Files
accounted/lib/auth/oauth-allowlist.ts
T
Jakob Wennberg ec27228a8e style: remove em/en dashes repo-wide, add CLAUDE.md rule against them (#890)
Em dashes (—) and en dashes (–) had spread across comments, docs, tests,
and a few UI strings, reading as AI-generated boilerplate rather than
house style. Replaced each with punctuation matching its context: colon
for explanatory clauses, comma for asides, plain hyphen for numeric/legal
ranges (e.g. "21-23§"), "to"/"till" for date ranges, parentheses for
paired-dash asides. messages/en.json and messages/sv.json were fixed by
hand together to keep sv/en in sync.

Left untouched where the dash is the functional subject rather than
decorative punctuation: date-range-parser.ts's separator regex,
charset-repair.ts's CP1252 byte-mapping table (and its test), the SIE
encoding mojibake docs, generic-csv.ts's minus-sign normalizer, the
agent system-prompt files that already instruct against em dashes, and
a golden iXBRL test fixture compared byte-for-byte.

Also fixes two bugs surfaced along the way: an off-by-one in
ApiKeysPanel's scope-label split (a leftover from an earlier partial
pass), and a charset-repair test that had lost the literal en-dash it
exists to verify.

Regenerated the agent atom seed migration (skills:generate) since 27
SKILL.md files changed. Added a CLAUDE.md rule against em/en dashes,
with an explicit carve-out for the functional-dash cases above.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04 15:58:06 +02:00

61 lines
2.1 KiB
TypeScript

import type { SupabaseClient } from '@supabase/supabase-js'
import { createServiceClientNoCookies } from './api-keys'
/**
* Built-in redirect URI patterns. These bypass the DB lookup entirely so
* Claude's connector keeps working without seeded rows, and so local
* development never depends on having a registration.
*/
export const BUILT_IN_REDIRECT_PATTERNS: readonly RegExp[] = [
/^https:\/\/claude\.ai\/api\//,
/^https:\/\/claude\.com\/api\//,
/^http:\/\/localhost(:\d+)?(\/|$)/,
/^http:\/\/127\.0\.0\.1(:\d+)?(\/|$)/,
]
export function isBuiltInRedirectUri(uri: string): boolean {
return BUILT_IN_REDIRECT_PATTERNS.some((pattern) => pattern.test(uri))
}
/**
* Resolve whether a redirect URI is allowed. Built-in patterns short-circuit;
* otherwise we look for a non-revoked registration in oauth_client_registrations.
*
* The supabase client should be supplied explicitly by the caller so the
* trust boundary is visible at the callsite (SOC 2 CC6.1). When omitted, the
* function falls back to a service-role client: required for the /register
* endpoint which has no user session yet. The lookup is by exact URI; the
* unique partial index on the table ensures at most one active row.
*
* Fails closed on any error (client construction, DB query): for an
* allowlist, "unknown → deny" is the safe default.
*/
export async function isAllowedRedirectUri(
uri: string,
supabase?: SupabaseClient
): Promise<boolean> {
if (typeof uri !== 'string' || uri.length === 0) return false
if (isBuiltInRedirectUri(uri)) return true
// Service-role client construction can throw when Supabase env vars are
// absent (unit tests, misconfigured deploys). Treat that as "not allowed":
// failing closed is the safe default for an allowlist.
let client: SupabaseClient
try {
client = supabase ?? createServiceClientNoCookies()
} catch {
return false
}
const { data, error } = await client
.from('oauth_client_registrations')
.select('id')
.eq('redirect_uri', uri)
.is('revoked_at', null)
.limit(1)
.maybeSingle()
if (error) return false
return data !== null
}