* feat(webshop-orders): schema, types and error codes for the orders surface webshop_orders (order/refund rows, financial-freeze trigger, member select/update RLS, no DELETE) + webshop_store_settings (per-store payment method -> account map), source_type 'webshop_order', multi-store index drop, customer_country, and a one-time woo cursor reset so the switch-over backfills and cross-marks existing feed rows. Tables classified in the full-archive export; pg-real coverage for RLS, freeze and CHECK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(webshop-orders): core service (ingest, booking lines) upsertWebshopOrders: two-phase order/refund upsert with FX enrichment, legacy-feed cross-marking, frozen-row protection and field-wise jsonb comparisons (Postgres does not preserve object key order). Booking-line builder: per-rate VAT split with SIGNED buckets (discounts book as revenue reductions), refund mirroring, 3740 residual, per-store account prefill, and advisory export/EU + OSS warnings. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(webshop-orders): API routes for list, booking, invoicing and mapping Booking is draft -> atomic claim -> commit (conditional link-back closes the concurrent double-book race; a lost claim cancels the voucher-free draft). Legacy-feed guard honors transactions.is_ignored on both the book and create-invoice paths. Invoice conversion reuses buildInvoiceWriteData for an unnumbered draft with dominant-rate fallback and drift-safe unit prices. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(webshop-orders): Orders page, booking/invoice dialogs and gated nav /orders lists per-store orders with status tabs (server-side filters), exception chips and one action per row. Booking dialog prefills from the per-store payment-method mapping with an opt-in remember; invoice dialog converts to a draft kundfaktura. The Order nav item renders only for companies with an active WooCommerce connection or existing order rows (Shopify deliberately excluded until its sync writes webshop_orders). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(woocommerce): switch the order sync to webshop_orders, multi-store The sync maps rich wc/v3 payloads (billing, line/shipping/fee taxes, refund allocations with parent-prorated VAT fallback) and upserts order rows instead of transactions-inbox rows; already-imported feed rows stay bookable and get cross-marked. Multi-store: several active connections per company, per-store panel cards with the account-mapping editor. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs(webshop-orders): decision log entries and ratchet baseline Baseline moves DOWN only: naive-ore-round 638 -> 637 via roundOre adoption; hand-rolled invariants stay at 115 (ACCOUNT_NUMBER_RE imported, not inlined). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(webshop-orders): resolve PR #1525 review findings and CI failures Review batch (Superagent, CodeRabbit, Swedish compliance review): - Mutual-exclusion claims: booking guards invoice_id, invoice link-back guards journal_entry_id AND treats zero matched rows as the conflict it is (409 + rollback), closing both TOCTOU races. - Freeze v2 migration (20260812124858): the link columns themselves are protected: invoice links immutable, journal links clearable only while the entry is still a draft (the booking rollback path). - Scraped orgnr no longer auto-written to customers.org_number; rate fallback applies only on single-VAT-bucket orders; refunds get their own WEBSHOP_ORDER_REFUND_NOT_CONVERTIBLE code; VAT advisories outrank the invoice-mode hint in the booking dialog. - Ingest compares every synced field (billing corrections no longer drop as unchanged); sync guards absent refunds arrays; /sync aggregates per-store results; panel disables all cards while a request runs; orders page separates load failure from empty; account field explains itself. CI: regenerated skills/accounted-api; pg tests restructured for transaction-abort/rollback semantics + freeze-link coverage; unresolvable- expression ceiling 375 -> 378 with documented reason (partial-update payloads in ingest, shapes covered by unit tests). Declined: CodeRabbit docstring-coverage advisory (house style: comments only where the code cannot say it). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
132 lines
5.2 KiB
TypeScript
132 lines
5.2 KiB
TypeScript
import { describe, it, expect } from 'vitest'
|
|
import { getPool, withUserContext } from './setup'
|
|
import { randomUUID } from 'crypto'
|
|
import { seedCompany } from './fixtures'
|
|
|
|
// Committed (pool) inserts persist across pg-real runs, and the store_url
|
|
// partial unique index is global: fixed URLs would collide with rows left by
|
|
// a previous run before the assertion under test is ever reached.
|
|
const uniqueStore = (label: string) => 'https://' + label + '-' + randomUUID() + '.example.se'
|
|
|
|
/**
|
|
* Covers migration 20260806170000_woocommerce_connections:
|
|
* 1. RLS: members insert and read their own company's connection,
|
|
* non-members see nothing and cannot insert for a foreign company.
|
|
* 2. Multiple ACTIVE connections per company (multi-store: the
|
|
* one-active-per-company index was dropped in 20260811073422).
|
|
* 3. One store actively connected to at most one company.
|
|
* 4. No DELETE policy: a member DELETE silently affects zero rows.
