* feat(arcim-migration): Briox provider with SIE-over-API import - Briox auth via account ID + application token (no app-level credentials); both tokens rotate on refresh and are persisted - New sie-fetcher pulls the general ledger as SIE through the provider API for Fortnox, Briox and Bjorn Lunden - Wizard stops on a failed SIE import and surfaces the real errors instead of proceeding to the misleading migrate-guard message - PROVIDER_SIE_ONLY_FORTNOX renamed to PROVIDER_SIE_NOT_SUPPORTED; new PROVIDER_TOKEN_INVALID for rejected provider credentials Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(bookkeeping): per-line accruals (periodisering) on invoices and supplier invoices Defer revenue/costs per invoice line to 29xx/17xx interim accounts with automatic monthly dissolution (nightly cron + catch-up at registration), schedule cancellation on credit, year-end auto-detect exclusion for already-scheduled invoices, invoice-inbox service-period extraction for prefill, and an MCP tool to list schedules. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(bokslut): iXBRL arsredovisning generation and Bolagsverket digital filing Generate the annual report as iXBRL from a generated taxonomy registry (K2 element lists, taxonomy:generate/check scripts + CI guard), expose it via the fiscal-period API, and add the bolagsverket extension for digital submission to eget utrymme with webhook-driven status tracking (submissions table + pg tests, lifecycle events, year-end wizard UI). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(mcp): raise origin-guard test timeout to 20s The dynamic import pulls in the full server module; the parse alone flirts with the 5s default under full-suite parallel load. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Add new scripts and documentation for K2 AB taxonomy generation and validation - Introduced `generate-taxonomy-registry.ts` to automate the generation of the iXBRL taxonomy concept registry from official element lists and tuple models. - Added `validate-ixbrl.mjs` for validating generated iXBRL reports against the official taxonomy package using Arelle. - Included new documentation files: - `k2-ab-arsredovisning-elementlista-2024-09-12_rev20250312_sv.xlsx` - `tuple-innehallsmodell-arsredovisning-k2-2024-09-12.xlsx` - `taxonomi-paket-2024-09-12_rev20250312.zip` * Add tests for bookkeeping accruals dissolution and supplier invoices - Implement tests for the POST /api/bookkeeping/accruals/[id]/dissolve route, covering success and error scenarios. - Add tests for the DELETE /api/supplier-invoices/[id] route, including authentication checks and validation of invoice deletion conditions. - Introduce tests for the Arcim migration provider client, ensuring token handling and error classification. - Create tests for the Bolagsverket extension, validating submission role enforcement and environment settings. - Add Zod schemas for Bolagsverket response payloads to ensure proper validation. - Implement tests for MCP server's list accrual schedules, confirming registration and scope mapping. - Add consistency tests for IXBRL document generation, ensuring duplicate facts and XML escaping are handled correctly. - Introduce typed domain errors for accrual schedules to improve error handling in the service. - Add tests for resolving consent with Briox token refresh concurrency, ensuring proper token management and error handling. * fix(tests): update payload size guard comments to reflect recent changes in tool descriptions and ceiling adjustments * fix(gitattributes): mark generated JSON files in bokslut taxonomy as linguist-generated * feat(migrations): add backfill for invoices.journal_entry_id and fallback for next_voucher_number user_id * feat(bokslut): enhance compliance and financial processing features with new submission details and security measures --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
114 lines
4.2 KiB
TypeScript
114 lines
4.2 KiB
TypeScript
import { describe, it, expect, vi, beforeEach, afterEach } from 'vitest';
|
|
import { exchangeBrioxCode, refreshBrioxToken } from '../oauth';
|
|
import { BrioxApiError } from '../client';
|
|
|
|
/**
|
|
* Guards the token-exchange contract against the Briox swagger:
|
|
* POST /token?clientid={accountId}&token={applicationToken}
|
|
* POST /tokenrefresh?refreshtoken={refreshToken}&token={currentAccessToken}
|
|
*
|
|
* The refresh test pins the exact param mapping — the original implementation
|
|
* sent the refresh token for BOTH params (and took the account id as an
|
|
* unused first argument), which Briox rejects.
