Files
accounted/app/api/clients/signup-access/__tests__/route.test.ts
T
MattssonandClaude Fable 5 4f6ecad549 feat(white-label): invite-only signup for brand domains (#1995)
* feat(white-label): invite-only signup for brand domains

A brand domain belongs to the partner's people (founder decision
2026-08-27): only allowlisted or invited users may create an account on
an invite-only brand domain; everyone else is shown an interstitial that
sends them to the canonical Accounted signup.

- brands.signup_mode ('open' default / 'invite_only') +
  brand_signup_allowlist (lowercase emails, team-scoped RLS, owner/admin
  writes) + create_company_for_brand_signup RPC, with pg-real coverage
- server-side gate (lib/auth/brand-signup-gate.ts) enforced on every
  signup path: email signup moved to POST /api/auth/signup (the browser
  used to call GoTrue directly, so a client-side check would be
  bypassable), BankID gated in /bankid/complete, Google covered by the
  dashboard layout's brand-domain bounce
- company invites bypass the allowlist: the invite is the authorization
- register page interstitial on gated brands (no email in the outbound
  URL), sv+en strings
- dashboard layout bounces non-belonging sessions off gated brand hosts
  to the canonical domain (navigation rule like WL-01, not a security
  boundary)
- allowlisted signups' onboarding-created companies attach to the
  brand's byra team via the new RPC, so WL-01 homes them on the brand
  domain; the allowlist entry recorded by an owner/admin stands in for
  the WL-15 admin gate
- byra cockpit page /clients/access + /api/clients/signup-access to
  manage the mode and the allowlist

All existing brands default to 'open': behavior is byte-identical until
a brand is flipped to invite_only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4

* fix(white-label): rollback brand-signup company with the service client

Skeptic (correctness) found that a brand-signup company created under the
service role rolled back with the cookie-session client: `companies` has
RLS and no FOR DELETE policy, so the delete was a silent 0-row no-op,
stranding a member-less ghost company on the partner's byra team. Pass an
optional rollbackClient to createCompanyCore and hand it the service
client on that path; user_preferences.active_company_id then clears itself
via its ON DELETE SET NULL FK once the company row is actually deleted.

Also map a validateBody 400 (flat envelope, no code) on the register page
to the specific email-invalid field message instead of the generic one,
since the client already pre-gates password strength.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4

* fix(white-label): fail-safe brand lookup, pg-test seed, anonymize fixtures

Second resolve-pr cycle: skeptic + CodeRabbit findings and a green-up.

- Fail safe on a brands-table error (CodeRabbit CWE-285): the gate treated a
  failed resolveBrandByHost as an unbranded host, opening invite-only signup
  during a transient DB blip. resolveBrandResultByHost now distinguishes
  "no brand" from "lookup failed"; the gate returns lookupFailed and the
  email + BankID routes answer 503 (retry), never creating an account.
- pg-real: the RLS delete test seeded its row inside withUserContext, which
  always rolls back, so the owner DELETE saw zero rows. Seed on the superuser
  pool instead.
- Anonymize every test/fixture brand to the repo's existing synthetic
  placeholder (Siffra / app.siffra.se): no real partner names in code.
- SignupAccessManager: functional setData updates so a concurrent mode
  toggle and an add/remove do not clobber each other's snapshot (CodeRabbit).
- Route a transient-error message through i18n instead of the raw envelope
  (raw-user-error guard); new register.error_temporary sv+en.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4

* test(white-label): anonymize new signup-gate fixtures; log oracle residual

Rename the placeholder brand in the four new brand-signup test files to a
clearly-fake, partner-unrelated name (Testbrand / app.testbrand.example);
the previous placeholder echoed a real partner. Scoped to files this PR
creates; the repo-wide legacy placeholder is left for a separate cleanup.

Also record in DECISIONS.md that the feature ships accepting the
low-severity allowlist-enumeration residual (captcha-free 403 vs 200 on
the signup endpoint), with rate-limiting as the follow-up option.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-27 18:32:52 +02:00

