* fix(security): bind api_keys to the caller, lock hash-as-bearer RPCs and provider token tables Security audit 2026-09-01, critical items. - api_keys INSERT requires user_id = auth.uid() again (an admin could forge a key for any co-member and act as them in every company they belong to); SELECT is own-keys-or-admin; a BEFORE trigger freezes the identity and credential columns against user-session UPDATEs. - rotate_mcp_refresh_token and validate_and_increment_api_key become service_role only: they match rows by a presented SHA-256, so a hash readable by co-members was a bearer credential. - validate_and_increment_api_key fails closed when the key's user is no longer a member of the key's company. - provider_consent_tokens and provider_otc: the DELETE policies collapsed to "caller has any team row" (correlated subquery on a non-existent team_members.company_id). All member policies dropped; service_role only, matching every existing code path. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(security): role gates, ownership guards and posting integrity in the database Security audit 2026-09-01, high items at the database layer. - One table-level guard, enforce_company_writer_role(), blocks the read-only viewer role on 55 company-scoped tables including through the 15 membership-only SECURITY DEFINER writers. Keyed on the JWT role claim so it fires inside definer bodies; no-op for service_role and trigger cascades. - company_members user_id/company_id immutable from user sessions; invitations can never grant owner; team_members gains a transition guard (admins keep non-owner role moves); companies team_id and archiving are owner-only and team attachment needs team membership. - Direct statements (current_user = authenticated) can no longer insert posted headers, add lines under posted verifikat, or post a draft with a voucher number the sequence never issued. Sanctioned RPCs run as the definer and are untouched; the engine's own draft-then-post shapes still pass. - create_document_version refuses viewers and foreign storage paths; validate_version_chain needs membership and loses anon EXECUTE; match_documents / match_booking_templates lose anon; cron maintenance RPCs become service_role only; the production-only seed_asset_categories is dropped. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * build: pin tsx as an exact devDependency instead of fetching it with npx at build time prebuild ran "npx tsx" with no lockfile entry, so every Vercel, Docker and CI build downloaded tsx@latest and its transitive tree from the registry with no integrity check, inside the build environment. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(security): refuse the viewer role on API-key and MCP write paths The v1 wrapper and the MCP company routing checked company membership but never role, and both run as service role, so a read-only viewer holding an API key could post vouchers and change settings through the API. Mutating methods and non-read scopes now return 403 ROLE_READ_ONLY for viewers on v1; MCP write tools refuse viewers the same way. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(security): stop serving uploaded SVG, XML and HTML as executable content on the app origin Uploads persisted the browser-declared mime type and the inline proxy served it verbatim, sandboxing only text/html; the storage proxy forwarded the uploader's Content-Type. Any writer, or any Peppol sender, could plant a scripted SVG or XHTML that executed on app.gnubok.se. - inline route: allow-list of natively safe types (PDF, raster images) served as before; everything else gets the opaque sandbox CSP. - storage proxy: octet-stream + attachment + sandbox unless the DB mime for the key is on the allow-list. - document-service: the stored mime is the magic-byte validated type. - logo upload: magic-byte validation, SVG refused. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(security): byrå brand logo upload decides the type by magic bytes and drops SVG Same pattern as the company logo route: the logos bucket is public, so a scripted SVG (or anything declared as an image) must never land there. The upload pickers stop advertising SVG. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(security): bind Enable Banking, Stripe and WooCommerce callbacks to the initiating user The callbacks resolved the pending row by oauth_state alone, so a victim who completed an attacker-initiated consent had their bank account, merchant account or store attached to the attacker's company. requireFlowInitiator() now requires the cookie session of the user who started the flow: no session redirects to login with the callback URL preserved, a different user is refused and nothing is exchanged. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(security): guard tenant-controlled outbound fetches and surface the disabled rate limiter WooCommerce and Shopify syncs fetched a member-editable store URL with plain fetch() and redirect following under the service role, and the invoice PDF renderer fetched company_settings.logo_url unguarded. All three go through a new safeFetch() (public-IP validation via url-guard, https only, redirect: 'manual', body size cap) and re-normalise the stored host at use time. checkRateLimit() keeps failing open on hosted but logs one error per process when Upstash is not configured and exports isRateLimiterConfigured(). