Consolidate audit-fixes branch: webhooks, integrations, and deploy hardening

Batch commit of the pending working tree on security/audit-fixes-2026-07.
Major areas:
- Outbound webhooks / Zapier: schema + signed delivery with retries, public
  v1 API (REST-hook subscribe/unsubscribe), settings UI, cron drain.
- Deploy hardening: email via SMTP2GO (Resend fully removed), verified DB TLS
  (DATABASE_SSL=require + DATABASE_CA), storage fails loud in production when
  Spaces is unconfigured instead of silently using ephemeral disk.
- Integrations & features (concurrent work): accounting (QuickBooks/Xero),
  e-signature (DocuSign/Dropbox Sign), PayPal, geocoding/maps, onboarding,
  expanded legal pages.
- DB migrations 0006–0009.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Leon Serfaty
2026-07-02 13:42:34 -04:00
co-authored by Claude Opus 4.8
parent 969d5d4c8a
commit c9968531e4
282 changed files with 41530 additions and 4013 deletions
+19
View File
@@ -31,6 +31,20 @@ export function RentActions({ payment }: { payment: any }) {
router.refresh()
}
async function sendLink() {
setLoading(true)
const res = await fetch("/api/rent/send-payment-link", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ payment_id: payment.id }),
})
const data = await res.json().catch(() => ({}))
setLoading(false)
if (res.ok) toast.success(data.message ?? "Payment link emailed to tenant")
else toast.error(data.error ?? "Failed to send payment link")
router.refresh()
}
if (loading) return <span className="text-xs text-white/30">Updating...</span>
return (
@@ -40,6 +54,11 @@ export function RentActions({ payment }: { payment: any }) {
Mark Paid
</button>
)}
{payment.status !== "paid" && (
<button onClick={sendLink} className="text-xs text-indigo-400 hover:text-indigo-300">
Send link
</button>
)}
{payment.status !== "overdue" && payment.status !== "paid" && (
<button onClick={() => markAs("overdue")} className="text-xs text-red-400 hover:text-red-300">
Mark Overdue