feat(bookkeeping): agent attribution into the immutable ledger layer (P0-1) (#678)

* feat(bookkeeping): agent attribution into the immutable ledger layer

Close the three attribution gaps left after 20260618120001 (which made
commit_method record 'api_key' for MCP-relayed approvals):

- journal_entries gains nullable committed_actor_type/committed_actor_label,
  stamped by commit_journal_entry in the same draft->posted UPDATE that
  writes commit_method. The RPC gains p_actor_type/p_actor_label
  (DEFAULT NULL; prior signature dropped first to avoid PostgREST overload
  ambiguity, same technique as 20260421140000).
- write_audit_log now populates audit_log.actor_type/actor_label from
  transaction-local gnubok.actor_* GUCs set by the RPC (the established
  gnubok.allow_delete pattern). Unset GUCs COALESCE to 'user' — byte-
  identical to the column's previous effective DEFAULT for every
  pre-existing write path.
- commitPendingOperation accepts opts.actor and runs the entire executor
  inside an AsyncLocalStorage runWithActor() scope read by commitEntry(),
  so EVERY journal commit an operation makes is attributed — closing the
  documented "commitMethod only reaches create_voucher" gap. MCP approve
  passes the api_key actor + key label; web single/bulk approve pass the
  user + email.

Known limitation (documented): reverseEntry posts reversal vouchers via
direct PostgREST writes, not the commit RPC — reversals keep NULL
attribution until that path is RPC-ified (follow-up).

pg-real coverage: lib/bookkeeping/__tests__/commit-actor.pg.test.ts
(RPC param stamping, audit GUC read, transaction-locality, CHECK
rejection, immutability of the new columns, single-signature guard).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(bookkeeping): split actor-context so client bundles never see node:async_hooks

CI core-only build failed: engine.ts is reachable from client component
bundles (invoices/[id] page), and the static node:async_hooks import in
actor-context.ts cannot be chunked for the browser. Split the module:

- actor-context.ts (isomorphic): CommitActor type + a storage registry +
  getActor(). In a client bundle the registry stays empty and getActor()
  returns undefined — identical to the server-side no-scope default.
- actor-context-node.ts (server-only): owns the AsyncLocalStorage, binds it
  into the registry on import, exports runWithActor(). Imported only by the
  approval paths (commit.ts), which are never client-reachable.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-06-06 10:05:48 +02:00
committed by GitHub
co-authored by Claude Opus 4.8
parent 0ca9c25aba
commit 8d2ff61599
14 changed files with 638 additions and 10 deletions
@@ -237,8 +237,13 @@ describe('POST /api/pending-operations/bulk-commit', () => {
expect.objectContaining({ id: VALID_ID_1 }),
// commit_method must be 'bulk_accept' so any journal_entries created
// during bulk approval are tagged distinctly from single-approval ones
// (BFNAR 2013:2 behandlingshistorik).
{ userEmail: 'test@test.se', commitMethod: 'bulk_accept' }
// (BFNAR 2013:2 behandlingshistorik). The actor option attributes the
// commits to the approving user (migration 20260619120000).
{
userEmail: 'test@test.se',
commitMethod: 'bulk_accept',
actor: { type: 'user', label: 'test@test.se' },
}
)
})
@@ -68,6 +68,7 @@ export async function POST(request: Request) {
const result = await commitPendingOperation(supabase, user.id, companyId, op, {
userEmail: user.email,
commitMethod: 'bulk_accept',
actor: { type: 'user', ...(user.email ? { label: user.email } : {}) },
})
if (result.status === 'committed') {
results.push({ id, status: 'committed' })