fix: hide API-archived customers and suppliers from lists and pickers (#1927)
* fix: hide API-archived customers and suppliers from lists and pickers The v1 API soft-archives customers and suppliers (archived_at, plus is_active=false on suppliers) and its own list routes hide those rows behind ?include_archived=true. No other surface filtered archived_at, so an archived counterparty stayed a normal row in the dashboard rosters, the internal /api/customers and /api/suppliers list routes, the MCP list tools and every customer/supplier picker. Apply the same canonical `archived_at IS NULL` filter on every non-v1 list and picker path: - /api/customers GET, /api/suppliers GET (feeds the customers page and the supplier-invoice form) - suppliers dashboard page (reads suppliers via browser Supabase) - InvoiceEditor and NewRecurringScheduleDialog customer pickers; an invoice or schedule being edited keeps its current customer visible (archiving does not refuse on drafts, so a draft can point at one) - deadlines page and CalendarWorkspace customer pickers - InvoicePreviewCard sample customer - gnubok_list_customers and gnubok_list_suppliers: hidden by default, optional include_archived boolean mirroring the v1 flag; rows now carry archived_at so an agent can tell them apart when opted in Detail routes and by-id lookups are untouched: an archived row still opens. The delete-vs-archive semantics are unchanged. The tools/list payload guard moves 60.7K to 60.8K: main had ~6 tokens of headroom, so even the bare boolean contract crossed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(schema): raise the unresolvable-expression ceiling by 2 for the archived-customer picker filters The two .or('archived_at.is.null,id.eq.<uuid>') filters keep an edited draft's archived customer selectable. The uuid is a runtime value, so the scanner cannot resolve the expression; both columns exist and the filter is covered by the archived-counterparty tests. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
Jakob Wennberg
parent
1185ab4294
commit
f338850bd0
@@ -0,0 +1,66 @@
|
||||
/**
|
||||
* GET /api/customers: the roster hides customers archived through the v1 API
|
||||
* (archived_at set). Archived rows stay in the table for BFL retention, so the
|
||||
* filter is the only thing keeping them out of the dashboard list.
|
||||
*/
|
||||
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
||||
import {
|
||||
createMockRequest,
|
||||
parseJsonResponse,
|
||||
createQueuedMockSupabase,
|
||||
makeCustomer,
|
||||
} from '@/tests/helpers'
|
||||
import { eventBus } from '@/lib/events'
|
||||
|
||||
const { supabase: mockSupabase, enqueue, reset, findCall } = createQueuedMockSupabase()
|
||||
vi.mock('@/lib/supabase/server', () => ({
|
||||
createClient: () => Promise.resolve(mockSupabase),
|
||||
}))
|
||||
|
||||
vi.mock('@/lib/init', () => ({
|
||||
ensureInitialized: vi.fn(),
|
||||
}))
|
||||
|
||||
vi.mock('@/lib/company/context', () => ({
|
||||
requireCompanyId: vi.fn().mockResolvedValue('company-1'),
|
||||
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
|
||||
}))
|
||||
|
||||
vi.mock('@/lib/auth/require-write', () => ({
|
||||
requireWritePermission: vi.fn().mockResolvedValue({ ok: true }),
|
||||
}))
|
||||
|
||||
import { GET } from '../route'
|
||||
|
||||
describe('GET /api/customers: archived rows', () => {
|
||||
const mockUser = { id: 'user-1', email: 'test@test.se' }
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks()
|
||||
reset()
|
||||
eventBus.clear()
|
||||
mockSupabase.auth.getUser.mockResolvedValue({ data: { user: mockUser } })
|
||||
})
|
||||
|
||||
it('returns 401 when not authenticated', async () => {
|
||||
mockSupabase.auth.getUser.mockResolvedValue({ data: { user: null } })
|
||||
|
||||
const response = await GET(createMockRequest('/api/customers'), { params: Promise.resolve({}) })
|
||||
const { status } = await parseJsonResponse(response)
|
||||
|
||||
expect(status).toBe(401)
|
||||
})
|
||||
|
||||
it('filters on archived_at IS NULL and still returns the active roster', async () => {
|
||||
const customers = [makeCustomer({ name: 'Beta AB' }), makeCustomer({ name: 'Alfa AB' })]
|
||||
enqueue({ data: customers, error: null })
|
||||
|
||||
const response = await GET(createMockRequest('/api/customers'), { params: Promise.resolve({}) })
|
||||
const { status, body } = await parseJsonResponse<{ data: Array<{ name: string }> }>(response)
|
||||
|
||||
expect(status).toBe(200)
|
||||
expect(body.data.map((c) => c.name)).toEqual(['Alfa AB', 'Beta AB'])
|
||||
expect(findCall('customers', 'eq')).toEqual(['company_id', 'company-1'])
|
||||
expect(findCall('customers', 'is')).toEqual(['archived_at', null])
|
||||
})
|
||||
})
|
||||
@@ -23,6 +23,10 @@ export const GET = withRouteContext(
|
||||
// hand the roster page a silently truncated customer list. Ordered on the
|
||||
// PK because paging is only stable under a unique total order; the
|
||||
// name sort callers expect is re-applied below.
|
||||
//
|
||||
// Archived rows (soft-deleted via the v1 API) stay in the table for BFL
|
||||
// retention but are not part of the roster: same canonical
|
||||
// `archived_at IS NULL` filter as the v1 list route.