|
|
*/
|
|
|
|
describe('woocommerce_connections RLS', () => {
|
|
it('a member can insert and read their company connection', async () => {
|
|
const { userId, companyId } = await seedCompany()
|
|
await withUserContext(userId, async (client) => {
|
|
const inserted = await client.query(
|
|
`INSERT INTO public.woocommerce_connections
|
|
(company_id, user_id, store_url, status, oauth_state)
|
|
VALUES ($1, $2, 'https://shop.example.se', 'pending', gen_random_uuid())
|
|
RETURNING id`,
|
|
[companyId, userId],
|
|
)
|
|
expect(inserted.rows).toHaveLength(1)
|
|
|
|
const read = await client.query(
|
|
`SELECT status, store_url FROM public.woocommerce_connections WHERE company_id = $1`,
|
|
[companyId],
|
|
)
|
|
expect(read.rows).toEqual([
|
|
{ status: 'pending', store_url: 'https://shop.example.se' },
|
|
])
|
|
})
|
|
})
|
|
|
|
it('a non-member sees nothing and cannot insert for a foreign company', async () => {
|
|
const { userId: ownerId, companyId } = await seedCompany()
|
|
await getPool().query(
|
|
`INSERT INTO public.woocommerce_connections (company_id, user_id, store_url, status)
|
|
VALUES ($1, $2, $3, 'active')`,
|
|
[companyId, ownerId, uniqueStore('foreign')],
|
|
)
|
|
const { userId: outsiderId } = await seedCompany() // member of a DIFFERENT company
|
|
|
|
await withUserContext(outsiderId, async (client) => {
|
|
const read = await client.query(
|
|
`SELECT id FROM public.woocommerce_connections WHERE company_id = $1`,
|
|
[companyId],
|
|
)
|
|
expect(read.rows).toHaveLength(0)
|
|
|
|
await expect(
|
|
client.query(
|
|
`INSERT INTO public.woocommerce_connections (company_id, user_id, store_url, status)
|
|
VALUES ($1, $2, 'https://intruder.example.se', 'pending')`,
|
|
[companyId, outsiderId],
|
|
),
|
|
).rejects.toThrow(/row-level security/i)
|
|
})
|
|
})
|
|
|
|
it('a company may hold several ACTIVE connections (multi-store)', async () => {
|
|
const { userId, companyId } = await seedCompany()
|
|
await getPool().query(
|
|
`INSERT INTO public.woocommerce_connections (company_id, user_id, store_url, status)
|
|
VALUES ($1, $2, $3, 'active')`,
|
|
[companyId, userId, uniqueStore('store-one')],
|
|
)
|
|
const second = await getPool().query(
|
|
`INSERT INTO public.woocommerce_connections (company_id, user_id, store_url, status)
|
|
VALUES ($1, $2, $3, 'active') RETURNING id`,
|
|
[companyId, userId, uniqueStore('store-two')],
|
|
)
|
|
expect(second.rows).toHaveLength(1)
|
|
})
|
|
|
|
it('a store may be actively connected to at most one company', async () => {
|
|
const { userId: userA, companyId: companyA } = await seedCompany()
|
|
const { userId: userB, companyId: companyB } = await seedCompany()
|
|
const sharedUrl = uniqueStore('shared')
|
|
await getPool().query(
|
|
`INSERT INTO public.woocommerce_connections (company_id, user_id, store_url, status)
|
|
VALUES ($1, $2, $3, 'active')`,
|
|
[companyA, userA, sharedUrl],
|
|
)
|
|
await expect(
|
|
getPool().query(
|
|
`INSERT INTO public.woocommerce_connections (company_id, user_id, store_url, status)
|
|
VALUES ($1, $2, $3, 'active')`,
|
|
[companyB, userB, sharedUrl],
|
|
),
|
|
).rejects.toMatchObject({ code: '23505' })
|
|
|
|
// A revoked row for the same store is fine (history is kept).
|
|
const revoked = await getPool().query(
|
|
`INSERT INTO public.woocommerce_connections (company_id, user_id, store_url, status)
|
|
VALUES ($1, $2, $3, 'revoked') RETURNING id`,
|
|
[companyB, userB, sharedUrl],
|
|
)
|
|
expect(revoked.rows).toHaveLength(1)
|
|
})
|
|
|
|
it('members cannot DELETE (no DELETE policy; revoke is a status flip)', async () => {
|
|
const { userId, companyId } = await seedCompany()
|
|
const { rows } = await getPool().query(
|
|
`INSERT INTO public.woocommerce_connections (company_id, user_id, store_url, status)
|
|
VALUES ($1, $2, $3, 'active') RETURNING id`,
|
|
[companyId, userId, uniqueStore('keep')],
|
|
)
|
|
await withUserContext(userId, async (client) => {
|
|
const del = await client.query(
|
|
`DELETE FROM public.woocommerce_connections WHERE id = $1`,
|
|
[rows[0].id],
|
|
)
|
|
expect(del.rowCount).toBe(0)
|
|
})
|
|
const still = await getPool().query(
|
|
`SELECT id FROM public.woocommerce_connections WHERE id = $1`,
|
|
[rows[0].id],
|
|
)
|
|
expect(still.rows).toHaveLength(1)
|
|
})
|
|
})
|