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(security): decide the API MFA gate from server-authenticated factors, not the session cookie getAuthenticatorAssuranceLevel() without arguments derives nextLevel from session.user.factors, which comes from the unsigned sb-*-auth-token cookie. Deleting factors from the cookie made an enrolled account look like it had nothing to step up to, on every /api route and in requireAuth. Both gates now read factors from the getUser() result or listFactors() and the level from the verified JWT claim, and fail closed on errors. Page-branch gate hardened the same way. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(security): bind Fortnox/Visma, Gmail and Skatteverket callbacks to the initiating user The arcim-migration callback exchanged the provider code onto whatever consent the one-time state named, with no check of who completed the flow and no org-number comparison, so a phished Fortnox admin handed their ledger to the attacker's company. provider_otc now records the initiating user (migration 20260902100000); the callback requires that session and, after the exchange, refuses a provider company whose org number differs from the consent's company. The Gmail and Skatteverket callbacks enforce the same initiator check. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(security): BankID signup confirms the email before linking the identity Signup created an email-confirmed, MFA-exempt account for any address the caller typed and returned a magic link, so an attacker could pre-register a victim's email and keep a permanent BankID login into the account the victim later adopted. The user is now created unconfirmed, the identity carries email_verified_at NULL (migration 20260902101000), bankid_linked is not set until the mailed confirmation is clicked, and BankID login of a pending identity is refused with the confirmation re-sent. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(security): bind MCP OAuth redirect URIs to the consenting user and cap scopes A user-registered redirect URI was allowlisted globally, the consent page named no client, and all scopes were pre-checked, so one phishing link handed an attacker a full-scope key for the victim's company. Registered URIs now resolve only for the registrant or a colleague sharing a company; the consent page shows the client identity and redirect host; non-built-in clients default to read-only pre-checks; scopes are capped by the user's role (viewer: read only) at consent and at /token. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(auth): client follow-ups for BankID confirmation, callback mismatch copy and decision log - register client handles the new confirmation_sent response from BankID signup with the existing inbox screen instead of calling verifyOtp. - BankID login surfaces the email_unconfirmed explanation. - WooCommerce settings map woocommerce_error=wrong_user to its own copy. - Logo help text no longer advertises SVG. - DECISIONS.md records the audit remediation choices. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fix(mcp-oauth): literal SoD columns in the api_keys insert so the phantom-column scanner resolves them Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * test(logo): type the upload fixtures as Uint8Array<ArrayBuffer> so they are valid BlobParts Fixes the typecheck ratchet on PR #2155 and ratchets the baseline down by the one legacy error the change removed. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
569 lines
20 KiB
TypeScript
569 lines
20 KiB
TypeScript
import { describe, it, expect, beforeEach, afterEach, vi, type Mock } from 'vitest'
|
|
import { createMockSupabase, createMockRequest, parseJsonResponse } from '@/tests/helpers'
|
|
import type { ExtensionContext } from '@/lib/extensions/types'
|
|
|
|
/**
|
|
* Locks the tenant boundary on the unauthenticated OAuth callback
|
|
* (GET /callback, skipAuth: true).
|
|
*
|
|
* The callback used to decode `state` as plain base64url JSON and trust
|
|
* `consentId` / `provider` straight out of it. Nothing was signed and no
|
|
* server-side session row was checked, so anyone who learned a victim's consent
|
|
* id (it is handed to the browser in the success redirect and postMessage)
|
|
* could run OAuth against their OWN provider account and call the callback with
|
|
* `state=base64url({consentId: victim})`. The attacker's provider tokens landed
|
|
* on the victim's consent, and the victim's next migration imported the
|
|
* attacker's ledger.
|
|
*
|
|
* The callback now resolves everything from a server-written provider_otc row
|
|
* that it consumes atomically. These tests pin that: nothing from the query
|
|
* string reaches exchangeAuthToken, and every state failure looks identical
|
|
* from outside.
