* feat(white-label): invite-only signup for brand domains
A brand domain belongs to the partner's people (founder decision
2026-08-27): only allowlisted or invited users may create an account on
an invite-only brand domain; everyone else is shown an interstitial that
sends them to the canonical Accounted signup.
- brands.signup_mode ('open' default / 'invite_only') +
brand_signup_allowlist (lowercase emails, team-scoped RLS, owner/admin
writes) + create_company_for_brand_signup RPC, with pg-real coverage
- server-side gate (lib/auth/brand-signup-gate.ts) enforced on every
signup path: email signup moved to POST /api/auth/signup (the browser
used to call GoTrue directly, so a client-side check would be
bypassable), BankID gated in /bankid/complete, Google covered by the
dashboard layout's brand-domain bounce
- company invites bypass the allowlist: the invite is the authorization
- register page interstitial on gated brands (no email in the outbound
URL), sv+en strings
- dashboard layout bounces non-belonging sessions off gated brand hosts
to the canonical domain (navigation rule like WL-01, not a security
boundary)
- allowlisted signups' onboarding-created companies attach to the
brand's byra team via the new RPC, so WL-01 homes them on the brand
domain; the allowlist entry recorded by an owner/admin stands in for
the WL-15 admin gate
- byra cockpit page /clients/access + /api/clients/signup-access to
manage the mode and the allowlist
All existing brands default to 'open': behavior is byte-identical until
a brand is flipped to invite_only.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4
* fix(white-label): rollback brand-signup company with the service client
Skeptic (correctness) found that a brand-signup company created under the
service role rolled back with the cookie-session client: `companies` has
RLS and no FOR DELETE policy, so the delete was a silent 0-row no-op,
stranding a member-less ghost company on the partner's byra team. Pass an
optional rollbackClient to createCompanyCore and hand it the service
client on that path; user_preferences.active_company_id then clears itself
via its ON DELETE SET NULL FK once the company row is actually deleted.
Also map a validateBody 400 (flat envelope, no code) on the register page
to the specific email-invalid field message instead of the generic one,
since the client already pre-gates password strength.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4
* fix(white-label): fail-safe brand lookup, pg-test seed, anonymize fixtures
Second resolve-pr cycle: skeptic + CodeRabbit findings and a green-up.
- Fail safe on a brands-table error (CodeRabbit CWE-285): the gate treated a
failed resolveBrandByHost as an unbranded host, opening invite-only signup
during a transient DB blip. resolveBrandResultByHost now distinguishes
"no brand" from "lookup failed"; the gate returns lookupFailed and the
email + BankID routes answer 503 (retry), never creating an account.
- pg-real: the RLS delete test seeded its row inside withUserContext, which
always rolls back, so the owner DELETE saw zero rows. Seed on the superuser
pool instead.
- Anonymize every test/fixture brand to the repo's existing synthetic
placeholder (Siffra / app.siffra.se): no real partner names in code.
- SignupAccessManager: functional setData updates so a concurrent mode
toggle and an add/remove do not clobber each other's snapshot (CodeRabbit).
- Route a transient-error message through i18n instead of the raw envelope
(raw-user-error guard); new register.error_temporary sv+en.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4
* test(white-label): anonymize new signup-gate fixtures; log oracle residual
Rename the placeholder brand in the four new brand-signup test files to a
clearly-fake, partner-unrelated name (Testbrand / app.testbrand.example);
the previous placeholder echoed a real partner. Scoped to files this PR
creates; the repo-wide legacy placeholder is left for a separate cleanup.
