* feat(onboarding): company setup from the conversation and POST /api/v1/companies Third PR of agent-first onboarding (#1814). Once connected, the agent can now set up a company end to end without the web wizard, and partner platforms can provision companies over REST. - create_company_for_user: service-role-only SECURITY DEFINER twin of create_company_with_owner taking the owner explicitly (service clients have no auth.uid()). pg-real test covers creation, role gating, unknown owner and foreign team. - lib/company/create-company.ts: the wizard's creation sequence (org number, TIC snapshot, BAS chart, settings, first fiscal period, tax deadlines, rollback) extracted into createCompanyCore; the Server Action delegates to it, behaviour unchanged. - lib/company/onboarding-input.ts: one Zod schema + planner for the agent/API paths; a VAT-registered company without moms_period is refused (a missing period silently yields zero VAT deadlines). - MCP: gnubok_create_company (two-phase: preview, then confirm=true; companies:write, company-independent), gnubok_connect_bank and gnubok_connect_skatteverket (status + the browser link, gated on bank_sync / skatteverket, search-only in the catalog), the "onboarding" skill, and initialize instructions pointing at it. - Consent page pre-ticks companies:write for an account with no company yet, so the setup does not dead-end on insufficient scope after signup. - POST /api/v1/companies (companies:write, dry-run aware) on the same core; scope map, registry, spec snapshot and the generated API skill updated. - tools/list payload ceiling raised 59.95K -> 60.4K for the one new default-catalog tool (documented in the guard). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * fix(onboarding): explicit f_skatt, org number when VAT-registered, EF first year ends 31 Dec Review findings on #1864 (Swedish compliance review): - f_skatt is required, never defaulted to approved (SE-R-005 risk). - org_number is required when vat_registered: the invoice momsregistreringsnummer derives from it (ML 17 kap 24 §). - An enskild firma's first fiscal year must end on 31 December and its start month is forced to 1 even with first_fiscal_year set, mirroring the wizard's own rule text (BFL 3 kap. 1 §). - POST /api/v1/companies no longer claims Idempotency-Key support (the wrapper only honours it on company-scoped routes). - pg-real: createCompanyCore's chart seed runs under the real service_role, which the unit tests could not prove. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * test(pg): starter chart has 41 accounts, assert non-empty The service_role chart-seed proof passed the part that mattered (no 42501 from seed_chart_of_accounts) and failed on a wrong row-count guess: the seeded chart is a curated starter set, not the full BAS list. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * fix(migrations): move create_company_for_user to 20260825120000 main gained 20260824170000_bulk_book_transactions_service_actor.sql with the same version while this branch was open; two files on one version abort every Supabase branch apply and the prod auto-apply. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * chore(api): refresh spec snapshot and generated skill after rebasing onto main Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * fix(mcp): flat create_company result, refuse localhost connect links, test hygiene CodeRabbit on #1864: the confirmed-create result was wrapped in the { data, next } envelope while its outputSchema promised top-level fields; it now returns the fields with next as a sibling. The two connect-link tools refuse to build a link when NEXT_PUBLIC_APP_URL is unset instead of handing a remote user a localhost URL. Tests clear mocks and the event bus in beforeEach. Not changed: the rollback already survives user_preferences.active_company_id (that FK is ON DELETE SET NULL since 20260331010000), and v1 error details stay in the surface's English developer convention. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
190 lines
6.3 KiB
TypeScript
190 lines
6.3 KiB
TypeScript
/**
|
|
* POST /api/v1/companies (issue #1814 PR 3): programmatic company creation
|
|
* for partner provisioning and agents. Same static-route context shape as the
|
|
* GET tests (Next.js 16 passes `{ params: undefined }`).
