* feat: cloud backup to Google Drive + full-archive all-scope Adds a cloud-backup extension that uploads a full-company backup ZIP to the user's own Google Drive via OAuth (drive.file scope only). Refresh tokens are AES-256-GCM encrypted before being stored in extension_data. The full-archive export gains a scope=all mode for whole-company backups (per-period SIE under sie/, per-period rapporter/ subfolders, flat dokument/ manifest tagged with fiscal_period_id). An 80 MB size guard short-circuits generation before the platform response limit. Also fixes a latent bug in lib/core/audit/audit-service.ts where the parameter was named userId while the query filtered by company_id; the audit-trail API route was passing user.id so audit queries returned empty unless user and company shared a UUID. Drive-by: scope the dashboard "fresh start" localStorage key per companyId so dismissing the setup checklist in one company no longer carries over to others. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: address review comments on cloud backup + archive export - Extend audit trail to_date to end-of-day so last-day entries aren't silently excluded from period-scoped archives. - Apply 413 size-limit guard regardless of include_documents, using the overhead-only figure when documents are excluded. - Use crypto.randomUUID() for Drive multipart boundary to eliminate any collision risk with ZIP payload bytes. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: migrate legacy setup-gate localStorage keys on dashboard Users who previously dismissed the setup checklist via the old global erp_setup_fresh_start or erp_checklist_dismissed keys were re-gated after the switch to a company-scoped key. Fall back to the legacy keys on read and migrate them to the scoped key on first hit. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: update customer email handling and anonymization rules in supportmail-to-ticket skill * test: update audit trail to_date expectation for end-of-day timestamp Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
209 lines
6.0 KiB
TypeScript
209 lines
6.0 KiB
TypeScript
/* eslint-disable @typescript-eslint/no-explicit-any */
|
|
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
|
import { createMockRequest, parseJsonResponse } from '@/tests/helpers'
|
|
|
|
vi.mock('@/lib/supabase/server', () => ({
|
|
createClient: vi.fn(),
|
|
}))
|
|
|
|
vi.mock('@/lib/company/context', () => ({
|
|
requireCompanyId: vi.fn().mockResolvedValue('company-1'),
|
|
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
|
|
}))
|
|
|
|
vi.mock('@/lib/reports/full-archive-export', () => ({
|
|
generateFullArchive: vi.fn(),
|
|
estimateArchiveSize: vi.fn(),
|
|
}))
|
|
|
|
import { createClient } from '@/lib/supabase/server'
|
|
import {
|
|
generateFullArchive,
|
|
estimateArchiveSize,
|
|
} from '@/lib/reports/full-archive-export'
|
|
import { GET } from '../route'
|
|
|
|
const mockCreateClient = vi.mocked(createClient)
|
|
const mockGenerate = vi.mocked(generateFullArchive)
|
|
const mockEstimate = vi.mocked(estimateArchiveSize)
|
|
|
|
function mockAuth(userId: string | null) {
|
|
mockCreateClient.mockResolvedValue({
|
|
auth: {
|
|
getUser: vi.fn().mockResolvedValue({
|
|
data: { user: userId ? { id: userId } : null },
|
|
}),
|
|
},
|
|
} as any)
|
|
}
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
})
|
|
|
|
describe('GET /api/reports/full-archive', () => {
|
|
it('returns 401 when not authenticated', async () => {
|
|
mockAuth(null)
|
|
const { status, body } = await parseJsonResponse(
|
|
await GET(createMockRequest('/api/reports/full-archive'))
|
|
)
|
|
expect(status).toBe(401)
|
|
expect(body).toEqual({ error: 'Unauthorized' })
|
|
})
|
|
|
|
it('returns estimate-only response when ?estimate=1', async () => {
|
|
mockAuth('user-1')
|
|
mockEstimate.mockResolvedValue({
|
|
total_bytes: 10_000_000,
|
|
document_bytes: 5_000_000,
|
|
document_count: 7,
|
|
})
|
|
|
|
const { status, body } = await parseJsonResponse<{
|
|
data: {
|
|
total_bytes: number
|
|
size_limit_bytes: number
|
|
within_limit: boolean
|
|
}
|
|
}>(
|
|
await GET(
|
|