Also record in DECISIONS.md that the feature ships accepting the
low-severity allowlist-enumeration residual (captcha-free 403 vs 200 on
the signup endpoint), with rate-limiting as the follow-up option.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByL5dQXG8gGLtNBPj8g2C4
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
318 lines
10 KiB
TypeScript
318 lines
10 KiB
TypeScript
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
|
import { createQueuedMockSupabase } from '@/tests/helpers'
|
|
import { hashInviteToken } from '@/lib/auth/invite-tokens'
|
|
import type { Brand } from '@/lib/branding/resolve'
|
|
|
|
const serviceClient = vi.hoisted(() => ({ current: null as unknown }))
|
|
|
|
vi.mock('@/lib/auth/api-keys', () => ({
|
|
createServiceClientNoCookies: vi.fn(() => serviceClient.current),
|
|
}))
|
|
|
|
// The gate resolves via resolveBrandResultByHost ({ brand, lookupFailed });
|
|
// resolveBrandDomainBounce still uses resolveBrandByHost. Mock both off one
|
|
// brand value, and let tests override lookupFailed when they need it.
|
|
const resolveBrandByHostMock = vi.hoisted(() => vi.fn())
|
|
const resolveBrandResultMock = vi.hoisted(() => vi.fn())
|
|
vi.mock('@/lib/branding/resolve', async (importOriginal) => {
|
|
const actual = await importOriginal<typeof import('@/lib/branding/resolve')>()
|
|
return {
|
|
...actual,
|
|
resolveBrandByHost: (...args: unknown[]) => resolveBrandByHostMock(...args),
|
|
resolveBrandResultByHost: (...args: unknown[]) => resolveBrandResultMock(...args),
|
|
}
|
|
})
|
|
|
|
import {
|
|
evaluateBrandSignupGate,
|
|
isEmailOnBrandAllowlist,
|
|
readInviteTokenFromCookieHeader,
|
|
resolveBrandDomainBounce,
|
|
} from '@/lib/auth/brand-signup-gate'
|
|
|
|
function makeBrand(overrides: Partial<Brand> = {}): Brand {
|
|
return {
|
|
id: 'brand-1',
|
|
teamId: 'team-1',
|
|
domain: 'app.testbrand.example',
|
|
appName: 'Testbrand',
|
|
logoUrl: null,
|
|
faviconUrl: null,
|
|
brandColor: '#123456',
|
|
chromeColor: null,
|
|
fontKey: 'default',
|
|
supportEmail: 'support@testbrand.example',
|
|
authEmailFrom: null,
|
|
senderDomain: null,
|
|
senderDomainStatus: 'unverified',
|
|
resendDomainId: null,
|
|
signupMode: 'invite_only',
|
|
...overrides,
|
|
}
|
|
}
|
|
|
|
let mock: ReturnType<typeof createQueuedMockSupabase>
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
mock = createQueuedMockSupabase()
|
|
serviceClient.current = mock.supabase
|
|
// By default the strict resolver mirrors resolveBrandByHostMock's value
|
|
// with lookupFailed:false, so the existing tests keep configuring one mock.
|
|
// The fail-safe test overrides this to return lookupFailed:true.
|
|
resolveBrandResultMock.mockImplementation(async (host: string) => ({
|
|
brand: await resolveBrandByHostMock(host),
|
|
lookupFailed: false,
|
|
}))
|
|
})
|
|
|
|
describe('evaluateBrandSignupGate', () => {
|
|
it('allows when the host has no brand', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(null)
|
|
const result = await evaluateBrandSignupGate({
|
|
host: 'app.accounted.se',
|
|
email: 'anyone@example.com',
|
|
})
|
|
expect(result).toEqual({ allowed: true, brand: null, via: 'no_brand' })
|
|
})
|
|
|
|
it('allows with no host at all', async () => {
|
|
const result = await evaluateBrandSignupGate({ host: '', email: 'a@b.se' })
|
|
expect(result.allowed).toBe(true)
|
|
expect(resolveBrandByHostMock).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('allows on an open brand without touching the allowlist', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand({ signupMode: 'open' }))
|
|
const result = await evaluateBrandSignupGate({
|
|
host: 'app.testbrand.example',
|
|
email: 'anyone@example.com',
|
|
})
|
|
expect(result.allowed).toBe(true)
|
|
expect(result.allowed && result.via).toBe('open')
|
|
expect(mock.supabase.from).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('allows an allowlisted email on an invite-only brand, case-insensitively', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
mock.enqueue({ data: { id: 'entry-1' } })
|
|
|
|
const result = await evaluateBrandSignupGate({
|
|
host: 'app.testbrand.example',
|
|
email: ' Kund@Example.COM ',
|
|
})
|
|
|
|
expect(result.allowed).toBe(true)
|
|
expect(result.allowed && result.via).toBe('allowlist')
|
|
// The lookup used the normalized address.
