* feat(skatteverket): ombudsregister grant verification, honest session expiry, daily ombud sync
Users reported the Skatteverket connection "just disappearing" with no
banner, needing BankID again every time. Two causes, both fixed here:
1. SKV's per-flow refresh token lives 65 minutes. /status and the
skv_disconnected notice called any stored refresh token "refreshable",
so a days-dead session reported healthy and the reconnect banner never
fired until a submission failed live. lib/skatteverket/session-lifetime
now decides refreshability (expires_at + 5 min, refresh cap) for both
surfaces; the settings panel states the one-hour session lifetime.
2. The durable fix is the ombud (system certificate) path, dormant since
July behind SKATTEVERKET_SYSTEM_AUTH_MODE. Skatteverket added scope
`obr` (Ombudshantering v2) to our application id on 2026-09-01, so grant
verification can now ask the ombudsregister instead of classifying 403s
from the read services:
- lib/ombud-client.ts: GET /ombud/autentisieratOmbud, GET /roller,
POST .../djuplank/utseombud, on the system identity, per the public
tjanstebeskrivning v2.0 (mirrored in dev_docs/skatteverket/ombudshantering).
Role codes are env-pinned (SKATTEVERKET_OMBUD_ROLL_LASOMBUD/_MOMS) or
matched on rollbeskrivning text; a deep link never mints with a
guessed code.
- grant-probe.ts: register first, read-service probes only as fallback.
- New daily cron /api/extensions/skatteverket/ombud/sync/cron (30 3 * * *):
one register call discovers every company that granted us, creates or
downgrades connection rows by org number, runs from shadow mode on,
and never mass-revokes on an empty register.
- POST /system-connection/deeplink + "Utse {app} som ombud" button:
the company lands in SKV's e-service with roles pre-selected.
- Default system scopes include `obr`; skvRequestWithAuth gains an
`accept` option (Ombudshantering requires the Accept header).
Still inert in prod until the org certificate and avtal land; the cron and
verify routes no-op while system auth is off or unconfigured.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HkLnhWnxt5wWB9j3vfMmxu
* fix(skatteverket): skeptic round on ombud sync, register 404 fallback, opt-in-only rows, mass-downgrade guard
Cron touches only existing connection rows (a tenant's own Verifiera or
deep-link opt-in; the deeplink route now records a pending row), so an
org-number twin never gets auto-verified, and rows the tenant revoked
locally stay revoked. A register 404 throws by default (spec: wrong URI)
and is empty only for the cron, which guards it. Decisions are planned
before any upsert; a run that would fully deny >= 3 rows and > 50% of the
granted ones applies no downgrade. Grants that classify as neither
behörighet are 'error', not 'denied'. Literal select in listConnections for
the phantom-column scanner. window.open without 'noopener' so the
pre-opened tab exists; opener nulled by hand. Deeplink route test added.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HkLnhWnxt5wWB9j3vfMmxu
* fix(skatteverket): CodeRabbit round: exact role labels, paginate connections, deny never-listed rows, fail deeplink without opt-in row
Role descriptions match the whole label so 'Momsdeklaration,
deklarationsombud' is never read as the narrow moms role. listConnections
pages through fetchAllRows on (created_at, id). A pending row the register
never lists is written once as denied instead of staying 'Inte verifierad'.
The deeplink route returns 500 when the opt-in row cannot be stored, and the
panel navigates in-tab when the pre-opened tab was blocked.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HkLnhWnxt5wWB9j3vfMmxu
* fix(skatteverket): fence ombud grants on contested org numbers; cron honours unrecognised role codes
An org number claimed by more than one live company is contested: verify
and deep link answer 409 ORG_NUMBER_CONTESTED and the nightly sync changes
nothing on it, so a tenant that typed a victim's public org number cannot
inherit the victim's grant. The sync also skips huvudmän whose register
roles classify as neither behörighet (pinning problem, never a denial),
mirroring probeViaOmbudsregister.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HkLnhWnxt5wWB9j3vfMmxu
* fix(skatteverket): validate the ombud deep link host; withdraw grants on contested org numbers
The register's djuplank must be an https skatteverket.se URL before it is
returned or navigated to (the settings page follows it). The nightly sync
now withdraws a grant already recorded on an org number that more than one
live company claims, instead of only refusing new ones.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HkLnhWnxt5wWB9j3vfMmxu
---------
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
70 lines
3.1 KiB
TypeScript
70 lines
3.1 KiB
TypeScript
/**
|
|
* Lifetime rules for Skatteverket's personal (`per` / BankID) OAuth2 session.
