Files
accounted/lib/invoices/pdf-render-helpers.ts
T
18cbc4c30a fix(security): audit remediation 2026-09-01: api_keys identity, viewer gates, OAuth binding, XSS, MFA gate (#2155)
* fix(security): bind api_keys to the caller, lock hash-as-bearer RPCs and provider token tables

Security audit 2026-09-01, critical items.

- api_keys INSERT requires user_id = auth.uid() again (an admin could
  forge a key for any co-member and act as them in every company they
  belong to); SELECT is own-keys-or-admin; a BEFORE trigger freezes the
  identity and credential columns against user-session UPDATEs.
- rotate_mcp_refresh_token and validate_and_increment_api_key become
  service_role only: they match rows by a presented SHA-256, so a hash
  readable by co-members was a bearer credential.
- validate_and_increment_api_key fails closed when the key's user is no
  longer a member of the key's company.
- provider_consent_tokens and provider_otc: the DELETE policies collapsed
  to "caller has any team row" (correlated subquery on a non-existent
  team_members.company_id). All member policies dropped; service_role
  only, matching every existing code path.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(security): role gates, ownership guards and posting integrity in the database

Security audit 2026-09-01, high items at the database layer.

- One table-level guard, enforce_company_writer_role(), blocks the
  read-only viewer role on 55 company-scoped tables including through
  the 15 membership-only SECURITY DEFINER writers. Keyed on the JWT role
  claim so it fires inside definer bodies; no-op for service_role and
  trigger cascades.
- company_members user_id/company_id immutable from user sessions;
  invitations can never grant owner; team_members gains a transition
  guard (admins keep non-owner role moves); companies team_id and
  archiving are owner-only and team attachment needs team membership.
- Direct statements (current_user = authenticated) can no longer insert
  posted headers, add lines under posted verifikat, or post a draft with
  a voucher number the sequence never issued. Sanctioned RPCs run as the
  definer and are untouched; the engine's own draft-then-post shapes
  still pass.
- create_document_version refuses viewers and foreign storage paths;
  validate_version_chain needs membership and loses anon EXECUTE;
  match_documents / match_booking_templates lose anon; cron maintenance
  RPCs become service_role only; the production-only
  seed_asset_categories is dropped.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* build: pin tsx as an exact devDependency instead of fetching it with npx at build time

prebuild ran "npx tsx" with no lockfile entry, so every Vercel, Docker
and CI build downloaded tsx@latest and its transitive tree from the
registry with no integrity check, inside the build environment.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(security): refuse the viewer role on API-key and MCP write paths

The v1 wrapper and the MCP company routing checked company membership
but never role, and both run as service role, so a read-only viewer
holding an API key could post vouchers and change settings through the
API. Mutating methods and non-read scopes now return 403 ROLE_READ_ONLY
for viewers on v1; MCP write tools refuse viewers the same way.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(security): stop serving uploaded SVG, XML and HTML as executable content on the app origin

Uploads persisted the browser-declared mime type and the inline proxy
served it verbatim, sandboxing only text/html; the storage proxy
forwarded the uploader's Content-Type. Any writer, or any Peppol sender,
could plant a scripted SVG or XHTML that executed on app.gnubok.se.

- inline route: allow-list of natively safe types (PDF, raster images)
  served as before; everything else gets the opaque sandbox CSP.
- storage proxy: octet-stream + attachment + sandbox unless the DB
  mime for the key is on the allow-list.
- document-service: the stored mime is the magic-byte validated type.
- logo upload: magic-byte validation, SVG refused.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(security): byrå brand logo upload decides the type by magic bytes and drops SVG

Same pattern as the company logo route: the logos bucket is public, so a
scripted SVG (or anything declared as an image) must never land there.
The upload pickers stop advertising SVG.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(security): bind Enable Banking, Stripe and WooCommerce callbacks to the initiating user

The callbacks resolved the pending row by oauth_state alone, so a
victim who completed an attacker-initiated consent had their bank
account, merchant account or store attached to the attacker's company.
requireFlowInitiator() now requires the cookie session of the user who
started the flow: no session redirects to login with the callback URL
preserved, a different user is refused and nothing is exchanged.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(security): guard tenant-controlled outbound fetches and surface the disabled rate limiter

WooCommerce and Shopify syncs fetched a member-editable store URL with
plain fetch() and redirect following under the service role, and the
invoice PDF renderer fetched company_settings.logo_url unguarded. All
three go through a new safeFetch() (public-IP validation via url-guard,
https only, redirect: 'manual', body size cap) and re-normalise the
stored host at use time. checkRateLimit() keeps failing open on hosted
but logs one error per process when Upstash is not configured and
exports isRateLimiterConfigured().

