* fix(tic): call /enrichment before /collect to avoid session-consume bug
TIC support confirmed (2026-04-24) that reading session status via /poll or
/collect after the BankID session reaches `complete` marks the session as
"consumed" server-side, after which /api/v1/enrichment refuses the sessionId
with `error: "Session not completed"` (returned as HTTP 200, not 400).
Today's flow inside POST /api/extensions/ext/tic/bankid/complete called
collectBankIdResult and then requestEnrichment — exactly the order that
triggers the bug. Login still succeeded (collect itself returns OK), but
enrichment failed 100% of the time, leaving extension_data.bankid_enrichment
empty and /select-company's CompanyRoles picker blank.
Reorder so /enrichment runs first, then /collect. Per TIC, the consume flag
only blocks subsequent /enrichment calls — collect after enrichment is
harmless. Refactor the existing fetchAndStoreEnrichment helper into
fetchEnrichmentSafely (pure fetch, returns EnrichmentData | null) and
storeEnrichment (pure DB upsert), so the data can be captured before the
collect/user-creation logic and persisted afterward.
Enrichment stays non-blocking: any /enrichment failure still logs a warning
and lets login proceed, exactly as today.
Adds a regression test asserting requestEnrichment is invoked before
collectBankIdResult (via mock.invocationCallOrder) plus tests for both
failure modes — enrichment throwing and TIC returning the production
"Session not completed" body shape.
Ref: TIC session 90f7da27-84b2-4f09-afc4-47239eef57c1.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(tic): drop redundant void _omit — _ prefix already silences lint
Per PR review: @typescript-eslint/no-unused-vars ignores `_`-prefixed
identifiers by default, so the void expression is dead weight.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>