Harden demo access and restore clean checks

This commit is contained in:
2026-08-14 16:45:02 -04:00
parent 29d7b498ae
commit 66a53f25f2
10 changed files with 114 additions and 11 deletions
+10 -4
View File
@@ -20,9 +20,15 @@ import {
RECEIPT_MAX_BYTES,
} from "~/lib/object-storage";
import { parseReceiptText } from "~/lib/receipt-parse";
import type { db } from "~/server/db";
export { EXPENSE_CATEGORIES };
type ExpenseContext = {
db: typeof db;
session: { user: { id: string } };
};
const createExpenseSchema = z.object({
date: z.date(),
description: z.string().min(1, "Description is required"),
@@ -43,7 +49,7 @@ const updateExpenseSchema = createExpenseSchema.partial().extend({
});
async function verifyClientAccess(
ctx: { db: typeof import("~/server/db").db; session: { user: { id: string } } },
ctx: ExpenseContext,
clientId: string,
) {
const client = await ctx.db.query.clients.findFirst({
@@ -62,7 +68,7 @@ async function verifyClientAccess(
}
async function verifyInvoiceAccess(
ctx: { db: typeof import("~/server/db").db; session: { user: { id: string } } },
ctx: ExpenseContext,
invoiceId: string,
) {
const invoice = await ctx.db.query.invoices.findFirst({
@@ -81,7 +87,7 @@ async function verifyInvoiceAccess(
}
async function resolveExpenseBusinessId(
ctx: { db: typeof import("~/server/db").db; session: { user: { id: string } } },
ctx: ExpenseContext,
businessId: string | null,
invoice?: { businessId: string | null } | null,
) {
@@ -98,7 +104,7 @@ async function resolveExpenseBusinessId(
}
async function getOwnedExpense(
ctx: { db: typeof import("~/server/db").db; session: { user: { id: string } } },
ctx: ExpenseContext,
expenseId: string,
) {
const expense = await ctx.db.query.expenses.findFirst({