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(security): decide the API MFA gate from server-authenticated factors, not the session cookie

getAuthenticatorAssuranceLevel() without arguments derives nextLevel
from session.user.factors, which comes from the unsigned sb-*-auth-token
cookie. Deleting factors from the cookie made an enrolled account look
like it had nothing to step up to, on every /api route and in
requireAuth. Both gates now read factors from the getUser() result or
listFactors() and the level from the verified JWT claim, and fail closed
on errors. Page-branch gate hardened the same way.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(security): bind Fortnox/Visma, Gmail and Skatteverket callbacks to the initiating user

The arcim-migration callback exchanged the provider code onto whatever
consent the one-time state named, with no check of who completed the
flow and no org-number comparison, so a phished Fortnox admin handed
their ledger to the attacker's company. provider_otc now records the
initiating user (migration 20260902100000); the callback requires that
session and, after the exchange, refuses a provider company whose org
number differs from the consent's company. The Gmail and Skatteverket
callbacks enforce the same initiator check.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(security): BankID signup confirms the email before linking the identity

Signup created an email-confirmed, MFA-exempt account for any address
the caller typed and returned a magic link, so an attacker could
pre-register a victim's email and keep a permanent BankID login into the
account the victim later adopted. The user is now created unconfirmed,
the identity carries email_verified_at NULL (migration 20260902101000),
bankid_linked is not set until the mailed confirmation is clicked, and
BankID login of a pending identity is refused with the confirmation
re-sent.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(security): bind MCP OAuth redirect URIs to the consenting user and cap scopes

A user-registered redirect URI was allowlisted globally, the consent page
named no client, and all scopes were pre-checked, so one phishing link
handed an attacker a full-scope key for the victim's company. Registered
URIs now resolve only for the registrant or a colleague sharing a
company; the consent page shows the client identity and redirect host;
non-built-in clients default to read-only pre-checks; scopes are capped
by the user's role (viewer: read only) at consent and at /token.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(auth): client follow-ups for BankID confirmation, callback mismatch copy and decision log

- register client handles the new confirmation_sent response from BankID
  signup with the existing inbox screen instead of calling verifyOtp.
- BankID login surfaces the email_unconfirmed explanation.
- WooCommerce settings map woocommerce_error=wrong_user to its own copy.
- Logo help text no longer advertises SVG.
- DECISIONS.md records the audit remediation choices.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fix(mcp-oauth): literal SoD columns in the api_keys insert so the phantom-column scanner resolves them

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(logo): type the upload fixtures as Uint8Array<ArrayBuffer> so they are valid BlobParts

Fixes the typecheck ratchet on PR #2155 and ratchets the baseline down
by the one legacy error the change removed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 11:38:30 +02:00

