fix: hide API-archived customers and suppliers from lists and pickers (#1927)

* fix: hide API-archived customers and suppliers from lists and pickers

The v1 API soft-archives customers and suppliers (archived_at, plus
is_active=false on suppliers) and its own list routes hide those rows
behind ?include_archived=true. No other surface filtered archived_at, so
an archived counterparty stayed a normal row in the dashboard rosters,
the internal /api/customers and /api/suppliers list routes, the MCP list
tools and every customer/supplier picker.

Apply the same canonical `archived_at IS NULL` filter on every non-v1
list and picker path:

- /api/customers GET, /api/suppliers GET (feeds the customers page and
  the supplier-invoice form)
- suppliers dashboard page (reads suppliers via browser Supabase)
- InvoiceEditor and NewRecurringScheduleDialog customer pickers; an
  invoice or schedule being edited keeps its current customer visible
  (archiving does not refuse on drafts, so a draft can point at one)
- deadlines page and CalendarWorkspace customer pickers
- InvoicePreviewCard sample customer
- gnubok_list_customers and gnubok_list_suppliers: hidden by default,
  optional include_archived boolean mirroring the v1 flag; rows now
  carry archived_at so an agent can tell them apart when opted in

Detail routes and by-id lookups are untouched: an archived row still
opens. The delete-vs-archive semantics are unchanged.

The tools/list payload guard moves 60.7K to 60.8K: main had ~6 tokens
of headroom, so even the bare boolean contract crossed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(schema): raise the unresolvable-expression ceiling by 2 for the archived-customer picker filters