|
|
*/
|
|
|
|
vi.mock('../lib/migration-orchestrator', () => ({
|
|
executeMigration: vi.fn().mockResolvedValue({}),
|
|
}))
|
|
|
|
// index.ts imports many helpers from provider-client at module load; stub the
|
|
// whole module. The two error classes are real classes because index.ts
|
|
// branches on `instanceof`.
|
|
vi.mock('../lib/provider-client', () => ({
|
|
createConsent: vi.fn(),
|
|
getConsent: vi.fn(),
|
|
listConsents: vi.fn(),
|
|
generateOtc: vi.fn(),
|
|
consumeOAuthState: vi.fn(),
|
|
getAuthUrl: vi.fn(),
|
|
exchangeAuthToken: vi.fn(),
|
|
submitProviderToken: vi.fn(),
|
|
acceptConsent: vi.fn(),
|
|
deleteConsent: vi.fn(),
|
|
resolveConsent: vi.fn(),
|
|
fetchCompanyInfoDirect: vi.fn(),
|
|
ProviderTokenInvalidError: class ProviderTokenInvalidError extends Error {},
|
|
ProviderCompanyMismatchError: class ProviderCompanyMismatchError extends Error {},
|
|
ConsentNotFoundError: class ConsentNotFoundError extends Error {},
|
|
}))
|
|
|
|
// The /connect handler unconditionally imports this module (for its
|
|
// pending-consent token check); the real one pulls in next/headers.
|
|
vi.mock('@/lib/supabase/server', () => ({
|
|
createClient: vi.fn(),
|
|
createServiceClient: vi.fn(),
|
|
}))
|
|
|
|
// The callback also binds the completing browser session to the user recorded
|
|
// on the state row. That check has its own tests
|
|
// (oauth-callback-initiator.test.ts); here it always passes so these tests
|
|
// stay about the state token itself.
|
|
vi.mock('@/lib/auth/oauth-flow-binding', () => ({
|
|
requireFlowInitiator: vi.fn(),
|
|
FLOW_INITIATOR_MISMATCH_MESSAGE: 'initiator mismatch',
|
|
}))
|
|
|
|
import { arcimMigrationExtension } from '../index'
|
|
import { requireFlowInitiator } from '@/lib/auth/oauth-flow-binding'
|
|
import {
|
|
consumeOAuthState,
|
|
exchangeAuthToken,
|
|
getConsent,
|
|
createConsent,
|
|
listConsents,
|
|
generateOtc,
|
|
getAuthUrl,
|
|
ConsentNotFoundError,
|
|
} from '../lib/provider-client'
|
|
|
|
type RouteHandler = (request: Request, ctx?: ExtensionContext) => Promise<Response>
|
|
|
|
const findRoute = (method: string, path: string) =>
|
|
(arcimMigrationExtension.apiRoutes ?? []).find(
|
|
(r) => r.method === method && r.path === path,
|
|
)!
|
|
|
|
const callbackHandler = findRoute('GET', '/callback').handler as RouteHandler
|
|
const previewHandler = findRoute('GET', '/preview').handler as RouteHandler
|
|
|
|
// Every state row below was minted by 'user-1', and 'user-1' is the one
|
|
// completing the flow. Set per test, after each describe's clearAllMocks.
|
|
beforeEach(() => {
|
|
;(requireFlowInitiator as Mock).mockResolvedValue({ ok: true, userId: 'user-1' })
|
|
})
|
|
|
|
const APP_URL = 'https://app.example.test'
|
|
|
|
/** The exact string the callback shows for every state failure. */
|
|
const GENERIC_REJECTION = 'Ingen giltig migrationssession hittades'
|
|
|
|
function callbackRequest(params: Record<string, string>) {
|
|
return createMockRequest(
|
|
'http://localhost/api/extensions/ext/arcim-migration/callback',
|
|
{ searchParams: params },
|
|
)
|
|
}
|
|
|
|
/** The forged payload the old implementation would have trusted. */
|
|
function forgedLegacyState(consentId: string, provider: string) {
|
|
return Buffer.from(JSON.stringify({ consentId, provider })).toString('base64url')
|
|
}
|
|
|
|
describe('GET /callback: OAuth state binding', () => {
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
vi.stubEnv('NEXT_PUBLIC_APP_URL', APP_URL)
|
|
// The exchange redirect_uri now consults the per-provider override; keep
|
|
// these tests on the NEXT_PUBLIC_APP_URL fallback regardless of local env.
