* feat(peppol): receive e-invoices via Qvalia: registration, inbound archive, inbox delivery Second Peppol slice (#546). Qvalia confirmed that sending needs no per-company account, so receiving keeps the consolidated partner account: each company publishes its 0007:orgnr on our account and inbound documents are routed by the AccountingCustomerParty endpoint. - PeppolTransport grows optional receiving methods (registerRecipient, unregisterRecipient, listInboundDocuments, fetchInboundDocumentXml); the Qvalia adapter implements them (PUT/DELETE /peppol/{id}, readinvoices / readcreditnotes, exact XML fetch). - lib/invoices/peppol-inbound-ubl.ts reads the provider's UBL-JSON (xml2js-style prefixed keys, verified against Qvalia's real inbound test invoice, kept as a fixture) into a neutral document: parties, payment means with SE:BANKGIRO/SE:PLUSGIRO/IBAN, totals, VAT subtotals, lines, embedded attachments, credit notes. - Migration 20260821170000: peppol_registrations (one live row per company and participant), peppol_inbound_documents (exact XML immutable and undeletable, routed once), invoice_inbox_items.source gains 'peppol' with a per-channel dedupe index; pg-real test covers RLS, uniqueness, immutability and routing. - POST/DELETE/GET /api/settings/peppol + "E-faktura via Peppol" switch in Settings > Fakturering; personnummer-based companies are refused until 0088 GLN exists; sandbox refused. - GET /api/peppol/inbound/cron every 10 minutes: archive, route, deliver. lib/invoices/peppol-inbox-delivery.ts archives the XML as a WORM document (upload_source e_invoice, extractionOwner none), an embedded PDF when present, and creates the inbox row with the extraction filled from the UBL (confidence 1, no model pass), matching the supplier by org number. The existing inbox review/convert flow takes over. - document-service accepts application/xml for the archive; inbox list shows a Peppol icon. Refs #546 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TqFpxeWqbpR7bcwUJLRERQ * test(peppol): archive contract, pg fixture and phantom-column ceiling for the receiving tables The two new tables are räkenskapsinformation and join MASTER_DATA_DUMP_TABLES; the pg fixture for a deregistered row now carries deregistered_at as the status-shape constraint requires; the archive insert is an inline literal and the one generic processing-state updater is accounted for in the ceiling. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TqFpxeWqbpR7bcwUJLRERQ --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
165 lines
6.7 KiB
TypeScript
165 lines
6.7 KiB
TypeScript
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest'
|
|
import { NextResponse } from 'next/server'
|
|
import { createMockRequest, createQueuedMockSupabase } from '@/tests/helpers'
|
|
import { registerPeppolTransport, type PeppolTransport } from '@/lib/invoices/peppol-transport'
|
|
|
|
const { supabase: mockSupabase, enqueue, reset } = createQueuedMockSupabase()
|
|
const service = createQueuedMockSupabase()
|
|
const requireAuthMock = vi.fn()
|
|
|
|
vi.mock('@/lib/init', () => ({ ensureInitialized: vi.fn() }))
|
|
vi.mock('@/lib/auth/require-auth', () => ({
|
|
requireAuth: (...args: unknown[]) => requireAuthMock(...args),
|
|
}))
|
|
vi.mock('@/lib/company/context', () => ({
|
|
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
|
|
}))
|
|
vi.mock('@/lib/auth/require-write', () => ({
|
|
requireWritePermission: vi.fn().mockResolvedValue({ ok: true }),
|
|
}))
|
|
vi.mock('@/lib/supabase/server', () => ({
|
|
createServiceClient: () => service.supabase,
|
|
}))
|
|
|
|
import { DELETE, GET, POST } from '../route'
|
|
|
|
const user = { id: 'user-1', email: 'owner@example.test' }
|
|
const registeredRow = {
|
|
id: 'reg-1',
|
|
company_id: 'company-1',
|
|
user_id: 'user-1',
|
|
provider: 'qvalia',
|
|
provider_account_reference: 'SE5595386219',
|
|
participant_scheme: '0007',
|
|