|
|
*/
|
|
import { beforeAll, beforeEach, describe, expect, it, vi } from 'vitest'
|
|
|
|
beforeAll(() => {
|
|
process.env.NEXT_PUBLIC_SUPABASE_URL ||= 'http://localhost:54321'
|
|
process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY ||= 'test-anon-key'
|
|
})
|
|
|
|
const mocks = vi.hoisted(() => ({
|
|
createCompanyCore: vi.fn(),
|
|
}))
|
|
|
|
vi.mock('@/lib/auth/api-keys', async () => {
|
|
const actual = await vi.importActual<typeof import('@/lib/auth/api-keys')>('@/lib/auth/api-keys')
|
|
return {
|
|
...actual,
|
|
validateApiKey: vi.fn(),
|
|
createServiceClientNoCookies: vi.fn(),
|
|
}
|
|
})
|
|
|
|
vi.mock('@supabase/supabase-js', async () => {
|
|
const actual = await vi.importActual<typeof import('@supabase/supabase-js')>('@supabase/supabase-js')
|
|
return { ...actual, createClient: vi.fn().mockReturnValue({}) }
|
|
})
|
|
|
|
vi.mock('@/lib/company/create-company', () => ({
|
|
createCompanyCore: (...args: unknown[]) => mocks.createCompanyCore(...args),
|
|
}))
|
|
|
|
import { validateApiKey, createServiceClientNoCookies } from '@/lib/auth/api-keys'
|
|
import { POST as createCompany } from '../route'
|
|
|
|
const mockValidate = validateApiKey as ReturnType<typeof vi.fn>
|
|
const mockServiceClient = createServiceClientNoCookies as ReturnType<typeof vi.fn>
|
|
|
|
const USER_ID = '930abb54-c5ef-4ae0-b274-30fb16e9a295'
|
|
const TEAM_ID = '44444444-4444-4444-8444-444444444444'
|
|
const COMPANY_ID = '55555555-5555-4555-8555-555555555555'
|
|
|
|
function makeSupabase(teamId: string | null) {
|
|
const chain: Record<string, ReturnType<typeof vi.fn>> = {
|
|
select: vi.fn(() => chain),
|
|
eq: vi.fn(() => chain),
|
|
order: vi.fn(() => chain),
|
|
limit: vi.fn(() => chain),
|
|
maybeSingle: vi.fn().mockResolvedValue({ data: teamId ? { team_id: teamId } : null, error: null }),
|
|
}
|
|
return {
|
|
from: vi.fn(() => chain),
|
|
rpc: vi.fn().mockResolvedValue({ data: COMPANY_ID, error: null }),
|
|
}
|
|
}
|
|
|
|
function makeRequest(body: unknown, headers: Record<string, string> = {}): Request {
|
|
return new Request('https://x.test/api/v1/companies', {
|
|
method: 'POST',
|
|
headers: {
|
|
Authorization: 'Bearer test-fixture-not-a-real-key',
|
|
'Content-Type': 'application/json',
|
|
'Idempotency-Key': 'idem-1',
|
|
...headers,
|
|
},
|
|
body: typeof body === 'string' ? body : JSON.stringify(body),
|
|
})
|
|
}
|
|
|
|
type PostCtx = Parameters<typeof createCompany>[1]
|
|
const staticRouteContext = () => ({ params: undefined } as unknown as PostCtx)
|
|
|
|
const validBody = {
|
|
name: 'Acme AB',
|
|
entity_type: 'aktiebolag',
|
|
org_number: '5560000001',
|
|
vat_registered: true,
|
|
moms_period: 'quarterly',
|
|
accounting_method: 'accrual',
|
|
f_skatt: true,
|
|
}
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
mockValidate.mockResolvedValue({
|
|
userId: USER_ID,
|
|
companyId: null,
|
|
apiKeyId: 'key-1',
|
|
apiKeyName: 'Partner key',
|
|
scopes: ['companies:write', 'companies:read'],
|
|
mode: 'live',
|
|
})
|
|
mockServiceClient.mockReturnValue(makeSupabase(TEAM_ID))
|
|
mocks.createCompanyCore.mockImplementation(
|
|
async (_client: unknown, _input: unknown, createRow: () => Promise<{ data: unknown; error: unknown }>) => {
|
|
const { data } = await createRow()
