Feat/cloud backup (#277)
* feat: cloud backup to Google Drive + full-archive all-scope Adds a cloud-backup extension that uploads a full-company backup ZIP to the user's own Google Drive via OAuth (drive.file scope only). Refresh tokens are AES-256-GCM encrypted before being stored in extension_data. The full-archive export gains a scope=all mode for whole-company backups (per-period SIE under sie/, per-period rapporter/ subfolders, flat dokument/ manifest tagged with fiscal_period_id). An 80 MB size guard short-circuits generation before the platform response limit. Also fixes a latent bug in lib/core/audit/audit-service.ts where the parameter was named userId while the query filtered by company_id; the audit-trail API route was passing user.id so audit queries returned empty unless user and company shared a UUID. Drive-by: scope the dashboard "fresh start" localStorage key per companyId so dismissing the setup checklist in one company no longer carries over to others. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: address review comments on cloud backup + archive export - Extend audit trail to_date to end-of-day so last-day entries aren't silently excluded from period-scoped archives. - Apply 413 size-limit guard regardless of include_documents, using the overhead-only figure when documents are excluded. - Use crypto.randomUUID() for Drive multipart boundary to eliminate any collision risk with ZIP payload bytes. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: migrate legacy setup-gate localStorage keys on dashboard Users who previously dismissed the setup checklist via the old global erp_setup_fresh_start or erp_checklist_dismissed keys were re-gated after the switch to a company-scoped key. Fall back to the legacy keys on read and migrate them to the scoped key on first hit. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: update customer email handling and anonymization rules in supportmail-to-ticket skill * test: update audit trail to_date expectation for end-of-day timestamp Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
2ea5a72b3d
commit
d708a85d4c
@@ -63,7 +63,7 @@ describe('GET /api/audit-trail', () => {
|
||||
expect(body.count).toBe(2)
|
||||
expect(mockGetAuditLog).toHaveBeenCalledWith(
|
||||
expect.anything(),
|
||||
'user-1',
|
||||
'company-1',
|
||||
expect.objectContaining({})
|
||||
)
|
||||
})
|
||||
@@ -88,7 +88,7 @@ describe('GET /api/audit-trail', () => {
|
||||
|
||||
expect(mockGetAuditLog).toHaveBeenCalledWith(
|
||||
expect.anything(),
|
||||
'user-1',
|
||||
'company-1',
|
||||
{
|
||||
action: 'INSERT',
|
||||
table_name: 'journal_entries',
|
||||
|
||||
@@ -27,7 +27,7 @@ export async function GET(request: Request) {
|
||||
}
|
||||
|
||||
try {
|
||||
const result = await getAuditLog(supabase, user.id, filters)
|
||||
const result = await getAuditLog(supabase, companyId, filters)
|
||||
return NextResponse.json({ data: result.data, count: result.count })
|
||||
} catch (err) {
|
||||
return NextResponse.json(
|
||||
|
||||
@@ -0,0 +1,208 @@
|
||||
/* eslint-disable @typescript-eslint/no-explicit-any */
|
||||
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
||||
import { createMockRequest, parseJsonResponse } from '@/tests/helpers'
|
||||
|
||||
vi.mock('@/lib/supabase/server', () => ({
|
||||
createClient: vi.fn(),
|
||||
}))
|
||||
|
||||
vi.mock('@/lib/company/context', () => ({
|
||||
requireCompanyId: vi.fn().mockResolvedValue('company-1'),
|
||||
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
|
||||
}))
|
||||
|
||||
vi.mock('@/lib/reports/full-archive-export', () => ({
|
||||
generateFullArchive: vi.fn(),
|
||||
estimateArchiveSize: vi.fn(),
|
||||
}))
|
||||
|
||||