|
|
expect(mock.findCalls('brand_signup_allowlist', 'eq')).toContainEqual([
|
|
'email',
|
|
'kund@example.com',
|
|
])
|
|
})
|
|
|
|
it('blocks a non-allowlisted email on an invite-only brand', async () => {
|
|
const brand = makeBrand()
|
|
resolveBrandByHostMock.mockResolvedValue(brand)
|
|
mock.enqueue({ data: null })
|
|
|
|
const result = await evaluateBrandSignupGate({
|
|
host: 'app.testbrand.example',
|
|
email: 'stranger@example.com',
|
|
})
|
|
|
|
expect(result).toEqual({ allowed: false, brand })
|
|
})
|
|
|
|
it('fails safe (lookupFailed) when the brand lookup itself errors', async () => {
|
|
resolveBrandResultMock.mockResolvedValue({ brand: null, lookupFailed: true })
|
|
|
|
const result = await evaluateBrandSignupGate({
|
|
host: 'app.testbrand.example',
|
|
email: 'anyone@example.com',
|
|
})
|
|
|
|
// Must NOT degrade to allowed no_brand: a transient DB error cannot open
|
|
// an invite-only domain.
|
|
expect(result).toEqual({ allowed: false, brand: null, lookupFailed: true })
|
|
})
|
|
|
|
it('fails closed when the allowlist lookup errors', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
mock.enqueue({ data: null, error: { message: 'boom' } })
|
|
|
|
const result = await evaluateBrandSignupGate({
|
|
host: 'app.testbrand.example',
|
|
email: 'kund@example.com',
|
|
})
|
|
|
|
expect(result.allowed).toBe(false)
|
|
})
|
|
|
|
it('allows a pending unexpired invite for the same email', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
// Allowlist miss, then the invite row.
|
|
mock.enqueueMany([
|
|
{ data: null },
|
|
{
|
|
data: {
|
|
email: 'Invitee@Example.com',
|
|
status: 'pending',
|
|
expires_at: new Date(Date.now() + 60_000).toISOString(),
|
|
},
|
|
},
|
|
])
|
|
|
|
const result = await evaluateBrandSignupGate({
|
|
host: 'app.testbrand.example',
|
|
email: 'invitee@example.com',
|
|
inviteToken: 'gnubok_inv_abc',
|
|
})
|
|
|
|
expect(result.allowed).toBe(true)
|
|
expect(result.allowed && result.via).toBe('invite')
|
|
// Lookup is by token hash, never the raw token.
