Files
accounted/lib/supabase/middleware.ts
T
Jakob Wennberg f3a3d07ed3 feat: one-click company setup from BankID directorships (#309)
* feat: one-click company setup from BankID directorships

After BankID auth, surface Bolagsverket companies where the user is a
director and provision a fully-configured gnubok company with one click
instead of walking the 4-step wizard. Also exposed via CompanySwitcher's
"Lägg till företag" for returning users.

- New /select-company route merges gnubok memberships with TIC
  CompanyRoles; cards flag already-registered org numbers.
- createCompanyFromTicRole server action derives entity_type, f-skatt,
  VAT, moms_period, and SPAR address defaults, then delegates to
  createCompanyFromOnboarding for consistent provisioning.
- TIC /bankid/complete now requests enrichment on login too, so
  returning users see fresh CompanyRoles in the picker.
- Middleware routes zero-membership users to /select-company when
  enrichment is available, /onboarding otherwise.
- Inline enrichment picker removed from WelcomeOnboarding (wizard is
  now the manual fallback); SPAR address pre-fill preserved.
- Unit tests for mapEntityType helper and createCompanyFromTicRole
  defaults (VAT-AB, non-VAT EF, unmappable, unauth).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: address PR review feedback on BankID company picker

Greptile P1 + swedish-compliance bot findings:

- Move enrichment row cleanup out of createCompanyFromOnboarding and
  into createCompanyFromTicRole. The manual wizard also goes through
  createCompanyFromOnboarding, and was wiping the enrichment row before
  the returning-user "Lägg till företag" flow could use it.
- Refuse to provision when TIC /lookup is missing. Silently defaulting
  vat_registered to false for a momsregistrerat bolag would create a
  company that issues invoices without moms (ML 17 kap violation). The
  picker now routes to the manual wizard with org_number pre-filled
  when the lookup fails, so the user confirms VAT/F-skatt manually.
- Default accounting_method by entity type: enskild firma → cash
  (K1/kontantmetoden per BFNAR 2013:2), aktiebolag → accrual (K2/K3).
- Document that moms_period='quarterly' is a provisional middle-tier
  default; Skatteverket's assigned period depends on turnover and the
  user can correct it in /settings/tax.
- Fix the misleading "re-fetch from BankID" comment — /select-company
  only reads the cached enrichment row; it's refreshed only on the next
  BankID auth.
- Extend test coverage: lookup-missing refusal, EF kontantmetoden default.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: tighten entity-type mapping and clarify K1 threshold

Second round of PR review fixes (swedish-compliance bot):

- mapEntityType now uses explicit allow-lists instead of substring
  matches. "Enskild stiftelse" / "Enskild näringsverksamhet utan firma"
  no longer false-match as enskild_firma (would have provisioned with
  K1/kontantmetoden — ML/BFL risk). Regression guard test added.
- Publikt aktiebolag explicitly included (same K2/K3 regime as private
  AB); Bankaktiebolag / Försäkringsaktiebolag excluded (FFFS regime).
- Remove misleading claim that onboarding UI flags moms_period as
  provisional — no such UI exists by design (approved one-click UX).
- Expand accounting_method comment to cite the 3 MSEK K1→K3 threshold
  (BFNAR 2013:2 vs 2017:3) so the EF→cash default is honest about its
  scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-22 13:21:55 +02:00