import { createClient } from '@/lib/supabase/server'
|
||||
import {
|
||||
generateFullArchive,
|
||||
estimateArchiveSize,
|
||||
} from '@/lib/reports/full-archive-export'
|
||||
import { GET } from '../route'
|
||||
|
||||
const mockCreateClient = vi.mocked(createClient)
|
||||
const mockGenerate = vi.mocked(generateFullArchive)
|
||||
const mockEstimate = vi.mocked(estimateArchiveSize)
|
||||
|
||||
function mockAuth(userId: string | null) {
|
||||
mockCreateClient.mockResolvedValue({
|
||||
auth: {
|
||||
getUser: vi.fn().mockResolvedValue({
|
||||
data: { user: userId ? { id: userId } : null },
|
||||
}),
|
||||
},
|
||||
} as any)
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks()
|
||||
})
|
||||
|
||||
describe('GET /api/reports/full-archive', () => {
|
||||
it('returns 401 when not authenticated', async () => {
|
||||
mockAuth(null)
|
||||
const { status, body } = await parseJsonResponse(
|
||||
await GET(createMockRequest('/api/reports/full-archive'))
|
||||
)
|
||||
expect(status).toBe(401)
|
||||
expect(body).toEqual({ error: 'Unauthorized' })
|
||||
})
|
||||
|
||||
it('returns estimate-only response when ?estimate=1', async () => {
|
||||
mockAuth('user-1')
|
||||
mockEstimate.mockResolvedValue({
|
||||
total_bytes: 10_000_000,
|
||||
document_bytes: 5_000_000,
|
||||
document_count: 7,
|
||||
})
|
||||
|
||||
const { status, body } = await parseJsonResponse<{
|
||||
data: {
|
||||
total_bytes: number
|
||||
size_limit_bytes: number
|
||||
within_limit: boolean
|
||||
}
|
||||
}>(
|
||||
await GET(
|
||||
createMockRequest('/api/reports/full-archive', {
|
||||
searchParams: { estimate: '1', scope: 'all' },
|
||||
})
|
||||
)
|
||||
)
|
||||
|
||||
expect(status).toBe(200)
|
||||
expect(body.data.total_bytes).toBe(10_000_000)
|
||||
expect(body.data.within_limit).toBe(true)
|
||||
expect(mockGenerate).not.toHaveBeenCalled()
|
||||
})
|
||||
|
||||
it('returns 413 archive_too_large when estimate exceeds limit', async () => {
|
||||
mockAuth('user-1')
|
||||
mockEstimate.mockResolvedValue({
|
||||
total_bytes: 200 * 1024 * 1024,
|
||||
document_bytes: 195 * 1024 * 1024,
|
||||
document_count: 200,
|
||||
})
|
||||
|
||||
const response = await GET(
|
||||
createMockRequest('/api/reports/full-archive', {
|
||||
searchParams: { scope: 'all' },
|
||||
})
|
||||
)
|
||||
const { status, body } = await parseJsonResponse<{
|
||||
error: string
|
||||
size_bytes: number
|
||||
size_limit_bytes: number
|
||||
}>(response)
|
||||
|
||||
expect(status).toBe(413)
|
||||
expect(body.error).toBe('archive_too_large')
|
||||
expect(body.size_bytes).toBe(200 * 1024 * 1024)
|
||||
expect(body.size_limit_bytes).toBe(80 * 1024 * 1024)
|
||||
expect(mockGenerate).not.toHaveBeenCalled()
|
||||
})
|
||||
|
||||
it('skips 413 when include_documents=false', async () => {
|
||||
mockAuth('user-1')
|
||||
mockEstimate.mockResolvedValue({
|
||||
total_bytes: 200 * 1024 * 1024,
|
||||
document_bytes: 195 * 1024 * 1024,
|
||||
document_count: 200,
|
||||
})
|
||||
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
|
||||
|
||||
const response = await GET(
|
||||
createMockRequest('/api/reports/full-archive', {
|
||||
searchParams: { scope: 'all', include_documents: 'false' },
|
||||
})
|
||||
)
|
||||
|
||||
expect(response.status).toBe(200)
|
||||
expect(response.headers.get('Content-Type')).toBe('application/zip')
|
||||
expect(mockGenerate).toHaveBeenCalledWith(
|
||||
expect.anything(),
|
||||
'company-1',
|
||||
expect.objectContaining({ scope: 'all', include_documents: false })
|
||||
)
|
||||
})
|
||||
|
||||
it('defaults to scope=all when no params given', async () => {
|
||||
mockAuth('user-1')
|
||||
mockEstimate.mockResolvedValue({
|
||||
total_bytes: 1_000_000,
|
||||
document_bytes: 500_000,
