Files
accounted/extensions/general/arcim-migration/lib/arcim-client.ts
T
78a581bca1 fix(import): guard against CP437-as-CP1252 mojibake entering via pre-decoded SIE text (#1569)
* refactor(arcim-migration): remove the dead gateway SIE export path

fetchSIEExport and SIEExportFile have had zero callers since the direct
provider clients replaced the Arcim Sync gateway (#181, #718). The path
returned SIE as a pre-decoded string, and the gateway's decode of CP437
bytes as windows-1252 is what wrote the 2026-03-17 mojibake into posted
entries. Deleting it makes the string-typed SIE fetch impossible to
re-wire; a comment marks the grave. The consent lifecycle and entity
accessors stay untouched.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(import): warn when SIE text carries CP437-as-CP1252 mojibake

The 2026-03-17 migration wrote mojibake ("L"neutbetalning"-style C1
specials) into posted entries because the retired gateway handed the
/import-sie handler an already-decoded string: byte-level encoding
detection never saw it, and nothing downstream checked. The live bug is
gone; this is the tripwire so the signature can never land silently
again.

- lib/import/sie-artifact-scan.ts: pure scanner over parsed SIE account
  names and voucher/line descriptions, reusing hasCp1252Artifact from
  charset-repair; flags at >= 2 hits so a lone legitimate curly quote or
  apostrophe cannot false-positive a whole file.
- arcim-migration /import-sie: warn-never-block; the Swedish warning
  rides on result.warnings, which the workspace UI already renders, plus
  a server-side log.warn.
- wizard parse route: same scan, surfaced through the existing
  parse-issue warnings card in the preview, pointing at the first
  affected line.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(bookkeeping): pin the reported gateway mojibake strings

Adds the four strings reported from the affected company's journal as
reverse_cp437 cases (all reverse losslessly) plus a false-positive
guard: space-padded typography must never route into the CP437
reversal.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-13 15:14:23 +02:00