|
||||
let rows: Customer[]
|
||||
try {
|
||||
rows = await fetchAllRows<Customer>(
|
||||
@@ -31,6 +35,7 @@ export const GET = withRouteContext(
|
||||
.from('customers')
|
||||
.select('*')
|
||||
.eq('company_id', companyId)
|
||||
.is('archived_at', null)
|
||||
.order('id', { ascending: true })
|
||||
.range(from, to),
|
||||
{ dedupeBy: (row) => row.id },
|
||||
|
||||
@@ -0,0 +1,84 @@
|
||||
/**
|
||||
* GET /api/suppliers: the roster hides suppliers archived through the v1 API
|
||||
* (archived_at set, is_active=false). Archived rows stay in the table for BFL
|
||||
* retention, so the filter is the only thing keeping them out of the list and
|
||||
* the supplier-invoice picker that reads this route.
|
||||
*/
|
||||
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
||||
import {
|
||||
createMockRequest,
|
||||
parseJsonResponse,
|
||||
createQueuedMockSupabase,
|
||||
makeSupplier,
|
||||
} from '@/tests/helpers'
|
||||
import { eventBus } from '@/lib/events'
|
||||
|
||||
const { supabase: mockSupabase, enqueue, reset, findCall } = createQueuedMockSupabase()
|
||||
vi.mock('@/lib/supabase/server', () => ({
|
||||
createClient: () => Promise.resolve(mockSupabase),
|
||||
}))
|
||||
|
||||
vi.mock('@/lib/init', () => ({
|
||||
ensureInitialized: vi.fn(),
|
||||
}))
|
||||
|
||||
vi.mock('@/lib/company/context', () => ({
|
||||
requireCompanyId: vi.fn().mockResolvedValue('company-1'),
|
||||
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
|
||||
}))
|
||||
|
||||
vi.mock('@/lib/auth/require-write', () => ({
|
||||
requireWritePermission: vi.fn().mockResolvedValue({ ok: true }),
|
||||
}))
|
||||
|
||||
import { GET } from '../route'
|
||||
|
||||
describe('GET /api/suppliers', () => {
|
||||
const mockUser = { id: 'user-1', email: 'test@test.se' }
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks()
|
||||
reset()
|
||||
eventBus.clear()
|
||||
mockSupabase.auth.getUser.mockResolvedValue({ data: { user: mockUser } })
|
||||
})
|
||||
|
||||
it('returns 401 when not authenticated', async () => {
|
||||
mockSupabase.auth.getUser.mockResolvedValue({ data: { user: null } })
|
||||
|
||||
const response = await GET(createMockRequest('/api/suppliers'), { params: Promise.resolve({}) })
|
||||
const { status } = await parseJsonResponse(response)
|
||||
|
||||
expect(status).toBe(401)
|
||||
})
|
||||
|
||||
it('lists suppliers for the active company', async () => {
|
||||
const suppliers = [makeSupplier({ name: 'Alfa AB' }), makeSupplier({ name: 'Beta AB' })]
|
||||
enqueue({ data: suppliers, error: null })
|
||||
|
||||
const response = await GET(createMockRequest('/api/suppliers'), { params: Promise.resolve({}) })
|
||||
const { status, body } = await parseJsonResponse<{ data: unknown[] }>(response)
|
||||
|
||||
expect(status).toBe(200)
|
||||
expect(body.data).toEqual(suppliers)
|
||||
expect(findCall('suppliers', 'eq')).toEqual(['company_id', 'company-1'])
|
||||
})
|
||||
|
||||
it('hides API-archived suppliers: filters on archived_at IS NULL', async () => {
|
||||
enqueue({ data: [], error: null })
|
||||
|
||||
await GET(createMockRequest('/api/suppliers'), { params: Promise.resolve({}) })
|
||||
|
||||
expect(findCall('suppliers', 'is')).toEqual(['archived_at', null])
|
||||
})
|
||||
|
||||
it('returns the error envelope when the query fails', async () => {
|
||||
enqueue({ data: null, error: { message: 'boom', code: '42P01' } })
|
||||
|
||||
const response = await GET(createMockRequest('/api/suppliers'), { params: Promise.resolve({}) })
|
||||
const { status, body } = await parseJsonResponse<{ error: unknown }>(response)
|
||||
|
||||
expect(status).toBeGreaterThanOrEqual(400)
|
||||
expect(body.error).toBeDefined()
|
||||
})
|
||||
})
|
||||
@@ -15,10 +15,14 @@ export const GET = withRouteContext(
|
||||
async (_request, ctx) => {
|
||||
const { supabase, companyId, log, requestId } = ctx
|
||||
|
||||
// Archived rows (soft-deleted via the v1 API: archived_at + is_active=false)
|
||||
// stay in the table for BFL retention but are not part of the roster.
|
||||
// Same canonical "active" filter as the v1 list route.
|
||||
const { data, error } = await supabase
|
||||
.from('suppliers')
|
||||
.select('*')
|
||||
.eq('company_id', companyId)
|
||||
.is('archived_at', null)
|
||||
.order('name', { ascending: true })
|
||||
|
||||
if (error) {
|
||||
|
||||
Reference in New Issue
Block a user