invoicerr-app/invoicerr

1 error, 191 warningsdev

192 issues need attention.

1 error and 191 warnings in the paths between 202 routes and 65 tables.

ROUTE FINDINGS127 of 202 · 7/7 rules
ROUTES
202
TABLES
65
FILES READ
120
RULES RUN
7/7

192 findings

  • POST /billing/webhooks/polar can reach polar_webhook_event without authenticating.

    auth-before-dataPOST /billing/webhooks/polar → polar_webhook_event

  • GET /legal/documents has no validator or rate limiter attached.

    public-entry-guarded

  • GET /legal/status has no validator or rate limiter attached.

    public-entry-guarded

  • POST /legal/accept has no validator or rate limiter attached.

    public-entry-guarded

  • GET /articles has no validator or rate limiter attached.

    public-entry-guarded

  • GET /articles/low-stock has no validator or rate limiter attached.

    public-entry-guarded

  • GET /articles/:id has no validator or rate limiter attached.

    public-entry-guarded

  • POST /articles has no validator or rate limiter attached.

    public-entry-guarded

  • PATCH /articles/:id has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/sso has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/sso/domains has no validator or rate limiter attached.

    public-entry-guarded

  • POST /companies has no validator or rate limiter attached.

    public-entry-guarded

  • POST /companies/switch has no validator or rate limiter attached.

    public-entry-guarded

  • DELETE /companies/leave has no validator or rate limiter attached.

    public-entry-guarded

  • GET /companies/members has no validator or rate limiter attached.

    public-entry-guarded

  • GET /health has no validator or rate limiter attached.

    public-entry-guarded

  • GET /billing/seats has no validator or rate limiter attached.

    public-entry-guarded

  • GET /clients has no validator or rate limiter attached.

    public-entry-guarded

  • GET /clients/search has no validator or rate limiter attached.

    public-entry-guarded

  • GET /clients/duplicates has no validator or rate limiter attached.

    public-entry-guarded

  • GET /clients/:id/statement has no validator or rate limiter attached.

    public-entry-guarded

  • GET /clients/:id has no validator or rate limiter attached.

    public-entry-guarded

  • POST /clients has no validator or rate limiter attached.

    public-entry-guarded

  • PATCH /clients/:id has no validator or rate limiter attached.

    public-entry-guarded

  • POST /mcp has no validator or rate limiter attached.

    public-entry-guarded

  • GET /sirene/siret/:siret has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/info has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/email-templates has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/mail-settings has no validator or rate limiter attached.

    public-entry-guarded

  • GET /version has no validator or rate limiter attached.

    public-entry-guarded

  • GET /billing/status has no validator or rate limiter attached.

    public-entry-guarded

  • GET /billing/billing-email has no validator or rate limiter attached.

    public-entry-guarded

  • GET /invitations/can-register has no validator or rate limiter attached.

    public-entry-guarded

  • GET /invitations/is-first-user has no validator or rate limiter attached.

    public-entry-guarded

  • POST /invitations/validate has no validator or rate limiter attached.

    public-entry-guarded

  • GET /account/transfers has no validator or rate limiter attached.

    public-entry-guarded

  • POST /account/transfers/:id/accept has no validator or rate limiter attached.

    public-entry-guarded

  • POST /auth-extended/set-password has no validator or rate limiter attached.

    public-entry-guarded

  • PATCH /auth-extended/preferences has no validator or rate limiter attached.

    public-entry-guarded

  • GET /payments/:documentId/sessions has no validator or rate limiter attached.

    public-entry-guarded

  • GET /projects has no validator or rate limiter attached.

    public-entry-guarded

  • GET /projects/:id has no validator or rate limiter attached.

    public-entry-guarded

  • POST /projects has no validator or rate limiter attached.

    public-entry-guarded

  • PATCH /projects/:id has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/atcud-series has no validator or rate limiter attached.

    public-entry-guarded

  • POST /billing/webhooks/polar has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/schedules has no validator or rate limiter attached.

    public-entry-guarded

  • POST /documents/schedules has no validator or rate limiter attached.

    public-entry-guarded

  • PATCH /documents/schedules/:id has no validator or rate limiter attached.

    public-entry-guarded

  • DELETE /documents/schedules/:id has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/types has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/email-templates has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/types/:typeId/email-template has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/types/:typeId has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/types/:typeId/fields/:fieldKey/rows has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/available-types has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/required-identifiers has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/b2g-routing has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/declarations has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/dashboard has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/statistics has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/transports has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/references/:entity/search has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/references/:entity/:refId has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/references/:entity/:refId/fields has no validator or rate limiter attached.

    public-entry-guarded

  • POST /documents/attachments/upload has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/attachments/:fileRef has no validator or rate limiter attached.

    public-entry-guarded

  • POST /documents/types/:typeId/actions/:actionId has no validator or rate limiter attached.