|
||||
document_count: 2,
|
||||
})
|
||||
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
|
||||
|
||||
const response = await GET(createMockRequest('/api/reports/full-archive'))
|
||||
|
||||
expect(response.status).toBe(200)
|
||||
expect(mockGenerate).toHaveBeenCalledWith(
|
||||
expect.anything(),
|
||||
'company-1',
|
||||
expect.objectContaining({ scope: 'all' })
|
||||
)
|
||||
})
|
||||
|
||||
it('uses scope=period when period_id is provided without explicit scope', async () => {
|
||||
mockAuth('user-1')
|
||||
mockEstimate.mockResolvedValue({
|
||||
total_bytes: 1_000_000,
|
||||
document_bytes: 500_000,
|
||||
document_count: 2,
|
||||
})
|
||||
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
|
||||
|
||||
const response = await GET(
|
||||
createMockRequest('/api/reports/full-archive', {
|
||||
searchParams: { period_id: 'period-1' },
|
||||
})
|
||||
)
|
||||
|
||||
expect(response.status).toBe(200)
|
||||
expect(mockGenerate).toHaveBeenCalledWith(
|
||||
expect.anything(),
|
||||
'company-1',
|
||||
expect.objectContaining({ scope: 'period', period_id: 'period-1' })
|
||||
)
|
||||
})
|
||||
|
||||
it('returns 400 when scope=period without period_id', async () => {
|
||||
mockAuth('user-1')
|
||||
const { status, body } = await parseJsonResponse(
|
||||
await GET(
|
||||
createMockRequest('/api/reports/full-archive', {
|
||||
searchParams: { scope: 'period' },
|
||||
})
|
||||
)
|
||||
)
|
||||
expect(status).toBe(400)
|
||||
expect(body).toEqual({ error: 'period_id is required when scope=period' })
|
||||
expect(mockGenerate).not.toHaveBeenCalled()
|
||||
expect(mockEstimate).not.toHaveBeenCalled()
|
||||
})
|
||||
|
||||
it('returns 404 when generate throws "not found"', async () => {
|
||||
mockAuth('user-1')
|
||||
mockEstimate.mockResolvedValue({
|
||||
total_bytes: 1_000_000,
|
||||
document_bytes: 500_000,
|
||||
document_count: 2,
|
||||
})
|
||||
mockGenerate.mockRejectedValue(new Error('Fiscal period not found'))
|
||||
|
||||
const { status, body } = await parseJsonResponse(
|
||||
await GET(
|
||||
createMockRequest('/api/reports/full-archive', {
|
||||
searchParams: { scope: 'period', period_id: 'nope' },
|
||||
})
|
||||
)
|
||||
)
|
||||
expect(status).toBe(404)
|
||||
expect(body).toEqual({ error: 'Fiscal period not found' })
|
||||
})
|
||||
})
|
||||
@@ -1,8 +1,17 @@
|
||||
import { createClient } from '@/lib/supabase/server'
|
||||
import { NextResponse } from 'next/server'
|
||||
import { generateFullArchive } from '@/lib/reports/full-archive-export'
|
||||
import {
|
||||
generateFullArchive,
|
||||
estimateArchiveSize,
|
||||
type ArchiveScope,
|
||||
} from '@/lib/reports/full-archive-export'
|
||||
import { requireCompanyId } from '@/lib/company/context'
|
||||
|
||||
export const runtime = 'nodejs'
|
||||
export const maxDuration = 300
|
||||
|
||||
const SIZE_LIMIT_BYTES = 80 * 1024 * 1024
|
||||
|
||||
export async function GET(request: Request) {
|
||||
const supabase = await createClient()
|
||||
const { data: { user } } = await supabase.auth.getUser()
|
||||
@@ -14,23 +23,69 @@ export async function GET(request: Request) {
|
||||
const companyId = await requireCompanyId(supabase, user.id)
|
||||
|
||||
const { searchParams } = new URL(request.url)
|
||||
const scopeParam = searchParams.get('scope')
|
||||
const periodId = searchParams.get('period_id')
|
||||
const estimateOnly = searchParams.get('estimate') === '1'
|
||||
const includeDocuments = searchParams.get('include_documents') !== 'false'
|
||||
|
||||
if (!periodId) {
|
||||
return NextResponse.json({ error: 'period_id is required' }, { status: 400 })
|
||||
// Backward compat: a bare `period_id` without `scope` is treated as scope=period.
