feat(bookkeeping): agent attribution into the immutable ledger layer (P0-1) (#678)

* feat(bookkeeping): agent attribution into the immutable ledger layer

Close the three attribution gaps left after 20260618120001 (which made
commit_method record 'api_key' for MCP-relayed approvals):

- journal_entries gains nullable committed_actor_type/committed_actor_label,
  stamped by commit_journal_entry in the same draft->posted UPDATE that
  writes commit_method. The RPC gains p_actor_type/p_actor_label
  (DEFAULT NULL; prior signature dropped first to avoid PostgREST overload
  ambiguity, same technique as 20260421140000).
- write_audit_log now populates audit_log.actor_type/actor_label from
  transaction-local gnubok.actor_* GUCs set by the RPC (the established
  gnubok.allow_delete pattern). Unset GUCs COALESCE to 'user' — byte-
  identical to the column's previous effective DEFAULT for every
  pre-existing write path.
- commitPendingOperation accepts opts.actor and runs the entire executor
  inside an AsyncLocalStorage runWithActor() scope read by commitEntry(),
  so EVERY journal commit an operation makes is attributed — closing the
  documented "commitMethod only reaches create_voucher" gap. MCP approve
  passes the api_key actor + key label; web single/bulk approve pass the
  user + email.

Known limitation (documented): reverseEntry posts reversal vouchers via
direct PostgREST writes, not the commit RPC — reversals keep NULL
attribution until that path is RPC-ified (follow-up).

pg-real coverage: lib/bookkeeping/__tests__/commit-actor.pg.test.ts
(RPC param stamping, audit GUC read, transaction-locality, CHECK
rejection, immutability of the new columns, single-signature guard).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(bookkeeping): split actor-context so client bundles never see node:async_hooks

CI core-only build failed: engine.ts is reachable from client component
bundles (invoices/[id] page), and the static node:async_hooks import in
actor-context.ts cannot be chunked for the browser. Split the module:

- actor-context.ts (isomorphic): CommitActor type + a storage registry +
  getActor(). In a client bundle the registry stays empty and getActor()
  returns undefined — identical to the server-side no-scope default.
- actor-context-node.ts (server-only): owns the AsyncLocalStorage, binds it
  into the registry on import, exports runWithActor(). Imported only by the
  approval paths (commit.ts), which are never client-reachable.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-06-06 10:05:48 +02:00
committed by GitHub
co-authored by Claude Opus 4.8
parent 0ca9c25aba
commit 8d2ff61599
14 changed files with 638 additions and 10 deletions
+29
View File
@@ -28,6 +28,8 @@ import {
createCreditNoteJournalEntry,
} from '@/lib/bookkeeping/invoice-entries'
import { createJournalEntry, findFiscalPeriod, reverseEntry, validateBalance } from '@/lib/bookkeeping/engine'
import { runWithActor } from '@/lib/bookkeeping/actor-context-node'
import type { CommitActor } from '@/lib/bookkeeping/actor-context'
import { correctEntry } from '@/lib/core/bookkeeping/storno-service'
import { closePeriod, lockPeriod, unlockPeriod, resolvePeriodStatusForDate } from '@/lib/core/bookkeeping/period-service'
import {
@@ -117,6 +119,16 @@ export interface CommitOptions {
* 20260505190027_drop_agent_auto_commit.
*/
commitMethod?: 'user_accept' | 'bulk_accept' | 'agent' | 'api_key'
/**
* WHO is relaying this approval (api_key with the key's display name, plain
* user, agent_chat, …). Propagated to every journal-entry commit made by the
* operation via the runWithActor() AsyncLocalStorage scope — unlike
* commitMethod, which only the create_voucher executor threads explicitly —
* and stamped onto journal_entries.committed_actor_* plus the audit_log
* COMMIT row by the commit_journal_entry RPC (migration 20260619120000).
* Omitted → NULL attribution, identical to pre-attribution behaviour.
*/
actor?: CommitActor
}
// ── Helper: ensure fiscal period covers the date ──────────────────
@@ -3019,6 +3031,12 @@ async function commitLinkTransactionJournalEntry(
*
* Used by both the human-approval route and the auto-commit path. Status row
* transitions are applied here so the two callers stay consistent.
*
* When opts.actor is set, the entire executor runs inside a runWithActor()
* scope so EVERY journal-entry commit the operation makes — regardless of
* which entry generator produced it — carries actor attribution into
* journal_entries.committed_actor_* and the audit_log COMMIT row via
* commitEntry() → commit_journal_entry RPC (migration 20260619120000).
*/
export async function commitPendingOperation(
supabase: SupabaseClient,
@@ -3026,6 +3044,17 @@ export async function commitPendingOperation(
companyId: string,
pendingOp: PendingOperation,
opts: CommitOptions = {}
): Promise<CommitResult> {
const run = () => commitPendingOperationInner(supabase, userId, companyId, pendingOp, opts)
return opts.actor ? runWithActor(opts.actor, run) : run()
}
async function commitPendingOperationInner(
supabase: SupabaseClient,
userId: string,
companyId: string,
pendingOp: PendingOperation,
opts: CommitOptions = {}
): Promise<CommitResult> {
// ── Atomic claim: flip status pending → committing in a single conditional
// update. If 0 rows are affected, another caller (auto-commit ↔ human