    public-entry-guarded

  • POST /documents/types/:typeId/actions/:actionId/params/defaults has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/:id/totals has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/:id/settlement has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/:id/tax-warnings has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/:id/correction-routes has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/:id/pdf has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/:id/formats/:syntax has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/:id/archives has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/:id/authority-events has no validator or rate limiter attached.

    public-entry-guarded

  • POST /documents/:id/archives/:archiveId/verify has no validator or rate limiter attached.

    public-entry-guarded

  • POST /documents/:id/share-link has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/:id/share-links has no validator or rate limiter attached.

    public-entry-guarded

  • DELETE /documents/:id/share-link/:tokenId has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/:id has no validator or rate limiter attached.

    public-entry-guarded

  • GET /sso/lookup has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/branding has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/branding/logo has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/branding/preview has no validator or rate limiter attached.

    public-entry-guarded

  • GET /time-entries has no validator or rate limiter attached.

    public-entry-guarded

  • POST /time-entries has no validator or rate limiter attached.

    public-entry-guarded

  • PATCH /time-entries/:id has no validator or rate limiter attached.

    public-entry-guarded

  • DELETE /time-entries/:id has no validator or rate limiter attached.

    public-entry-guarded

  • POST /time-entries/generate-invoice has no validator or rate limiter attached.

    public-entry-guarded

  • POST /clients/:clientId/portal-access has no validator or rate limiter attached.

    public-entry-guarded

  • GET /clients/:clientId/portal-access has no validator or rate limiter attached.

    public-entry-guarded

  • DELETE /clients/:clientId/portal-access/:tokenId has no validator or rate limiter attached.

    public-entry-guarded

  • DELETE /clients/:clientId/portal-access has no validator or rate limiter attached.

    public-entry-guarded

  • GET /public/documents/:token/pdf has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/channels has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company-lookup/capabilities has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company-lookup/capabilities/:countryCode has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company-lookup has no validator or rate limiter attached.

    public-entry-guarded

  • GET /payment-methods has no validator or rate limiter attached.

    public-entry-guarded

  • GET /accounting-export has no validator or rate limiter attached.

    public-entry-guarded

  • GET /country-readiness/fully-supported has no validator or rate limiter attached.

    public-entry-guarded

  • GET /country-readiness/mention-window-alerts has no validator or rate limiter attached.

    public-entry-guarded

  • GET /country-readiness/:countryCode has no validator or rate limiter attached.

    public-entry-guarded

  • POST /public/payments/:providerId/:companyId/webhook has no validator or rate limiter attached.

    public-entry-guarded

  • POST /bank-reconciliation/statements has no validator or rate limiter attached.

    public-entry-guarded

  • GET /bank-reconciliation/statements has no validator or rate limiter attached.

    public-entry-guarded

  • GET /bank-reconciliation/statements/:id/lines has no validator or rate limiter attached.

    public-entry-guarded

  • POST /bank-reconciliation/lines/:id/reconcile has no validator or rate limiter attached.

    public-entry-guarded

  • POST /public/sdi/notifiche/:token has no validator or rate limiter attached.

    public-entry-guarded

  • POST /public/sdi/notifiche has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/signing-certificates has no validator or rate limiter attached.

    public-entry-guarded

  • GET /custom-fields has no validator or rate limiter attached.

    public-entry-guarded

  • GET /custom-fields/resolved has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/expense-categories has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/currency-rates has no validator or rate limiter attached.

    public-entry-guarded

  • GET /company/currency-rates/gaps has no validator or rate limiter attached.

    public-entry-guarded

  • GET /public/signatures/:token has no validator or rate limiter attached.

    public-entry-guarded

  • GET /public/signatures/:token/document has no validator or rate limiter attached.

    public-entry-guarded

  • POST /public/signatures/:token/otp has no validator or rate limiter attached.

    public-entry-guarded

  • POST /public/signatures/:token/sign has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/received-invoices/reconciliation-settings has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/received-invoices/upload/:fileRef/ocr has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/received-invoices/:id/reconciliation has no validator or rate limiter attached.

    public-entry-guarded

  • POST /documents/received-invoices/upload has no validator or rate limiter attached.

    public-entry-guarded

  • GET /documents/received-invoices/:id/file has no validator or rate limiter attached.

    public-entry-guarded

  • PDFConfig is not connected to anything.

    no-orphan-datastore

  • Company is not connected to anything.

    no-orphan-datastore

  • Client is not connected to anything.

    no-orphan-datastore

  • MailTemplate is not connected to anything.

    no-orphan-datastore

  • Quote is not connected to anything.

    no-orphan-datastore

  • QuoteItem is not connected to anything.

    no-orphan-datastore

  • Invoice is not connected to anything.

    no-orphan-datastore

  • InvoiceItem is not connected to anything.

    no-orphan-datastore

  • RecurringInvoice is not connected to anything.

    no-orphan-datastore

  • RecurringInvoiceItem is not connected to anything.

    no-orphan-datastore

  • ReceiptItem is not connected to anything.

    no-orphan-datastore

  • Receipt is not connected to anything.

