Files
accounted/app/api/reports/full-archive/__tests__/route.test.ts
T
MattssonandClaude Opus 4.7 d708a85d4c Feat/cloud backup (#277)
* feat: cloud backup to Google Drive + full-archive all-scope

Adds a cloud-backup extension that uploads a full-company backup ZIP to
the user's own Google Drive via OAuth (drive.file scope only). Refresh
tokens are AES-256-GCM encrypted before being stored in extension_data.

The full-archive export gains a scope=all mode for whole-company
backups (per-period SIE under sie/, per-period rapporter/ subfolders,
flat dokument/ manifest tagged with fiscal_period_id). An 80 MB size
guard short-circuits generation before the platform response limit.

Also fixes a latent bug in lib/core/audit/audit-service.ts where the
parameter was named userId while the query filtered by company_id; the
audit-trail API route was passing user.id so audit queries returned
empty unless user and company shared a UUID.

Drive-by: scope the dashboard "fresh start" localStorage key per
companyId so dismissing the setup checklist in one company no longer
carries over to others.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: address review comments on cloud backup + archive export

- Extend audit trail to_date to end-of-day so last-day entries aren't
  silently excluded from period-scoped archives.
- Apply 413 size-limit guard regardless of include_documents, using the
  overhead-only figure when documents are excluded.
- Use crypto.randomUUID() for Drive multipart boundary to eliminate any
  collision risk with ZIP payload bytes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: migrate legacy setup-gate localStorage keys on dashboard

Users who previously dismissed the setup checklist via the old global
erp_setup_fresh_start or erp_checklist_dismissed keys were re-gated after
the switch to a company-scoped key. Fall back to the legacy keys on read
and migrate them to the scoped key on first hit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: update customer email handling and anonymization rules in supportmail-to-ticket skill

* test: update audit trail to_date expectation for end-of-day timestamp

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-20 10:49:59 +02:00

209 lines
6.0 KiB
TypeScript

/* eslint-disable @typescript-eslint/no-explicit-any */
import { describe, it, expect, vi, beforeEach } from 'vitest'
import { createMockRequest, parseJsonResponse } from '@/tests/helpers'
vi.mock('@/lib/supabase/server', () => ({
createClient: vi.fn(),
}))
vi.mock('@/lib/company/context', () => ({
requireCompanyId: vi.fn().mockResolvedValue('company-1'),
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
}))
vi.mock('@/lib/reports/full-archive-export', () => ({
generateFullArchive: vi.fn(),
estimateArchiveSize: vi.fn(),
}))
import { createClient } from '@/lib/supabase/server'
import {
generateFullArchive,
estimateArchiveSize,
} from '@/lib/reports/full-archive-export'
import { GET } from '../route'
const mockCreateClient = vi.mocked(createClient)
const mockGenerate = vi.mocked(generateFullArchive)
const mockEstimate = vi.mocked(estimateArchiveSize)
function mockAuth(userId: string | null) {
mockCreateClient.mockResolvedValue({
auth: {
getUser: vi.fn().mockResolvedValue({
data: { user: userId ? { id: userId } : null },
}),
},
} as any)
}
beforeEach(() => {
vi.clearAllMocks()
})
describe('GET /api/reports/full-archive', () => {
it('returns 401 when not authenticated', async () => {
mockAuth(null)
const { status, body } = await parseJsonResponse(
await GET(createMockRequest('/api/reports/full-archive'))
)
expect(status).toBe(401)
expect(body).toEqual({ error: 'Unauthorized' })
})
it('returns estimate-only response when ?estimate=1', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 10_000_000,
document_bytes: 5_000_000,
document_count: 7,
})
const { status, body } = await parseJsonResponse<{
data: {
total_bytes: number
size_limit_bytes: number
within_limit: boolean
}
}>(
await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { estimate: '1', scope: 'all' },
})
)
)
expect(status).toBe(200)
expect(body.data.total_bytes).toBe(10_000_000)
expect(body.data.within_limit).toBe(true)
expect(mockGenerate).not.toHaveBeenCalled()
})
it('returns 413 archive_too_large when estimate exceeds limit', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 200 * 1024 * 1024,
document_bytes: 195 * 1024 * 1024,
document_count: 200,
})
const response = await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { scope: 'all' },
})
)
const { status, body } = await parseJsonResponse<{
error: string
size_bytes: number
size_limit_bytes: number
}>(response)
expect(status).toBe(413)
expect(body.error).toBe('archive_too_large')
expect(body.size_bytes).toBe(200 * 1024 * 1024)
expect(body.size_limit_bytes).toBe(80 * 1024 * 1024)
expect(mockGenerate).not.toHaveBeenCalled()
})
it('skips 413 when include_documents=false', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 200 * 1024 * 1024,
document_bytes: 195 * 1024 * 1024,
document_count: 200,
})
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
const response = await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { scope: 'all', include_documents: 'false' },
})
)
expect(response.status).toBe(200)
expect(response.headers.get('Content-Type')).toBe('application/zip')
expect(mockGenerate).toHaveBeenCalledWith(
expect.anything(),
'company-1',
expect.objectContaining({ scope: 'all', include_documents: false })
)
})
it('defaults to scope=all when no params given', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 1_000_000,
document_bytes: 500_000,
document_count: 2,
})
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
const response = await GET(createMockRequest('/api/reports/full-archive'))
expect(response.status).toBe(200)
expect(mockGenerate).toHaveBeenCalledWith(
expect.anything(),
'company-1',
expect.objectContaining({ scope: 'all' })
)
})
it('uses scope=period when period_id is provided without explicit scope', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 1_000_000,
document_bytes: 500_000,
document_count: 2,
})
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
const response = await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { period_id: 'period-1' },
})
)
expect(response.status).toBe(200)
expect(mockGenerate).toHaveBeenCalledWith(
expect.anything(),
'company-1',
expect.objectContaining({ scope: 'period', period_id: 'period-1' })
)
})
it('returns 400 when scope=period without period_id', async () => {
mockAuth('user-1')
const { status, body } = await parseJsonResponse(
await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { scope: 'period' },
})
)
)
expect(status).toBe(400)
expect(body).toEqual({ error: 'period_id is required when scope=period' })
expect(mockGenerate).not.toHaveBeenCalled()
expect(mockEstimate).not.toHaveBeenCalled()
})
it('returns 404 when generate throws "not found"', async () => {
mockAuth('user-1')
mockEstimate.mockResolvedValue({
total_bytes: 1_000_000,
document_bytes: 500_000,
document_count: 2,
})
mockGenerate.mockRejectedValue(new Error('Fiscal period not found'))
const { status, body } = await parseJsonResponse(
await GET(
createMockRequest('/api/reports/full-archive', {
searchParams: { scope: 'period', period_id: 'nope' },
})
)
)
expect(status).toBe(404)
expect(body).toEqual({ error: 'Fiscal period not found' })
})
})