331 lines
13 KiB
TypeScript

/**
* Shared helpers for invoice PDF render call sites.
*
* Three responsibilities:
* 1. Build the branding object from company settings.
* 2. Resolve the company logo into a format @react-pdf/renderer can draw.
* 3. Build the optional Swish payment QR.
*
* Why the logo needs resolving (issue #772: "Logotyp kommer inte med på
* fakturor"): @react-pdf/renderer's <Image> only decodes JPG and PNG, but the
* logo upload route and the `logos` storage bucket both accept SVG and WebP.
* When the logo is an SVG/WebP, @react-pdf fails to decode it and *silently*
* swallows the error (a console.warn inside a try/catch in its fetchImage step):
* so the invoice renders fine but with no logo, and nothing surfaces.
*
* Fix: fetch the stored logo and re-encode it to a PNG data URL via sharp, then
* hand the template a company whose `logo_url` is that data URL. This makes the
* logo render regardless of the uploaded format and removes the render-time
* dependency on a remote fetch succeeding inside @react-pdf.
*/
import QRCode from 'qrcode'
import type { CompanySettings, Currency, Invoice } from '@/types'
import { brandingFromCompanySettings, SHOW_SWISH_ON_INVOICE, type InvoiceBranding } from '@/lib/invoices/pdf-template'
import { buildSwishQrPayload } from '@/lib/payments/swish'
import { getAmountToPay } from '@/lib/invoices/rounding'
import { createLogger } from '@/lib/logger'
import { isUnsafeUrlError, readBodyWithCap, safeFetch } from '@/lib/http/safe-fetch'
import { LOGO_UPLOAD_MAX_BYTES } from '@/lib/invoices/branding-constants'
import { prepareInvoiceFont } from '@/lib/invoices/pdf-fonts'
import {
assertInvoicePaymentAccountForRender,
companyWithInvoicePaymentAccount,
} from '@/lib/invoices/payment-accounts'
const log = createLogger('invoice.swish-qr')
const paymentLinkLog = createLogger('invoice.payment-link-qr')
const logoLog = createLogger('invoice.logo')
export interface InvoicePdfRenderExtras {
branding: InvoiceBranding
/**
* The company settings to pass to InvoicePDF. Identical to the input except
* `logo_url` is replaced by an embedded PNG data URL when the stored logo
* could be fetched and re-encoded, or set to null when the stored URL was
* refused by the outbound URL guard (the invoice then renders without a
* logo). A transient failure keeps the original URL only when it points at
* the deployment's own storage origin; @react-pdf must never be handed an
* arbitrary remote URL to fetch unguarded.
*/
company: CompanySettings
}
export interface InvoicePdfRenderOptions {
paymentAccountRequired?: boolean
}
// A company's logo is reused across every invoice render, and twice per send
// (preflight + final render), and once per invoice in recurring/batch loops:
// so cache the re-encoded result keyed by logo URL. Only successes are cached
// (with a short TTL); a transient fetch blip is retried on the next render
// rather than sticking around as a logo-less invoice. Bounded so a long-lived
// self-hosted process doesn't grow the map without limit.
const LOGO_CACHE_TTL_MS = 5 * 60 * 1000
const LOGO_CACHE_MAX = 50
const logoDataUrlCache = new Map<string, { dataUrl: string; at: number }>()
// The invoice draws the logo at up to 240pt by 80pt, so 600px keeps it crisp
// while bounding the embedded base64 payload.
const LOGO_MAX_PX = 600
// Bound the logo fetch so a slow or oversized response can't hang or balloon an
// invoice render. The upload route only ever writes Supabase `logos`-bucket
// URLs, but company members can PATCH `company_settings.logo_url` directly
// through PostgREST, so the stored value is tenant-controlled input that this
// server fetches: it goes through `safeFetch` (public address only, no
// redirects) unless it sits on the deployment's own storage origin.
const LOGO_FETCH_TIMEOUT_MS = 5_000
/**
* What became of a stored logo URL:
* embedded: fetched, re-encoded, safe to hand to @react-pdf as a data URL
* refused: the outbound URL guard said no (private address, non-http(s),
* redirect); the invoice renders without a logo
* failed: transient or decode failure after the guard passed
*/
type LogoResolution =
| { kind: 'embedded'; dataUrl: string }
| { kind: 'refused' }
| { kind: 'failed' }
// Coalesce concurrent renders of the same logo (preflight + final on a send, and
// every invoice in a recurring/batch loop) onto one in-flight fetch+encode
