f3a3d07ed3
* feat: one-click company setup from BankID directorships After BankID auth, surface Bolagsverket companies where the user is a director and provision a fully-configured gnubok company with one click instead of walking the 4-step wizard. Also exposed via CompanySwitcher's "Lägg till företag" for returning users. - New /select-company route merges gnubok memberships with TIC CompanyRoles; cards flag already-registered org numbers. - createCompanyFromTicRole server action derives entity_type, f-skatt, VAT, moms_period, and SPAR address defaults, then delegates to createCompanyFromOnboarding for consistent provisioning. - TIC /bankid/complete now requests enrichment on login too, so returning users see fresh CompanyRoles in the picker. - Middleware routes zero-membership users to /select-company when enrichment is available, /onboarding otherwise. - Inline enrichment picker removed from WelcomeOnboarding (wizard is now the manual fallback); SPAR address pre-fill preserved. - Unit tests for mapEntityType helper and createCompanyFromTicRole defaults (VAT-AB, non-VAT EF, unmappable, unauth). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: address PR review feedback on BankID company picker Greptile P1 + swedish-compliance bot findings: - Move enrichment row cleanup out of createCompanyFromOnboarding and into createCompanyFromTicRole. The manual wizard also goes through createCompanyFromOnboarding, and was wiping the enrichment row before the returning-user "Lägg till företag" flow could use it. - Refuse to provision when TIC /lookup is missing. Silently defaulting vat_registered to false for a momsregistrerat bolag would create a company that issues invoices without moms (ML 17 kap violation). The picker now routes to the manual wizard with org_number pre-filled when the lookup fails, so the user confirms VAT/F-skatt manually. - Default accounting_method by entity type: enskild firma → cash (K1/kontantmetoden per BFNAR 2013:2), aktiebolag → accrual (K2/K3). - Document that moms_period='quarterly' is a provisional middle-tier default; Skatteverket's assigned period depends on turnover and the user can correct it in /settings/tax. - Fix the misleading "re-fetch from BankID" comment — /select-company only reads the cached enrichment row; it's refreshed only on the next BankID auth. - Extend test coverage: lookup-missing refusal, EF kontantmetoden default. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: tighten entity-type mapping and clarify K1 threshold Second round of PR review fixes (swedish-compliance bot): - mapEntityType now uses explicit allow-lists instead of substring matches. "Enskild stiftelse" / "Enskild näringsverksamhet utan firma" no longer false-match as enskild_firma (would have provisioned with K1/kontantmetoden — ML/BFL risk). Regression guard test added. - Publikt aktiebolag explicitly included (same K2/K3 regime as private AB); Bankaktiebolag / Försäkringsaktiebolag excluded (FFFS regime). - Remove misleading claim that onboarding UI flags moms_period as provisional — no such UI exists by design (approved one-click UX). - Expand accounting_method comment to cite the 3 MSEK K1→K3 threshold (BFNAR 2013:2 vs 2017:3) so the EF→cash default is honest about its scope. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
249 lines
8.7 KiB
TypeScript
249 lines
8.7 KiB
TypeScript
import { createServerClient } from '@supabase/ssr'
|
|
import { NextResponse, type NextRequest } from 'next/server'
|
|
import { shouldEnforceMfa } from '@/lib/auth/mfa'
|
|
|
|
export async function updateSession(request: NextRequest) {
|
|
let supabaseResponse = NextResponse.next({
|
|
request,
|
|
})
|
|
|
|
const supabase = createServerClient(
|
|
process.env.NEXT_PUBLIC_SUPABASE_URL!,
|
|
process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY!,
|
|
{
|
|
cookies: {
|
|
getAll() {
|
|
return request.cookies.getAll()
|
|
},
|
|
setAll(cookiesToSet) {
|
|
cookiesToSet.forEach(({ name, value }) =>
|
|
request.cookies.set(name, value)
|
|
)
|
|
supabaseResponse = NextResponse.next({
|
|
request,
|
|
})
|
|
cookiesToSet.forEach(({ name, value, options }) =>
|
|
supabaseResponse.cookies.set(name, value, options)
|
|
)
|
|
},
|
|
},
|
|
}
|
|
)
|
|
|
|
// IMPORTANT: Avoid writing any logic between createServerClient and
|
|
// supabase.auth.getUser(). A simple mistake could make it very hard to debug
|
|
// issues with users being randomly logged out.
