Superadmin impersonation, hardened auth/upload paths, dependency updates

- Add superadmin impersonation: sessions.impersonated_by (migration 0003) is
  stamped onto audit rows so impersonated actions are attributable, with a
  persistent ImpersonationBanner in the app shell.
- Harden auth and upload handling across routes (safe redirect targets,
  filename sanitization, checkout grant handling).
- Update dependencies: Sentry 8 -> 10, @fastify/static 8 -> 10,
  react-router-dom 6.30.6; add find-my-way / fast-uri overrides.
- Add tests for safe-next, checkout-grant, and upload-filename.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Leon Serfaty
2026-08-26 10:25:39 -04:00
co-authored by Claude Opus 5
parent 4a1122a7c9
commit eb36b81dc9
28 changed files with 7936 additions and 5763 deletions
+66
View File
@@ -0,0 +1,66 @@
import { describe, it, expect } from 'vitest';
// Mirrors the grant decision in src/routes/webhooks-stripe.ts. `checkout.session.completed` fires
// as soon as Checkout finishes, which for delayed-notification payment methods (ACH debit, bank
// transfer, some wallets) happens BEFORE any money moves — payment_status 'unpaid'. Granting on
// the event alone hands out a paid plan for an unsettled payment.
type PaymentStatus = 'paid' | 'unpaid' | 'no_payment_required';
function shouldGrantPlan(paymentStatus: PaymentStatus): boolean {
return paymentStatus === 'paid' || paymentStatus === 'no_payment_required';
}
// Mirrors the subscription-status branch in the same file.
type SubStatus =
| 'active'
| 'trialing'
| 'past_due'
| 'unpaid'
| 'canceled'
| 'incomplete'
| 'incomplete_expired';
function planForSubscription(status: SubStatus): 'pro' | 'starter' | null {
if (status === 'active' || status === 'trialing') return 'pro';
if (status === 'unpaid' || status === 'incomplete_expired') return 'starter';
return null; // leave the current plan untouched
}
describe('checkout grant decision', () => {
it('grants on a settled payment', () => {
expect(shouldGrantPlan('paid')).toBe(true);
});
it('grants when no payment was required (e.g. a 100% coupon)', () => {
expect(shouldGrantPlan('no_payment_required')).toBe(true);
});
it('withholds the plan while the payment is unsettled', () => {
// The regression this guards: a delayed-payment method completing Checkout unpaid used to
// grant 'lifetime' outright.
expect(shouldGrantPlan('unpaid')).toBe(false);
});
});
describe('subscription status mapping', () => {
it('treats only active and trialing as paying', () => {
expect(planForSubscription('active')).toBe('pro');
expect(planForSubscription('trialing')).toBe('pro');
});
it('does not upgrade on past_due, and does not downgrade mid-retry either', () => {
// Stripe is still retrying the charge — flipping the plan in either direction here would
// either hand out Pro for a failed renewal or cut off a customer whose retry succeeds.
expect(planForSubscription('past_due')).toBeNull();
});
it('drops to starter on terminal non-payment states', () => {
expect(planForSubscription('unpaid')).toBe('starter');
expect(planForSubscription('incomplete_expired')).toBe('starter');
});
it('leaves the plan alone for states that carry no payment signal', () => {
expect(planForSubscription('incomplete')).toBeNull();
expect(planForSubscription('canceled')).toBeNull(); // handled by subscription.deleted instead
});
});