* feat(white-label): invite-only signup for brand domains
A brand domain belongs to the partner's people (founder decision
2026-08-27): only allowlisted or invited users may create an account on
an invite-only brand domain; everyone else is shown an interstitial that
sends them to the canonical Accounted signup.
- brands.signup_mode ('open' default / 'invite_only') +
brand_signup_allowlist (lowercase emails, team-scoped RLS, owner/admin
writes) + create_company_for_brand_signup RPC, with pg-real coverage
- server-side gate (lib/auth/brand-signup-gate.ts) enforced on every
signup path: email signup moved to POST /api/auth/signup (the browser
used to call GoTrue directly, so a client-side check would be
bypassable), BankID gated in /bankid/complete, Google covered by the
dashboard layout's brand-domain bounce
- company invites bypass the allowlist: the invite is the authorization
- register page interstitial on gated brands (no email in the outbound
URL), sv+en strings
- dashboard layout bounces non-belonging sessions off gated brand hosts
to the canonical domain (navigation rule like WL-01, not a security
boundary)
- allowlisted signups' onboarding-created companies attach to the
brand's byra team via the new RPC, so WL-01 homes them on the brand
domain; the allowlist entry recorded by an owner/admin stands in for
the WL-15 admin gate
- byra cockpit page /clients/access + /api/clients/signup-access to
manage the mode and the allowlist
All existing brands default to 'open': behavior is byte-identical until
a brand is flipped to invite_only.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4
* fix(white-label): rollback brand-signup company with the service client
Skeptic (correctness) found that a brand-signup company created under the
service role rolled back with the cookie-session client: `companies` has
RLS and no FOR DELETE policy, so the delete was a silent 0-row no-op,
stranding a member-less ghost company on the partner's byra team. Pass an
optional rollbackClient to createCompanyCore and hand it the service
client on that path; user_preferences.active_company_id then clears itself
via its ON DELETE SET NULL FK once the company row is actually deleted.
Also map a validateBody 400 (flat envelope, no code) on the register page
to the specific email-invalid field message instead of the generic one,
since the client already pre-gates password strength.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4
* fix(white-label): fail-safe brand lookup, pg-test seed, anonymize fixtures
Second resolve-pr cycle: skeptic + CodeRabbit findings and a green-up.
- Fail safe on a brands-table error (CodeRabbit CWE-285): the gate treated a
failed resolveBrandByHost as an unbranded host, opening invite-only signup
during a transient DB blip. resolveBrandResultByHost now distinguishes
"no brand" from "lookup failed"; the gate returns lookupFailed and the
email + BankID routes answer 503 (retry), never creating an account.
- pg-real: the RLS delete test seeded its row inside withUserContext, which
always rolls back, so the owner DELETE saw zero rows. Seed on the superuser
pool instead.
- Anonymize every test/fixture brand to the repo's existing synthetic
placeholder (Siffra / app.siffra.se): no real partner names in code.
- SignupAccessManager: functional setData updates so a concurrent mode
toggle and an add/remove do not clobber each other's snapshot (CodeRabbit).
- Route a transient-error message through i18n instead of the raw envelope
(raw-user-error guard); new register.error_temporary sv+en.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4
* test(white-label): anonymize new signup-gate fixtures; log oracle residual
Rename the placeholder brand in the four new brand-signup test files to a
clearly-fake, partner-unrelated name (Testbrand / app.testbrand.example);
the previous placeholder echoed a real partner. Scoped to files this PR
creates; the repo-wide legacy placeholder is left for a separate cleanup.
Also record in DECISIONS.md that the feature ships accepting the
low-severity allowlist-enumeration residual (captcha-free 403 vs 200 on
the signup endpoint), with rate-limiting as the follow-up option.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
136 lines
5.3 KiB
TypeScript
136 lines
5.3 KiB
TypeScript
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest'
|
|
import { readFileSync } from 'node:fs'
|
|
import path from 'node:path'
|
|
import { eventBus } from '@/lib/events/bus'
|
|
import {
|
|
captchaTokenOptions,
|
|
getTurnstileRolloutState,
|
|
isTurnstileSubmissionBlocked,
|
|
resolveTurnstileSiteKey,
|
|
} from '../turnstile'
|
|
|
|
const readRepoFile = (file: string) =>
|
|
readFileSync(path.join(process.cwd(), file), 'utf8')
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
eventBus.clear()
|
|
})
|
|
|
|
afterEach(() => {
|
|
vi.unstubAllEnvs()
|
|
})
|
|
|
|
describe('Turnstile rollout state', () => {