|
|
*
|
|
* Skatteverket issues the access token for 60 minutes and the refresh token
|
|
* for 65 minutes, counted from the same issue moment, and allows at most 10
|
|
* refreshes per BankID consent. A stored refresh token is therefore only
|
|
* usable inside a five-minute window after the access token expires: after
|
|
* that, nothing on our side can revive the session and only a fresh BankID
|
|
* consent helps.
|
|
*
|
|
* Every surface that decides "can this connection still refresh itself"
|
|
* (the extension's /status route, the skv_disconnected notice, the settings
|
|
* panel) must agree on this rule. Before it lived here, /status and the
|
|
* notice both answered "yes, it can refresh" for as long as a refresh token
|
|
* existed, so a connection dead for days still showed as healthy and the
|
|
* reconnect banner never fired until a submission failed live.
|
|
*
|
|
* Core code (lib/notices) consumes this, so it lives in lib/, not in the
|
|
* extension.
|
|
*/
|
|
|
|
/** Access-token lifetime Skatteverket grants in the per flow. */
|
|
export const SKV_ACCESS_TOKEN_LIFETIME_MS = 60 * 60 * 1000
|
|
|
|
/** Refresh-token lifetime Skatteverket grants in the per flow. */
|
|
export const SKV_REFRESH_TOKEN_LIFETIME_MS = 65 * 60 * 1000
|
|
|
|
/**
|
|
* How long past access-token expiry the refresh token still works: the
|
|
* difference between the two lifetimes above.
|
|
*/
|
|
export const SKV_REFRESH_WINDOW_AFTER_EXPIRY_MS =
|
|
SKV_REFRESH_TOKEN_LIFETIME_MS - SKV_ACCESS_TOKEN_LIFETIME_MS
|
|
|
|
/** Maximum refreshes Skatteverket allows per BankID consent. */
|
|
export const SKV_MAX_REFRESH_COUNT = 10
|
|
|
|
export interface SkvSessionLike {
|
|
/** Access-token expiry as epoch ms, ISO string, or Date. */
|
|
expiresAt: number | string | Date | null | undefined
|
|
/** Whether a refresh token is stored at all (ciphertext presence is enough). */
|
|
hasRefreshToken: boolean
|
|
refreshCount: number | null | undefined
|
|
}
|
|
|
|
function toEpochMs(value: number | string | Date | null | undefined): number | null {
|
|
if (value === null || value === undefined) return null
|
|
if (typeof value === 'number') return Number.isFinite(value) ? value : null
|
|
const ms = value instanceof Date ? value.getTime() : new Date(value).getTime()
|
|
return Number.isFinite(ms) ? ms : null
|
|
}
|
|
|
|
/**
|
|
* True when the stored session can still be refreshed without a new BankID
|
|
* consent: a refresh token exists, the refresh cap is not reached, and the
|
|
* refresh token itself has not expired (65 minutes from issue, i.e. five
|
|
* minutes past access-token expiry).
|
|
*
|
|
* A session with no parsable expiry is treated as unrefreshable: claiming
|
|
* health for a row we cannot reason about is exactly the bug this replaces.
|
|
*/
|
|
export function isSkvSessionRefreshable(session: SkvSessionLike, now: number | Date = Date.now()): boolean {
|
|
if (!session.hasRefreshToken) return false
|
|
if ((session.refreshCount ?? 0) >= SKV_MAX_REFRESH_COUNT) return false
|
|
const expiresAt = toEpochMs(session.expiresAt)
|
|
if (expiresAt === null) return false
|
|
const nowMs = now instanceof Date ? now.getTime() : now
|
|
return nowMs < expiresAt + SKV_REFRESH_WINDOW_AFTER_EXPIRY_MS
|
|
}
|