|
|
return { companyId: data as string }
|
|
}
|
|
)
|
|
})
|
|
|
|
describe('POST /api/v1/companies', () => {
|
|
it('returns 401 for a missing bearer token', async () => {
|
|
const request = new Request('https://x.test/api/v1/companies', {
|
|
method: 'POST',
|
|
body: JSON.stringify(validBody),
|
|
headers: { 'Content-Type': 'application/json' },
|
|
})
|
|
const res = await createCompany(request, staticRouteContext())
|
|
expect(res.status).toBe(401)
|
|
})
|
|
|
|
it('returns 403 without companies:write', async () => {
|
|
mockValidate.mockResolvedValue({
|
|
userId: USER_ID,
|
|
companyId: null,
|
|
apiKeyId: 'key-1',
|
|
apiKeyName: 'Read key',
|
|
scopes: ['companies:read'],
|
|
mode: 'live',
|
|
})
|
|
const res = await createCompany(makeRequest(validBody), staticRouteContext())
|
|
expect(res.status).toBe(403)
|
|
expect(mocks.createCompanyCore).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('returns 400 for a VAT-registered company without a moms period', async () => {
|
|
const res = await createCompany(makeRequest({ ...validBody, moms_period: undefined }), staticRouteContext())
|
|
expect(res.status).toBe(400)
|
|
const body = await res.json()
|
|
expect(JSON.stringify(body)).toContain('moms_period')
|
|
expect(mocks.createCompanyCore).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('returns 400 for a body that is not JSON', async () => {
|
|
const res = await createCompany(makeRequest('not json'), staticRouteContext())
|
|
expect(res.status).toBe(400)
|
|
})
|
|
|
|
it('creates the company through the service-role RPC for the key user and returns 201', async () => {
|
|
const supabase = makeSupabase(TEAM_ID)
|
|
mockServiceClient.mockReturnValue(supabase)
|
|
|
|
const res = await createCompany(makeRequest(validBody), staticRouteContext())
|
|
expect(res.status).toBe(201)
|
|
const body = await res.json()
|
|
expect(body.data).toMatchObject({
|
|
id: COMPANY_ID,
|
|
name: 'Acme AB',
|
|
entity_type: 'aktiebolag',
|
|
org_number: '5560000001',
|
|
vat_registered: true,
|
|
moms_period: 'quarterly',
|
|
team_id: TEAM_ID,
|
|
})
|
|
expect(body.data.fiscal_period.name).toContain('Räkenskapsår')
|
|
expect(supabase.rpc).toHaveBeenCalledWith('create_company_for_user', {
|
|
p_user_id: USER_ID,
|
|
p_name: 'Acme AB',
|
|
p_entity_type: 'aktiebolag',
|
|
p_team_id: TEAM_ID,
|
|
})
|
|
})
|
|
|
|
it('previews without creating for a test-mode key (dry run)', async () => {
|
|
mockValidate.mockResolvedValue({
|
|
userId: USER_ID,
|
|
companyId: null,
|
|
apiKeyId: 'key-1',
|
|
apiKeyName: 'Test key',
|
|
scopes: ['companies:write'],
|
|
mode: 'test',
|
|
})
|
|
const res = await createCompany(makeRequest(validBody), staticRouteContext())
|
|
expect(res.status).toBe(200)
|
|
const body = await res.json()
|
|
expect(body.data.dry_run).toBe(true)
|
|
expect(body.data.preview.name).toBe('Acme AB')
|
|
expect(mocks.createCompanyCore).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('maps a creation failure to INTERNAL_ERROR', async () => {
|
|
mocks.createCompanyCore.mockResolvedValue({ error: 'Kunde inte skapa kontoplan. Försök igen.' })
|
|
const res = await createCompany(makeRequest(validBody), staticRouteContext())
|
|
expect(res.status).toBe(500)
|
|
})
|
|
})
|