Files
accounted/app/api/events/cleanup/cron/route.ts
T
Jakob WennbergandClaude Opus 4.8 bc61862e76 feat(agent): telemetry + CI-gate quick wins from the "AI systems that ship" audit (#677)
* feat(agent): telemetry completeness + durability, CI gates, commit_method provenance

Quick wins from the "Building AI systems that ship" audit:

- mcp.tool_called gains errorMessage (message_sv, truncated 500 chars) on
  all failure exits; new mcp.skill_loaded event on every gnubok_load_skill
  (all tiers) so atom usage is finally measurable
- event_log: (event_type, created_at) index; cleanup cron keeps
  mcp.*/agent.* telemetry 180 days (delivery events stay 30)
- CI: lint ratchet (npm run check:lint — 60 legacy errors baselined,
  fails only on NEW errors) and a pg-real coverage gate (migrations
  touching trigger/RPC/RLS/DEFERRABLE require a *.pg.test.ts change;
  escape hatch: -- pg-test: covered-by/skip)
- journal_entries.commit_method CHECK widened with 'api_key'/'agent';
  the MCP approve path records 'api_key' truthfully instead of
  'user_accept' (agent_first_vision §8 P0-1). 'agent' is reserved — ALL
  MCP traffic (incl. claude.ai OAuth, whose access_token is a minted
  API key) authenticates as api_key today

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(import): derive opening balances from prior-year #UB when SIE lacks #IB (#675)

SIE files exported without #IB 0 rows (only #UB -1) previously imported
with zero opening balances. getEffectiveOpeningBalances() now derives IB
from prior-year UB for balance-sheet accounts when explicit #IB is
absent, surfaces the derivation as an info issue in the import preview,
and excludes share-capital vouchers from opening-balance detection.
Detection regexes are shared between parser and importer so the two
checks cannot drift. 507 lib/import tests pass.

(Authored in a parallel session in this checkout; included per request.)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(review): address PR #677 bot findings — RoPA entry, execFileSync, gate scope note

Triage of the compliance-swarm + Greptile findings:

Applied:
- .compliance/ropa.yaml: new mcp.telemetry processing activity declaring
  the 180-day mcp.*/agent.* retention, lawful basis, data categories, and
  the no-args/no-results minimisation (ISO A.8.10, GDPR Art.5(1)(c) —
  the retention split is now formally documented, referenced from the cron)
- check-pg-test-coverage.mjs: execFileSync with argv array — no shell, so
  a hostile base-ref can't inject (ASVS V13.2.1); verified an injection
  attempt exits 2 without executing
- check-pg-test-coverage.mjs: documented the PR-level (not per-migration)
  scope of the gate so reviewers know to check coverage per migration when
  a PR carries several risky migrations (Greptile P2)

Acknowledged, no change:
- errorMessage PII risk: messages are domain-mapped strings; event_log
  already persists far richer delivery payloads under the same RLS; now
  declared in ropa.yaml
- cron error envelope: errorResponse maps to the canonical safe envelope
  and the endpoint is CRON_SECRET-gated
- two-pass delete "partial state": TTL deletes are idempotent — the next
  daily run sweeps whatever a failed pass left behind
- skill_loaded actorLabel/sessionId: mirrors the pre-existing
  mcp.tool_called payload; sessionId is the join key the analytics exist for

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 15:47:13 +02:00

68 lines
2.6 KiB
TypeScript

import { createServiceClient } from '@/lib/supabase/server'
import { NextResponse } from 'next/server'
import { withCronContext } from '@/lib/api/with-cron-context'
import { errorResponse } from '@/lib/errors/get-structured-error'
/**
* GET /api/events/cleanup/cron — daily 02:00 UTC.
*
* Differentiated retention:
* - Delivery events (invoice.created, transaction.synced, …): 30 days. They
* exist for external automation polling (n8n/Make/Zapier) and go stale fast.
* - Agent telemetry (mcp.*, agent.*): 180 days. Error-rate trends and
* skill-load correlation need more than one month of signal — a 30-day
* window made it impossible to tell whether a tool or skill change actually
* moved failure rates.
*
* Retention is declared in .compliance/ropa.yaml (id: mcp.telemetry).
*/
const DELIVERY_RETENTION_DAYS = 30
const TELEMETRY_RETENTION_DAYS = 180
export const GET = withCronContext('cron.events_cleanup', async (_request, ctx) => {
const supabase = createServiceClient()
const deliveryCutoff = new Date()
deliveryCutoff.setDate(deliveryCutoff.getDate() - DELIVERY_RETENTION_DAYS)
const telemetryCutoff = new Date()
telemetryCutoff.setDate(telemetryCutoff.getDate() - TELEMETRY_RETENTION_DAYS)
// Pass 1: delivery events past 30 days. Telemetry (mcp.*, agent.*) is
// excluded here and swept by the 180-day pass below.
const { error: deliveryError, count: deliveryCount } = await supabase
.from('event_log')
.delete({ count: 'exact' })
.lt('created_at', deliveryCutoff.toISOString())
.not('event_type', 'like', 'mcp.%')
.not('event_type', 'like', 'agent.%')
if (deliveryError) {
ctx.log.error('event log delivery cleanup failed', deliveryError)
return errorResponse(deliveryError, ctx.log, { requestId: ctx.requestId })
}
// Pass 2: everything past 180 days — catches the telemetry rows pass 1 skipped.
const { error: telemetryError, count: telemetryCount } = await supabase
.from('event_log')
.delete({ count: 'exact' })
.lt('created_at', telemetryCutoff.toISOString())
if (telemetryError) {
ctx.log.error('event log telemetry cleanup failed', telemetryError)
return errorResponse(telemetryError, ctx.log, { requestId: ctx.requestId })
}
const deletedDelivery = deliveryCount ?? 0
const deletedTelemetry = telemetryCount ?? 0
const deleted = deletedDelivery + deletedTelemetry
ctx.log.info('event log cleanup summary', {
deleted,
deletedDelivery,
deletedTelemetry,
deliveryCutoff: deliveryCutoff.toISOString(),
telemetryCutoff: telemetryCutoff.toISOString(),
})
return NextResponse.json({ success: true, deleted, deletedDelivery, deletedTelemetry })
})