Deploy on DigitalOcean App Platform (GitHub-source build) + consolidate audit-fixes

Deploy config:
- .do/app.yaml: build the Dockerfile directly from GitHub (deploy_on_push) instead
  of a pre-built DOCR image; NEXT_PUBLIC_* set RUN_AND_BUILD_TIME with the
  propertymanagement.network domain so they bake into the client bundle; add
  custom domains block (apex + www); wire Sentry DSN (server + browser).

Included pending work from the audit-fixes branch:
- AI provider abstraction (OpenAI/Anthropic, admin-selectable; Anthropic default)
- Per-landlord e-signature (DocuSign OAuth + Dropbox Sign) + migration 0010
- Outbound webhooks / Zapier integration
- PayPal removal (Stripe-only billing)
- Storage hardening (fail-loud when Spaces unconfigured), security fixes

Verified: full production Docker build (same build-args as DO) passes clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Leon Serfaty
2026-07-03 04:45:24 -04:00
co-authored by Claude Opus 4.8
parent 917a06ee85
commit 5495b94924
86 changed files with 7647 additions and 1182 deletions
+28 -9
View File
@@ -1,22 +1,41 @@
import crypto from "crypto"
// Signed OAuth `state` (HMAC-SHA256) — carries the initiating owner + provider
// and is tamper-proof, so the callback can't be forged/CSRF'd.
const SECRET = process.env.BETTER_AUTH_SECRET ?? "dev-secret"
// Signed OAuth `state` (HMAC-SHA256) — carries the initiating owner + provider,
// a random nonce (bound to a cookie by the connect route for CSRF protection),
// and an issued-at timestamp so a leaked state can't be replayed indefinitely.
export function signState(data: { ownerId: string; provider: string }): string {
const payload = Buffer.from(JSON.stringify(data)).toString("base64url")
const sig = crypto.createHmac("sha256", SECRET).update(payload).digest("base64url")
const STATE_TTL_MS = 10 * 60 * 1000 // 10 minutes
// Short-lived httpOnly cookie the connect route sets and the callback verifies
// against the state's nonce (binds the OAuth round-trip to the initiating browser).
export const OAUTH_NONCE_COOKIE = "acct_oauth_nonce"
// No insecure fallback: signing/verifying state without the real secret would
// let anyone forge a state for any owner, so we fail closed (mirrors lib/crypto.ts).
function secret(): string {
const s = process.env.BETTER_AUTH_SECRET
if (!s) throw new Error("BETTER_AUTH_SECRET is not set — required to sign OAuth state")
return s
}
export type OAuthState = { ownerId: string; provider: string; nonce: string }
export function signState(data: OAuthState): string {
const payload = Buffer.from(JSON.stringify({ ...data, iat: Date.now() })).toString("base64url")
const sig = crypto.createHmac("sha256", secret()).update(payload).digest("base64url")
return `${payload}.${sig}`
}
export function verifyState(state: string): { ownerId: string; provider: string } | null {
export function verifyState(state: string): OAuthState | null {
const [payload, sig] = state.split(".")
if (!payload || !sig) return null
const expect = crypto.createHmac("sha256", SECRET).update(payload).digest("base64url")
const expect = crypto.createHmac("sha256", secret()).update(payload).digest("base64url")
if (sig.length !== expect.length || !crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(expect))) return null
try {
return JSON.parse(Buffer.from(payload, "base64url").toString("utf8"))
const obj = JSON.parse(Buffer.from(payload, "base64url").toString("utf8")) as OAuthState & { iat?: number }
if (!obj.iat || Date.now() - obj.iat > STATE_TTL_MS) return null
if (!obj.ownerId || !obj.provider || !obj.nonce) return null
return { ownerId: obj.ownerId, provider: obj.provider, nonce: obj.nonce }
} catch {
return null
}