Files
accounted/app/api/pending-operations/expire/cron/__tests__/route.test.ts
T
Jakob WennbergandClaude Fable 5 0521c385d2 feat(transactions): underlag status badges + attach dialog; auto-expire stale pending ops (#712)
* feat(transactions): per-row underlag status + attach-document dialog

- New "Matcha mot underlag" dialog on /transactions (inbox pick or fresh
  upload), the tx→doc mirror of the Documents view's matcher
- Per-row Underlag/Underlag saknas badges on booked history rows, driven
  by computeJeUnderlagStatus — same posted-only, exemption-aware scope as
  the worklist count so badge and count never disagree
- attach-document route + commit dispatcher now propagate the doc onto
  the verifikation when the tx is already booked (BFL 5 kap 6 §), with a
  409 guard for docs consumed by a different verifikation, idempotent
  re-attach (no same-value rewrite under period lock), and an honest 409
  when the period-lock trigger blocks the propagation
- Booking-dialog doc links also pin the doc to the transaction row
  (first linked doc wins) via the link route's new transaction_id param

messages/{sv,en}.json also carries the strings for the pending-ops
expiry UI that lands in the next commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(pending-operations): auto-expire stale staged operations after 30 days

- New daily cron (02:30 UTC, vercel.json + both docker crontabs) flips
  >30-day-old pending ops to rejected with the dispatcher's
  { auto_rejected: true, reason: 'expired' } result_data shape — rows are
  never deleted, the table is the audit trail
- /pending renders an "Utgick automatiskt" badge + detail line for these,
  orders terminal tabs by resolved_at so a fresh expiry sweep isn't
  buried, and adds a first-time-reviewer explainer
- Origin labels spell out where a proposal came from (AI chat, MCP key,
  API, cron) instead of the raw actor_label
- agent_chat actor type added to PendingOperationActorType/AuditLogEntry
  (DB CHECK already widened in 20260519090000) and to the agent filter
- ApprovalCard notes that ignoring a proposal is safe

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(mcp): surface the client telemetry marker in connect instructions

Tag the connector URLs shown in ApiKeysPanel, the connect-claude doc and
the gnubok-mcp README with ?client=<surface> (claude-connector /
claude-code) and GNUBOK_CLIENT=claude-desktop for the npm bridge.
Telemetry-only — the server already reads the param/header; this just
lets us measure which Claude surface connected.

The claude mcp add copy blocks quote the URL: an unquoted ? in the query
string trips zsh globbing ("no matches found").

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* review: fix stale-closure badge flip + zod-validate link route body (PR #712)

- handleDocumentAttached read journal_entry_id off the render-time
  transactions snapshot; if the list changed while the attach dialog was
  open the optimistic badge flip was silently skipped. Read it off the
  dialog's own subject (attachDocTx) instead.
- POST /api/documents/[id]/link now validates the body against the new
  LinkDocumentSchema (uuid-strict, all four fields) instead of a bare
  presence check on journal_entry_id — same canonical VALIDATION_ERROR
  envelope. Test fixtures switched to real UUIDs accordingly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 11:13:51 +02:00