createMockRequest('/api/reports/full-archive', {
|
|
searchParams: { estimate: '1', scope: 'all' },
|
|
})
|
|
)
|
|
)
|
|
|
|
expect(status).toBe(200)
|
|
expect(body.data.total_bytes).toBe(10_000_000)
|
|
expect(body.data.within_limit).toBe(true)
|
|
expect(mockGenerate).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('returns 413 archive_too_large when estimate exceeds limit', async () => {
|
|
mockAuth('user-1')
|
|
mockEstimate.mockResolvedValue({
|
|
total_bytes: 200 * 1024 * 1024,
|
|
document_bytes: 195 * 1024 * 1024,
|
|
document_count: 200,
|
|
})
|
|
|
|
const response = await GET(
|
|
createMockRequest('/api/reports/full-archive', {
|
|
searchParams: { scope: 'all' },
|
|
})
|
|
)
|
|
const { status, body } = await parseJsonResponse<{
|
|
error: string
|
|
size_bytes: number
|
|
size_limit_bytes: number
|
|
}>(response)
|
|
|
|
expect(status).toBe(413)
|
|
expect(body.error).toBe('archive_too_large')
|
|
expect(body.size_bytes).toBe(200 * 1024 * 1024)
|
|
expect(body.size_limit_bytes).toBe(80 * 1024 * 1024)
|
|
expect(mockGenerate).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('skips 413 when include_documents=false', async () => {
|
|
mockAuth('user-1')
|
|
mockEstimate.mockResolvedValue({
|
|
total_bytes: 200 * 1024 * 1024,
|
|
document_bytes: 195 * 1024 * 1024,
|
|
document_count: 200,
|
|
})
|
|
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
|
|
|
|
const response = await GET(
|
|
createMockRequest('/api/reports/full-archive', {
|
|
searchParams: { scope: 'all', include_documents: 'false' },
|
|
})
|
|
)
|
|
|
|
expect(response.status).toBe(200)
|
|
expect(response.headers.get('Content-Type')).toBe('application/zip')
|
|
expect(mockGenerate).toHaveBeenCalledWith(
|
|
expect.anything(),
|
|
'company-1',
|
|
expect.objectContaining({ scope: 'all', include_documents: false })
|
|
)
|
|
})
|
|
|
|
it('defaults to scope=all when no params given', async () => {
|
|
mockAuth('user-1')
|
|
mockEstimate.mockResolvedValue({
|
|
total_bytes: 1_000_000,
|
|
document_bytes: 500_000,
|
|
document_count: 2,
|
|
})
|
|
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
|
|
|
|
const response = await GET(createMockRequest('/api/reports/full-archive'))
|
|
|
|
expect(response.status).toBe(200)
|
|
expect(mockGenerate).toHaveBeenCalledWith(
|
|
expect.anything(),
|
|
'company-1',
|
|
expect.objectContaining({ scope: 'all' })
|
|
)
|
|
})
|
|
|
|
it('uses scope=period when period_id is provided without explicit scope', async () => {
|
|
mockAuth('user-1')
|
|
mockEstimate.mockResolvedValue({
|
|
total_bytes: 1_000_000,
|
|
document_bytes: 500_000,
|
|
document_count: 2,
|
|
})
|
|
mockGenerate.mockResolvedValue(new ArrayBuffer(1024))
|
|
|
|
const response = await GET(
|
|
createMockRequest('/api/reports/full-archive', {
|
|
searchParams: { period_id: 'period-1' },
|
|
})
|
|
)
|
|
|
|
expect(response.status).toBe(200)
|
|
expect(mockGenerate).toHaveBeenCalledWith(
|
|
expect.anything(),
|
|
'company-1',
|
|
expect.objectContaining({ scope: 'period', period_id: 'period-1' })
|
|
)
|
|
})
|
|
|
|
it('returns 400 when scope=period without period_id', async () => {
|
|
mockAuth('user-1')
|
|
const { status, body } = await parseJsonResponse(
|
|
await GET(
|
|
createMockRequest('/api/reports/full-archive', {
|
|
searchParams: { scope: 'period' },
|
|
})
|
|
)
|
|
)
|
|
expect(status).toBe(400)
|
|
expect(body).toEqual({ error: 'period_id is required when scope=period' })
|
|
expect(mockGenerate).not.toHaveBeenCalled()
|
|
expect(mockEstimate).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('returns 404 when generate throws "not found"', async () => {
|
|
mockAuth('user-1')
|
|
mockEstimate.mockResolvedValue({
|
|
total_bytes: 1_000_000,
|
|
document_bytes: 500_000,
|
|
document_count: 2,
|
|
})
|
|
mockGenerate.mockRejectedValue(new Error('Fiscal period not found'))
|
|
|
|
const { status, body } = await parseJsonResponse(
|
|
await GET(
|
|
createMockRequest('/api/reports/full-archive', {
|
|
searchParams: { scope: 'period', period_id: 'nope' },
|
|
})
|
|
)
|
|
)
|
|
expect(status).toBe(404)
|
|
expect(body).toEqual({ error: 'Fiscal period not found' })
|
|
})
|
|
})
|