|
|
vi.stubEnv('FORTNOX_REDIRECT_URI', '')
|
|
vi.stubEnv('VISMA_REDIRECT_URI', '')
|
|
// The callback route is dispatched without an ExtensionContext (skipAuth
|
|
// routes get no ctx), so console is the logger. Keep the output quiet.
|
|
vi.spyOn(console, 'error').mockImplementation(() => {})
|
|
})
|
|
|
|
afterEach(() => {
|
|
vi.unstubAllEnvs()
|
|
vi.restoreAllMocks()
|
|
})
|
|
|
|
it('rejects a forged state: an unknown token never reaches token exchange', async () => {
|
|
;(consumeOAuthState as Mock).mockResolvedValue(null)
|
|
|
|
const res = await callbackHandler(
|
|
callbackRequest({
|
|
code: 'provider-auth-code',
|
|
state: forgedLegacyState('victim-consent-id', 'fortnox'),
|
|
}),
|
|
)
|
|
const html = await res.text()
|
|
|
|
expect(exchangeAuthToken).not.toHaveBeenCalled()
|
|
expect(html).toContain(GENERIC_REJECTION)
|
|
// The response must not echo anything the attacker put in the state.
|
|
expect(html).not.toContain('victim-consent-id')
|
|
})
|
|
|
|
it('rejects an expired state with the same generic message as a forged one', async () => {
|
|
// consumeOAuthState collapses expired into "no row": the expiry predicate
|
|
// lives in the UPDATE's WHERE clause (see provider-client tests).
|
|
;(consumeOAuthState as Mock).mockResolvedValue(null)
|
|
|
|
const res = await callbackHandler(
|
|
callbackRequest({ code: 'provider-auth-code', state: 'expired-token' }),
|
|
)
|
|
const html = await res.text()
|
|
|
|
expect(exchangeAuthToken).not.toHaveBeenCalled()
|
|
expect(html).toContain(GENERIC_REJECTION)
|
|
})
|
|
|
|
it('rejects a replayed state: the second callback with the same token fails', async () => {
|
|
// First delivery consumes the row, second finds nothing left to consume.
|
|
;(consumeOAuthState as Mock)
|
|
.mockResolvedValueOnce({ consentId: 'consent-1', provider: 'fortnox', userId: 'user-1' })
|
|
.mockResolvedValueOnce(null)
|
|
|
|
const first = await callbackHandler(
|
|
callbackRequest({ code: 'provider-auth-code', state: 'one-time-token' }),
|
|
)
|
|
const second = await callbackHandler(
|
|
callbackRequest({ code: 'provider-auth-code', state: 'one-time-token' }),
|
|
)
|
|
|
|
expect(await first.text()).toContain('Anslutningen lyckades')
|
|
expect(await second.text()).toContain(GENERIC_REJECTION)
|
|
// Exactly one exchange: the replay bought the attacker nothing.
|
|
expect(exchangeAuthToken).toHaveBeenCalledTimes(1)
|
|
expect(consumeOAuthState).toHaveBeenNthCalledWith(1, 'one-time-token')
|
|
expect(consumeOAuthState).toHaveBeenNthCalledWith(2, 'one-time-token')
|
|
})
|
|
|
|
it('takes consent and provider from the state ROW, never from the query string', async () => {
|
|
;(consumeOAuthState as Mock).mockResolvedValue({
|
|
consentId: 'consent-owned-by-caller',
|
|
provider: 'visma',
|
|
userId: 'user-1',
|
|
})
|
|
|
|
// The token names a different consent and provider. It must be ignored:
|
|
// the row wins.
