Files
accounted/lib
Jakob Wennberg 335d908614 fix(domains,skatteverket): #1087 follow-ups: auth-path redirect exclusions, SKV callback hardening (#1094)
- Exclude auth/ and reset-password from the legacy-host redirect (#1092):
  email links sent before the cutover carry a PKCE code or recovery
  session whose cookies live on app.gnubok.se; forwarding them to the
  new domain breaks password resets and signup confirmations clicked
  after the flip. login/MFA stay redirected on purpose: a usable login
  page on the legacy host would establish sessions there and loop.
  Exclusion pattern extracted to lib/domains/legacy-redirect.ts with a
  unit test pinning the behavior.
- Clean up ephemeral oauth state rows (incl. oauth_user_id) when the
  SKV token exchange fails (#1090): identity data must not outlive the
  flow; best-effort so cleanup failure never masks the user-facing error.
- Assert the stored user is still a member of the company before the
  service-role storeTokens write (#1091): membership can be revoked
  between /authorize and the callback, and RLS no longer backstops the
  write. Checked before the exchange so the one-shot code is not burned.

Fixes #1090, fixes #1091, fixes #1092.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-21 13:48:01 +02:00
..
2026-07-08 20:19:02 +02:00
2026-07-07 01:14:59 +02:00
2026-07-05 03:05:09 +02:00
2026-07-15 15:53:15 +02:00
2026-07-15 15:53:15 +02:00
2026-07-12 19:14:12 +02:00
2026-07-15 15:53:15 +02:00
2026-07-13 22:54:33 +02:00
2026-04-22 18:14:01 +02:00
2026-07-12 19:14:12 +02:00
2026-05-28 15:43:48 +02:00
2026-07-15 15:53:15 +02:00