feat(peppol): receiving sits behind the access request, switch only once granted (#1795)

The settings group showed the receiving switch (disabled) and a status row
to every company, which read as "anyone can receive". Now the switch and its
status exist only once the operators granted receiving (or a registration
already exists that the company must be able to see and withdraw), and the
access request carries a "we also want to receive" checkbox that lands in the
request note and the support mail (with --receive in the enable command).
The access line says whether receiving is included.


Claude-Session: https://claude.ai/code/session_01TqFpxeWqbpR7bcwUJLRERQ

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-08-21 17:57:10 +02:00
committed by GitHub
co-authored by Jakob Wennberg Claude Fable 5
parent 3ac80edc96
commit 3af95bec3f
5 changed files with 62 additions and 36 deletions
@@ -92,7 +92,7 @@ describe('POST /api/settings/peppol/access', () => {
enqueue({ data: { company_name: 'Kund AB', org_number: '556677-8899' }, error: null }) // company settings
service.enqueue({ data: requestedRow, error: null }) // summary read
const response = await post({ note: 'Vi fakturerar Region Skåne' })
const response = await post({ note: 'Vi fakturerar Region Skåne', wants_receiving: true })
const body = await response.json()
expect(response.status).toBe(201)
@@ -101,8 +101,12 @@ describe('POST /api/settings/peppol/access', () => {
const mail = sendEmailMock.mock.calls[0][0] as { to: string; subject: string; text: string }
expect(mail.to).toBe('support@example.test')
expect(mail.subject).toContain('Kund AB')
expect(mail.subject).toContain('mottagning')
expect(mail.text).toContain('company-1')
expect(mail.text).toContain('Region Skåne')
expect(mail.text).toContain('--receive')
const upsert = service.calls.find((c) => c.method === 'upsert')?.args[0] as Record<string, unknown>
expect(upsert.request_note).toBe('[vill ta emot e-fakturor] Vi fakturerar Region Skåne')
})
it('is idempotent for a repeated request (no second e-mail) and 409 when already enabled', async () => {
+13 -5
View File
@@ -18,7 +18,9 @@ import { getSupportRecipientEmail } from '@/lib/support'
ensureInitialized()
const RequestAccessSchema = z.object({
note: z.string().trim().max(2000).optional(),
note: z.string().trim().max(1800).optional(),
/** The company also wants to receive (one of the contracted tenant slots). */
wants_receiving: z.boolean().optional(),
})
function escapeHtml(value: string): string {
@@ -37,7 +39,13 @@ export const POST = withRouteContext(
async (request, { supabase, companyId, user, log, requestId }) => {
const validation = await validateBody(request, RequestAccessSchema)
if (!validation.success) return validation.response
const note = validation.data.note?.trim() || null
const wantsReceiving = validation.data.wants_receiving === true
const userNote = validation.data.note?.trim() || null
// The receiving wish travels in the request note so the operators see it
// in `access.ts list` and in the mail, and grant it with --receive.
const note = [wantsReceiving ? '[vill ta emot e-fakturor]' : null, userNote]
.filter((part): part is string => !!part)
.join(' ') || null
if (await isSandboxCompany(supabase, companyId)) {
return privateNoStore(errorResponseFromCode('PEPPOL_SANDBOX_NOT_ALLOWED', log, { requestId }))
@@ -62,16 +70,16 @@ export const POST = withRouteContext(
const orgNumber = (company as { org_number?: string | null } | null)?.org_number ?? 'saknas'
const sent = await emailService.sendEmail({
to: getSupportRecipientEmail(),
subject: `[${getBranding().appName.toLowerCase()} peppol] Åtkomstbegäran: ${companyName}`,
subject: `[${getBranding().appName.toLowerCase()} peppol] Åtkomstbegäran${wantsReceiving ? ' (+ mottagning)' : ''}: ${companyName}`,
replyTo: user.email,
html: [
`<p><strong>Bolag:</strong> ${escapeHtml(companyName)} (${escapeHtml(orgNumber)})</p>`,
`<p><strong>Company ID:</strong> ${companyId}</p>`,
`<p><strong>Begärd av:</strong> ${escapeHtml(user.email ?? '')} (${user.id})</p>`,
note ? `<hr /><p>${escapeHtml(note).replace(/\n/g, '<br />')}</p>` : '',
`<hr /><p>Aktivera: <code>npx tsx --env-file=.env.local scripts/peppol/access.ts enable ${companyId} --max-sends 50</code></p>`,
`<hr /><p>Aktivera: <code>npx tsx --env-file=.env.local scripts/peppol/access.ts enable ${companyId} --max-sends 50${wantsReceiving ? ' --receive' : ''}</code></p>`,
].join('\n'),
text: `Bolag: ${companyName} (${orgNumber})\nCompany ID: ${companyId}\nBegärd av: ${user.email ?? ''} (${user.id})\n\n${note ?? ''}\n\nAktivera: npx tsx --env-file=.env.local scripts/peppol/access.ts enable ${companyId} --max-sends 50`,
text: `Bolag: ${companyName} (${orgNumber})\nCompany ID: ${companyId}\nBegärd av: ${user.email ?? ''} (${user.id})\n\n${note ?? ''}\n\nAktivera: npx tsx --env-file=.env.local scripts/peppol/access.ts enable ${companyId} --max-sends 50${wantsReceiving ? ' --receive' : ''}`,
})
if (!sent.success) {
log.warn('peppol access request e-mail failed', { companyId, reason: sent.error })