|
|
const res = await callbackHandler(
|
|
callbackRequest({
|
|
code: 'provider-auth-code',
|
|
state: forgedLegacyState('victim-consent-id', 'fortnox'),
|
|
}),
|
|
)
|
|
|
|
expect(exchangeAuthToken).toHaveBeenCalledTimes(1)
|
|
expect(exchangeAuthToken).toHaveBeenCalledWith(
|
|
'consent-owned-by-caller',
|
|
'visma',
|
|
'provider-auth-code',
|
|
`${APP_URL}/api/extensions/ext/arcim-migration/callback`,
|
|
)
|
|
expect(await res.text()).toContain('consent-owned-by-caller')
|
|
})
|
|
})
|
|
|
|
/**
|
|
* The callback's no-opener arm used to be near-dead: the wizard only ever
|
|
* reached this route through a popup, which always has a window.opener.
|
|
* ArcimMigrationWorkspace now falls back to a full-page OAuth flow when the
|
|
* popup is blocked (a discarded window.open return value made a blocked popup
|
|
* look exactly like a successful one), so that arm is a live user path and the
|
|
* only way a popup-blocked user finishes the migration.
|
|
*
|
|
* These pin the URL it navigates to, because the wizard reads it on the other
|
|
* end: `/import?migration=...` sets mode='migration'
|
|
* (app/(dashboard)/import/page.tsx:1990) and handleOAuthReturn consumes
|
|
* `consentId` / `reason` from there. Dropping the arm, or renaming a param,
|
|
* would strand every popup-blocked user on this HTML page.
|
|
*/
|
|
describe('GET /callback: full-page fallback when there is no opener', () => {
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
vi.stubEnv('NEXT_PUBLIC_APP_URL', APP_URL)
|
|
vi.spyOn(console, 'error').mockImplementation(() => {})
|
|
})
|
|
|
|
afterEach(() => {
|
|
vi.unstubAllEnvs()
|
|
vi.restoreAllMocks()
|
|
})
|
|
|
|
/** The URL the page navigates to when window.opener is absent. */
|
|
function fallbackNavigation(html: string): URL {
|
|
// Both arms are emitted; the opener arm postMessages instead of navigating.
|
|
expect(html).toContain('window.opener')
|
|
// replace(), not href: the callback URL carries a spent one-time state and
|
|
// must not stay in session history. See the replay describe below.
|
|
const match = html.match(/window\.location\.replace\("([^"]+)"\)/)
|
|
expect(match, 'callback HTML has no no-opener navigation').not.toBeNull()
|
|
return new URL(match![1])
|
|
}
|
|
|
|
it('sends a successful connect back to the wizard with the consent id', async () => {
|
|
;(consumeOAuthState as Mock).mockResolvedValue({
|
|
consentId: 'consent-1',
|
|
provider: 'fortnox',
|
|
userId: 'user-1',
|
|
})
|
|
|
|
const res = await callbackHandler(
|
|
callbackRequest({ code: 'provider-auth-code', state: 'one-time-token' }),
|
|
)
|
|
const target = fallbackNavigation(await res.text())
|
|
|
|
expect(target.origin).toBe(APP_URL)
|
|
expect(target.pathname).toBe('/import')
|
|
expect(target.searchParams.get('migration')).toBe('connected')
|
|
expect(target.searchParams.get('consentId')).toBe('consent-1')
|
|
})
|
|
|
|
it('sends a failure back to the wizard with the reason attached', async () => {
|
|
;(consumeOAuthState as Mock).mockResolvedValue(null)
|
|
|
|
const res = await callbackHandler(
|
|
callbackRequest({ code: 'provider-auth-code', state: 'forged-token' }),
|
|
)
|
|
const target = fallbackNavigation(await res.text())
|
|
|
|
expect(target.pathname).toBe('/import')
|
|
expect(target.searchParams.get('migration')).toBe('error')
|
|
expect(target.searchParams.get('reason')).toContain(GENERIC_REJECTION)
|
|
})
|
|
|
|
it('includes the consent id when a full-page provider error can be resumed', async () => {
|
|
;(consumeOAuthState as Mock).mockResolvedValue({
|
|
consentId: 'consent-1',
|
|
provider: 'fortnox',
|
|
userId: 'user-1',
|
|
})
|
|
|
|
const res = await callbackHandler(
|
|
callbackRequest({
|
|
error: 'access_denied',
|
|
error_description: 'User denied consent',
|
|
state: 'one-time-token',
|
|
}),
|
|
)
|
|
const target = fallbackNavigation(await res.text())
|
|
|
|
expect(target.searchParams.get('migration')).toBe('error')
|
|
expect(target.searchParams.get('consentId')).toBe('consent-1')
|
|
expect(exchangeAuthToken).not.toHaveBeenCalled()
|
|
})
|
|
})
|
|
|
|
/**
|
|
* The redirect_uri sent in the authorization request and the one sent in the
|
|
* token exchange must be byte-identical (RFC 6749 §4.1.3) or the provider
|
|
* rejects the code exchange. These broke apart once already: the authorize leg
|
|
* honored the FORTNOX_REDIRECT_URI override while the exchange hardcoded the
|
|
* NEXT_PUBLIC_APP_URL fallback, so when the app moved to app.accounted.se and
|
|
* the env var still pointed at app.gnubok.se, every Fortnox connect died at
|
|
* the exchange with no visible error (the error postMessage was then dropped
|
|
* by the opener's origin check). Both legs now resolve through
|
|
* resolveArcimCallbackUrl; these tests pin the symmetry.