172 lines
5.1 KiB
TypeScript

import { describe, it, expect, vi, beforeEach } from 'vitest'
import { NextResponse } from 'next/server'
import { createQueuedMockSupabase, parseJsonResponse } from '@/tests/helpers'
const { supabase, enqueue, reset } = createQueuedMockSupabase()
const service = createQueuedMockSupabase()
const requireAuthMock = vi.hoisted(() => vi.fn())
vi.mock('@/lib/auth/require-auth', () => ({
requireAuth: (...args: unknown[]) => requireAuthMock(...args),
}))
const byraMembershipMock = vi.hoisted(() => vi.fn())
vi.mock('@/lib/clients/fetch-client-overview', () => ({
getByraMembership: (...args: unknown[]) => byraMembershipMock(...args),
}))
const brandForTeamMock = vi.hoisted(() => vi.fn())
vi.mock('@/lib/branding/resolve', async (importOriginal) => {
const actual = await importOriginal<typeof import('@/lib/branding/resolve')>()
return {
...actual,
resolveBrandForTeam: (...args: unknown[]) => brandForTeamMock(...args),
clearBrandCache: vi.fn(),
}
})
vi.mock('@/lib/auth/api-keys', () => ({
createServiceClientNoCookies: vi.fn(() => service.supabase),
}))
import { GET, PATCH, POST, DELETE } from '../route'
const BRAND = {
id: 'brand-1',
teamId: 'team-1',
domain: 'app.testbrand.example',
appName: 'Testbrand',
signupMode: 'invite_only',
}
function makeRequest(method: string, body?: unknown): Request {
return new Request('https://app.test/api/clients/signup-access', {
method,
headers: { 'Content-Type': 'application/json' },
body: body === undefined ? undefined : JSON.stringify(body),
})
}
function authed() {
requireAuthMock.mockResolvedValue({
user: { id: 'user-1', email: 'byra@example.com' },
supabase,
error: null,
})
}
beforeEach(() => {
vi.clearAllMocks()
reset()
service.reset()
authed()
byraMembershipMock.mockResolvedValue({
teamId: 'team-1',
teamName: 'Byrån',
role: 'owner',
})
brandForTeamMock.mockResolvedValue(BRAND)
})
describe('/api/clients/signup-access', () => {
it('401s when unauthenticated', async () => {
requireAuthMock.mockResolvedValue({
user: null,
supabase,
error: NextResponse.json({ error: 'Unauthorized' }, { status: 401 }),
})
const res = await GET()
expect(res.status).toBe(401)
})
it('403s for non-byrå users', async () => {
byraMembershipMock.mockResolvedValue(null)
const res = await GET()
expect(res.status).toBe(403)
})
it('404s when the team has no brand', async () => {
brandForTeamMock.mockResolvedValue(null)
const res = await GET()
expect(res.status).toBe(404)
})
it('returns mode, role and entries', async () => {
enqueue({
data: [{ id: 'e1', email: 'kund@example.com', note: null, created_at: '2026-08-27' }],
})
const res = await GET()
const { body } = await parseJsonResponse<{
data: {
brand: { domain: string; signupMode: string }
role: string
entries: unknown[]
}
}>(res)
expect(res.status).toBe(200)
expect(body.data.brand.signupMode).toBe('invite_only')
expect(body.data.role).toBe('owner')
expect(body.data.entries).toHaveLength(1)
})
it('PATCH 403s for plain members', async () => {
byraMembershipMock.mockResolvedValue({
teamId: 'team-1',
teamName: 'Byrån',
role: 'member',
})
const res = await PATCH(makeRequest('PATCH', { signup_mode: 'invite_only' }))
expect(res.status).toBe(403)
expect(service.supabase.from).not.toHaveBeenCalled()
})
it('PATCH 400s on an unknown mode', async () => {
const res = await PATCH(makeRequest('PATCH', { signup_mode: 'wide_open' }))
expect(res.status).toBe(400)
})
it('PATCH flips the mode through the service client', async () => {
service.enqueue({ data: null, error: null })
const res = await PATCH(makeRequest('PATCH', { signup_mode: 'invite_only' }))
expect(res.status).toBe(200)
expect(service.findCall('brands', 'update')).toEqual([
{ signup_mode: 'invite_only' },
])
expect(service.findCall('brands', 'eq')).toEqual(['id', 'brand-1'])
})
it('POST adds a lowercased entry', async () => {
enqueue({
data: { id: 'e1', email: 'ny@example.com', note: 'VD', created_at: '2026-08-27' },
})
const res = await POST(
makeRequest('POST', { email: ' NY@Example.com ', note: 'VD' }),
)
expect(res.status).toBe(200)
const insert = supabase.from as unknown as ReturnType<typeof vi.fn>
expect(insert).toHaveBeenCalledWith('brand_signup_allowlist')
})
it('POST 409s on a duplicate email', async () => {
enqueue({ data: null, error: { code: '23505', message: 'duplicate' } })
const res = await POST(makeRequest('POST', { email: 'kund@example.com' }))
expect(res.status).toBe(409)
})
it('POST 400s on an invalid email', async () => {
const res = await POST(makeRequest('POST', { email: 'not-an-email' }))
expect(res.status).toBe(400)
})
it('DELETE removes scoped to the brand', async () => {
enqueue({ data: null, error: null })
const res = await DELETE(
makeRequest('DELETE', { id: '11111111-1111-4111-8111-111111111111' }),
)
expect(res.status).toBe(200)
})
})