The two .or('archived_at.is.null,id.eq.<uuid>') filters keep an edited
draft's archived customer selectable. The uuid is a runtime value, so the
scanner cannot resolve the expression; both columns exist and the filter is
covered by the archived-counterparty tests.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-08-26 13:35:27 +02:00
committed by GitHub
co-authored by Claude Fable 5 Jakob Wennberg
parent 1185ab4294
commit f338850bd0
14 changed files with 273 additions and 27 deletions
@@ -0,0 +1,51 @@
/**
* gnubok_list_customers / gnubok_list_suppliers: rows archived through the v1
* API (archived_at set) are hidden by default and only returned when the
* caller passes include_archived=true, mirroring the v1 list routes.
*/
import { describe, expect, it } from 'vitest'
import { createQueuedMockSupabase } from '@/tests/helpers'
import { tools } from '../server'
const listCustomers = () => tools.find((t) => t.name === 'gnubok_list_customers')!
const listSuppliers = () => tools.find((t) => t.name === 'gnubok_list_suppliers')!
describe('archived counterparties are hidden from the MCP list tools by default', () => {
it('gnubok_list_customers filters on archived_at IS NULL unless include_archived=true', async () => {
const { supabase, enqueue, findCalls, reset } = createQueuedMockSupabase()
enqueue({ data: [{ id: 'c-1', name: 'Acme AB', customer_type: 'swedish_business', org_number: null, personal_number: null }] })
const result = (await listCustomers().execute({}, 'company-1', 'user-1', supabase as never)) as { count: number }
expect(result.count).toBe(1)
expect(findCalls('customers', 'is')).toEqual([['archived_at', null]])
reset()
enqueue({ data: [] })
await listCustomers().execute({ include_archived: true }, 'company-1', 'user-1', supabase as never)
expect(findCalls('customers', 'is')).toEqual([])
})
it('gnubok_list_suppliers filters on archived_at IS NULL unless include_archived=true', async () => {
const { supabase, enqueue, findCalls, reset } = createQueuedMockSupabase()
enqueue({ data: [{ id: 's-1', name: 'Leverantör AB' }] })
const result = (await listSuppliers().execute({}, 'company-1', 'user-1', supabase as never)) as { count: number }
expect(result.count).toBe(1)
expect(findCalls('suppliers', 'is')).toEqual([['archived_at', null]])
reset()
enqueue({ data: [] })
await listSuppliers().execute({ include_archived: true }, 'company-1', 'user-1', supabase as never)
expect(findCalls('suppliers', 'is')).toEqual([])
})
it('declares include_archived as an optional boolean on both tools', () => {
for (const tool of [listCustomers(), listSuppliers()]) {
const schema = tool.inputSchema as { additionalProperties: boolean; properties: Record<string, { type: string }>; required?: string[] }
expect(schema.additionalProperties).toBe(false)
expect(schema.properties.include_archived).toEqual(expect.objectContaining({ type: 'boolean' }))
expect(schema.required ?? []).not.toContain('include_archived')
expect(tool.description.length).toBeLessThanOrEqual(280)
}
})
})
+30 -14
View File
@@ -5295,8 +5295,12 @@ export const tools: McpTool[] = [
{
name: 'gnubok_list_customers',
title: 'List Customers',
description: 'List all customers for the active company. Use to look up customer_id for invoice creation.',
inputSchema: { type: 'object', additionalProperties: false, properties: {} },
description: 'List active customers. Use to look up customer_id for invoice creation. include_archived=true adds archived rows.',
inputSchema: {
type: 'object',
additionalProperties: false,
properties: { include_archived: { type: 'boolean' } },
},
outputSchema: {
type: 'object',
additionalProperties: false,
@@ -5312,7 +5316,10 @@ export const tools: McpTool[] = [
idempotentHint: true,
openWorldHint: false,
},
async execute(_args, companyId, userId, supabase) {
async execute(args, companyId, userId, supabase) {
// Archived rows (v1 API soft-delete) are hidden by default: same
// `archived_at IS NULL` convention and opt-in flag as the v1 list.
const includeArchived = args.include_archived === true
// Paginated (fetchAllRows): PostgREST silently caps un-ranged selects at
// 1000 rows. Page on the unique id, then re-sort by name for display.
type ListedCustomer = {
@@ -5324,14 +5331,15 @@ export const tools: McpTool[] = [
}
let rows: ListedCustomer[]
try {
rows = await fetchAllRows<ListedCustomer>(({ from, to }) =>
supabase
rows = await fetchAllRows<ListedCustomer>(({ from, to }) => {
const query = supabase
.from('customers')
.select('id, name, customer_type, email, org_number, vat_number, personal_number, default_payment_terms, city, country')
.select('id, name, customer_type, email, org_number, vat_number, personal_number, default_payment_terms, city, country, archived_at')
.eq('company_id', companyId)
return (includeArchived ? query : query.is('archived_at', null))
.order('id', { ascending: true })
.range(from, to)
)
})
} catch (error) {
throw new Error(`Database error: ${error instanceof Error ? error.message : 'unknown error'}`)
}
@@ -6971,8 +6979,12 @@ export const tools: McpTool[] = [
{
name: 'gnubok_list_suppliers',
title: 'List Suppliers (Leverantörer)',
description: 'List all suppliers (leverantörer) with contact and payment details, sorted by name.',
inputSchema: { type: 'object', additionalProperties: false, properties: {} },
description: 'List active suppliers (leverantörer) with contact and payment details, sorted by name. include_archived=true adds archived rows.',
inputSchema: {
type: 'object',
additionalProperties: false,
properties: { include_archived: { type: 'boolean' } },
},
outputSchema: {
type: 'object',
additionalProperties: false,
@@ -6988,19 +7000,23 @@ export const tools: McpTool[] = [
idempotentHint: true,
openWorldHint: false,
},
async execute(_args, companyId, userId, supabase) {
async execute(args, companyId, userId, supabase) {
// Archived rows (v1 API soft-delete) are hidden by default: same
// `archived_at IS NULL` convention and opt-in flag as the v1 list.
const includeArchived = args.include_archived === true
// Paginated (fetchAllRows): PostgREST silently caps un-ranged selects at
// 1000 rows. Page on the unique id, then re-sort by name for display.
let suppliers: { id: string; name: string }[]
try {
suppliers = await fetchAllRows<{ id: string; name: string }>(({ from, to }) =>
supabase
suppliers = await fetchAllRows<{ id: string; name: string }>(({ from, to }) => {
const query = supabase
.from('suppliers')
.select('id, name, supplier_type, email, phone, org_number, vat_number, default_expense_account, default_payment_terms, default_currency, city, country')
.select('id, name, supplier_type, email, phone, org_number, vat_number, default_expense_account, default_payment_terms, default_currency, city, country, archived_at')
.eq('company_id', companyId)
return (includeArchived ? query : query.is('archived_at', null))
.order('id', { ascending: true })
.range(from, to)
)
})
} catch (error) {
throw new Error(`Database error: ${error instanceof Error ? error.message : 'unknown error'}`)
}