|
|
*/
|
|
describe('OAuth redirect_uri symmetry between authorize and exchange', () => {
|
|
const OVERRIDE_URI = 'https://dev-tunnel.example.test/api/extensions/ext/arcim-migration/callback'
|
|
|
|
const connectHandler = findRoute('POST', '/connect').handler as RouteHandler
|
|
|
|
function connectCtx(): ExtensionContext {
|
|
const { supabase } = createMockSupabase()
|
|
;(supabase as unknown as { auth: unknown }).auth = {
|
|
getUser: vi.fn().mockResolvedValue({ data: { user: { id: 'user-1' } } }),
|
|
}
|
|
return { supabase, companyId: 'company-1' } as unknown as ExtensionContext
|
|
}
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
vi.stubEnv('NEXT_PUBLIC_APP_URL', APP_URL)
|
|
vi.stubEnv('FORTNOX_REDIRECT_URI', OVERRIDE_URI)
|
|
vi.spyOn(console, 'error').mockImplementation(() => {})
|
|
;(listConsents as Mock).mockResolvedValue([])
|
|
;(createConsent as Mock).mockResolvedValue({ id: 'consent-new' })
|
|
;(generateOtc as Mock).mockResolvedValue({ code: 'otc-code-1' })
|
|
;(getAuthUrl as Mock).mockResolvedValue({ url: 'https://apps.fortnox.se/oauth-v1/auth?x=1' })
|
|
})
|
|
|
|
afterEach(() => {
|
|
vi.unstubAllEnvs()
|
|
vi.restoreAllMocks()
|
|
})
|
|
|
|
it('authorize leg passes the env-override redirect URI to getAuthUrl', async () => {
|
|
const res = await connectHandler(
|
|
createMockRequest('http://localhost/api/extensions/ext/arcim-migration/connect', {
|
|
method: 'POST',
|
|
body: { provider: 'fortnox' },
|
|
}),
|
|
connectCtx(),
|
|
)
|
|
|
|
expect(res.status).toBe(200)
|
|
expect(getAuthUrl).toHaveBeenCalledWith(
|
|
'fortnox',
|
|
'otc-code-1',
|
|
OVERRIDE_URI,
|
|
// A first connect never asks for the voucher-attachment scopes: those
|
|
// carry a Fortnox licence requirement and belong to the opt-in underlag
|
|
// reconnect only.
|
|
{ documentScopes: undefined },
|
|
)
|
|
})
|
|
|
|
// The underlag follow-up is the only caller allowed to widen the consent.