// instead of each doing the full round-trip before the first result is cached.
const logoInflight = new Map<string, Promise<LogoResolution>>()
/**
* The origin the app's own Supabase storage lives on. Logos uploaded through
* the app always resolve here, and on a self-hosted install this origin may
* legitimately be a private address (a NAS on the LAN), so it is exempt from
* the public-address check. Redirect refusal and the size cap still apply.
*/
function trustedLogoOrigins(): string[] {
const raw = process.env.NEXT_PUBLIC_SUPABASE_URL
if (!raw) return []
try {
return [new URL(raw).origin]
} catch {
return []
}
}
function isTrustedLogoOrigin(logoUrl: string): boolean {
try {
return trustedLogoOrigins().includes(new URL(logoUrl).origin)
} catch {
return false
}
}
/**
* Fetch a stored logo and re-encode it to a PNG data URL. Concurrent calls
* for the same URL share a single in-flight request; only successes are
* cached so a transient blip is retried on the next render.
*/
async function resolveLogoDataUrl(logoUrl: string): Promise<LogoResolution> {
// Already embedded: nothing to fetch or convert.
if (logoUrl.startsWith('data:')) return { kind: 'embedded', dataUrl: logoUrl }
const cached = logoDataUrlCache.get(logoUrl)
if (cached && Date.now() - cached.at < LOGO_CACHE_TTL_MS) {
return { kind: 'embedded', dataUrl: cached.dataUrl }
}
const inflight = logoInflight.get(logoUrl)
if (inflight) return inflight
const work = encodeLogo(logoUrl)
logoInflight.set(logoUrl, work)
try {
return await work
} finally {
// Only successes are cached (in encodeLogo); dropping the in-flight entry
// here lets a transient failure be retried on the next render.
logoInflight.delete(logoUrl)
}
}
async function encodeLogo(logoUrl: string): Promise<LogoResolution> {
let res: Response
try {
res = await safeFetch(
logoUrl,
{ signal: AbortSignal.timeout(LOGO_FETCH_TIMEOUT_MS) },
{ trustedOrigins: trustedLogoOrigins() },
)
} catch (err) {
if (isUnsafeUrlError(err)) {
logoLog.warn('logo URL refused by outbound URL guard; rendering without logo', {
reason: err.reason,
detail: err.detail,
})
return { kind: 'refused' }
}
return { kind: 'failed' }
}
try {
if (!res.ok) return { kind: 'failed' }
// Declared Content-Length is checked before any byte is read, and the
// stream is cut off at the cap in case the header lied or was absent.
const input = await readBodyWithCap(res, LOGO_UPLOAD_MAX_BYTES)
if (!input) return { kind: 'failed' }
// SVGs must be rasterized at a higher density or sharp renders them at
// their intrinsic (often tiny) pixel size and the result looks blurry.
const contentType = res.headers.get('content-type') ?? ''
const isSvg =
/svg/i.test(contentType) ||
input.subarray(0, 256).toString('utf8').trimStart().startsWith('<')
// Lazy, isolated import: if sharp ever fails to load in a given runtime we
// degrade instead of breaking invoice sending entirely.
const { default: sharp } = await import('sharp')
const png = await sharp(input, isSvg ? { density: 288 } : {})
.resize({
width: LOGO_MAX_PX,
height: LOGO_MAX_PX,
fit: 'inside',
withoutEnlargement: true,
})
.png()
.toBuffer()
const dataUrl = `data:image/png;base64,${png.toString('base64')}`
// Refresh insertion order so eviction is LRU-ish, then bound the cache.
logoDataUrlCache.delete(logoUrl)
if (logoDataUrlCache.size >= LOGO_CACHE_MAX) {
const oldest = logoDataUrlCache.keys().next().value
if (oldest !== undefined) logoDataUrlCache.delete(oldest)
}
logoDataUrlCache.set(logoUrl, { dataUrl, at: Date.now() })
return { kind: 'embedded', dataUrl }
} catch {
return { kind: 'failed' }
}
}
/**
* Apply the logo resolution to the company handed to the PDF template.
*
* On a transient failure the original URL is kept only when it points at our
* own storage origin (the pre-existing "never worse than before" fallback:
* @react-pdf can still draw a PNG/JPEG from there). For any other origin the
* logo is dropped instead: handing @react-pdf a remote URL means it fetches
* it with a plain, redirect-following fetch, which is exactly the unguarded
* request this module exists to prevent.
*/
function applyLogoResolution(company: CompanySettings, resolution: LogoResolution): CompanySettings {
if (resolution.kind === 'embedded') {
return resolution.dataUrl === company.logo_url
? company
: { ...company, logo_url: resolution.dataUrl }
}