|
|
it('keeps Auth available while the public site key is absent', () => {
|
|
expect(resolveTurnstileSiteKey(undefined)).toBeNull()
|
|
expect(resolveTurnstileSiteKey('')).toBeNull()
|
|
expect(resolveTurnstileSiteKey(' ')).toBeNull()
|
|
expect(getTurnstileRolloutState(undefined)).toBe('disabled')
|
|
expect(isTurnstileSubmissionBlocked(null, undefined)).toBe(false)
|
|
})
|
|
|
|
it('treats an unsubstituted Docker sentinel as disabled', () => {
|
|
const sentinel = '__NEXT_PUBLIC_TURNSTILE_SITE_KEY__'
|
|
expect(resolveTurnstileSiteKey(sentinel)).toBeNull()
|
|
expect(getTurnstileRolloutState(sentinel)).toBe('disabled')
|
|
expect(isTurnstileSubmissionBlocked(null, sentinel)).toBe(false)
|
|
})
|
|
|
|
it('fails closed after the client site key is configured', () => {
|
|
const siteKey = ' public-site-key '
|
|
expect(resolveTurnstileSiteKey(siteKey)).toBe('public-site-key')
|
|
expect(getTurnstileRolloutState(siteKey)).toBe('client-enabled')
|
|
expect(isTurnstileSubmissionBlocked(null, siteKey)).toBe(true)
|
|
expect(isTurnstileSubmissionBlocked('', siteKey)).toBe(true)
|
|
expect(isTurnstileSubmissionBlocked('verified-token', siteKey)).toBe(false)
|
|
})
|
|
|
|
it('reads the runtime-substituted environment value at call time', () => {
|
|
vi.stubEnv('NEXT_PUBLIC_TURNSTILE_SITE_KEY', '')
|
|
expect(getTurnstileRolloutState()).toBe('disabled')
|
|
|
|
vi.stubEnv('NEXT_PUBLIC_TURNSTILE_SITE_KEY', 'runtime-site-key')
|
|
expect(getTurnstileRolloutState()).toBe('client-enabled')
|
|
})
|
|
|
|
it('forwards only a non-empty token to Supabase Auth', () => {
|
|
expect(captchaTokenOptions(null)).toEqual({})
|
|
expect(captchaTokenOptions(undefined)).toEqual({})
|
|
expect(captchaTokenOptions(' ')).toEqual({})
|
|
expect(captchaTokenOptions(' token-value ')).toEqual({
|
|
captchaToken: 'token-value',
|
|
})
|
|
})
|
|
})
|
|
|
|
describe('Turnstile integration contract', () => {
|
|
it('protects every public Supabase Auth flow in scope', () => {
|
|
const login = readRepoFile('app/(auth)/login/login-client.tsx')
|
|
const register = readRepoFile('app/(auth)/register/page.tsx')
|
|
const sandbox = readRepoFile('app/sandbox/page.tsx')
|
|
|
|
expect(login).toMatch(
|
|
/signInWithPassword\([\s\S]*?options: captchaTokenOptions\(passwordCaptchaToken\)/,
|
|
)
|
|
expect(login).toMatch(
|
|
/resetPasswordForEmail\([\s\S]*?captchaTokenOptions\(resetCaptchaToken\)/,
|
|
)
|
|
expect(login).toContain('action="accounted_login"')
|
|
expect(login).toContain('action="accounted_password_reset"')
|
|
|
|
// The register page's email flow moved server-side (invite-only brand
|
|
// domain gate, 2026-08-27): the captcha token must travel to
|
|
// POST /api/auth/signup, and that route must forward it into the GoTrue
|
|
// signUp call, so the CAPTCHA still guards the flow end to end.
|
|
expect(register).toMatch(
|
|
/fetch\('\/api\/auth\/signup'[\s\S]*?captchaTokenOptions\(captchaToken\)/,
|
|
)
|
|
expect(register).toContain('action="accounted_signup"')
|
|
const signupRoute = readRepoFile('app/api/auth/signup/route.ts')
|
|
expect(signupRoute).toMatch(/signUp\(\{[\s\S]*?captchaToken/)
|
|
|
|
expect(sandbox).toMatch(
|
|
/signInAnonymously\([\s\S]*?captchaTokenOptions\(captchaToken\)/,
|
|
)
|
|
expect(sandbox).toContain('action="accounted_sandbox"')
|
|
})
|
|
|
|
it('keeps the public key, CSP, and Docker runtime contract in sync', () => {
|
|
const envExample = readRepoFile('.env.example')
|
|
const dockerEnvExample = readRepoFile('.env.docker.example')
|
|
const dockerfile = readRepoFile('Dockerfile')
|
|
const entrypoint = readRepoFile('docker-entrypoint.sh')
|
|
const nextConfig = readRepoFile('next.config.ts')
|
|
|
|
expect(envExample).toContain('NEXT_PUBLIC_TURNSTILE_SITE_KEY=')
|
|
expect(dockerEnvExample).toContain('NEXT_PUBLIC_TURNSTILE_SITE_KEY=')
|
|
expect(dockerfile).toContain(
|
|
'NEXT_PUBLIC_TURNSTILE_SITE_KEY=__NEXT_PUBLIC_TURNSTILE_SITE_KEY__',
|
|
)
|
|
expect(entrypoint).toContain('__NEXT_PUBLIC_TURNSTILE_SITE_KEY__')
|
|
expect(nextConfig).toContain('https://challenges.cloudflare.com')
|
|
expect(nextConfig).toMatch(/script-src[\s\S]*?turnstileOrigin/)
|
|
expect(nextConfig).toMatch(/frame-src[\s\S]*?turnstileOrigin/)
|
|
expect(envExample).not.toContain('TURNSTILE_SECRET_KEY')
|
|
expect(dockerEnvExample).not.toContain('TURNSTILE_SECRET_KEY')
|
|
})
|
|
|
|
it('ships matching Swedish and English challenge messages', () => {
|
|
const swedish = JSON.parse(readRepoFile('messages/sv.json')).auth
|
|
const english = JSON.parse(readRepoFile('messages/en.json')).auth
|
|
const keys = [
|
|
'turnstile_checking',
|
|
'turnstile_required',
|
|
'turnstile_error',
|
|
]
|
|
|
|
for (const key of keys) {
|
|
expect(swedish[key]).toBeTypeOf('string')
|
|
expect(swedish[key]).not.toBe('')
|
|
expect(english[key]).toBeTypeOf('string')
|
|
expect(english[key]).not.toBe('')
|
|
}
|
|
})
|
|
})
|