|
|
it('reconnect asks for the attachment scopes only when the underlag flow requests them', async () => {
|
|
;(listConsents as Mock).mockResolvedValue([
|
|
{ id: 'consent-1', provider: 'fortnox', status: 1 },
|
|
])
|
|
|
|
const reconnect = (documentScopes?: boolean) =>
|
|
connectHandler(
|
|
createMockRequest('http://localhost/api/extensions/ext/arcim-migration/connect', {
|
|
method: 'POST',
|
|
body: { provider: 'fortnox', reconnect: true, ...(documentScopes === undefined ? {} : { documentScopes }) },
|
|
}),
|
|
connectCtx(),
|
|
)
|
|
|
|
expect((await reconnect(true)).status).toBe(200)
|
|
expect(getAuthUrl).toHaveBeenLastCalledWith(
|
|
'fortnox',
|
|
'otc-code-1',
|
|
OVERRIDE_URI,
|
|
{ documentScopes: true },
|
|
)
|
|
|
|
expect((await reconnect()).status).toBe(200)
|
|
expect(getAuthUrl).toHaveBeenLastCalledWith(
|
|
'fortnox',
|
|
'otc-code-1',
|
|
OVERRIDE_URI,
|
|
{ documentScopes: false },
|
|
)
|
|
})
|
|
|
|
it('exchange leg passes the SAME env-override redirect URI to exchangeAuthToken', async () => {
|
|
;(consumeOAuthState as Mock).mockResolvedValue({
|
|
consentId: 'consent-new',
|
|
provider: 'fortnox',
|
|
userId: 'user-1',
|
|
})
|
|
|
|
await callbackHandler(
|
|
callbackRequest({ code: 'provider-auth-code', state: 'one-time-token' }),
|
|
)
|
|
|
|
expect(exchangeAuthToken).toHaveBeenCalledWith(
|
|
'consent-new',
|
|
'fortnox',
|
|
'provider-auth-code',
|
|
OVERRIDE_URI,
|
|
)
|
|
})
|
|
})
|
|
|
|
/**
|
|
* The error page must stay open: its postMessage is dropped whenever the
|
|
* popup's origin differs from the opener's, and a window.close() right after
|
|
* turns that into "I approve in Fortnox and then nothing happens". The success
|
|
* page still closes itself.
|
|
*/
|
|
describe('GET /callback: error popup stays open, success popup closes', () => {
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
vi.stubEnv('NEXT_PUBLIC_APP_URL', APP_URL)
|
|
vi.spyOn(console, 'error').mockImplementation(() => {})
|
|
})
|
|
|
|
afterEach(() => {
|
|
vi.unstubAllEnvs()
|
|
vi.restoreAllMocks()
|
|
})
|
|
|
|
it('keeps the error popup open with the reason visible', async () => {
|
|
;(consumeOAuthState as Mock).mockResolvedValue(null)
|
|
|
|
const res = await callbackHandler(
|
|
callbackRequest({ code: 'provider-auth-code', state: 'bad-token' }),
|
|
)
|
|
const html = await res.text()
|
|
|
|
expect(html).toContain('Anslutningen misslyckades')
|
|
expect(html).not.toContain('window.close')
|
|
})
|
|
|
|
it('still closes the success popup', async () => {
|
|
;(consumeOAuthState as Mock).mockResolvedValue({
|
|
consentId: 'consent-1',
|
|
provider: 'fortnox',
|
|
userId: 'user-1',
|
|
})
|
|
|
|
const res = await callbackHandler(
|
|
callbackRequest({ code: 'provider-auth-code', state: 'one-time-token' }),
|
|
)
|
|
const html = await res.text()
|
|
|
|
expect(html).toContain('Anslutningen lyckades')
|
|
expect(html).toContain('window.close()')
|
|
})
|
|
})
|
|
|
|
describe('GET /preview: cross-tenant consent status oracle', () => {
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
vi.spyOn(console, 'error').mockImplementation(() => {})
|
|
})
|
|
|
|
afterEach(() => {
|
|
vi.restoreAllMocks()
|
|
})
|
|
|
|
function buildCtx(): ExtensionContext {
|
|
const { supabase } = createMockSupabase()
|
|
;(supabase as unknown as { auth: unknown }).auth = {
|
|
getUser: vi.fn().mockResolvedValue({ data: { user: { id: 'user-1' } } }),
|
|
}
|
|
return { supabase, companyId: 'company-1' } as unknown as ExtensionContext
|
|
}
|
|
|
|
it('scopes the consent read to the caller company', async () => {
