* feat(arcim-migration): Briox provider with SIE-over-API import - Briox auth via account ID + application token (no app-level credentials); both tokens rotate on refresh and are persisted - New sie-fetcher pulls the general ledger as SIE through the provider API for Fortnox, Briox and Bjorn Lunden - Wizard stops on a failed SIE import and surfaces the real errors instead of proceeding to the misleading migrate-guard message - PROVIDER_SIE_ONLY_FORTNOX renamed to PROVIDER_SIE_NOT_SUPPORTED; new PROVIDER_TOKEN_INVALID for rejected provider credentials Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(bookkeeping): per-line accruals (periodisering) on invoices and supplier invoices Defer revenue/costs per invoice line to 29xx/17xx interim accounts with automatic monthly dissolution (nightly cron + catch-up at registration), schedule cancellation on credit, year-end auto-detect exclusion for already-scheduled invoices, invoice-inbox service-period extraction for prefill, and an MCP tool to list schedules. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(bokslut): iXBRL arsredovisning generation and Bolagsverket digital filing Generate the annual report as iXBRL from a generated taxonomy registry (K2 element lists, taxonomy:generate/check scripts + CI guard), expose it via the fiscal-period API, and add the bolagsverket extension for digital submission to eget utrymme with webhook-driven status tracking (submissions table + pg tests, lifecycle events, year-end wizard UI). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(mcp): raise origin-guard test timeout to 20s The dynamic import pulls in the full server module; the parse alone flirts with the 5s default under full-suite parallel load. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Add new scripts and documentation for K2 AB taxonomy generation and validation - Introduced `generate-taxonomy-registry.ts` to automate the generation of the iXBRL taxonomy concept registry from official element lists and tuple models. - Added `validate-ixbrl.mjs` for validating generated iXBRL reports against the official taxonomy package using Arelle. - Included new documentation files: - `k2-ab-arsredovisning-elementlista-2024-09-12_rev20250312_sv.xlsx` - `tuple-innehallsmodell-arsredovisning-k2-2024-09-12.xlsx` - `taxonomi-paket-2024-09-12_rev20250312.zip` * Add tests for bookkeeping accruals dissolution and supplier invoices - Implement tests for the POST /api/bookkeeping/accruals/[id]/dissolve route, covering success and error scenarios. - Add tests for the DELETE /api/supplier-invoices/[id] route, including authentication checks and validation of invoice deletion conditions. - Introduce tests for the Arcim migration provider client, ensuring token handling and error classification. - Create tests for the Bolagsverket extension, validating submission role enforcement and environment settings. - Add Zod schemas for Bolagsverket response payloads to ensure proper validation. - Implement tests for MCP server's list accrual schedules, confirming registration and scope mapping. - Add consistency tests for IXBRL document generation, ensuring duplicate facts and XML escaping are handled correctly. - Introduce typed domain errors for accrual schedules to improve error handling in the service. - Add tests for resolving consent with Briox token refresh concurrency, ensuring proper token management and error handling. * fix(tests): update payload size guard comments to reflect recent changes in tool descriptions and ceiling adjustments * fix(gitattributes): mark generated JSON files in bokslut taxonomy as linguist-generated * feat(migrations): add backfill for invoices.journal_entry_id and fallback for next_voucher_number user_id * feat(bokslut): enhance compliance and financial processing features with new submission details and security measures --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
83 lines
2.9 KiB
TypeScript
83 lines
2.9 KiB
TypeScript
import { BRIOX_TOKEN_URL, BRIOX_REFRESH_URL } from './config';
|
|
import { BrioxApiError } from './client';
|
|
import type { TokenResponse } from '../types';
|
|
import {
|
|
fetchWithTimeout,
|
|
OAUTH_TIMEOUT_MS,
|
|
} from '@/lib/http/fetch-with-timeout';
|
|
|
|
interface BrioxTokenData {
|
|
access_token: string;
|
|
refresh_token: string;
|
|
// Swagger declares both as strings ("35649125", "1640772931") but be
|
|
// tolerant of numbers — toTokenResponse coerces before arithmetic.
|
|
client_id: string | number;
|
|
expire_date: string;
|
|
expire_timestamp: string | number;
|
|
}
|
|
|
|
interface BrioxTokenApiResponse {
|
|
data: BrioxTokenData;
|
|
}
|
|
|
|
function toTokenResponse(brioxData: BrioxTokenData): TokenResponse {
|
|
const expiresIn = Number(brioxData.expire_timestamp) - Math.floor(Date.now() / 1000);
|
|
return {
|
|
access_token: brioxData.access_token,
|
|
refresh_token: brioxData.refresh_token,
|
|
token_type: 'Bearer',
|
|
expires_in: Number.isFinite(expiresIn) && expiresIn > 0 ? expiresIn : 3600,
|
|
};
|
|
}
|
|
|
|
async function postForToken(url: string, description: string): Promise<TokenResponse> {
|
|
const response = await fetchWithTimeout(
|
|
url,
|
|
{
|
|
method: 'POST',
|
|
headers: {
|
|
'Content-Type': 'application/json',
|
|
},
|
|
},
|
|
{ timeoutMs: OAUTH_TIMEOUT_MS, description },
|
|
);
|
|
|
|
if (!response.ok) {
|
|
const body = await response.text().catch(() => '');
|
|
// BrioxApiError carries statusCode so callers can tell wrong credentials
|
|
// (400/401/404 from /token) apart from transient upstream failures.
|
|
throw new BrioxApiError(`${description} failed: ${response.status} ${body}`, response.status, body);
|
|
}
|
|
|
|
const result = await response.json() as BrioxTokenApiResponse;
|
|
return toTokenResponse(result.data);
|
|
}
|
|
|
|
/**
|
|
* Exchange the user's account ID + application token for an access/refresh
|
|
* token pair. The "clientid" is the user's Briox account ID (the long number
|
|
* next to the company name under "Your Account"), NOT an app-level credential
|
|
* — Briox has no developer client id/secret on our side.
|
|
*/
|
|
export async function exchangeBrioxCode(
|
|
accountId: string,
|
|
applicationToken: string,
|
|
): Promise<TokenResponse> {
|
|
const url = `${BRIOX_TOKEN_URL}?clientid=${encodeURIComponent(accountId)}&token=${encodeURIComponent(applicationToken)}`;
|
|
return postForToken(url, 'Briox token exchange');
|
|
}
|
|
|
|
/**
|
|
* Refresh an expired access token. Per the swagger, /tokenrefresh takes the
|
|
* refresh token as `refreshtoken` and the CURRENT (expired) access token as
|
|
* `token`. Briox rotates both tokens — the caller must persist the new
|
|
* refresh_token from the response or the next refresh will fail.
|
|
*/
|
|
export async function refreshBrioxToken(
|
|
refreshToken: string,
|
|
currentAccessToken: string,
|
|
): Promise<TokenResponse> {
|
|
const url = `${BRIOX_REFRESH_URL}?refreshtoken=${encodeURIComponent(refreshToken)}&token=${encodeURIComponent(currentAccessToken)}`;
|
|
return postForToken(url, 'Briox token refresh');
|
|
}
|