02f94ef631
* fix: add 15s timeout to accounting provider HTTP clients Node's built-in fetch has no default timeout, so a stalled provider could hold a serverless worker open for many minutes — worse with withRetry (6x on Fortnox, 3x on others) and getPaginated stacking across pages. Wrap each fetch() in the Fortnox, Visma, Bokio, Briox, and Björn Lundén clients with signal: AbortSignal.timeout(15_000), and treat TimeoutError/AbortError as retryable so a single stalled attempt retries cleanly instead of hanging the request. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: add timeouts to OAuth token endpoints Wrap every OAuth2 token exchange, refresh, and revoke POST in an AbortController via a new fetchWithTimeout helper. Without this, a hung provider endpoint holds the request thread indefinitely — worst case being Skatteverket, where refreshAccessToken sits on the hot path of every bookkeeping action and exchangeCodeForTokens races the 5-minute BankID auth-code TTL. On timeout, the Skatteverket OAuth callback now redirects to /reports?tab=vat-declaration with a Swedish retry message instead of leaving the user stranded on the callback URL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: close RLS escalation on membership and settings tables Any authenticated user who was a member (including viewer) could issue a direct PostgREST PATCH against company_members and promote themselves to owner, bypassing the app-layer requireWritePermission guard entirely. Reproduced on prod, then verified the fix on staging. Tighten INSERT/UPDATE/DELETE policies on company_members, team_members, api_keys, company_invitations, team_invitations, companies, teams, and company_settings to require the caller to hold role IN ('owner','admin') in the target company/team. Role check is wrapped in SECURITY DEFINER helpers (user_is_company_admin, user_is_team_admin, user_role_in_company) to avoid RLS recursion when a policy on company_members references company_members in its subquery. Add a BEFORE UPDATE trigger on company_members that rejects any role change unless the caller already holds role='owner', so admins cannot mint further owners even though they can otherwise write. Legitimate write paths are unaffected: company creation goes through the create_company_with_owner SECURITY DEFINER RPC, invite acceptance uses the service role, and team->company membership syncs via SECURITY DEFINER triggers. All bypass RLS. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(migrations): resolve duplicate schema_migrations version 20260421160000 Two migration files shared timestamp 20260421160000 on main (booking_template_usage.sql and opening_balances_rpc.sql), causing supabase_migrations.schema_migrations PK collisions on any fresh CI run: duplicate key value violates unique constraint "schema_migrations_pkey" Key (version)=(20260421160000) already exists. Bump opening_balances_rpc.sql to 20260421160500. booking_template_usage keeps 20260421160000 because its table already exists on prod; the renamed file has an idempotent CREATE OR REPLACE FUNCTION body and has not yet been deployed to prod, so moving its version is free. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(migrations): make booking_template_usage migration idempotent The table already exists on prod (applied out-of-band) but prod's schema_migrations does not track version 20260421160000, so the next PR-driven deploy would re-run this migration and fail on `CREATE TABLE public.booking_template_usage` with a duplicate-relation error. Add IF NOT EXISTS to CREATE TABLE and CREATE INDEX, and DROP POLICY IF EXISTS before each CREATE POLICY. No functional change on fresh databases; prod just silently no-ops the table/index creates and re-declares policies without dropping-then-missing them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: implement isTimeoutError utility and enforce role restrictions on company_members insert * fix: implement fallback for user_id in commit_journal_entry function when auth.uid() is NULL --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
81 lines
3.0 KiB
PL/PgSQL
81 lines
3.0 KiB
PL/PgSQL
-- =============================================================================
|
|
-- Close INSERT bypass in company_members owner-role guard.
|
|
--
|
|
-- 20260422120000_fix_rls_role_gates_on_membership_tables.sql added a
|
|
-- BEFORE UPDATE trigger that blocks non-owners from promoting members to
|
|
-- role='owner'. The trigger fires only on UPDATE, and the INSERT policy
|
|
-- (company_members_insert) passes any caller with role IN ('owner','admin')
|
|
-- with no constraint on NEW.role. An admin could therefore bypass the guard
|
|
-- entirely via a direct PostgREST INSERT with role='owner', contradicting
|
|
-- the stated guarantee that only owners can mint further owners.
|
|
--
|
|
-- Fix: add a BEFORE INSERT trigger that blocks role='owner' unless the
|
|
-- caller already holds role='owner' in the target company.
|
|
--
|
|
-- Bootstrap case: create_company_with_owner() (SECURITY DEFINER RPC)
|
|
-- preserves auth.uid() while inserting the first owner membership for a
|
|
-- freshly created company. The trigger must allow this path. The helper
|
|
-- user_role_in_company() returns NULL at that moment (no prior membership),
|
|
-- so we permit the insert when (a) the caller is inserting themselves and
|
|
-- (b) the company has no existing owner. Both conditions together pin the
|
|
-- escape hatch to genuine first-time bootstrap; a subsequent attempt to
|
|
-- inject a second owner fails on condition (b).
|
|
-- =============================================================================
|
|
|
|
CREATE OR REPLACE FUNCTION public.enforce_company_member_role_on_insert()
|
|
RETURNS trigger
|
|
LANGUAGE plpgsql
|
|
AS $$
|
|
DECLARE
|
|
caller_role text;
|
|
BEGIN
|
|
-- Service role and direct SQL (migration apply, admin console) have no
|
|
-- auth context; pass through unchanged.
|
|
IF auth.uid() IS NULL THEN
|
|
RETURN NEW;
|
|
END IF;
|
|
|
|
-- Only the 'owner' role is gated; admin/member/viewer pass through so that
|
|
-- admins retain the ability to add non-owner members.
|
|
IF NEW.role IS DISTINCT FROM 'owner' THEN
|
|
RETURN NEW;
|
|
END IF;
|
|
|
|
caller_role := public.user_role_in_company(NEW.company_id);
|
|
|
|
-- Existing owners can always mint owners.
|
|
IF caller_role = 'owner' THEN
|
|
RETURN NEW;
|
|
END IF;
|
|
|
|
-- Bootstrap: create_company_with_owner RPC inserts the first owner
|
|
-- membership. The caller has no prior membership (caller_role IS NULL)
|
|
-- and inserts themselves. Reject if an owner already exists to prevent
|
|
-- this path from being reused to mint a second owner.
|
|
IF caller_role IS NULL
|
|
AND NEW.user_id = auth.uid()
|
|
AND NOT EXISTS (
|
|
SELECT 1 FROM public.company_members
|
|
WHERE company_id = NEW.company_id
|
|
AND role = 'owner'
|
|
)
|
|
THEN
|
|
RETURN NEW;
|
|
END IF;
|
|
|
|
RAISE EXCEPTION
|
|
'Only owners can add members with role ''owner'' (your role: %)',
|
|
COALESCE(caller_role, 'none');
|
|
END;
|
|
$$;
|
|
|
|
DROP TRIGGER IF EXISTS enforce_company_member_role_on_insert
|
|
ON public.company_members;
|
|
|
|
CREATE TRIGGER enforce_company_member_role_on_insert
|
|
BEFORE INSERT ON public.company_members
|
|
FOR EACH ROW
|
|
EXECUTE FUNCTION public.enforce_company_member_role_on_insert();
|
|
|
|
NOTIFY pgrst, 'reload schema';
|