241 lines
7.3 KiB
TypeScript

/**
* HTTP client for the Arcim Sync gateway API.
*
* Targets the consent-based resource API (/api/v1/consents/...) which
* provides typed, normalized access to any Swedish accounting provider.
*/
import type {
ArcimProvider,
ConsentRecord,
OtcResponse,
PaginatedResponse,
CompanyInformationDto,
CustomerDto,
SupplierDto,
SalesInvoiceDto,
SupplierInvoiceDto,
} from '../types'
function getBaseUrl(): string {
const url = process.env.ARCIM_SYNC_GATEWAY_URL
if (!url) throw new Error('ARCIM_SYNC_GATEWAY_URL is not configured')
return url.replace(/\/$/, '')
}
function getApiKey(): string {
const key = process.env.ARCIM_SYNC_API_KEY
if (!key) throw new Error('ARCIM_SYNC_API_KEY is not configured')
return key
}
const MAX_RETRIES = 2
const RETRY_DELAY_MS = 1_000
const RETRYABLE_STATUSES = [429, 502, 503, 504]
async function request<T>(
path: string,
options: RequestInit = {},
timeoutMs: number = 120_000
): Promise<T> {
const url = `${getBaseUrl()}${path}`
for (let attempt = 0; attempt <= MAX_RETRIES; attempt++) {
const controller = new AbortController()
const timer = setTimeout(() => controller.abort(), timeoutMs)
let response: Response
try {
response = await fetch(url, {
...options,
signal: controller.signal,
headers: {
'Authorization': `Bearer ${getApiKey()}`,
'Content-Type': 'application/json',
...options.headers,
},
})
} catch (err) {
const isAbort = err instanceof DOMException || (err instanceof Error && err.name === 'AbortError')
if (attempt < MAX_RETRIES && isAbort) {
console.warn(`[arcim] ${path} timed out, retrying (attempt ${attempt + 1})`)
await new Promise(r => setTimeout(r, RETRY_DELAY_MS * (attempt + 1)))
continue
}
if (isAbort) {
throw new Error(`Arcim API timeout after ${Math.round(timeoutMs / 1000)}s: ${path}`)
}
throw err
} finally {
clearTimeout(timer)
}
if (attempt < MAX_RETRIES && RETRYABLE_STATUSES.includes(response.status)) {
console.warn(`[arcim] ${path} returned ${response.status}, retrying (attempt ${attempt + 1})`)
await new Promise(r => setTimeout(r, RETRY_DELAY_MS * (attempt + 1)))
continue
}
if (!response.ok) {
const body = await response.text().catch(() => '')
throw new Error(`Arcim API ${response.status}: ${body || response.statusText}`)
}
return response.json()
}
throw new Error(`Arcim API failed after ${MAX_RETRIES + 1} attempts: ${path}`)
}
// ── Consent lifecycle ───────────────────────────────────────────────
export async function createConsent(
provider: ArcimProvider,
name: string,
orgNumber?: string,
companyName?: string
): Promise<ConsentRecord> {
return request<ConsentRecord>('/api/v1/consents', {
method: 'POST',
body: JSON.stringify({ name, provider, orgNumber, companyName }),
})
}
export async function getConsent(consentId: string): Promise<ConsentRecord> {
return request<ConsentRecord>(`/api/v1/consents/${consentId}`)
}
export async function generateOtc(
consentId: string,
expiresInMinutes: number = 60
): Promise<OtcResponse> {
return request<OtcResponse>(`/api/v1/consents/${consentId}/otc`, {
method: 'POST',
body: JSON.stringify({ expiresInMinutes }),
})
}
export async function deleteConsent(consentId: string): Promise<void> {
await request(`/api/v1/consents/${consentId}`, { method: 'DELETE' })
}
// ── OAuth helpers ───────────────────────────────────────────────────
export async function getAuthUrl(
provider: ArcimProvider,
state?: string,
redirectUri?: string
): Promise<{ url: string }> {
const params = new URLSearchParams()
if (state) params.set('state', state)
if (redirectUri) params.set('redirectUri', redirectUri)
const qs = params.toString()
return request<{ url: string }>(`/api/v1/auth/${provider}/url${qs ? `?${qs}` : ''}`)
}
export async function exchangeAuthToken(
consentId: string,
provider: ArcimProvider,
otcCode: string,
oauthCode: string,
redirectUri?: string
): Promise<{ success: boolean; consentId: string }> {
return request(`/api/v1/auth/${provider}/callback`, {
method: 'POST',
body: JSON.stringify({
code: oauthCode,
consentId,
otcCode,
...(redirectUri ? { redirectUri } : {}),
}),
})
}
// ── Token-based auth (Bokio, Björn Lundén, Briox) ──────────────────
export async function submitProviderToken(
consentId: string,
provider: ArcimProvider,
apiToken: string,
companyId?: string
): Promise<{ success: boolean; consentId: string }> {
return request(`/api/v1/auth/${provider}/callback`, {
method: 'POST',
body: JSON.stringify({
code: apiToken,
consentId,
...(companyId ? { companyId } : {}),
}),
})
}
// ── Resource fetching (paginated) ───────────────────────────────────
async function fetchAllPages<T>(
consentId: string,
resource: string,
params?: Record<string, string>,
pageSize: number = 100,
maxPages: number = 500
): Promise<T[]> {
const all: T[] = []
let page = 1
while (page <= maxPages) {
const query = new URLSearchParams({
page: String(page),
pageSize: String(pageSize),
...params,
})
const result = await request<PaginatedResponse<T>>(
`/api/v1/consents/${consentId}/${resource}?${query}`
)
all.push(...result.data)
if (!result.hasMore || result.data.length === 0) break
page++
}
return all
}
// ── Typed resource accessors ────────────────────────────────────────
export async function fetchCompanyInfo(
consentId: string
): Promise<CompanyInformationDto | null> {
// CompanyInformation is a singleton resource: gateway returns { data: object }
const result = await request<{ data: CompanyInformationDto }>(
`/api/v1/consents/${consentId}/companyinformation`
)
return result.data ?? null
}
export async function fetchCustomers(consentId: string): Promise<CustomerDto[]> {
return fetchAllPages<CustomerDto>(consentId, 'customers')
}
export async function fetchSuppliers(consentId: string): Promise<SupplierDto[]> {
return fetchAllPages<SupplierDto>(consentId, 'suppliers')
}
export async function fetchSalesInvoices(
consentId: string,
params?: Record<string, string>
): Promise<SalesInvoiceDto[]> {
return fetchAllPages<SalesInvoiceDto>(consentId, 'salesinvoices', params)
}
export async function fetchSupplierInvoices(
consentId: string,
params?: Record<string, string>
): Promise<SupplierInvoiceDto[]> {
return fetchAllPages<SupplierInvoiceDto>(consentId, 'supplierinvoices', params)
}
// The gateway SIE export path (fetchSIEExport/SIEExportFile) was deliberately
// removed: it returned SIE as a pre-decoded string, and the gateway's decode of
// CP437 bytes as windows-1252 caused the 2026-03-17 mojibake incident. Provider
// SIE now travels as raw bytes through lib/sie-fetcher.ts and the repo's own
// encoding detection. Do not re-add a string-typed SIE fetch here.