feat(categorize): Tier 1 candidate gathering + the proposal route (#1781)
The auto-booking cascade end to end (retrieval → selector), minus the write. - lib/agent/categorize/candidates.ts (Tier 1): assembles the deterministic candidate slate for a transaction — the learned counterparty template (strongest, carries its own VAT) plus mapping rules / patterns / per-merchant history via the same engine gnubok_suggest_categories uses. No model call. Deduped by account (highest confidence wins), capped; suggestions get the category's default VAT treatment derived. - POST /api/agent/categorize: loads the transaction + company VAT context, runs Tier 1 → Tier 2 selectAccount, returns the proposed account + VAT + confidence + reasoning + the candidate slate. Never posts anything — the caller renders an approval card. Gated on configured (any provider incl. local), same gates as /api/agent/ask. 12 tests: candidate merge/dedupe/VAT-derivation, and the route (401/429/400/ 403/404/503 + happy path threading entity type, VAT, underlag, samples). Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Jakob Wennberg
Claude Opus 4.8
parent
b17878e58f
commit
e7a5e65ecf
@@ -0,0 +1,109 @@
|
||||
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
||||
import { NextResponse } from 'next/server'
|
||||
import { createMockRequest, parseJsonResponse } from '@/tests/helpers'
|
||||
|
||||
const requireAuthMock = vi.fn()
|
||||
vi.mock('@/lib/auth/require-auth', () => ({ requireAuth: () => requireAuthMock() }))
|
||||
vi.mock('@/lib/company/context', () => ({ getActiveCompanyId: vi.fn().mockResolvedValue('company-1') }))
|
||||
const checkRate = vi.fn()
|
||||
vi.mock('@/lib/rate-limits/agent', () => ({
|
||||
checkAgentRateLimit: () => checkRate(),
|
||||
agentRateLimitResponseBody: () => ({ error: 'rate' }),
|
||||
}))
|
||||
vi.mock('@/lib/sandbox/guard', () => ({ guardSandbox: vi.fn().mockResolvedValue(null) }))
|
||||
const requireCapability = vi.fn()
|
||||
vi.mock('@/lib/entitlements/has-capability', () => ({ requireCapability: () => requireCapability() }))
|
||||
vi.mock('@/lib/entitlements/keys', () => ({ CAPABILITY: { ai: 'ai' } }))
|
||||
const aiStatus = vi.fn()
|
||||
vi.mock('@/lib/ai', () => ({ getAiStatus: () => aiStatus() }))
|
||||
const gatherCandidates = vi.fn()
|
||||
vi.mock('@/lib/agent/categorize/candidates', () => ({ gatherCandidates: (...a: unknown[]) => gatherCandidates(...a) }))
|
||||
const selectAccount = vi.fn()
|
||||
vi.mock('@/lib/agent/categorize/select-account', () => ({ selectAccount: (...a: unknown[]) => selectAccount(...a) }))
|
||||
|
||||
import { POST } from '../route'
|
||||
|
||||
// supabase router: membership + transactions + companies + company_settings.
|
||||
function makeSupabase(opts: { tx?: unknown } = {}) {
|
||||
return {
|
||||
from(table: string) {
|
||||
const rows: Record<string, unknown> = {
|
||||
company_members: { user_id: 'user-1' },
|
||||
transactions: opts.tx === undefined ? { id: 'tx-1' } : opts.tx,
|
||||
companies: { entity_type: 'aktiebolag' },
|
||||
company_settings: { vat_registered: true },
|
||||
}
|
||||
const chain = {
|
||||
select: () => chain,
|
||||
eq: () => chain,
|
||||
maybeSingle: async () => ({ data: rows[table] ?? null }),
|
||||
}
|
||||
return chain
|
||||
},
|
||||
}
|
||||
}
|
||||
const supabase = makeSupabase()
|
||||
|
||||
const VALID_TX = '11111111-1111-4111-8111-111111111111'
|
||||
const body = (o: Record<string, unknown> = {}) => ({ transaction_id: VALID_TX, ...o })
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks()
|
||||
requireAuthMock.mockResolvedValue({ user: { id: 'user-1' }, supabase, error: null })
|
||||
checkRate.mockResolvedValue({ ok: true })
|
||||
requireCapability.mockResolvedValue(null)
|
||||
aiStatus.mockReturnValue({ configured: true })
|
||||
gatherCandidates.mockResolvedValue([{ account: '5410', label: 'Material', vatTreatment: 'standard_25', source: 'counterparty_template', confidence: 0.9 }])
|
||||
selectAccount.mockResolvedValue({
|
||||
account: '5410', category: null, vatTreatment: 'standard_25', reverseCharge: false,
|
||||