|
|
|
|
const {
|
|
data: { user },
|
|
error: authError,
|
|
} = await supabase.auth.getUser()
|
|
|
|
// Get the pathname
|
|
const pathname = request.nextUrl.pathname
|
|
|
|
// Salary feature is temporarily disabled in production — block page and API
|
|
// routes. Sidebar links render as "Kommer snart" and direct URL access is
|
|
// blocked. Local dev (NODE_ENV === 'development') keeps everything enabled
|
|
// so we can continue building the feature.
|
|
const SALARY_DISABLED = process.env.NODE_ENV !== 'development'
|
|
if (SALARY_DISABLED && (pathname === '/salary' || pathname.startsWith('/salary/') || pathname.startsWith('/api/salary/'))) {
|
|
if (pathname.startsWith('/api/')) {
|
|
return NextResponse.json({ error: 'Lön är inte tillgängligt ännu.' }, { status: 404 })
|
|
}
|
|
return NextResponse.redirect(new URL('/', request.url))
|
|
}
|
|
|
|
// If the refresh token is stale/invalid, clear the session cookies
|
|
// so the browser stops sending them on every request.
|
|
// Skip on auth routes — the callback needs PKCE cookies intact.
|
|
if (authError && !user && !pathname.startsWith('/auth')) {
|
|
await supabase.auth.signOut()
|
|
}
|
|
|
|
// Invite pages — accessible to everyone, signed in or not. A user who
|
|
// already has an account and is signed in should still be able to land on
|
|
// /invite/[token] to accept the invite with one click (see
|
|
// app/invite/[token]/page.tsx). If we bounce them to '/', they never see
|
|
// the invite at all.
|
|
if (pathname.startsWith('/invite')) {
|
|
return supabaseResponse
|
|
}
|
|
|
|
// Public auth routes — allow access
|
|
if (
|
|
pathname.startsWith('/login') ||
|
|
pathname.startsWith('/register') ||
|
|
pathname.startsWith('/auth') ||
|
|
pathname.startsWith('/reset-password') ||
|
|
pathname.startsWith('/sandbox')
|
|
) {
|
|
// If user is logged in and trying to access auth pages, redirect to dashboard
|
|
if (user) {
|
|
return NextResponse.redirect(new URL('/', request.url))
|
|
}
|
|
return supabaseResponse
|
|
}
|
|
|
|
// Protected routes - require authentication
|
|
if (!user) {
|
|
const url = request.nextUrl.clone()
|
|
url.pathname = '/login'
|
|
return NextResponse.redirect(url)
|
|
}
|
|
|
|
// MFA pages — accessible to authenticated users (AAL1+), skip MFA enforcement
|
|
if (pathname.startsWith('/mfa/')) {
|
|
return supabaseResponse
|
|
}
|
|
|
|
// MFA enforcement (application-side only, not RLS)
|
|
if (shouldEnforceMfa(user)) {
|
|
const { data: aal } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel()
|
|
|
|
// User has MFA enrolled but hasn't verified this session → redirect to verify
|
|
if (aal?.nextLevel === 'aal2' && aal?.currentLevel === 'aal1') {
|
|
return NextResponse.redirect(new URL('/mfa/verify', request.url))
|
|
}
|
|
|
|
// MFA required but user has no factor enrolled yet → force enrollment
|
|
// Skip for users with no companies (still setting up)
|
|
const companyIdForMfa = await resolveCompanyForMiddleware(supabase, user.id, request)
|
|
if (companyIdForMfa) {
|
|
const { data: factors } = await supabase.auth.mfa.listFactors()
|
|
const hasVerifiedFactor = factors?.totp?.some(f => f.status === 'verified')
|
|
|
|
if (!hasVerifiedFactor) {
|
|
return NextResponse.redirect(new URL('/mfa/enroll', request.url))
|
|
}
|
|
}
|
|
}
|
|
|
|
// Forward the pathname so server layouts can branch on it (e.g. render a
|
|
// no-company shell for /settings/account).
|
|
supabaseResponse.headers.set('x-pathname', pathname)
|
|
|
|
// Company context resolution
|
|
const cookieCompanyId = request.cookies.get('gnubok-company-id')?.value
|
|
const companyId = await resolveCompanyForMiddleware(supabase, user.id, request)
|
|
|
|
// If the cookie pointed at a company we can no longer resolve (e.g.
|
|
// archived), clear it so the browser stops sending it.
|
|
if (cookieCompanyId && cookieCompanyId !== companyId) {
|
|
supabaseResponse.cookies.set('gnubok-company-id', '', { path: '/', maxAge: 0 })
|
|
}
|
|
|
|
// Routes that stay accessible when the user has no active company.
|
|
// Needed so a user who archived their last company can still delete
|
|
// their account without being trapped on /onboarding forever.
