Depends on: feat: add authentication and secure account-scoped invoice persistence
Goal
Add a Send invoice action that emails the invoice to the recipient from Invora and records the delivery attempt on the saved invoice.
User flow
- A signed-in user opens a saved invoice.
- The user selects Send invoice.
- A dialog shows the recipient email, subject, optional message, and invoice attachment/link.
- The user confirms the send.
- Invora displays the result and records delivery metadata.
Scope
- Send button in the editor and saved-invoice detail flow.
- Recipient email prefilled from client information but editable before sending.
- Subject and optional message fields.
- Server-side PDF generation or a secure, time-limited invoice link.
- Server-only email provider integration.
- Reply-to set to the authenticated user's verified business email where supported.
- Delivery status, provider message ID, sent timestamp, and failure reason.
- Clear success, retry, and failure states.
- Rate limiting and duplicate-send protection.
- Email template that is readable on mobile and includes the invoice number, amount, due date, and sender identity.
Security and reliability requirements
- Keep email provider credentials server-only.
- Validate recipient addresses and invoice ownership on the server.
- Prevent arbitrary users from sending another user's invoice.
- Do not expose permanent public invoice URLs unless explicitly enabled.
- Use idempotency or an equivalent mechanism to reduce accidental duplicate sends.
- Configure and document sender-domain verification, SPF, DKIM, and DMARC requirements.
- Do not mark an invoice as sent until the provider accepts the request.
Depends on:
feat: add authentication and secure account-scoped invoice persistenceGoal
Add a Send invoice action that emails the invoice to the recipient from Invora and records the delivery attempt on the saved invoice.
User flow
Scope
Security and reliability requirements