fix(migration): resumable underlag import without inline extraction + same-origin MCP storage URLs (#1783)
* fix(migration): resumable underlag import without inline extraction, same-origin MCP storage URLs The Fortnox underlag import ran every file's AI extraction inline inside one request and hit the hosted 300 s function limit after ~17 of 113 files (twice on 2026-08-21); the UI showed the generic "underlagen kunde inte importeras" although the files it did reach were linked. The import now works in time-budgeted slices with a stable cursor (the UI loops until the server reports the end and shows "x av y") and opts out of extraction (extractionOwner 'none', stamped skipped:opted_out): every file is linked to its posted verifikat on arrival, so the booking is already known. MCP signed Storage URLs (upload_url, signed_url, download_url) are served through a same-origin proxy, /api/storage/[...path], because Claude Desktop's sandbox only reaches the MCP host and blocked the PUT to <project>.supabase.co. The signed token stays the only credential; the proxy forwards only signed documents-bucket paths to our own Storage host and is a no-op rewrite when NEXT_PUBLIC_APP_URL is unset. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013YoZ8iboyTj221axW6Gdtm * fix(mcp): keep the storage-proxy note out of the size-capped tool descriptions The per-tool 280-char cap and the tools/list payload ceiling both tripped on the two sentences added to gnubok_create_document_upload and gnubok_get_document_content; the why now lives in a code comment. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013YoZ8iboyTj221axW6Gdtm * fix(review): id cursor, stall = error, capped upload body, encoded dot segments Review follow-ups on #1783: - the import cursor is the last handled provider attachment id, not an index, so a file Fortnox adds or removes mid-sweep shifts nothing - a partial answer whose cursor does not advance (or the round guard) is reported as ARCIM_DOCUMENT_IMPORT_STALLED instead of "complete"; the slices already landed stay reported and the retry button resumes - the storage proxy reads the PUT body as a capped stream instead of buffering an unbounded payload before measuring it - object paths are rejected when any segment decodes to "." or ".." (or holds a separator), and the URL fetch() would actually request is re-checked against the allowlist after normalisation - download_url description no longer claims a direct Storage URL Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013YoZ8iboyTj221axW6Gdtm --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
Jakob Wennberg
parent
0531576807
commit
524d9978f1
@@ -2076,6 +2076,33 @@ const PROVIDER_MIGRATION: Record<string, StructuredErrorEntry> = {
|
||||
message_sv: 'Kunde inte importera underlag från leverantören.',
|
||||
message_en: 'Failed to import documents from provider.',
|
||||
},
|
||||
// Same-origin storage proxy (/api/storage): signed Storage URLs served
|
||||
// from the app's own host for agent sandboxes that only reach the MCP host.
|
||||
STORAGE_PROXY_UNSUPPORTED_PATH: {
|
||||
httpStatus: 404,
|
||||
message_sv: 'Sökvägen stöds inte av lagringsproxyn.',
|
||||
message_en: 'The storage proxy does not serve this path.',
|
||||
},
|
||||
STORAGE_PROXY_TOKEN_REQUIRED: {
|
||||
httpStatus: 400,
|
||||
message_sv: 'Länken saknar sin signerade token.',
|
||||
message_en: 'The link is missing its signed token.',
|
||||
},
|
||||
STORAGE_PROXY_BODY_TOO_LARGE: {
|
||||
httpStatus: 413,
|
||||
message_sv: 'Filen är för stor för att laddas upp via länken.',
|
||||
message_en: 'The file is too large to upload through this link.',
|
||||
},
|
||||
STORAGE_PROXY_UNCONFIGURED: {
|
||||
httpStatus: 503,
|
||||
message_sv: 'Lagringen är inte konfigurerad på den här servern.',
|
||||
message_en: 'Storage is not configured on this server.',
|
||||
},
|
||||
STORAGE_PROXY_UPSTREAM_UNAVAILABLE: {
|
||||
httpStatus: 502,
|
||||
message_sv: 'Lagringen svarade inte.',
|
||||
message_en: 'Storage did not respond.',
|
||||
},
|
||||
PROVIDER_DOCUMENT_SCOPES_REQUIRED: {
|
||||
httpStatus: 403,
|
||||
message_sv:
|
||||
|
||||
Reference in New Issue
Block a user