audit: Tier 1/3/4/5/7 batch — SSE, gates, dedup, URL escape, FK constraints
Tier 1.6: S3Backend.put now sets ServerSideEncryption=AES256 — closes the cleartext-at-rest gap for signed contracts, GDPR exports, pg_dumps. Tier 3.7: New safeUrl() helper in lib/email/shell.ts. Scheme allow-list (http/https/mailto/tel/relative only — javascript:/data:/vbscript:/file: rewritten to about:blank) + HTML-attribute escape. Retrofitted across all 7 transactional templates (crm-invite, portal-auth, document-signing, notification-digest, residential-inquiry, admin-email-change). Tier 4.2: /api/v1/alerts GET now gated on admin.view_audit_log. Tier 4.3: Documenso webhook handler emits captureErrorEvent on catch. Admin/errors no longer silent on webhook crashes. Tier 4.6: Inquiry-funnel email dedup is now case-insensitive (LOWER(value)) and stores normalized email on insert. Capital-letter resubmissions no longer spawn duplicate client+yacht+interest rows. Tier 5.6 + data-model H1: migration 0056 adds FK user_permission_overrides.user_id → user(id) cascade, same for user_port_roles.userId, plus partial unique index on user_email_changes pending rows. Tier 7.6: @types/node bumped from ^25 to ^20.19.0 — matches the runtime. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -15,6 +15,7 @@ import {
|
||||
import { logger } from '@/lib/logger';
|
||||
import { createAuditLog } from '@/lib/audit';
|
||||
import { checkRateLimit, rateLimiters } from '@/lib/rate-limit';
|
||||
import { captureErrorEvent } from '@/lib/services/error-events.service';
|
||||
|
||||
// BR-024: Dedup via signatureHash unique index on documentEvents
|
||||
// Always return 200 from webhook (webhook best practice)
|
||||
@@ -263,6 +264,15 @@ export async function POST(req: NextRequest): Promise<NextResponse> {
|
||||
}
|
||||
} catch (err) {
|
||||
logger.error({ err, event }, 'Error processing Documenso webhook');
|
||||
// The audit caught that webhook handlers were the only API surface
|
||||
// bypassing the platform-error pipeline — admin/errors was silent on
|
||||
// Documenso webhook crashes. Pipe them in so they surface alongside
|
||||
// every other 5xx.
|
||||
void captureErrorEvent({
|
||||
statusCode: 500,
|
||||
error: err,
|
||||
metadata: { source: 'webhook', provider: 'documenso', event },
|
||||
});
|
||||
}
|
||||
|
||||
return NextResponse.json({ ok: true }, { status: 200 });
|
||||
|
||||
Reference in New Issue
Block a user