Files
accounted/lib/events/handlers/event-log-handler.ts
T
Jakob WennbergandClaude Opus 4.7 a0485ca1c1 fix: BankID signup takeover + supplier invoice dedup + event_log RLS visibility (#358)
* fix(tic): reject BankID signup when email is already registered (CWE-287)

Signup previously linked BankID to any pre-existing profile matching the
submitted email. Because BankID proves identity but not email ownership,
an attacker who knew a victim's email could bind their own BankID to the
victim's account and then log in via BankID (which skips TOTP MFA).

Now signup returns 409 account_exists; the register page shows a Swedish
error toast and redirects to /login so the user can authenticate with
their password first and link BankID from settings (via the authenticated
/bankid/link route that already exists).

Covered by new bankid-complete.test.ts with an explicit regression test
asserting no side-effects occur on the account_exists path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(bookkeeping): prevent duplicate registration entries for supplier invoices

The invoice-inbox convert flow creates the registration journal entry
inline and then emits supplier_invoice.confirmed. The core handler was
also creating one, producing a second voucher on 2440/2641/expense and
overwriting registration_journal_entry_id on the row.

Two guards in the core handler:
- Payload guard: skip if supplierInvoice.registration_journal_entry_id
  is already set (fast path for callers that include it in the payload).
- DB re-fetch guard: re-read the row and skip if it has been linked
  since the payload was built (handles stale-payload callers).

The inbox extension now stamps registration_journal_entry_id onto the
in-memory invoice before emitting so the fast path trips.

Also fixes a latent bug where the handler filtered company_settings by
userId instead of companyId, which would have selected the wrong row
(or none) on multi-company accounts.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(events): write company_id on event_log rows and refuse unscoped events

event_log has a company-scoped SELECT RLS policy, so rows written with
NULL company_id are invisible to every user — effectively silently
dropped from the automation feed. The handler now reads companyId from
the payload (all persisted event types mandate it in TS) and includes
it in both single and batch inserts.

If a caller ever bypasses the type system and emits without companyId,
the handler logs an error and skips persistence rather than writing a
poisoned row.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: address PR review nits (event-log meta strip, redirect timer)

- event-log-handler: rename stripUserId → stripMetaFields and also drop
  companyId from the stored data JSONB so it isn't duplicated alongside
  its dedicated column.
- register page: drop the 1500ms setTimeout before router.push('/login')
  on the account_exists branch — the timer had no cleanup and fired a
  stale-closure push if the component unmounted first. The toast survives
  the route change via the root layout's Toaster.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 12:51:56 +02:00

170 lines
5.5 KiB
TypeScript

import { eventBus } from '@/lib/events/bus'
import type { CoreEventType } from '@/lib/events/types'
import { createServiceClientNoCookies } from '@/lib/auth/api-keys'
import { createLogger } from '@/lib/logger'
const log = createLogger('event-log')
/**
* Event types persisted to the event_log table for external automation platforms.
* Excludes noise events that are always followed by an actionable event.
*/
const PERSISTED_EVENT_TYPES: CoreEventType[] = [
'journal_entry.committed',
'journal_entry.reversed',
'journal_entry.corrected',
'document.uploaded',
'document.accessed',
'invoice.created',
'invoice.sent',
'credit_note.created',
'transaction.synced',
'transaction.categorized',
'transaction.reconciled',
'period.locked',
'period.year_closed',
'customer.created',
'receipt.matched',
'receipt.confirmed',
'supplier_invoice.registered',
'supplier_invoice.approved',
'supplier_invoice.paid',
'supplier_invoice.credited',
'invoice.match_confirmed',
'supplier_invoice.match_confirmed',
'supplier_invoice.confirmed',
]
// Excluded (with reasoning):
// - journal_entry.drafted: always followed by .committed
// - receipt.extracted: intermediate AI step; .matched/.confirmed are actionable
// - supplier_invoice.received: inbox receipt; .confirmed is actionable
// - supplier_invoice.extracted: intermediate AI step
/**
* Extract the primary entity ID from an event payload.
*/
function extractEntityId(payload: Record<string, unknown>): string | null {
// Try common entity shapes in priority order
const entityKeys = [
'entry', 'invoice', 'transaction', 'customer', 'receipt',
'supplierInvoice', 'creditNote', 'period', 'document', 'inboxItem',
] as const
for (const key of entityKeys) {
const entity = payload[key]
if (entity && typeof entity === 'object' && 'id' in entity) {
const id = (entity as Record<string, unknown>).id
if (typeof id === 'string') return id
}
}
// For journal_entry.corrected: use the corrected entry's ID
if ('corrected' in payload) {
const corrected = payload.corrected
if (corrected && typeof corrected === 'object' && 'id' in corrected) {
const id = (corrected as Record<string, unknown>).id
if (typeof id === 'string') return id
}
}
// For journal_entry.reversed: use the reversal entry's ID
if ('reversalEntry' in payload) {
const reversalEntry = payload.reversalEntry
if (reversalEntry && typeof reversalEntry === 'object' && 'id' in reversalEntry) {
const id = (reversalEntry as Record<string, unknown>).id
if (typeof id === 'string') return id
}
}
return null
}
/**
* Strip userId and companyId from payload (each stored in its own column) and
* return clean data for the JSONB blob.
*/
function stripMetaFields(payload: Record<string, unknown>): Record<string, unknown> {
const { userId: _userId, companyId: _companyId, ...data } = payload
return data
}
/**
* Persist a single event to the event_log table.
*/
async function persistEvent(
eventType: string,
userId: string,
companyId: string,
entityId: string | null,
data: Record<string, unknown>
): Promise<void> {
const supabase = createServiceClientNoCookies()
const { error } = await supabase
.from('event_log')
.insert({
user_id: userId,
company_id: companyId,
event_type: eventType,
entity_id: entityId,
data,
})
if (error) {
log.error(`Failed to persist event ${eventType}:`, error.message)
}
}
/**
* Register event log handlers on the event bus.
* Persists events to the event_log table for external automation platforms.
* Returns an array of unsubscribe functions.
*/
export function registerEventLogHandler(): (() => void)[] {
return PERSISTED_EVENT_TYPES.map((eventType) =>
eventBus.on(eventType, async (payload) => {
try {
const rawPayload = payload as Record<string, unknown>
const userId = rawPayload.userId as string
const companyId = rawPayload.companyId
// All persisted event payloads mandate companyId in TypeScript; this guard
// protects against any caller that bypasses the type system. Writing NULL
// would make the row invisible to the company_id-scoped SELECT RLS policy.
if (typeof companyId !== 'string' || companyId.length === 0) {
log.error(`Event ${eventType} missing companyId; skipping persistence`)
return
}
// transaction.synced carries an array — batch insert
if (eventType === 'transaction.synced' && Array.isArray(rawPayload.transactions)) {
const transactions = rawPayload.transactions as Array<Record<string, unknown>>
if (transactions.length === 0) return
const rows = transactions.map(tx => ({
user_id: userId,
company_id: companyId,
event_type: eventType,
entity_id: typeof tx.id === 'string' ? tx.id : null,
data: { transaction: tx },
}))
const supabase = createServiceClientNoCookies()
const { error } = await supabase.from('event_log').insert(rows)
if (error) {
log.error(`Failed to persist batch transaction.synced:`, error.message)
}
return
}
const entityId = extractEntityId(rawPayload)
const data = stripMetaFields(rawPayload)
await persistEvent(eventType, userId, companyId, entityId, data)
} catch (err) {
log.error(`Event log handler error for ${eventType}:`, err)
}
})
)
}