Files
accounted/app/api/kpi/preferences/route.ts
T
Mattsson e11f70b347 Bug/gh issues fiz (#1103)
* refactor: optimize page loading and data fetching

* fix: resolve recurring production runtime errors

* feat: add MCP company and customer updates

* fix: handle year-end tax adjustments

* feat: harden annual report compliance

* fix: expand invoice logo and font support

* fix: sanitize API route error responses

* fix: sanitize user-facing error messages

* feat: persist onboarding and tax assessment notices

* fix: reduce cloud backup audit churn

* feat: refine invoice editor layout

* fix: show saved tax adjustments in INK2

* fix: complete annual report API mappings

* docs: record operational safeguards and decisions

* fix: harden annual report review findings

* fix: adjust column span for description based on VAT registration

* New css class name
2026-07-21 23:00:15 +02:00

80 lines
2.4 KiB
TypeScript

import { NextResponse } from 'next/server'
import { withRouteContext } from '@/lib/api/with-route-context'
import { mergeWithDefaults } from '@/lib/reports/kpi-definitions'
import type { KPIPreferences } from '@/types'
import { getErrorMessage as getUserErrorMessage } from '@/lib/errors/get-error-message'
const EXTENSION_ID = 'core/kpi'
const KEY = 'preferences'
export const GET = withRouteContext('kpi.preferences.get', async (_request, { supabase, companyId }) => {
const { data } = await supabase
.from('extension_data')
.select('value')
.eq('company_id', companyId)
.eq('extension_id', EXTENSION_ID)
.eq('key', KEY)
.single()
const preferences = mergeWithDefaults((data?.value as Partial<KPIPreferences>) ?? {})
return NextResponse.json({ data: preferences })
})
export const PUT = withRouteContext(
'kpi.preferences.update',
async (request, { supabase, companyId, user }) => {
let body: unknown
try {
body = await request.json()
} catch {
return NextResponse.json({ error: 'Invalid JSON' }, { status: 400 })
}
const prefs = body as Partial<KPIPreferences>
// Validate account overrides: must be 4-digit numeric strings
if (prefs.accountOverrides) {
for (const [kpiId, accounts] of Object.entries(prefs.accountOverrides)) {
if (!Array.isArray(accounts)) {
return NextResponse.json(
{ error: `accountOverrides.${kpiId} must be an array` },
{ status: 400 }
)
}
for (const acc of accounts) {
if (typeof acc !== 'string' || !/^\d{4}$/.test(acc)) {
return NextResponse.json(
{ error: `Invalid account number "${acc}" in ${kpiId}: must be 4 digits` },
{ status: 400 }
)
}
}
}
}
const merged = mergeWithDefaults(prefs)
const { data, error } = await supabase
.from('extension_data')
.upsert(
{
user_id: user.id,
company_id: companyId,
extension_id: EXTENSION_ID,
key: KEY,
value: merged,
},
{ onConflict: 'user_id,extension_id,key' }
)
.select()
.single()
if (error) {
return NextResponse.json({ error: getUserErrorMessage(error) }, { status: 500 })
}
return NextResponse.json({ data: data.value })
},
{ requireWrite: true }
)