|
|
expect(mock.findCall('company_invitations', 'eq')).toEqual([
|
|
'token_hash',
|
|
hashInviteToken('gnubok_inv_abc'),
|
|
])
|
|
})
|
|
|
|
it('blocks when the invite is for a different email', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
mock.enqueueMany([
|
|
{ data: null },
|
|
{
|
|
data: {
|
|
email: 'someone-else@example.com',
|
|
status: 'pending',
|
|
expires_at: new Date(Date.now() + 60_000).toISOString(),
|
|
},
|
|
},
|
|
])
|
|
|
|
const result = await evaluateBrandSignupGate({
|
|
host: 'app.testbrand.example',
|
|
email: 'stranger@example.com',
|
|
inviteToken: 'gnubok_inv_abc',
|
|
})
|
|
|
|
expect(result.allowed).toBe(false)
|
|
})
|
|
|
|
it('blocks when the invite is expired', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
mock.enqueueMany([
|
|
{ data: null },
|
|
{
|
|
data: {
|
|
email: 'invitee@example.com',
|
|
status: 'pending',
|
|
expires_at: new Date(Date.now() - 60_000).toISOString(),
|
|
},
|
|
},
|
|
])
|
|
|
|
const result = await evaluateBrandSignupGate({
|
|
host: 'app.testbrand.example',
|
|
email: 'invitee@example.com',
|
|
inviteToken: 'gnubok_inv_abc',
|
|
})
|
|
|
|
expect(result.allowed).toBe(false)
|
|
})
|
|
})
|
|
|
|
describe('isEmailOnBrandAllowlist', () => {
|
|
it('returns false for an empty email without querying', async () => {
|
|
expect(await isEmailOnBrandAllowlist('brand-1', ' ')).toBe(false)
|
|
expect(mock.supabase.from).not.toHaveBeenCalled()
|
|
})
|
|
})
|
|
|
|
describe('resolveBrandDomainBounce', () => {
|
|
const base = {
|
|
host: 'app.testbrand.example',
|
|
userEmail: 'user@example.com',
|
|
teamIds: [] as string[],
|
|
companyTeamIds: [] as Array<string | null>,
|
|
hasPendingInviteCookie: false,
|
|
canonicalAppUrl: 'https://app.accounted.se',
|
|
}
|
|
|
|
it('stays on open brands and brandless hosts', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(null)
|
|
expect(await resolveBrandDomainBounce(base)).toBeNull()
|
|
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand({ signupMode: 'open' }))
|
|
expect(await resolveBrandDomainBounce(base)).toBeNull()
|
|
})
|
|
|
|
it('stays for brand team members and brand-homed company members', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
expect(
|
|
await resolveBrandDomainBounce({ ...base, teamIds: ['team-1'] }),
|
|
).toBeNull()
|
|
expect(
|
|
await resolveBrandDomainBounce({ ...base, companyTeamIds: [null, 'team-1'] }),
|
|
).toBeNull()
|
|
})
|
|
|
|
it('stays when a pending invite cookie rides along', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
expect(
|
|
await resolveBrandDomainBounce({ ...base, hasPendingInviteCookie: true }),
|
|
).toBeNull()
|
|
})
|
|
|
|
it('stays for an allowlisted email', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
mock.enqueue({ data: { id: 'entry-1' } })
|
|
expect(await resolveBrandDomainBounce(base)).toBeNull()
|
|
})
|
|
|
|
it('bounces a non-belonging session to the canonical URL', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
mock.enqueue({ data: null })
|
|
expect(await resolveBrandDomainBounce(base)).toBe('https://app.accounted.se')
|
|
})
|
|
|
|
it('never bounces onto the same host', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
mock.enqueue({ data: null })
|
|
expect(
|
|
await resolveBrandDomainBounce({
|
|
...base,
|
|
canonicalAppUrl: 'https://app.testbrand.example',
|
|
}),
|
|
).toBeNull()
|
|
})
|
|
|
|
it('never bounces on a malformed canonical URL', async () => {
|
|
resolveBrandByHostMock.mockResolvedValue(makeBrand())
|
|
mock.enqueue({ data: null })
|
|
expect(
|
|
await resolveBrandDomainBounce({ ...base, canonicalAppUrl: '' }),
|
|
).toBeNull()
|
|
})
|
|
})
|
|
|
|
describe('readInviteTokenFromCookieHeader', () => {
|
|
it('reads the invite token among other cookies', () => {
|
|
expect(
|
|
readInviteTokenFromCookieHeader(
|
|
'a=1; gnubok-invite-token=gnubok_inv_x; b=2',
|
|
),
|
|
).toBe('gnubok_inv_x')
|
|
})
|
|
|
|
it('decodes URI-encoded values and tolerates missing cookies', () => {
|
|
expect(
|
|
readInviteTokenFromCookieHeader('gnubok-invite-token=abc%3D%3D'),
|
|
).toBe('abc==')
|
|
expect(readInviteTokenFromCookieHeader(null)).toBeNull()
|
|
expect(readInviteTokenFromCookieHeader('a=1; b=2')).toBeNull()
|
|
expect(readInviteTokenFromCookieHeader('gnubok-invite-token=')).toBeNull()
|
|
})
|
|
})
|