|
|
;(getConsent as Mock).mockResolvedValue({ id: 'consent-1', status: 5, provider: 'fortnox' })
|
|
|
|
await previewHandler(
|
|
createMockRequest('http://localhost/api/extensions/ext/arcim-migration/preview', {
|
|
searchParams: { consentId: 'consent-1' },
|
|
}),
|
|
buildCtx(),
|
|
)
|
|
|
|
expect(getConsent).toHaveBeenCalledWith('consent-1', 'company-1')
|
|
})
|
|
|
|
it('answers 404 without a status for a consent owned by another company', async () => {
|
|
;(getConsent as Mock).mockRejectedValue(new ConsentNotFoundError())
|
|
|
|
const res = await previewHandler(
|
|
createMockRequest('http://localhost/api/extensions/ext/arcim-migration/preview', {
|
|
searchParams: { consentId: 'other-tenants-consent' },
|
|
}),
|
|
buildCtx(),
|
|
)
|
|
const { status, body } = await parseJsonResponse<{
|
|
error: { code: string; details?: Record<string, unknown> }
|
|
}>(res)
|
|
|
|
expect(status).toBe(404)
|
|
expect(body.error.code).toBe('PROVIDER_CONSENT_NOT_FOUND')
|
|
// No consent state may leak: not the numeric status, not the provider.
|
|
// 404 with no state is exactly what a nonexistent consent returns too.
|
|
expect(body.error.details ?? {}).not.toHaveProperty('status')
|
|
expect(body.error.details ?? {}).not.toHaveProperty('provider')
|
|
})
|
|
})
|
|
|
|
/**
|
|
* A callback URL is single-use: the state it carries is spent the moment
|
|
* consumeOAuthState returns. Prod caught the consequence of leaving it in
|
|
* session history: a callback that had already succeeded was delivered a
|
|
* second time 19 seconds later, and the user was told "Ingen giltig
|
|
* migrationssession hittades" about a connection that had just worked.
|
|
*
|
|
* The page therefore replaces its history entry instead of pushing one, and
|
|
* the response is no-store so no Back/reload can serve it from cache. The
|
|
* state check itself is deliberately untouched: the callback is
|
|
* unauthenticated, so it still answers consumed, expired, forged and unknown
|
|
* with the same sentence.
|
|
*/
|
|
describe('GET /callback: the spent callback URL cannot come back', () => {
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
vi.stubEnv('NEXT_PUBLIC_APP_URL', APP_URL)
|
|
vi.spyOn(console, 'error').mockImplementation(() => {})
|
|
})
|
|
|
|
afterEach(() => {
|
|
vi.unstubAllEnvs()
|
|
vi.restoreAllMocks()
|
|
})
|
|
|
|
it('sends no-store and replaces history on a successful callback', async () => {
|
|
;(consumeOAuthState as Mock).mockResolvedValue({
|
|
consentId: 'consent-1',
|
|
provider: 'fortnox',
|
|
userId: 'user-1',
|
|
})
|
|
|
|
const res = await callbackHandler(
|
|
callbackRequest({ code: 'provider-auth-code', state: 'one-time-token' }),
|
|
)
|
|
const html = await res.text()
|
|
|
|
expect(res.headers.get('Cache-Control')).toBe('no-store')
|
|
expect(html).toContain('window.location.replace(')
|
|
expect(html).not.toContain('window.location.href')
|
|
})
|
|
|
|
it('sends no-store and replaces history on a rejected callback too', async () => {
|
|
;(consumeOAuthState as Mock).mockResolvedValue(null)
|
|
|
|
const res = await callbackHandler(
|
|
callbackRequest({ code: 'provider-auth-code', state: 'spent-token' }),
|
|
)
|
|
const html = await res.text()
|
|
|
|
expect(res.headers.get('Cache-Control')).toBe('no-store')
|
|
expect(html).toContain('window.location.replace(')
|
|
expect(html).not.toContain('window.location.href')
|
|
// The anti-oracle property stands: a consumed state still reads exactly
|
|
// like a forged one.
|
|
expect(html).toContain(GENERIC_REJECTION)
|
|
})
|
|
})
|