|
|
*/
|
|
|
|
function tokenResponse(over: Record<string, unknown> = {}): Response {
|
|
return new Response(
|
|
JSON.stringify({
|
|
data: {
|
|
client_id: '35649125',
|
|
access_token: 'access-1',
|
|
refresh_token: 'refresh-1',
|
|
expire_date: '2026-06-10 12:00:00',
|
|
// Swagger declares expire_timestamp as a STRING
|
|
expire_timestamp: String(Math.floor(Date.now() / 1000) + 7200),
|
|
...over,
|
|
},
|
|
}),
|
|
{ status: 200, headers: { 'Content-Type': 'application/json' } },
|
|
);
|
|
}
|
|
|
|
describe('briox oauth', () => {
|
|
let fetchSpy: ReturnType<typeof vi.spyOn>;
|
|
|
|
beforeEach(() => {
|
|
fetchSpy = vi.spyOn(globalThis, 'fetch');
|
|
});
|
|
|
|
afterEach(() => {
|
|
fetchSpy.mockRestore();
|
|
});
|
|
|
|
it('exchange POSTs /token?clientid={accountId}&token={applicationToken}', async () => {
|
|
fetchSpy.mockResolvedValueOnce(tokenResponse());
|
|
|
|
const result = await exchangeBrioxCode('35649125', 'app-token-åäö');
|
|
|
|
expect(fetchSpy).toHaveBeenCalledTimes(1);
|
|
const [url, init] = fetchSpy.mock.calls[0];
|
|
expect(String(url)).toBe(
|
|
'https://api-se.briox.services/v2/token?clientid=35649125&token=app-token-%C3%A5%C3%A4%C3%B6',
|
|
);
|
|
expect((init as RequestInit).method).toBe('POST');
|
|
expect(result.access_token).toBe('access-1');
|
|
expect(result.refresh_token).toBe('refresh-1');
|
|
});
|
|
|
|
it('refresh POSTs /tokenrefresh?refreshtoken={refreshToken}&token={currentAccessToken}', async () => {
|
|
fetchSpy.mockResolvedValueOnce(
|
|
tokenResponse({ access_token: 'access-2', refresh_token: 'refresh-2' }),
|
|
);
|
|
|
|
const result = await refreshBrioxToken('refresh-1', 'expired-access-1');
|
|
|
|
const [url, init] = fetchSpy.mock.calls[0];
|
|
expect(String(url)).toBe(
|
|
'https://api-se.briox.services/v2/tokenrefresh?refreshtoken=refresh-1&token=expired-access-1',
|
|
);
|
|
expect((init as RequestInit).method).toBe('POST');
|
|
// Briox rotates both tokens — the new pair must be surfaced so the
|
|
// caller persists the rotated refresh token.
|
|
expect(result.access_token).toBe('access-2');
|
|
expect(result.refresh_token).toBe('refresh-2');
|
|
});
|
|
|
|
it('derives expires_in from a string expire_timestamp', async () => {
|
|
const now = Math.floor(Date.now() / 1000);
|
|
fetchSpy.mockResolvedValueOnce(tokenResponse({ expire_timestamp: String(now + 1800) }));
|
|
|
|
const result = await exchangeBrioxCode('1', 't');
|
|
|
|
expect(result.expires_in).toBeGreaterThan(1700);
|
|
expect(result.expires_in).toBeLessThanOrEqual(1800);
|
|
});
|
|
|
|
it('falls back to 3600 when expire_timestamp is in the past or unparseable', async () => {
|
|
const now = Math.floor(Date.now() / 1000);
|
|
|
|
fetchSpy.mockResolvedValueOnce(tokenResponse({ expire_timestamp: String(now - 60) }));
|
|
expect((await exchangeBrioxCode('1', 't')).expires_in).toBe(3600);
|
|
|
|
fetchSpy.mockResolvedValueOnce(tokenResponse({ expire_timestamp: 'not-a-number' }));
|
|
expect((await exchangeBrioxCode('1', 't')).expires_in).toBe(3600);
|
|
});
|
|
|
|
it('exchange throws BrioxApiError carrying the HTTP status on rejection', async () => {
|
|
fetchSpy.mockResolvedValueOnce(new Response('Unauthorized', { status: 401 }));
|
|
|
|
const err = await exchangeBrioxCode('1', 'wrong-token').catch((e: unknown) => e);
|
|
|
|
expect(err).toBeInstanceOf(BrioxApiError);
|
|
expect((err as BrioxApiError).statusCode).toBe(401);
|
|
});
|
|
|
|
it('refresh throws BrioxApiError carrying the HTTP status on rejection', async () => {
|
|
fetchSpy.mockResolvedValueOnce(new Response('Bad request', { status: 400 }));
|
|
|
|
const err = await refreshBrioxToken('r', 'a').catch((e: unknown) => e);
|
|
|
|
expect(err).toBeInstanceOf(BrioxApiError);
|
|
expect((err as BrioxApiError).statusCode).toBe(400);
|
|
});
|
|
});
|