* fix: add 15s timeout to accounting provider HTTP clients Node's built-in fetch has no default timeout, so a stalled provider could hold a serverless worker open for many minutes — worse with withRetry (6x on Fortnox, 3x on others) and getPaginated stacking across pages. Wrap each fetch() in the Fortnox, Visma, Bokio, Briox, and Björn Lundén clients with signal: AbortSignal.timeout(15_000), and treat TimeoutError/AbortError as retryable so a single stalled attempt retries cleanly instead of hanging the request. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: add timeouts to OAuth token endpoints Wrap every OAuth2 token exchange, refresh, and revoke POST in an AbortController via a new fetchWithTimeout helper. Without this, a hung provider endpoint holds the request thread indefinitely — worst case being Skatteverket, where refreshAccessToken sits on the hot path of every bookkeeping action and exchangeCodeForTokens races the 5-minute BankID auth-code TTL. On timeout, the Skatteverket OAuth callback now redirects to /reports?tab=vat-declaration with a Swedish retry message instead of leaving the user stranded on the callback URL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: close RLS escalation on membership and settings tables Any authenticated user who was a member (including viewer) could issue a direct PostgREST PATCH against company_members and promote themselves to owner, bypassing the app-layer requireWritePermission guard entirely. Reproduced on prod, then verified the fix on staging. Tighten INSERT/UPDATE/DELETE policies on company_members, team_members, api_keys, company_invitations, team_invitations, companies, teams, and company_settings to require the caller to hold role IN ('owner','admin') in the target company/team. Role check is wrapped in SECURITY DEFINER helpers (user_is_company_admin, user_is_team_admin, user_role_in_company) to avoid RLS recursion when a policy on company_members references company_members in its subquery. Add a BEFORE UPDATE trigger on company_members that rejects any role change unless the caller already holds role='owner', so admins cannot mint further owners even though they can otherwise write. Legitimate write paths are unaffected: company creation goes through the create_company_with_owner SECURITY DEFINER RPC, invite acceptance uses the service role, and team->company membership syncs via SECURITY DEFINER triggers. All bypass RLS. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(migrations): resolve duplicate schema_migrations version 20260421160000 Two migration files shared timestamp 20260421160000 on main (booking_template_usage.sql and opening_balances_rpc.sql), causing supabase_migrations.schema_migrations PK collisions on any fresh CI run: duplicate key value violates unique constraint "schema_migrations_pkey" Key (version)=(20260421160000) already exists. Bump opening_balances_rpc.sql to 20260421160500. booking_template_usage keeps 20260421160000 because its table already exists on prod; the renamed file has an idempotent CREATE OR REPLACE FUNCTION body and has not yet been deployed to prod, so moving its version is free. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(migrations): make booking_template_usage migration idempotent The table already exists on prod (applied out-of-band) but prod's schema_migrations does not track version 20260421160000, so the next PR-driven deploy would re-run this migration and fail on `CREATE TABLE public.booking_template_usage` with a duplicate-relation error. Add IF NOT EXISTS to CREATE TABLE and CREATE INDEX, and DROP POLICY IF EXISTS before each CREATE POLICY. No functional change on fresh databases; prod just silently no-ops the table/index creates and re-declares policies without dropping-then-missing them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: implement isTimeoutError utility and enforce role restrictions on company_members insert * fix: implement fallback for user_id in commit_journal_entry function when auth.uid() is NULL --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
165 lines
4.5 KiB
TypeScript
165 lines
4.5 KiB
TypeScript
import { TokenBucketRateLimiter } from '../rate-limiter';
|
|
import { withRetry } from '../retry';
|
|
import { BRIOX_BASE_URL, BRIOX_RATE_LIMIT } from './config';
|
|
import { isTimeoutError } from '@/lib/http/fetch-with-timeout';
