Feat/cloud backup (#277)

* feat: cloud backup to Google Drive + full-archive all-scope

Adds a cloud-backup extension that uploads a full-company backup ZIP to
the user's own Google Drive via OAuth (drive.file scope only). Refresh
tokens are AES-256-GCM encrypted before being stored in extension_data.

The full-archive export gains a scope=all mode for whole-company
backups (per-period SIE under sie/, per-period rapporter/ subfolders,
flat dokument/ manifest tagged with fiscal_period_id). An 80 MB size
guard short-circuits generation before the platform response limit.

Also fixes a latent bug in lib/core/audit/audit-service.ts where the
parameter was named userId while the query filtered by company_id; the
audit-trail API route was passing user.id so audit queries returned
empty unless user and company shared a UUID.

Drive-by: scope the dashboard "fresh start" localStorage key per
companyId so dismissing the setup checklist in one company no longer
carries over to others.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: address review comments on cloud backup + archive export

- Extend audit trail to_date to end-of-day so last-day entries aren't
  silently excluded from period-scoped archives.
- Apply 413 size-limit guard regardless of include_documents, using the
  overhead-only figure when documents are excluded.
- Use crypto.randomUUID() for Drive multipart boundary to eliminate any
  collision risk with ZIP payload bytes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: migrate legacy setup-gate localStorage keys on dashboard

Users who previously dismissed the setup checklist via the old global
erp_setup_fresh_start or erp_checklist_dismissed keys were re-gated after
the switch to a company-scoped key. Fall back to the legacy keys on read
and migrate them to the scoped key on first hit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: update customer email handling and anonymization rules in supportmail-to-ticket skill

