* fix(reports): paginate 8 more report/ledger queries (1000-row truncation) Raw .select() without fetchAllRows() silently caps at PostgREST's 1000-row limit, producing wrong statutory output for high-volume companies. Following #806 (trial-balance/VAT), wrap the remaining offenders in fetchAllRows + a stable .order('id') + dedupeBy: - ink2-engine / ne-engine: INK2 & NE-bilaga tax declarations under-counted - ar-reconciliation (1510/1513), supplier-reconciliation (2440): phantom "Ej avstämd" gaps - full-archive-export: 7-year DR archive (added a unique total order so rows are not silently skipped/duplicated across pages) - avgifter-basis, currency-revaluation, vat-declaration Adds a regression guard test asserting >1000 ledger lines are summed, not truncated at 1000. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(api): close extension-dispatcher MFA gap, scope /api/events to API key, sweep dead code Security/correctness: - ext/[...path] dispatcher now uses requireAuth() instead of inline supabase.auth.getUser(), enforcing MFA (AAL2) on hosted across the whole enabled-extension surface (banking sync, document upload/booking, supplier invoices, migration). Ratchets antipatterns-baseline raw-route-auth 168->165. - /api/events now filters by the API key's bound company_id instead of the user's active company (was a cross-company read with a scoped key). - enable-banking OAuth callback calls ensureInitialized() at module load so the PSD2 consent audit event (ASVS V16 / GDPR Art.30) isn't dropped on a cold-start instance. Dead-code sweep (all confirmed zero importers): - delete lib/tax/calculator.ts, lib/salary/engangsskatt.ts (+test), lib/email/resend.ts, lib/salary/salary-transaction-matcher.ts, lib/webhooks/diff.ts, lib/salary/effective-values.ts, lib/bookkeeping/template-prompt.ts - trim unused lib/vat/eu-countries.ts helpers (keep EU_COUNTRIES) - remove dead getAutomaticStatus() and the abandoned Activepieces CSP entry Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(invoices): fail closed when a payment journal entry doesn't post Three mark-paid paths (legacy route, v1 API, agent commit) diverged on the "mark paid but the JE failed" case — two would flip the invoice to paid (or leave an orphaned posted voucher) with no booking, silently diverging the GL from the AR/AP sub-ledger. Unify on fail-closed: - legacy + v1 + agent commitMarkInvoicePaid: never mark paid without a posted voucher; on a null/failed JE return INVOICE_PAID_BOOK_FAILED before any state mutation (v1 mirrors the match-invoice strict mode). - agent path: add the .in('status',[...]).select('id') CAS guard and cancel the orphaned voucher (cancelOrphanedPaymentEntry) on a lost race or update error, matching the web route. - legacy route: cancel the orphan on a non-race update error too (was only handled on the race branch). - supplier mark-paid: stop swallowing a failed supplier_invoice_payments insert — that row drives the reversal amount in payment-sync; roll back the status flip and cancel the voucher instead. - pending-ops orchestrator: error-check the terminal 'committed' write so an op stranded in 'committing' (the expire sweep only targets 'pending') is at least logged loudly. Adds a guard test for the legacy fail-closed path. Full unit suite green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(ci): unblock core build + address compliance-review findings - avgifter-basis.ts: fix the core-build TypeScript error — PostgREST's type-level select parser models the salary_run embed as an array, which wasn't assignable to the object-typed generic. Type it `unknown` (rows are read via an explicit cast), making it robust across postgrest-js versions. - /api/events: add a non-null companyId guard before the event_log query (defense-in-depth for the API-key-bound scope) — addresses ASVS V8.2.1 / ISO A.5.15. - supplier mark-paid: add a CAS guard (.eq('status', newStatus)) to the payment-insert-failure rollback so a concurrent settlement can't be clobbered — addresses ASVS V2.3. - dispatcher: add an AAL2 regression test asserting a non-MFA session is rejected (403) and the extension handler never runs — addresses the GDPR Art.32 review ask for the single extension chokepoint. Verified deletions are safe: effective-values.ts was a dead duplicate — the live AGI/payslip path inlines the same `?? override` coalescing (generate-declaration.ts), so AGI correctness is unaffected. next build: exit 0. Full unit suite: 6147 passing. ESLint clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
94 lines
3.3 KiB
TypeScript
94 lines
3.3 KiB
TypeScript
import { createClient } from '@/lib/supabase/server'
|
|
import { NextResponse } from 'next/server'
|
|
import { extractBearerToken, validateApiKey, createServiceClientNoCookies } from '@/lib/auth/api-keys'
|
|
import { validateQuery } from '@/lib/api/validate'
|
|
import { EventsQuerySchema } from '@/lib/api/schemas'
|
|
import { requireCompanyId } from '@/lib/company/context'
|
|
import type { SupabaseClient } from '@supabase/supabase-js'
|
|
|
|
/**
|
|
* GET /api/events
|
|
*
|
|
* Cursor-based polling endpoint for external automation platforms (n8n, Make, Zapier).
