Files
accounted/lib/providers/briox/oauth.ts
T
MattssonandClaude Fable 5 db8983ba9e Add/bokslut (#718)
* feat(arcim-migration): Briox provider with SIE-over-API import

- Briox auth via account ID + application token (no app-level
  credentials); both tokens rotate on refresh and are persisted
- New sie-fetcher pulls the general ledger as SIE through the
  provider API for Fortnox, Briox and Bjorn Lunden
- Wizard stops on a failed SIE import and surfaces the real errors
  instead of proceeding to the misleading migrate-guard message
- PROVIDER_SIE_ONLY_FORTNOX renamed to PROVIDER_SIE_NOT_SUPPORTED;
  new PROVIDER_TOKEN_INVALID for rejected provider credentials

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(bookkeeping): per-line accruals (periodisering) on invoices and supplier invoices

Defer revenue/costs per invoice line to 29xx/17xx interim accounts with
automatic monthly dissolution (nightly cron + catch-up at registration),
schedule cancellation on credit, year-end auto-detect exclusion for
already-scheduled invoices, invoice-inbox service-period extraction for
prefill, and an MCP tool to list schedules.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(bokslut): iXBRL arsredovisning generation and Bolagsverket digital filing

Generate the annual report as iXBRL from a generated taxonomy registry
(K2 element lists, taxonomy:generate/check scripts + CI guard), expose it
via the fiscal-period API, and add the bolagsverket extension for digital
submission to eget utrymme with webhook-driven status tracking
(submissions table + pg tests, lifecycle events, year-end wizard UI).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(mcp): raise origin-guard test timeout to 20s

The dynamic import pulls in the full server module; the parse alone
flirts with the 5s default under full-suite parallel load.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Add new scripts and documentation for K2 AB taxonomy generation and validation

- Introduced `generate-taxonomy-registry.ts` to automate the generation of the iXBRL taxonomy concept registry from official element lists and tuple models.
- Added `validate-ixbrl.mjs` for validating generated iXBRL reports against the official taxonomy package using Arelle.
- Included new documentation files:
  - `k2-ab-arsredovisning-elementlista-2024-09-12_rev20250312_sv.xlsx`
  - `tuple-innehallsmodell-arsredovisning-k2-2024-09-12.xlsx`
  - `taxonomi-paket-2024-09-12_rev20250312.zip`

* Add tests for bookkeeping accruals dissolution and supplier invoices

- Implement tests for the POST /api/bookkeeping/accruals/[id]/dissolve route, covering success and error scenarios.
- Add tests for the DELETE /api/supplier-invoices/[id] route, including authentication checks and validation of invoice deletion conditions.
- Introduce tests for the Arcim migration provider client, ensuring token handling and error classification.
- Create tests for the Bolagsverket extension, validating submission role enforcement and environment settings.
- Add Zod schemas for Bolagsverket response payloads to ensure proper validation.
- Implement tests for MCP server's list accrual schedules, confirming registration and scope mapping.
- Add consistency tests for IXBRL document generation, ensuring duplicate facts and XML escaping are handled correctly.
- Introduce typed domain errors for accrual schedules to improve error handling in the service.
- Add tests for resolving consent with Briox token refresh concurrency, ensuring proper token management and error handling.

* fix(tests): update payload size guard comments to reflect recent changes in tool descriptions and ceiling adjustments

* fix(gitattributes): mark generated JSON files in bokslut taxonomy as linguist-generated

* feat(migrations): add backfill for invoices.journal_entry_id and fallback for next_voucher_number user_id

* feat(bokslut): enhance compliance and financial processing features with new submission details and security measures

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-06-12 16:35:30 +02:00

83 lines
2.9 KiB
TypeScript

import { BRIOX_TOKEN_URL, BRIOX_REFRESH_URL } from './config';
import { BrioxApiError } from './client';
import type { TokenResponse } from '../types';
import {
fetchWithTimeout,
OAUTH_TIMEOUT_MS,
} from '@/lib/http/fetch-with-timeout';
interface BrioxTokenData {
access_token: string;
refresh_token: string;
// Swagger declares both as strings ("35649125", "1640772931") but be
// tolerant of numbers — toTokenResponse coerces before arithmetic.
client_id: string | number;
expire_date: string;
expire_timestamp: string | number;
}
interface BrioxTokenApiResponse {
data: BrioxTokenData;
}
function toTokenResponse(brioxData: BrioxTokenData): TokenResponse {
const expiresIn = Number(brioxData.expire_timestamp) - Math.floor(Date.now() / 1000);
return {
access_token: brioxData.access_token,
refresh_token: brioxData.refresh_token,
token_type: 'Bearer',
expires_in: Number.isFinite(expiresIn) && expiresIn > 0 ? expiresIn : 3600,
};
}
async function postForToken(url: string, description: string): Promise<TokenResponse> {
const response = await fetchWithTimeout(
url,
{
method: 'POST',
headers: {
'Content-Type': 'application/json',
},
},
{ timeoutMs: OAUTH_TIMEOUT_MS, description },
);
if (!response.ok) {
const body = await response.text().catch(() => '');
// BrioxApiError carries statusCode so callers can tell wrong credentials
// (400/401/404 from /token) apart from transient upstream failures.
throw new BrioxApiError(`${description} failed: ${response.status} ${body}`, response.status, body);
}
const result = await response.json() as BrioxTokenApiResponse;
return toTokenResponse(result.data);
}
/**
* Exchange the user's account ID + application token for an access/refresh
* token pair. The "clientid" is the user's Briox account ID (the long number
* next to the company name under "Your Account"), NOT an app-level credential
* — Briox has no developer client id/secret on our side.
*/
export async function exchangeBrioxCode(
accountId: string,
applicationToken: string,
): Promise<TokenResponse> {
const url = `${BRIOX_TOKEN_URL}?clientid=${encodeURIComponent(accountId)}&token=${encodeURIComponent(applicationToken)}`;
return postForToken(url, 'Briox token exchange');
}
/**
* Refresh an expired access token. Per the swagger, /tokenrefresh takes the
* refresh token as `refreshtoken` and the CURRENT (expired) access token as
* `token`. Briox rotates both tokens — the caller must persist the new
* refresh_token from the response or the next refresh will fail.
*/
export async function refreshBrioxToken(
refreshToken: string,
currentAccessToken: string,
): Promise<TokenResponse> {
const url = `${BRIOX_REFRESH_URL}?refreshtoken=${encodeURIComponent(refreshToken)}&token=${encodeURIComponent(currentAccessToken)}`;
return postForToken(url, 'Briox token refresh');
}