|
|
|
|
const FETCH_TIMEOUT_MS = 15_000;
|
|
|
|
export class BrioxApiError extends Error {
|
|
constructor(
|
|
message: string,
|
|
public readonly statusCode: number,
|
|
public readonly body?: string,
|
|
) {
|
|
super(message);
|
|
this.name = 'BrioxApiError';
|
|
}
|
|
}
|
|
|
|
function isRetryableError(error: unknown): boolean {
|
|
if (isTimeoutError(error)) return true;
|
|
if (error instanceof BrioxApiError) {
|
|
if (error.statusCode === 401 || error.statusCode === 403 || error.statusCode === 404) {
|
|
return false;
|
|
}
|
|
return error.statusCode === 429 || error.statusCode >= 500;
|
|
}
|
|
return false;
|
|
}
|
|
|
|
interface BrioxListResponse {
|
|
data: Record<string, unknown> & {
|
|
metainformation?: {
|
|
total_pages: number;
|
|
current_page: number;
|
|
total_count: number;
|
|
};
|
|
};
|
|
}
|
|
|
|
export class BrioxClient {
|
|
private readonly rateLimiter: TokenBucketRateLimiter;
|
|
private readonly baseUrl: string;
|
|
|
|
constructor(baseUrl?: string) {
|
|
this.baseUrl = baseUrl ?? BRIOX_BASE_URL;
|
|
this.rateLimiter = new TokenBucketRateLimiter(BRIOX_RATE_LIMIT, 'ratelimit:briox');
|
|
}
|
|
|
|
async get<T>(accessToken: string, path: string): Promise<T> {
|
|
return withRetry(
|
|
async () => {
|
|
await this.rateLimiter.acquire();
|
|
const url = `${this.baseUrl}${path}`;
|
|
const response = await fetch(url, {
|
|
headers: {
|
|
Authorization: accessToken,
|
|
Accept: 'application/json',
|
|
'Content-Type': 'application/json',
|
|
},
|
|
signal: AbortSignal.timeout(FETCH_TIMEOUT_MS),
|
|
});
|
|
|
|
if (!response.ok) {
|
|
const body = await response.text().catch(() => '');
|
|
throw new BrioxApiError(
|
|
`Briox API error: ${response.status} ${response.statusText}`,
|
|
response.status,
|
|
body,
|
|
);
|
|
}
|
|
|
|
return response.json() as Promise<T>;
|
|
},
|
|
{
|
|
maxAttempts: 3,
|
|
initialDelayMs: 1000,
|
|
shouldRetry: isRetryableError,
|
|
},
|
|
);
|
|
}
|
|
|
|
async getPage<T>(
|
|
accessToken: string,
|
|
path: string,
|
|
listKey: string,
|
|
options?: {
|
|
page?: number;
|
|
pageSize?: number;
|
|
fromModifiedDate?: string;
|
|
},
|
|
): Promise<{ items: T[]; page: number; totalPages: number; totalCount: number }> {
|
|
const params = new URLSearchParams();
|
|
params.set('page', String(options?.page ?? 1));
|
|
if (options?.pageSize) {
|
|
params.set('limit', String(options.pageSize));
|
|
}
|
|
if (options?.fromModifiedDate) {
|
|
params.set('frommodifieddate', options.fromModifiedDate);
|
|
}
|
|
|
|
const separator = path.includes('?') ? '&' : '?';
|
|
const fullPath = `${path}${separator}${params.toString()}`;
|
|
|
|
const response = await this.get<BrioxListResponse>(accessToken, fullPath);
|
|
|
|
const meta = response.data?.metainformation;
|
|
const totalPages = meta?.total_pages ?? 1;
|
|
const currentPage = meta?.current_page ?? (options?.page ?? 1);
|
|
const totalCount = meta?.total_count ?? 0;
|
|
|
|
const items = listKey ? response.data?.[listKey] : response.data;
|
|
|
|
return {
|
|
items: Array.isArray(items) ? items as T[] : [],
|
|
page: currentPage,
|
|
totalPages,
|
|
totalCount,
|
|
};
|
|
}
|
|
|
|
async getPaginated<T>(
|
|
accessToken: string,
|
|
path: string,
|
|
listKey: string,
|
|
options?: {
|
|
fromModifiedDate?: string;
|
|
pageSize?: number;
|
|
},
|
|
): Promise<T[]> {
|
|
const allItems: T[] = [];
|
|
let page = 1;
|
|
let totalPages = 1;
|
|
|
|
do {
|
|
const result = await this.getPage<T>(accessToken, path, listKey, {
|
|
page,
|
|
pageSize: options?.pageSize,
|
|
fromModifiedDate: options?.fromModifiedDate,
|
|
});
|
|
|
|
allItems.push(...result.items);
|
|
totalPages = result.totalPages;
|
|
page++;
|
|
} while (page <= totalPages);
|
|
|
|
return allItems;
|
|
}
|
|
|
|
async getCurrentFinancialYear(accessToken: string): Promise<string> {
|
|
const response = await this.get<{
|
|
data: {
|
|
financialyears: { id: string; fromdate: string; todate: string }[];
|
|
};
|
|
}>(accessToken, '/financialyear');
|
|
|
|
const years = response.data?.financialyears ?? [];
|
|
if (years.length === 0) {
|
|
throw new BrioxApiError('No financial years found in Briox', 404);
|
|
}
|
|
const now = new Date().toISOString().slice(0, 10);
|
|
const completed = years.filter((y) => y.todate < now);
|
|
return completed.length > 0 ? completed[completed.length - 1]!.id : years[0]!.id;
|
|
}
|
|
}
|