Skip to content

feat: add authentication and secure account-scoped invoice persistence #4

Description

@Navdeepannu

Goal

Allow users to create an account, sign in, and persist invoices securely so their data is available across devices and sessions.

The current project has no authentication or database dependency, so this issue establishes the account and persistence foundation. Select and document the auth and database providers before implementation.

Product behavior

  • Guests may continue creating an invoice locally.
  • Signing in enables durable cloud saves and cross-device access.
  • Users can only read, update, or delete records that belong to their account.
  • Existing public/shared invoice behavior must be explicit rather than exposing account-owned records by default.

Scope

Authentication

  • Sign up, sign in, sign out, and session restoration.
  • Protected account routes and server-side authorization.
  • Clear signed-in and signed-out navigation states.
  • Loading, error, and expired-session handling.

Persistence

  • Database schema and migrations for users and invoices.
  • Account ownership on every invoice.
  • Store structured invoice data, not only rendered HTML or PDF.
  • Create, read, update, and delete server operations with validation.
  • Created/updated timestamps and a stable invoice identifier.
  • Safe handling of client/company data and invoice line items.
  • Environment-variable and local-development documentation.

Security requirements

  • Enforce authorization on the server for every account-owned operation.
  • Never trust a user ID supplied by the client.
  • Prevent one user from loading or mutating another user's invoice by changing a URL.
  • Validate and sanitize persisted invoice data.
  • Keep provider and database secrets server-only.
  • Define whether shared invoice links use revocable tokens or a separate public identifier.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions