Files
accounted/app/api/extensions/enable-banking/sync/cron/route.ts
T
MattssonandClaude Opus 4.7 9e1e13d388 Fix/bank and onboarding (#413)
* fix(onboarding): validate org number at step 2 instead of final submit

Run normalizeOrgNumber (Luhn + 10/12-digit check) inside the Step 2
Zod schema and gate the duplicate-check and TIC lookup effects on it,
so users get an inline error on the field they just typed instead of
filling out two more steps and being bounced back from the server.
Server-side check stays as defense in depth. Also fixes the old regex
incorrectly rejecting valid 12-digit org numbers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(reconciliation): pass real userId to transaction.reconciled events

runReconciliation and manualLink fell back to companyId when no userId
was provided, causing FK violations on event_log.user_id (which references
auth.users). Make userId a required arg in both functions, drop the
fallback, and forward a real user id from every caller (user.id from
authed routes, connection.user_id from the cron path).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* refactor(enable-banking): use local companyId instead of reinlining ctx fallback

Three sites in the enable-banking sync handler reinline `ctx?.companyId ?? user.id`
instead of using the local `companyId` declared at the top of the block. Collapse
all three to the local for consistency and to remove drift risk if the fallback
expression ever changes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-07 13:32:06 +02:00

326 lines
11 KiB
TypeScript

import { createClient, type SupabaseClient } from '@supabase/supabase-js'
import { NextResponse } from 'next/server'
import { syncAccountTransactions } from '@/extensions/general/enable-banking/lib/sync'
import { runReconciliation } from '@/lib/reconciliation/bank-reconciliation'
import { isConsentExpiringSoon, getDaysUntilExpiry } from '@/extensions/general/enable-banking/lib/api-client'
import { getEmailService } from '@/lib/email/service'
import {
generateConsentExpiryEmailHtml,
generateConsentExpiryEmailText,
generateConsentExpiryEmailSubject,
} from '@/lib/email/consent-notification-templates'
import { ensureInitialized } from '@/lib/init'
import { withCronContext } from '@/lib/api/with-cron-context'
import { errorResponse, errorResponseFromCode } from '@/lib/errors/get-structured-error'
import { getBranding } from '@/lib/branding/service'
import type { StoredAccount } from '@/extensions/general/enable-banking/types'
ensureInitialized()
/**
* GET /api/extensions/enable-banking/sync/cron
* Automatic daily bank transaction sync
* Runs at 05:00 UTC (07:00 Swedish time)
*
* Processes up to 50 connections per run (Vercel Pro 300s timeout).
* Prioritizes connections not synced for the longest time.
* Deduplication via external_id makes repeated runs safe.
*/
export const GET = withCronContext('cron.bank_sync', async (_request, ctx) => {
const supabaseUrl = process.env.NEXT_PUBLIC_SUPABASE_URL
const supabaseServiceKey = process.env.SUPABASE_SERVICE_ROLE_KEY
if (!supabaseUrl || !supabaseServiceKey) {
return errorResponseFromCode('INTERNAL_ERROR', ctx.log, {
requestId: ctx.requestId,
details: { reason: 'Missing Supabase configuration' },
})
}
const supabase = createClient(supabaseUrl, supabaseServiceKey)
// Clean up stale pending connections (older than 1 hour)
const oneHourAgo = new Date(Date.now() - 60 * 60 * 1000).toISOString()
const { data: stalePending } = await supabase
.from('bank_connections')
.delete()
.eq('status', 'pending')
.lt('created_at', oneHourAgo)
.select('id')
if (stalePending?.length) {
ctx.log.info('cleaned up stale pending connections', { count: stalePending.length })
}
const { data: connections, error: connError } = await supabase
.from('bank_connections')
.select('*')
.eq('status', 'active')
.order('last_synced_at', { ascending: true, nullsFirst: true })
.limit(50)
if (connError) {
ctx.log.error('failed to fetch bank connections', connError, {
message: connError.message,
code: connError.code,
})
return errorResponse(connError, ctx.log, { requestId: ctx.requestId })
}
if (!connections || connections.length === 0) {
return NextResponse.json({ message: 'No active connections to sync', processed: 0 })
}
const startTime = Date.now()
const TIME_BUDGET_MS = 50_000 // 50s — leave 10s margin for Vercel timeout
const baseUrl = process.env.NEXT_PUBLIC_APP_URL || 'http://localhost:3000'
const results: {
connectionId: string
userId: string
bankName: string
imported: number
duplicates: number
errors: number
status: 'synced' | 'expired' | 'expiring_soon' | 'error'
daysUntilExpiry?: number | null
}[] = []
for (const connection of connections) {
if (Date.now() - startTime > TIME_BUDGET_MS) {
ctx.log.info('time budget reached', { processedSoFar: results.length })
break
}
try {
const daysLeft = getDaysUntilExpiry(connection.consent_expires)
const isExpired = daysLeft !== null && daysLeft <= 0
if (isExpired) {
await supabase
.from('bank_connections')
.update({ status: 'expired' })
.eq('id', connection.id)
// Send expiry notification
await sendConsentExpiryNotification(
supabase, connection, 0, true, baseUrl
)
results.push({
connectionId: connection.id,
userId: connection.user_id,
bankName: connection.bank_name,
imported: 0,
duplicates: 0,
errors: 0,
status: 'expired',
daysUntilExpiry: 0,
})
continue
}
const expiringSoon = isConsentExpiringSoon(connection.consent_expires)
// Send consent expiry notifications at 7-day and 3-day thresholds