    no-orphan-datastore

  • PaymentMethod is not connected to anything.

    no-orphan-datastore

  • Signature is not connected to anything.

    no-orphan-datastore

  • CurrencyConversion is not connected to anything.

    no-orphan-datastore

  • Plugin is not connected to anything.

    no-orphan-datastore

  • Webhook is not connected to anything.

    no-orphan-datastore

  • invitation_code is not connected to anything.

    no-orphan-datastore

  • user is not connected to anything.

    no-orphan-datastore

  • session is not connected to anything.

    no-orphan-datastore

  • account is not connected to anything.

    no-orphan-datastore

  • verification is not connected to anything.

    no-orphan-datastore

  • Log is not connected to anything.

    no-orphan-datastore

  • company_subscription is not connected to anything.

    no-orphan-datastore

  • CurrencyRate is not connected to anything.

    no-orphan-datastore

  • user_company is not connected to anything.

    no-orphan-datastore

  • PartyIdentifier is not connected to anything.

    no-orphan-datastore

  • Article is not connected to anything.

    no-orphan-datastore

  • Project is not connected to anything.

    no-orphan-datastore

  • TimeEntry is not connected to anything.

    no-orphan-datastore

  • company_ownership_transfer is not connected to anything.

    no-orphan-datastore

  • legal_acceptance is not connected to anything.

    no-orphan-datastore

  • legal_document_release is not connected to anything.

    no-orphan-datastore

  • legal_document_release_notification is not connected to anything.

    no-orphan-datastore

  • api_key is not connected to anything.

    no-orphan-datastore

  • DocumentInstance is not connected to anything.

    no-orphan-datastore

  • DocumentSchedule is not connected to anything.

    no-orphan-datastore

  • DocumentPayment is not connected to anything.

    no-orphan-datastore

  • PaymentCheckoutSession is not connected to anything.

    no-orphan-datastore

  • BankStatement is not connected to anything.

    no-orphan-datastore

  • BankStatementLine is not connected to anything.

    no-orphan-datastore

  • DocumentReminder is not connected to anything.

    no-orphan-datastore

  • DocumentArchive is not connected to anything.

    no-orphan-datastore

  • PendingDocumentArchive is not connected to anything.

    no-orphan-datastore

  • PendingStorageErasure is not connected to anything.

    no-orphan-datastore

  • DocumentAuthorityEvent is not connected to anything.

    no-orphan-datastore

  • DocumentDownloadToken is not connected to anything.

    no-orphan-datastore

  • DangerOtp is not connected to anything.

    no-orphan-datastore

  • InstanceResetOtp is not connected to anything.

    no-orphan-datastore

  • ClientPortalToken is not connected to anything.

    no-orphan-datastore

  • DocumentNumberSequence is not connected to anything.

    no-orphan-datastore

  • PecFilenameSequence is not connected to anything.

    no-orphan-datastore

  • DocumentCountryActionRule is not connected to anything.

    no-orphan-datastore

  • CountryIdentifierRequirement is not connected to anything.

    no-orphan-datastore

  • B2gRoutingRule is not connected to anything.

    no-orphan-datastore

  • CompanyChannelConfig is not connected to anything.

    no-orphan-datastore

  • CompanyPaymentMethodConfig is not connected to anything.

    no-orphan-datastore

  • CompanyCustomField is not connected to anything.

    no-orphan-datastore

  • ExpenseCategory is not connected to anything.

    no-orphan-datastore

  • CompanySsoProvider is not connected to anything.

    no-orphan-datastore

  • CompanySsoDomain is not connected to anything.

    no-orphan-datastore

  • CompanySigningCertificate is not connected to anything.

    no-orphan-datastore

  • CompanyAtcudSeries is not connected to anything.

    no-orphan-datastore

  • BackupRun is not connected to anything.

    no-orphan-datastore

Part of this repository was not read, so this report is incomplete. Read 120 of 1,127 files, schemas and routes first. Point Wyro at a single service directory to read one in full. Unread: backend/src/modules/logger/logger.controller.ts, backend/src/prisma/sync-schema.ts, backend/src/modules/health/health.controller.ts.

Free account, no card. The repository opens as an editable graph.

Add this check to the README

wyro architecture badge
[![wyro architecture](https://wyro.in/api/badge/invoicerr-app/invoicerr)](https://wyro.in/scan/invoicerr-app/invoicerr)

It updates itself whenever the repository changes and links back to this report.

What this is

Wyro reads the repository’s routes and data models and checks the paths between them: whether a route can reach a table without passing a guard, whether a datastore holding personal data is exposed to a public read, whether an endpoint that issues credentials requires the credentials it issues.

It is rule-based, not a model. The same commit produces the same result every time, and it does not guess at business rules it cannot see. A rule with nothing to look at is reported as not having run — never as a pass.

This check runs on public source through GitHub’s own API and needs no account. A free account adds the editable architecture canvas, private repositories on paid plans, and a CI gate. No card required.