142 lines
4.9 KiB
TypeScript

/**
* Tests for the pending_operations expiry cron: stale (>30 days) pending
* staged operations are auto-rejected with the commit dispatcher's
* result_data shape ({ auto_rejected: true, reason: 'expired' }) so the
* /pending UI can render them as "Utgick automatiskt".
*/
import { describe, it, expect, vi, beforeEach } from 'vitest'
import { NextResponse } from 'next/server'
vi.mock('@/lib/auth/cron', () => ({
verifyCronSecret: vi.fn(() => null),
}))
interface FilterCall {
method: string
args: unknown[]
}
interface UpdateCapture {
payload: Record<string, unknown> | null
filters: FilterCall[]
}
const updateCalls: UpdateCapture[] = []
let updateResults: Array<{ data: unknown; error: unknown }> = []
vi.mock('@/lib/supabase/server', () => ({
createServiceClient: vi.fn(() => ({
from: vi.fn(() => {
const capture: UpdateCapture = { payload: null, filters: [] }
updateCalls.push(capture)
const result = updateResults.shift() ?? { data: [], error: null }
const chain: Record<string, unknown> = {}
chain.update = vi.fn((payload: Record<string, unknown>) => {
capture.payload = payload
return chain
})
chain.eq = vi.fn((...args: unknown[]) => {
capture.filters.push({ method: 'eq', args })
return chain
})
chain.lt = vi.fn((...args: unknown[]) => {
capture.filters.push({ method: 'lt', args })
return chain
})
chain.select = vi.fn((...args: unknown[]) => {
capture.filters.push({ method: 'select', args })
return chain
})
// Thenable — awaiting the builder resolves the queued result.
chain.then = (resolve: (v: unknown) => unknown) => Promise.resolve(result).then(resolve)
return chain
}),
})),
}))
import { GET } from '../route'
import { verifyCronSecret } from '@/lib/auth/cron'
import { createServiceClient } from '@/lib/supabase/server'
function cronRequest(): Request {
return new Request('http://localhost:3000/api/pending-operations/expire/cron')
}
function daysAgo(iso: string): number {
return (Date.now() - new Date(iso).getTime()) / 86_400_000
}
beforeEach(() => {
vi.clearAllMocks()
updateCalls.length = 0
updateResults = []
})
describe('GET /api/pending-operations/expire/cron', () => {
it('flips stale pending rows to rejected with the auto-expired marker', async () => {
updateResults = [
{ data: [{ id: 'op-1', company_id: 'c-1' }, { id: 'op-2', company_id: 'c-2' }], error: null },
]
const response = await GET(cronRequest())
const json = await response.json()
expect(json.success).toBe(true)
expect(json.expired).toBe(2)
expect(daysAgo(json.cutoff)).toBeCloseTo(30, 0)
expect(updateCalls).toHaveLength(1)
const call = updateCalls[0]
// The update payload: terminal rejected status + the exact result_data
// shape the commit dispatcher uses for its own auto-rejects, with the
// strict 'expired' reason the UI badge keys on. rejection_category and
// rejection_reason must NOT be set — those carry user-feedback semantics.
expect(call.payload).toBeTruthy()
expect(call.payload!.status).toBe('rejected')
expect(Number.isNaN(new Date(call.payload!.resolved_at as string).getTime())).toBe(false)
expect(call.payload!.result_data).toEqual({ auto_rejected: true, reason: 'expired' })
expect(call.payload).not.toHaveProperty('rejection_category')
expect(call.payload).not.toHaveProperty('rejection_reason')
// CAS on status='pending' (skips concurrently-claimed 'committing' rows)
// + the 30-day created_at cutoff.
const eq = call.filters.find((f) => f.method === 'eq')!
expect(eq.args).toEqual(['status', 'pending'])
const lt = call.filters.find((f) => f.method === 'lt')!
expect(lt.args[0]).toBe('created_at')
expect(daysAgo(lt.args[1] as string)).toBeCloseTo(30, 0)
// .select() must be chained — without it PostgREST returns no rows and
// the endpoint would permanently report expired: 0.
expect(call.filters.some((f) => f.method === 'select')).toBe(true)
})
it('reports zero when no rows are stale', async () => {
updateResults = [{ data: [], error: null }]
const response = await GET(cronRequest())
const json = await response.json()
expect(json).toEqual({ success: true, expired: 0, cutoff: expect.any(String) })
})
it('returns 401 without touching the database when cron auth fails', async () => {
vi.mocked(verifyCronSecret).mockReturnValueOnce(
NextResponse.json({ error: 'Unauthorized' }, { status: 401 }),
)
const response = await GET(cronRequest())
expect(response.status).toBe(401)
expect(vi.mocked(createServiceClient)).not.toHaveBeenCalled()
})
it('returns an error envelope when the update fails', async () => {
updateResults = [{ data: null, error: { message: 'boom', code: 'XX000' } }]
const response = await GET(cronRequest())
expect(response.status).toBeGreaterThanOrEqual(500)
})
})