if (resolution.kind === 'refused') return { ...company, logo_url: null }
return company.logo_url && isTrustedLogoOrigin(company.logo_url)
? company
: { ...company, logo_url: null }
}
export async function prepareInvoicePdfRender(
company: CompanySettings,
currency?: Currency,
options: InvoicePdfRenderOptions = {},
): Promise<InvoicePdfRenderExtras> {
if (currency && options.paymentAccountRequired !== false) {
assertInvoicePaymentAccountForRender(company, currency)
}
const branding = await prepareInvoiceFont(
company,
brandingFromCompanySettings(company),
)
const paymentCompany = currency
? companyWithInvoicePaymentAccount(company, currency)
: company
if (!paymentCompany.logo_url) return { branding, company: paymentCompany }
const resolution = await resolveLogoDataUrl(paymentCompany.logo_url)
return { branding, company: applyLogoResolution(paymentCompany, resolution) }
}
/**
* Build the payment-link QR for an invoice as a PNG data URL, or null when the
* invoice carries no payment_link_url or it isn't a payable document (credit
* notes, proformas and delivery notes show no payment box). The URL was
* https-validated at write time (lib/api/schemas.ts); the QR simply encodes it
* locally with the `qrcode` lib: no call to any payment provider.
*/
export async function buildPaymentLinkQrDataUrl(invoice: Invoice): Promise<string | null> {
const url = invoice.payment_link_url?.trim()
if (!url) return null
const docType = invoice.document_type || 'invoice'
if (docType !== 'invoice' || invoice.credited_invoice_id) return null
try {
return await QRCode.toDataURL(url, { margin: 1, width: 240, errorCorrectionLevel: 'M' })
} catch (err) {
paymentLinkLog.warn('payment link QR generation failed', {
invoiceId: invoice.id,
error: err instanceof Error ? err.message : String(err),
})
return null
}
}
/**
* Build the Swish payment QR for an invoice as a PNG data URL, or null when:
* Swish display is off, the document isn't a payable invoice (credit notes,
* proformas and delivery notes collect no payment), there's no/invalid Swish
* number, the invoice isn't in SEK (Swish is SEK-only), or the amount to pay
* is not positive. The encoded amount is the customer-facing "Att betala"
* from getAmountToPay: the rounded total minus any ROT/RUT deduction, the
* same figure the PDF totals block and the invoice email state. The Swish payload locks the amount (editmask 0),
* so encoding anything else makes the customer overpay with no way to correct
* it in the app. A fully deducted invoice (toPay = 0) therefore renders no QR.
* Generated locally with the `qrcode` lib: no call to any Swish API. Pass the
* result to InvoicePDF's `swishQrDataUrl` prop; the template gates rendering
* on the same payment box that already shows the Swish number.
*/
export async function buildSwishQrDataUrl(
company: CompanySettings,
invoice: Invoice,
): Promise<string | null> {
// Swish on invoices is "coming soon": gated off in pdf-template. Bail before
// any work while the feature is disabled.
if (!SHOW_SWISH_ON_INVOICE) return null
// Swish display off is the normal "no QR" case: stay quiet. Every other
// skip is logged so a missing QR is diagnosable instead of silent.
if (!(company.invoice_show_swish ?? false)) return null
// Non-payable documents: the PDF hides the whole payment box for them, and
// a locked payment QR on a kreditfaktura (a refund document, "Er tillgodo")
// must stay impossible even if a template regression ever exposed the
// corner. Same gate as buildPaymentLinkQrDataUrl; quiet like display-off.
const docType = invoice.document_type || 'invoice'
if (docType !== 'invoice' || invoice.credited_invoice_id) return null
if ((invoice.currency ?? 'SEK') !== 'SEK') {
log.info('swish QR skipped: invoice not in SEK', { invoiceId: invoice.id, currency: invoice.currency })
return null
}
const amount = getAmountToPay(invoice, company).toPay
const payload = buildSwishQrPayload(company.swish, amount, invoice.invoice_number ?? '')
if (!payload) {
log.warn('swish QR skipped: invalid number or non-positive amount', {
invoiceId: invoice.id,
hasSwish: !!company.swish,
amount,
})
return null
}
try {
return await QRCode.toDataURL(payload, { margin: 1, width: 240, errorCorrectionLevel: 'M' })
} catch (err) {
log.warn('swish QR generation failed', {
invoiceId: invoice.id,
error: err instanceof Error ? err.message : String(err),
})
return null
}
}