|
||||
const scope: ArchiveScope =
|
||||
scopeParam === 'period' || (!scopeParam && periodId) ? 'period' : 'all'
|
||||
|
||||
if (scope === 'period' && !periodId) {
|
||||
return NextResponse.json(
|
||||
{ error: 'period_id is required when scope=period' },
|
||||
{ status: 400 }
|
||||
)
|
||||
}
|
||||
|
||||
try {
|
||||
const zipBuffer = await generateFullArchive(supabase, companyId, {
|
||||
period_id: periodId,
|
||||
include_documents: searchParams.get('include_documents') !== 'false',
|
||||
})
|
||||
const estimate = await estimateArchiveSize(
|
||||
supabase,
|
||||
companyId,
|
||||
scope,
|
||||
scope === 'period' ? periodId! : undefined
|
||||
)
|
||||
|
||||
if (estimateOnly) {
|
||||
return NextResponse.json({
|
||||
data: {
|
||||
...estimate,
|
||||
size_limit_bytes: SIZE_LIMIT_BYTES,
|
||||
within_limit: estimate.total_bytes <= SIZE_LIMIT_BYTES,
|
||||
},
|
||||
})
|
||||
}
|
||||
|
||||
if (includeDocuments && estimate.total_bytes > SIZE_LIMIT_BYTES) {
|
||||
return NextResponse.json(
|
||||
{
|
||||
error: 'archive_too_large',
|
||||
size_bytes: estimate.total_bytes,
|
||||
size_limit_bytes: SIZE_LIMIT_BYTES,
|
||||
},
|
||||
{ status: 413 }
|
||||
)
|
||||
}
|
||||
|
||||
const zipBuffer = await generateFullArchive(
|
||||
supabase,
|
||||
companyId,
|
||||
scope === 'period'
|
||||
? { scope: 'period', period_id: periodId!, include_documents: includeDocuments }
|
||||
: { scope: 'all', include_documents: includeDocuments }
|
||||
)
|
||||
|
||||
const filename =
|
||||
scope === 'period'
|
||||
? `arkiv_${periodId}.zip`
|
||||
: `arkiv_full_${companyId}_${formatDateStamp(new Date())}.zip`
|
||||
|
||||
return new NextResponse(zipBuffer, {
|
||||
status: 200,
|
||||
headers: {
|
||||
'Content-Type': 'application/zip',
|
||||
'Content-Disposition': `attachment; filename="arkiv_${periodId}.zip"`,
|
||||
'Content-Disposition': `attachment; filename="${filename}"`,
|
||||
},
|
||||
})
|
||||
} catch (err) {
|
||||
@@ -39,3 +94,10 @@ export async function GET(request: Request) {
|
||||
return NextResponse.json({ error: message }, { status })
|
||||
}
|
||||
}
|
||||
|
||||
function formatDateStamp(d: Date): string {
|
||||
const y = d.getUTCFullYear()
|
||||
const m = String(d.getUTCMonth() + 1).padStart(2, '0')
|
||||
const day = String(d.getUTCDate()).padStart(2, '0')
|
||||
return `${y}${m}${day}`
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user