Files
accounted/lib/entitlements/__tests__/capability-maps.test.ts
T
Jakob WennbergandClaude Opus 4.8 db843a7a5b fix(entitlements): gate paid MCP tools (send_invoice/agi_submit/vat_declaration_submit) server-side (#846)
The HTTP routes call requireCapability at every paid chokepoint, but the
MCP/agent path bypassed the paywall entirely: the three external-service
tools stage operations whose commit calls the email / Skatteverket services
directly, with no capability check. After the 2026-07-07 trial cutover a
trial-connected non-payer using the gnubok MCP connector could still send
invoice emails and file AGI/VAT.

Close the gap with two layers, mirroring the existing TOOL_SCOPE_MAP gate:

- Dispatch gate (mcp-server/server.ts): MCP_TOOL_CAPABILITY_MAP, checked
  right after the scope check, blocks a non-entitled company before any
  pending op is staged. Emits errorKind='capability_denied' telemetry.
- Commit-time gate (commitPendingOperation): PAID_OPERATION_CAPABILITY_MAP,
  checked before the atomic claim. The real external-service chokepoint —
  applies to the MCP approve tool AND the UI approval path, and closes the
  trial-connected-token window (the grant has expired by commit time). A
  blocked op stays 'pending', so it is re-approvable once the company subscribes.

Adds a transport-free capabilityBlockedError() helper (shared bilingual
copy) and locks both maps with tests (maps, dispatch gate, commit gate).
Only the three write/submit tools are gated; SKV read/local tools stay free
per the statutory carve-out. No DB/migration change; self-hosted stays all-on.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-30 16:38:14 +02:00

52 lines
1.7 KiB
TypeScript

import { describe, it, expect } from 'vitest'
import {
MCP_TOOL_CAPABILITY_MAP,
PAID_OPERATION_CAPABILITY_MAP,
PAID_CAPABILITIES,
CAPABILITY,
} from '../keys'
/**
* These maps are the contract that gates the paid MCP/agent path (dispatch +
* commit). Locking the exact entries is the guard against a future paid
* external-service tool silently bypassing the paywall — mirrors the
* TOOL_SCOPE_MAP assertions in the mcp-server tests.
*/
describe('MCP_TOOL_CAPABILITY_MAP', () => {
it('gates exactly the three paid external-service MCP tools', () => {
expect(MCP_TOOL_CAPABILITY_MAP).toEqual({
gnubok_send_invoice: CAPABILITY.email_send,
gnubok_vat_declaration_submit: CAPABILITY.skatteverket,
gnubok_agi_submit: CAPABILITY.skatteverket,
})
})
it('only maps tools to PAID capabilities', () => {
for (const key of Object.values(MCP_TOOL_CAPABILITY_MAP)) {
expect(PAID_CAPABILITIES).toContain(key)
}
})
})
describe('PAID_OPERATION_CAPABILITY_MAP', () => {
it('gates exactly the three paid pending-operation types', () => {
expect(PAID_OPERATION_CAPABILITY_MAP).toEqual({
send_invoice: CAPABILITY.email_send,
submit_vat_declaration: CAPABILITY.skatteverket,
submit_agi: CAPABILITY.skatteverket,
})
})
it('only maps operations to PAID capabilities', () => {
for (const key of Object.values(PAID_OPERATION_CAPABILITY_MAP)) {
expect(PAID_CAPABILITIES).toContain(key)
}
})
it('covers the same set of capabilities as the MCP tool map (dispatch ↔ commit parity)', () => {
expect(new Set(Object.values(PAID_OPERATION_CAPABILITY_MAP))).toEqual(
new Set(Object.values(MCP_TOOL_CAPABILITY_MAP)),
)
})
})