* feat(auth): surface duplicate-account traps around BankID login
Three escape hatches for the stale-duplicate-account trap (#1231, the
Chillen support case): a user whose BankID resolves to an abandoned
account got an empty app with no hint that their real bookkeeping
lives in another account.
- check-org-number: new exists_elsewhere signal (service role, reduced
to one boolean) + a warn chip in the onboarding journey when the org
number already exists in an account the user is not a member of.
- Hem: one AttnLine under the greeting when the whole account has zero
journal entries but a same-orgnr company elsewhere has real
bookkeeping, with a sign-out action. Common case costs one indexed
existence probe.
- scripts/support/unlink-bankid.ts: dry-run-by-default support action
that unlinks a BankID identity (delete + app_metadata clear +
append-only SECURITY_EVENT audit_log row). Replaces the raw SQL used
to resolve the original ticket.
Closes#1231
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(auth): harden unlink script and paginate hint queries per review
- other-account-hint: fetchAllRows() on both company listings (PostgREST
1000-row cap; byrå users can hold many memberships); the journal probes
stay limit(1) existence checks.
- unlink-bankid: audit_log row is written BEFORE the delete so a partial
failure can never delete without a trace; context queries fail closed
instead of rendering an unknown account as empty; stdout no longer
prints the personnummer hash or ciphertext (the unsalted hash is
brute-forceable over the personnummer space); record_id now carries the
identity row id and the snapshot includes id + linked_at.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>