|
|
const isNoCompanyAllowed =
|
|
pathname.startsWith('/onboarding') ||
|
|
pathname.startsWith('/select-company') ||
|
|
pathname.startsWith('/settings/account') ||
|
|
pathname.startsWith('/api/account/') ||
|
|
pathname.startsWith('/api/company')
|
|
|
|
// No companies — redirect to the picker if we have BankID enrichment for
|
|
// this user, otherwise the manual wizard. Either way, allow the escape-hatch
|
|
// routes to pass through.
|
|
if (!companyId) {
|
|
if (isNoCompanyAllowed) {
|
|
return supabaseResponse
|
|
}
|
|
|
|
const { data: enrichmentRow } = await supabase
|
|
.from('extension_data')
|
|
.select('id')
|
|
.eq('user_id', user.id)
|
|
.eq('extension_id', 'tic')
|
|
.eq('key', 'bankid_enrichment')
|
|
.maybeSingle()
|
|
|
|
const destination = enrichmentRow ? '/select-company' : '/onboarding'
|
|
return NextResponse.redirect(new URL(destination, request.url))
|
|
}
|
|
|
|
// Set company cookie on the response so downstream requests have it
|
|
supabaseResponse.cookies.set('gnubok-company-id', companyId, {
|
|
path: '/',
|
|
httpOnly: true,
|
|
secure: process.env.NODE_ENV === 'production',
|
|
sameSite: 'lax',
|
|
maxAge: 60 * 60 * 24 * 365,
|
|
})
|
|
|
|
// Allow access to onboarding (for adding new companies), select-company, and companies/new
|
|
if (pathname.startsWith('/select-company') || pathname.startsWith('/companies/new') || pathname.startsWith('/onboarding')) {
|
|
return supabaseResponse
|
|
}
|
|
|
|
return supabaseResponse
|
|
}
|
|
|
|
/**
|
|
* Resolve the active company for the authenticated user.
|
|
*
|
|
* Resolution: user_preferences → first non-archived membership.
|
|
*
|
|
* `user_preferences.active_company_id` is the authoritative source for
|
|
* the active company on both the Next.js and Postgres RLS side. The
|
|
* `gnubok-company-id` cookie is still refreshed for legacy read paths
|
|
* but it is no longer READ here, because RLS (via
|
|
* `current_active_company_id()`) cannot see cookies — so letting the
|
|
* cookie override the database would re-introduce the divergence this
|
|
* entire migration exists to fix.
|
|
*
|
|
* When we fall back to "first membership" (no user_preferences row yet),
|
|
* we also upsert user_preferences so subsequent RLS lookups agree with
|
|
* us without needing the fallback scan.
|
|
*
|
|
* Cannot use lib/company/context.ts because middleware runs on Edge.
|
|
*/
|
|
async function resolveCompanyForMiddleware(
|
|
supabase: ReturnType<typeof createServerClient>,
|
|
userId: string,
|
|
_request: NextRequest
|
|
): Promise<string | null> {
|
|
// 1. user_preferences (authoritative)
|
|
const { data: prefs } = await supabase
|
|
.from('user_preferences')
|
|
.select('active_company_id')
|
|
.eq('user_id', userId)
|
|
.maybeSingle()
|
|
|
|
if (prefs?.active_company_id) {
|
|
const { data: membership } = await supabase
|
|
.from('company_members')
|
|
.select('company_id, companies!inner(archived_at)')
|
|
.eq('company_id', prefs.active_company_id)
|
|
.eq('user_id', userId)
|
|
.is('companies.archived_at', null)
|
|
.maybeSingle()
|
|
|
|
if (membership) return membership.company_id
|
|
}
|
|
|
|
// 2. Fallback: first non-archived membership by created_at
|
|
const { data: firstCompany } = await supabase
|
|
.from('company_members')
|
|
.select('company_id, companies!inner(archived_at)')
|
|
.eq('user_id', userId)
|
|
.is('companies.archived_at', null)
|
|
.order('created_at', { ascending: true })
|
|
.limit(1)
|
|
.maybeSingle()
|
|
|
|
if (!firstCompany) return null
|
|
|
|
// Write the fallback back to user_preferences so future RLS lookups
|
|
// see the same active company without needing this fallback scan.
|
|
await supabase
|
|
.from('user_preferences')
|
|
.upsert(
|
|
{ user_id: userId, active_company_id: firstCompany.company_id },
|
|
{ onConflict: 'user_id' }
|
|
)
|
|
|
|
return firstCompany.company_id
|
|
}
|