
} finally {
|
|
await client.query('ROLLBACK').catch(() => {})
|
|
client.release()
|
|
}
|
|
}
|
|
|
|
await expect(callAsAnon(UNLINKED)).rejects.toThrow(/permission denied/i)
|
|
await expect(callAsAnon(MATCHING)).rejects.toThrow(/permission denied/i)
|
|
})
|
|
})
|