* test: update audit trail to_date expectation for end-of-day timestamp

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-04-20 10:49:59 +02:00
committed by GitHub
co-authored by Claude Opus 4.7
parent 2ea5a72b3d
commit d708a85d4c
34 changed files with 2900 additions and 314 deletions
+2 -2
View File
@@ -63,7 +63,7 @@ describe('GET /api/audit-trail', () => {
expect(body.count).toBe(2)
expect(mockGetAuditLog).toHaveBeenCalledWith(
expect.anything(),
'user-1',
'company-1',
expect.objectContaining({})
)
})
@@ -88,7 +88,7 @@ describe('GET /api/audit-trail', () => {
expect(mockGetAuditLog).toHaveBeenCalledWith(
expect.anything(),
'user-1',
'company-1',
{
action: 'INSERT',
table_name: 'journal_entries',
+1 -1
View File
@@ -27,7 +27,7 @@ export async function GET(request: Request) {
}
try {
const result = await getAuditLog(supabase, user.id, filters)
const result = await getAuditLog(supabase, companyId, filters)
return NextResponse.json({ data: result.data, count: result.count })
} catch (err) {
return NextResponse.json(
@@ -0,0 +1,208 @@
/* eslint-disable @typescript-eslint/no-explicit-any */
import { describe, it, expect, vi, beforeEach } from 'vitest'
import { createMockRequest, parseJsonResponse } from '@/tests/helpers'
vi.mock('@/lib/supabase/server', () => ({
createClient: vi.fn(),
}))
vi.mock('@/lib/company/context', () => ({
requireCompanyId: vi.fn().mockResolvedValue('company-1'),
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
}))
vi.mock('@/lib/reports/full-archive-export', () => ({
generateFullArchive: vi.fn(),
estimateArchiveSize: vi.fn(),
}))
import { createClient } from '@/lib/supabase/server'
import {
generateFullArchive,
estimateArchiveSize,
} from '@/lib/reports/full-archive-export'
import { GET } from '../route'
const mockCreateClient = vi.mocked(createClient)
const mockGenerate = vi.mocked(generateFullArchive)
const mockEstimate = vi.mocked(estimateArchiveSize)
function mockAuth(userId: string | null) {
mockCreateClient.mockResolvedValue({
auth: {
getUser: vi.fn().mockResolvedValue({
data: { user: userId ? { id: userId } : null },
}),
},
} as any)
}
beforeEach(() => {
vi.clearAllMocks()
})
describe('GET /api/reports/full-archive', () => {
it('returns 401 when not authenticated', async () => {
mockAuth(null)
const { status, body } = await parseJsonResponse(
await GET(createMockRequest('/api/reports/full-archive'))
)
expect(status).toBe(401)
expect(body).toEqual({ error: 'Unauthorized' })
})
it('returns estimate-only response when ?estimate=1', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 10_000_000,
document_bytes: 5_000_000,
document_count: 7,
})
const { status, body } = await parseJsonResponse<{
data: {
total_bytes: number
size_limit_bytes: number
within_limit: boolean
}
}>(
await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { estimate: '1', scope: 'all' },
})
)
)
expect(status).toBe(200)
expect(body.data.total_bytes).toBe(10_000_000)
expect(body.data.within_limit).toBe(true)
expect(mockGenerate).not.toHaveBeenCalled()
})
it('returns 413 archive_too_large when estimate exceeds limit', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 200 * 1024 * 1024,
document_bytes: 195 * 1024 * 1024,
document_count: 200,
})
const response = await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { scope: 'all' },
})
)
const { status, body } = await parseJsonResponse<{
error: string
size_bytes: number
size_limit_bytes: number
}>(response)
expect(status).toBe(413)
expect(body.error).toBe('archive_too_large')
expect(body.size_bytes).toBe(200 * 1024 * 1024)
expect(body.size_limit_bytes).toBe(80 * 1024 * 1024)
expect(mockGenerate).not.toHaveBeenCalled()
})
it('skips 413 when include_documents=false', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 200 * 1024 * 1024,
document_bytes: 195 * 1024 * 1024,
document_count: 200,
})
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
const response = await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { scope: 'all', include_documents: 'false' },
})
)
expect(response.status).toBe(200)
expect(response.headers.get('Content-Type')).toBe('application/zip')
expect(mockGenerate).toHaveBeenCalledWith(
expect.anything(),
'company-1',
expect.objectContaining({ scope: 'all', include_documents: false })
)
})
it('defaults to scope=all when no params given', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 1_000_000,
document_bytes: 500_000,
document_count: 2,
})
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
const response = await GET(createMockRequest('/api/reports/full-archive'))
expect(response.status).toBe(200)
expect(mockGenerate).toHaveBeenCalledWith(
expect.anything(),
'company-1',
expect.objectContaining({ scope: 'all' })
)
})
it('uses scope=period when period_id is provided without explicit scope', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 1_000_000,
document_bytes: 500_000,
document_count: 2,
})
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
const response = await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { period_id: 'period-1' },
})
)
expect(response.status).toBe(200)
expect(mockGenerate).toHaveBeenCalledWith(
expect.anything(),
'company-1',
expect.objectContaining({ scope: 'period', period_id: 'period-1' })
)
})
it('returns 400 when scope=period without period_id', async () => {
mockAuth('user-1')
const { status, body } = await parseJsonResponse(
await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { scope: 'period' },
})
)
)
expect(status).toBe(400)
expect(body).toEqual({ error: 'period_id is required when scope=period' })
expect(mockGenerate).not.toHaveBeenCalled()
expect(mockEstimate).not.toHaveBeenCalled()
})
it('returns 404 when generate throws "not found"', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 1_000_000,
document_bytes: 500_000,
document_count: 2,
})
mockGenerate.mockRejectedValue(new Error('Fiscal period not found'))
const { status, body } = await parseJsonResponse(
await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { scope: 'period', period_id: 'nope' },
})
)
)
expect(status).toBe(404)
expect(body).toEqual({ error: 'Fiscal period not found' })
})
})
+70 -8
View File
@@ -1,8 +1,17 @@
import { createClient } from '@/lib/supabase/server'
import { NextResponse } from 'next/server'
import { generateFullArchive } from '@/lib/reports/full-archive-export'
import {
generateFullArchive,
estimateArchiveSize,
type ArchiveScope,
} from '@/lib/reports/full-archive-export'
import { requireCompanyId } from '@/lib/company/context'
export const runtime = 'nodejs'
export const maxDuration = 300
const SIZE_LIMIT_BYTES = 80 * 1024 * 1024
export async function GET(request: Request) {
const supabase = await createClient()
const { data: { user } } = await supabase.auth.getUser()
@@ -14,23 +23,69 @@ export async function GET(request: Request) {
const companyId = await requireCompanyId(supabase, user.id)
const { searchParams } = new URL(request.url)
const scopeParam = searchParams.get('scope')
const periodId = searchParams.get('period_id')
const estimateOnly = searchParams.get('estimate') === '1'
const includeDocuments = searchParams.get('include_documents') !== 'false'
if (!periodId) {
return NextResponse.json({ error: 'period_id is required' }, { status: 400 })
// Backward compat: a bare `period_id` without `scope` is treated as scope=period.
const scope: ArchiveScope =
scopeParam === 'period' || (!scopeParam && periodId) ? 'period' : 'all'
if (scope === 'period' && !periodId) {
return NextResponse.json(
{ error: 'period_id is required when scope=period' },
{ status: 400 }
)
}
try {
const zipBuffer = await generateFullArchive(supabase, companyId, {
period_id: periodId,
include_documents: searchParams.get('include_documents') !== 'false',
})
const estimate = await estimateArchiveSize(
supabase,
companyId,
scope,
scope === 'period' ? periodId! : undefined
)
if (estimateOnly) {
return NextResponse.json({
data: {
...estimate,
size_limit_bytes: SIZE_LIMIT_BYTES,
within_limit: estimate.total_bytes <= SIZE_LIMIT_BYTES,
},
})
}
if (includeDocuments && estimate.total_bytes > SIZE_LIMIT_BYTES) {
return NextResponse.json(
{
error: 'archive_too_large',
size_bytes: estimate.total_bytes,
size_limit_bytes: SIZE_LIMIT_BYTES,
},
{ status: 413 }
)
}
const zipBuffer = await generateFullArchive(
supabase,
companyId,
scope === 'period'
? { scope: 'period', period_id: periodId!, include_documents: includeDocuments }
: { scope: 'all', include_documents: includeDocuments }
)
const filename =
scope === 'period'
? `arkiv_${periodId}.zip`
: `arkiv_full_${companyId}_${formatDateStamp(new Date())}.zip`
return new NextResponse(zipBuffer, {
status: 200,
headers: {
'Content-Type': 'application/zip',
'Content-Disposition': `attachment; filename="arkiv_${periodId}.zip"`,
'Content-Disposition': `attachment; filename="${filename}"`,
},
})
} catch (err) {
@@ -39,3 +94,10 @@ export async function GET(request: Request) {
return NextResponse.json({ error: message }, { status })
}
}
function formatDateStamp(d: Date): string {
const y = d.getUTCFullYear()
const m = String(d.getUTCMonth() + 1).padStart(2, '0')
const day = String(d.getUTCDate()).padStart(2, '0')
return `${y}${m}${day}`
}