249 lines
8.7 KiB
TypeScript

import { createServerClient } from '@supabase/ssr'
import { NextResponse, type NextRequest } from 'next/server'
import { shouldEnforceMfa } from '@/lib/auth/mfa'
export async function updateSession(request: NextRequest) {
let supabaseResponse = NextResponse.next({
request,
})
const supabase = createServerClient(
process.env.NEXT_PUBLIC_SUPABASE_URL!,
process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY!,
{
cookies: {
getAll() {
return request.cookies.getAll()
},
setAll(cookiesToSet) {
cookiesToSet.forEach(({ name, value }) =>
request.cookies.set(name, value)
)
supabaseResponse = NextResponse.next({
request,
})
cookiesToSet.forEach(({ name, value, options }) =>
supabaseResponse.cookies.set(name, value, options)
)
},
},
}
)
// IMPORTANT: Avoid writing any logic between createServerClient and
// supabase.auth.getUser(). A simple mistake could make it very hard to debug
// issues with users being randomly logged out.
const {
data: { user },
error: authError,
} = await supabase.auth.getUser()
// Get the pathname
const pathname = request.nextUrl.pathname
// Salary feature is temporarily disabled in production — block page and API
// routes. Sidebar links render as "Kommer snart" and direct URL access is
// blocked. Local dev (NODE_ENV === 'development') keeps everything enabled
// so we can continue building the feature.
const SALARY_DISABLED = process.env.NODE_ENV !== 'development'
if (SALARY_DISABLED && (pathname === '/salary' || pathname.startsWith('/salary/') || pathname.startsWith('/api/salary/'))) {
if (pathname.startsWith('/api/')) {
return NextResponse.json({ error: 'Lön är inte tillgängligt ännu.' }, { status: 404 })
}
return NextResponse.redirect(new URL('/', request.url))
}
// If the refresh token is stale/invalid, clear the session cookies
// so the browser stops sending them on every request.
// Skip on auth routes — the callback needs PKCE cookies intact.
if (authError && !user && !pathname.startsWith('/auth')) {
await supabase.auth.signOut()
}
// Invite pages — accessible to everyone, signed in or not. A user who
// already has an account and is signed in should still be able to land on
// /invite/[token] to accept the invite with one click (see
// app/invite/[token]/page.tsx). If we bounce them to '/', they never see
// the invite at all.
if (pathname.startsWith('/invite')) {
return supabaseResponse
}
// Public auth routes — allow access
if (
pathname.startsWith('/login') ||
pathname.startsWith('/register') ||
pathname.startsWith('/auth') ||
pathname.startsWith('/reset-password') ||
pathname.startsWith('/sandbox')
) {
// If user is logged in and trying to access auth pages, redirect to dashboard
if (user) {
return NextResponse.redirect(new URL('/', request.url))
}
return supabaseResponse
}
// Protected routes - require authentication
if (!user) {
const url = request.nextUrl.clone()
url.pathname = '/login'
return NextResponse.redirect(url)
}
// MFA pages — accessible to authenticated users (AAL1+), skip MFA enforcement
if (pathname.startsWith('/mfa/')) {
return supabaseResponse
}
// MFA enforcement (application-side only, not RLS)
if (shouldEnforceMfa(user)) {
const { data: aal } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel()
// User has MFA enrolled but hasn't verified this session → redirect to verify
if (aal?.nextLevel === 'aal2' && aal?.currentLevel === 'aal1') {
return NextResponse.redirect(new URL('/mfa/verify', request.url))
}
// MFA required but user has no factor enrolled yet → force enrollment
// Skip for users with no companies (still setting up)
const companyIdForMfa = await resolveCompanyForMiddleware(supabase, user.id, request)
if (companyIdForMfa) {
const { data: factors } = await supabase.auth.mfa.listFactors()
const hasVerifiedFactor = factors?.totp?.some(f => f.status === 'verified')
if (!hasVerifiedFactor) {
return NextResponse.redirect(new URL('/mfa/enroll', request.url))
}
}
}
// Forward the pathname so server layouts can branch on it (e.g. render a
// no-company shell for /settings/account).
supabaseResponse.headers.set('x-pathname', pathname)
// Company context resolution
const cookieCompanyId = request.cookies.get('gnubok-company-id')?.value
const companyId = await resolveCompanyForMiddleware(supabase, user.id, request)
// If the cookie pointed at a company we can no longer resolve (e.g.
// archived), clear it so the browser stops sending it.
if (cookieCompanyId && cookieCompanyId !== companyId) {
supabaseResponse.cookies.set('gnubok-company-id', '', { path: '/', maxAge: 0 })
}
// Routes that stay accessible when the user has no active company.
// Needed so a user who archived their last company can still delete
// their account without being trapped on /onboarding forever.
const isNoCompanyAllowed =
pathname.startsWith('/onboarding') ||
pathname.startsWith('/select-company') ||
pathname.startsWith('/settings/account') ||
pathname.startsWith('/api/account/') ||
pathname.startsWith('/api/company')
// No companies — redirect to the picker if we have BankID enrichment for
// this user, otherwise the manual wizard. Either way, allow the escape-hatch
// routes to pass through.
if (!companyId) {
if (isNoCompanyAllowed) {
return supabaseResponse
}
const { data: enrichmentRow } = await supabase
.from('extension_data')
.select('id')
.eq('user_id', user.id)
.eq('extension_id', 'tic')
.eq('key', 'bankid_enrichment')
.maybeSingle()
const destination = enrichmentRow ? '/select-company' : '/onboarding'
return NextResponse.redirect(new URL(destination, request.url))
}
// Set company cookie on the response so downstream requests have it
supabaseResponse.cookies.set('gnubok-company-id', companyId, {
path: '/',
httpOnly: true,
secure: process.env.NODE_ENV === 'production',
sameSite: 'lax',
maxAge: 60 * 60 * 24 * 365,
})
// Allow access to onboarding (for adding new companies), select-company, and companies/new
if (pathname.startsWith('/select-company') || pathname.startsWith('/companies/new') || pathname.startsWith('/onboarding')) {
return supabaseResponse
}
return supabaseResponse
}
/**
* Resolve the active company for the authenticated user.
*
* Resolution: user_preferences → first non-archived membership.
*
* `user_preferences.active_company_id` is the authoritative source for
* the active company on both the Next.js and Postgres RLS side. The
* `gnubok-company-id` cookie is still refreshed for legacy read paths
* but it is no longer READ here, because RLS (via
* `current_active_company_id()`) cannot see cookies — so letting the
* cookie override the database would re-introduce the divergence this
* entire migration exists to fix.
*
* When we fall back to "first membership" (no user_preferences row yet),
* we also upsert user_preferences so subsequent RLS lookups agree with
* us without needing the fallback scan.
*
* Cannot use lib/company/context.ts because middleware runs on Edge.
*/
async function resolveCompanyForMiddleware(
supabase: ReturnType<typeof createServerClient>,
userId: string,
_request: NextRequest
): Promise<string | null> {
// 1. user_preferences (authoritative)
const { data: prefs } = await supabase
.from('user_preferences')
.select('active_company_id')
.eq('user_id', userId)
.maybeSingle()
if (prefs?.active_company_id) {
const { data: membership } = await supabase
.from('company_members')
.select('company_id, companies!inner(archived_at)')
.eq('company_id', prefs.active_company_id)
.eq('user_id', userId)
.is('companies.archived_at', null)
.maybeSingle()
if (membership) return membership.company_id
}
// 2. Fallback: first non-archived membership by created_at
const { data: firstCompany } = await supabase
.from('company_members')
.select('company_id, companies!inner(archived_at)')
.eq('user_id', userId)
.is('companies.archived_at', null)
.order('created_at', { ascending: true })
.limit(1)
.maybeSingle()
if (!firstCompany) return null
// Write the fallback back to user_preferences so future RLS lookups
// see the same active company without needing this fallback scan.
await supabase
.from('user_preferences')
.upsert(
{ user_id: userId, active_company_id: firstCompany.company_id },
{ onConflict: 'user_id' }
)
return firstCompany.company_id
}