confidence: 0.86, modelConfidence: 'high', agreement: 1, reasoning: 'r',
|
||||
choice: { kind: 'candidate', account: '5410' }, model: 'qwen3.8', fromCandidate: true,
|
||||
})
|
||||
})
|
||||
|
||||
describe('POST /api/agent/categorize', () => {
|
||||
it('401 when unauthenticated', async () => {
|
||||
requireAuthMock.mockResolvedValue({ user: null, supabase, error: NextResponse.json({ error: 'x' }, { status: 401 }) })
|
||||
expect((await POST(createMockRequest('/x', { method: 'POST', body: body() }))).status).toBe(401)
|
||||
})
|
||||
it('429 when rate limited', async () => {
|
||||
checkRate.mockResolvedValue({ ok: false })
|
||||
expect((await POST(createMockRequest('/x', { method: 'POST', body: body() }))).status).toBe(429)
|
||||
})
|
||||
it('400 on a missing/invalid transaction_id', async () => {
|
||||
expect((await POST(createMockRequest('/x', { method: 'POST', body: {} }))).status).toBe(400)
|
||||
expect((await POST(createMockRequest('/x', { method: 'POST', body: { transaction_id: 'nope' } }))).status).toBe(400)
|
||||
})
|
||||
it('403 without the ai capability', async () => {
|
||||
requireCapability.mockResolvedValue(NextResponse.json({ error: 'pay' }, { status: 403 }))
|
||||
expect((await POST(createMockRequest('/x', { method: 'POST', body: body() }))).status).toBe(403)
|
||||
})
|
||||
it('503 when no backend is configured', async () => {
|
||||
aiStatus.mockReturnValue({ configured: false })
|
||||
const res = await POST(createMockRequest('/x', { method: 'POST', body: body() }))
|
||||
const { status, body: b } = await parseJsonResponse<{ code: string }>(res)
|
||||
expect(status).toBe(503)
|
||||
expect(b.code).toBe('ai_unconfigured')
|
||||
expect(selectAccount).not.toHaveBeenCalled()
|
||||
})
|
||||
it('404 when the transaction is not found / not this company', async () => {
|
||||
requireAuthMock.mockResolvedValue({ user: { id: 'user-1' }, supabase: makeSupabase({ tx: null }), error: null })
|
||||
const res = await POST(createMockRequest('/x', { method: 'POST', body: body() }))
|
||||
expect(res.status).toBe(404)
|
||||
expect(selectAccount).not.toHaveBeenCalled()
|
||||
})
|
||||
it('returns the selection + candidate slate on the happy path', async () => {
|
||||
const res = await POST(createMockRequest('/x', { method: 'POST', body: body({ samples: 3, underlag: 'Biltema AB 499 kr' }) }))
|
||||
const { status, body: b } = await parseJsonResponse<{
|
||||
data: { account: string; confidence: number; candidates: { account: string }[] }
|
||||
}>(res)
|
||||
expect(status).toBe(200)
|
||||
expect(b.data.account).toBe('5410')
|
||||
expect(b.data.confidence).toBe(0.86)
|
||||
expect(b.data.candidates[0].account).toBe('5410')
|
||||
// entity type + vat_registered threaded from the company rows; underlag + samples passed through
|
||||
expect(selectAccount).toHaveBeenCalledWith(
|
||||
expect.objectContaining({ entityType: 'aktiebolag', vatRegistered: true, underlag: 'Biltema AB 499 kr', samples: 3 }),
|
||||
)
|
||||
})
|
||||
})
|
||||
@@ -0,0 +1,114 @@
|
||||
import { NextResponse } from 'next/server'
|
||||
import { z } from 'zod'
|
||||
import { requireAuth } from '@/lib/auth/require-auth'
|
||||
import { getActiveCompanyId } from '@/lib/company/context'
|
||||
import { checkAgentRateLimit, agentRateLimitResponseBody } from '@/lib/rate-limits/agent'
|
||||
import { guardSandbox } from '@/lib/sandbox/guard'
|
||||
import { requireCapability } from '@/lib/entitlements/has-capability'
|
||||
import { CAPABILITY } from '@/lib/entitlements/keys'
|
||||
import { getAiStatus } from '@/lib/ai'
|
||||
import { gatherCandidates } from '@/lib/agent/categorize/candidates'
|
||||
import { selectAccount } from '@/lib/agent/categorize/select-account'
|
||||
import { getErrorMessage as getUserErrorMessage } from '@/lib/errors/get-error-message'
|
||||
import type { EntityType, Transaction } from '@/types'
|
||||
|
||||
/**
|
||||
* POST /api/agent/categorize: a provider-agnostic booking proposal for one
|
||||
* transaction — the auto-booking cascade end to end (Tier 1 retrieval → Tier 2
|
||||
* selector), minus the write.