|
|
* Returns events from the event_log table in sequence order.
|
|
*
|
|
* Query params:
|
|
* - after (bigint, optional): return events with sequence > this value
|
|
* - types (string, optional): comma-separated event type filter
|
|
* - limit (int, optional): max results, default 50, cap 100
|
|
*
|
|
* Supports both session auth (browser) and API key auth (automation platforms).
|
|
*/
|
|
export async function GET(request: Request) {
|
|
// Dual auth: API key or session
|
|
let userId: string
|
|
let supabase: SupabaseClient
|
|
// When authenticated via an API key, the key is BOUND to a specific company.
|
|
// Honor that binding (least privilege) rather than resolving the user's
|
|
// active company — otherwise a key scoped to company A would leak company B's
|
|
// events whenever the user's active_company_id happened to point elsewhere.
|
|
let keyCompanyId: string | null = null
|
|
|
|
const token = extractBearerToken(request)
|
|
if (token?.startsWith('gnubok_sk_')) {
|
|
const authResult = await validateApiKey(token)
|
|
if ('error' in authResult) {
|
|
return NextResponse.json({ error: authResult.error }, { status: authResult.status })
|
|
}
|
|
userId = authResult.userId
|
|
keyCompanyId = authResult.companyId
|
|
supabase = createServiceClientNoCookies()
|
|
} else {
|
|
supabase = await createClient()
|
|
const { data: { user } } = await supabase.auth.getUser()
|
|
if (!user) {
|
|
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
|
|
}
|
|
userId = user.id
|
|
}
|
|
|
|
// Session auth resolves the active company; API-key auth uses the key's bound company.
|
|
const companyId = keyCompanyId ?? await requireCompanyId(supabase, userId)
|
|
// Defense in depth: never run the event_log query with an empty/undefined
|
|
// scope. requireCompanyId throws when there is no company, but guard the
|
|
// key-bound path too so a malformed binding can't widen the query scope.
|
|
if (!companyId) {
|
|
return NextResponse.json({ error: 'Forbidden' }, { status: 403 })
|
|
}
|
|
|
|
// Validate query params
|
|
const result = validateQuery(request, EventsQuerySchema)
|
|
if (!result.success) return result.response
|
|
const { after, types, limit } = result.data
|
|
|
|
// Build query
|
|
let query = supabase
|
|
.from('event_log')
|
|
.select('sequence, event_type, entity_id, data, created_at')
|
|
.eq('company_id', companyId)
|
|
.order('sequence', { ascending: true })
|
|
.limit(limit)
|
|
|
|
if (after !== undefined) {
|
|
query = query.gt('sequence', after)
|
|
}
|
|
|
|
if (types && types.length > 0) {
|
|
query = query.in('event_type', types)
|
|
}
|
|
|
|
const { data, error } = await query
|
|
|
|
if (error) {
|
|
return NextResponse.json({ error: error.message }, { status: 500 })
|
|
}
|
|
|
|
const events = data ?? []
|
|
|
|
return NextResponse.json({
|
|
data: events,
|
|
cursor: events.length > 0 ? events[events.length - 1].sequence : (after ?? 0),
|
|
has_more: events.length === limit,
|
|
})
|
|
}
|