if (expiringSoon && daysLeft !== null && (daysLeft <= 3 || daysLeft === 7)) {
await sendConsentExpiryNotification(
supabase, connection, daysLeft, false, baseUrl
)
}
const toDate = new Date().toISOString().split('T')[0]
// First sync: 90-day lookback (PSD2 max). Subsequent: 7-day window.
const isFirstSync = !connection.last_synced_at
const lookbackDays = isFirstSync ? 90 : 7
if (isFirstSync) {
ctx.log.info('first sync for connection — using 90-day lookback', {
connectionId: connection.id,
lookbackDays,
})
}
const fromDate = new Date(Date.now() - lookbackDays * 24 * 60 * 60 * 1000)
.toISOString()
.split('T')[0]
const accounts = (connection.accounts_data as StoredAccount[] || []).map(a => ({ ...a }))
// Detect SIE overlap — skip auto-categorization if the sync range
// overlaps with a completed SIE import to prevent double-booking
const { data: sieOverlap } = await supabase
.from('sie_imports')
.select('id')
.eq('company_id', connection.company_id)
.eq('status', 'completed')
.gte('fiscal_year_end', fromDate)
.limit(1)
.maybeSingle()
const syncOptions = sieOverlap
? { skipAutoCategorization: true }
: undefined
const syncResults = await Promise.all(
accounts.map(account => syncAccountTransactions(
supabase,
connection.company_id,
connection.user_id,
connection.id,
account,
fromDate,
toDate,
undefined,
syncOptions
))
)
const totalImported = syncResults.reduce((sum, r) => sum + r.imported, 0)
const totalDuplicates = syncResults.reduce((sum, r) => sum + r.duplicates, 0)
const totalErrors = syncResults.reduce((sum, r) => sum + r.errors, 0)
// Batch reconciliation sweep when SIE overlap detected
if (sieOverlap && totalImported > 0) {
try {
await runReconciliation(supabase, connection.company_id, connection.user_id, {
dateFrom: fromDate,
dateTo: toDate,
})
} catch {
// Non-critical
}
}
// Successful sync: update connection and clear any previous error state
await supabase
.from('bank_connections')
.update({
accounts_data: accounts,
last_synced_at: new Date().toISOString(),
...(connection.error_message ? { error_message: null } : {}),
})
.eq('id', connection.id)
results.push({
connectionId: connection.id,
userId: connection.user_id,
bankName: connection.bank_name,
imported: totalImported,
duplicates: totalDuplicates,
errors: totalErrors,
status: expiringSoon ? 'expiring_soon' : 'synced',
daysUntilExpiry: daysLeft,
})
} catch (error) {
const message = error instanceof Error ? error.message : 'Unknown error'
ctx.log.error('sync failed for connection', error as Error, {
connectionId: connection.id,
userId: connection.user_id,
bankName: connection.bank_name,
consentExpires: connection.consent_expires,
lastSyncedAt: connection.last_synced_at,
})
// Persist error status on sync failure
await supabase
.from('bank_connections')
.update({ status: 'error', error_message: message })
.eq('id', connection.id)
results.push({
connectionId: connection.id,
userId: connection.user_id,
bankName: connection.bank_name,
imported: 0,
duplicates: 0,
errors: 1,
status: 'error',
})
}
}
const totalImported = results.reduce((sum, r) => sum + r.imported, 0)
const totalExpired = results.filter(r => r.status === 'expired').length
const totalExpiringSoon = results.filter(r => r.status === 'expiring_soon').length
const totalFailed = results.filter(r => r.status === 'error').length
ctx.log.info('bank sync summary', {
processed: results.length,
totalImported,
totalExpired,
totalExpiringSoon,
totalFailed,
})
return NextResponse.json({
processed: results.length,
totalImported,
totalExpired,
totalExpiringSoon,
totalFailed,
results,
})
})
/**
* Send consent expiry notification email.
* Guards with last_expiry_notification_at to avoid spamming (2-day cooldown).
*/
// eslint-disable-next-line @typescript-eslint/no-explicit-any
async function sendConsentExpiryNotification(
supabase: SupabaseClient<any>,
connection: Record<string, unknown>,
daysLeft: number,
isExpired: boolean,
baseUrl: string
): Promise<void> {
try {
// Check cooldown: skip if notified within last 2 days
const lastNotified = connection.last_expiry_notification_at as string | null
if (lastNotified) {
const hoursSinceNotified = (Date.now() - new Date(lastNotified).getTime()) / (1000 * 60 * 60)
if (hoursSinceNotified < 48) return
}
const emailService = getEmailService()
if (!emailService.isConfigured()) return
const userId = connection.user_id as string
// Look up user email
const { data: userData } = await supabase.auth.admin.getUserById(userId)
if (!userData?.user?.email) return
// Look up company name
const { data: companySettings } = await supabase
.from('company_settings')
.select('company_name')
.eq('company_id', connection.company_id)
.single()
const emailData = {
bankName: connection.bank_name as string,
daysUntilExpiry: daysLeft,
renewalUrl: `${baseUrl}/settings/banking`,
companyName: companySettings?.company_name || getBranding().appName.toLowerCase(),
isExpired,
}
await emailService.sendEmail({
to: userData.user.email,
subject: generateConsentExpiryEmailSubject(emailData),
html: generateConsentExpiryEmailHtml(emailData),
text: generateConsentExpiryEmailText(emailData),
})
// Update last notification timestamp
await supabase
.from('bank_connections')
.update({ last_expiry_notification_at: new Date().toISOString() })
.eq('id', connection.id as string)
} catch (error) {
// Notification failure must not break the cron job — log only.
// eslint-disable-next-line no-console
console.error('[bank-sync-cron] failed to send consent expiry notification:', error)
}
}