The founder wants the yellow boxes gone everywhere. The design system
already agreed: status colors are data, not chrome (convention 12) and
attention is a single ochre sentence, never a banner (convention 6).
This enforces it:
- ConfirmationDialog: the amber warning panel is now an AttnLine, and
the hardcoded Swedish default warningText is gone: it injected an
immutability warning into dialogs whose authors never asked for one
(every current caller passes the prop explicitly, so no behavior
change at any call site).
- Badge warning variant: amber fill replaced with a hairline chip and
ochre text.
- DestructiveConfirmDialog warning variant: neutral icon disc, default
primary confirm button (only --destructive survives as chrome).
- BankSyncStatusChip stale state: same neutral shape as the healthy
chip, ochre text carries the signal.
- SandboxBanner: solid amber bar becomes secondary-on-border chrome.
- BankIdAuth, BankIdCompanyPicker, SessionTimeoutModal: the last three
raw-amber (bg-amber-*) holdouts moved onto tokens, the company-picker
banner becoming a plain AttnLine.
- Mechanical sweep of the ~58 hand-rolled bg-warning/border-warning
boxes across 45 files: fills to bg-muted/30 (icon discs bg-muted),
borders to border-border, text-warning-foreground to text-attn. The
account-class dots in account-number.tsx keep bg-warning: they are
data indicators, not chrome.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(auth): enforce session idle and absolute timeouts
Hosted browser sessions now carry an HMAC-signed, HttpOnly cookie holding
session start, last activity and sign-in method, bound to the Supabase
session. Middleware enforces a 30 min idle and 12 h absolute limit
(reason-coded redirects to /login), a heartbeat route advances idle
activity from real user input, and a client controller warns 2 minutes
before expiry. BankID users are routed back to BankID on re-auth via a
short-lived method hint. API-key and MCP bearer surfaces are exempt;
self-hosted installs default off and can opt in via env vars.
Fixes#362
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(auth): derive session-timeout signing key via HKDF
The HMAC key is now HKDF-derived with a purpose-bound info string, so
the SUPABASE_SERVICE_ROLE_KEY fallback never uses the privileged
credential directly as a signing key. Addresses the security review
finding on PR #1387.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(auth): back signature bytes with a plain ArrayBuffer
crypto.subtle.verify requires a BufferSource; Uint8Array.from is typed
over ArrayBufferLike, which the Vercel TypeScript build rejects. Decode
base64url into a Uint8Array constructed over a fresh ArrayBuffer.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(auth): address session-timeout review findings
- signSessionTimeoutState returns null on signing failure instead of
throwing, so a missing secret degrades the timeout feature in line
with verifySessionTimeoutState rather than crashing authenticated
requests; middleware and heartbeat skip the cookie write when null
- heartbeat initializes a fresh signed state for a missing or
session-mismatched cookie, mirroring middleware, instead of
returning SESSION_EXPIRED during normal initialization
- sessionStateMatchesUser treats an unresolved current session id as
a mismatch for session-bound state so another session's cookie is
never accepted on the userId fallback alone
- drop aria-live from the countdown DialogDescription so screen
readers are not interrupted every second
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>