|
||||
*
|
||||
* It gathers the deterministic candidate accounts (counterparty templates,
|
||||
* rules, history) with NO model call, then has the model SELECT among them
|
||||
* (self-consistency sampled), and returns the proposed account + VAT +
|
||||
* confidence + reasoning + the candidate slate. It never posts anything: the
|
||||
* caller (the transaction row) renders the proposal as an approval card.
|
||||
*
|
||||
* Runs on any configured backend (Bedrock or a local model), so it is gated on
|
||||
* `configured`, not `assistantAvailable` — same as /api/agent/ask.
|
||||
*/
|
||||
|
||||
const Schema = z.object({
|
||||
transaction_id: z.string().uuid(),
|
||||
company_id: z.string().uuid().optional(),
|
||||
/** Extracted receipt/invoice text, if the caller already has it. */
|
||||
underlag: z.string().max(24_000).optional(),
|
||||
/** Self-consistency samples (default 3). */
|
||||
samples: z.number().int().min(1).max(5).optional(),
|
||||
})
|
||||
|
||||
export async function POST(request: Request): Promise<Response> {
|
||||
const { user, supabase, error } = await requireAuth()
|
||||
if (error) return error
|
||||
|
||||
const rate = await checkAgentRateLimit(supabase, user.id)
|
||||
if (!rate.ok) return NextResponse.json(agentRateLimitResponseBody(rate), { status: 429 })
|
||||
|
||||
let body: unknown
|
||||
try {
|
||||
body = await request.json()
|
||||
} catch {
|
||||
return NextResponse.json({ error: 'Invalid JSON' }, { status: 400 })
|
||||
}
|
||||
const parsed = Schema.safeParse(body)
|
||||
if (!parsed.success) {
|
||||
return NextResponse.json({ error: 'Ogiltig förfrågan.', type: 'validation_error' }, { status: 400 })
|
||||
}
|
||||
|
||||
const companyId = parsed.data.company_id ?? (await getActiveCompanyId(supabase, user.id))
|
||||
if (!companyId) return NextResponse.json({ error: 'No active company' }, { status: 400 })
|
||||
|
||||
const { data: membership } = await supabase
|
||||
.from('company_members')
|
||||
.select('user_id')
|
||||
.eq('company_id', companyId)
|
||||
.eq('user_id', user.id)
|
||||
.maybeSingle()
|
||||
if (!membership) return NextResponse.json({ error: 'Forbidden' }, { status: 403 })
|
||||
|
||||
const blocked = await guardSandbox(supabase, companyId)
|
||||
if (blocked) return blocked
|
||||
|
||||
const capBlocked = await requireCapability(supabase, companyId, CAPABILITY.ai)
|
||||
if (capBlocked) return capBlocked
|
||||
|
||||
if (!getAiStatus().configured) {
|
||||
return NextResponse.json(
|
||||
{ error: 'Assistenten är inte konfigurerad på den här installationen.', code: 'ai_unconfigured' },
|
||||
{ status: 503 },
|
||||
)
|
||||
}
|
||||
|
||||
const { data: tx } = await supabase
|
||||
.from('transactions')
|
||||
.select('id, merchant_name, description, original_description, amount, date, currency, category, is_business')
|
||||
.eq('id', parsed.data.transaction_id)
|
||||
.eq('company_id', companyId)
|
||||
.maybeSingle()
|
||||
if (!tx) return NextResponse.json({ error: 'Transaktionen hittades inte.' }, { status: 404 })
|
||||
|
||||
const [{ data: company }, { data: settings }] = await Promise.all([
|
||||
supabase.from('companies').select('entity_type').eq('id', companyId).maybeSingle(),
|
||||
supabase.from('company_settings').select('vat_registered').eq('company_id', companyId).maybeSingle(),
|
||||
])
|
||||
|
||||
try {
|
||||
const candidates = await gatherCandidates(supabase, companyId, tx as Transaction)
|
||||
const selection = await selectAccount({
|
||||
transaction: {
|
||||
merchantName: (tx as Transaction).merchant_name,
|
||||
description: (tx as Transaction).description,
|
||||
amount: (tx as Transaction).amount,
|
||||
date: (tx as Transaction).date,
|
||||
currency: (tx as Transaction).currency,
|
||||
},
|
||||
underlag: parsed.data.underlag,
|
||||
candidates,
|
||||
entityType: ((company?.entity_type as EntityType | undefined) ?? 'enskild_firma'),
|
||||
vatRegistered: settings?.vat_registered ?? false,
|
||||
samples: parsed.data.samples,
|
||||
})
|
||||
return NextResponse.json({ data: { ...selection, candidates } })
|
||||
} catch (err) {
|
||||
return NextResponse.json({ error: getUserErrorMessage(err) }, { status: 500 })
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user