participant_identifier: '5595386219',
|
|
status: 'registered',
|
|
business_card: {},
|
|
document_types: [],
|
|
registered_at: '2026-08-21T16:00:00.000Z',
|
|
deregistered_at: null,
|
|
last_error: null,
|
|
created_at: '2026-08-21T15:59:00.000Z',
|
|
updated_at: '2026-08-21T16:00:00.000Z',
|
|
}
|
|
|
|
function makeTransport(overrides: Partial<PeppolTransport> = {}): PeppolTransport {
|
|
return {
|
|
provider: 'qvalia',
|
|
lookupRecipient: vi.fn(),
|
|
submit: vi.fn(),
|
|
verifyWebhook: vi.fn(),
|
|
retrieveEvidence: vi.fn(),
|
|
registerRecipient: vi.fn().mockResolvedValue({
|
|
status: 'registered',
|
|
participant: { scheme: '0007', identifier: '5595386219' },
|
|
providerAccountReference: 'SE5595386219',
|
|
raw: {},
|
|
}),
|
|
unregisterRecipient: vi.fn().mockResolvedValue(undefined),
|
|
...overrides,
|
|
}
|
|
}
|
|
|
|
describe('/api/settings/peppol', () => {
|
|
let unregister: (() => void) | null = null
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
reset()
|
|
service.reset()
|
|
process.env.PEPPOL_TRANSPORT_PROVIDER = 'qvalia'
|
|
requireAuthMock.mockResolvedValue({ user, supabase: mockSupabase, error: null })
|
|
})
|
|
|
|
afterEach(() => {
|
|
unregister?.()
|
|
unregister = null
|
|
delete process.env.PEPPOL_TRANSPORT_PROVIDER
|
|
})
|
|
|
|
it('GET returns 401 when not authenticated', async () => {
|
|
requireAuthMock.mockResolvedValue({
|
|
user: null,
|
|
supabase: mockSupabase,
|
|
error: NextResponse.json({ error: 'Unauthorized' }, { status: 401 }),
|
|
})
|
|
const response = await GET(createMockRequest('/api/settings/peppol'))
|
|
expect(response.status).toBe(401)
|
|
})
|
|
|
|
it('GET tells the truth when no access point is switched on', async () => {
|
|
delete process.env.PEPPOL_TRANSPORT_PROVIDER
|
|
const response = await GET(createMockRequest('/api/settings/peppol'))
|
|
const body = await response.json()
|
|
expect(response.status).toBe(200)
|
|
expect(body.data).toMatchObject({
|
|
transport: { available: false },
|
|
receiving_supported: false,
|
|
registration: null,
|
|
})
|
|
})
|
|
|
|
it('GET returns the live registration when the adapter supports receiving', async () => {
|
|
unregister = registerPeppolTransport(makeTransport())
|
|
enqueue({ data: [registeredRow], error: null })
|
|
const response = await GET(createMockRequest('/api/settings/peppol'))
|
|
const body = await response.json()
|
|
expect(response.status).toBe(200)
|
|
expect(body.data.receiving_supported).toBe(true)
|
|
expect(body.data.registration).toMatchObject({ status: 'registered', participant_identifier: '5595386219' })
|
|
expect(body.data.registration).not.toHaveProperty('business_card')
|
|
})
|
|
|
|
it('POST refuses without a transport and in the sandbox', async () => {
|
|
delete process.env.PEPPOL_TRANSPORT_PROVIDER
|
|
expect((await POST(createMockRequest('/api/settings/peppol', { method: 'POST' }))).status).toBe(503)
|
|
|
|
process.env.PEPPOL_TRANSPORT_PROVIDER = 'qvalia'
|
|
unregister = registerPeppolTransport(makeTransport())
|
|
enqueue({ data: { is_sandbox: true }, error: null })
|
|
const response = await POST(createMockRequest('/api/settings/peppol', { method: 'POST' }))
|
|
expect(response.status).toBe(403)
|
|
expect((await response.json()).error.code).toBe('PEPPOL_SANDBOX_NOT_ALLOWED')
|
|
})
|
|
|
|
it('POST registers the company and returns the minimized registration', async () => {
|
|
const transport = makeTransport()
|
|
unregister = registerPeppolTransport(transport)
|
|
enqueue({ data: { is_sandbox: false }, error: null })
|
|
enqueue({ data: { org_number: '559538-6219', company_name: 'Arcim Technology AB', vat_number: 'SE559538621901', city: 'Stockholm', country: 'SE' }, error: null })
|
|
service.enqueue({ data: [], error: null }) // existing
|
|
service.enqueue({ data: { id: 'reg-1' }, error: null }) // insert pending
|
|
service.enqueue({ data: registeredRow, error: null }) // finalize
|
|
|
|
const response = await POST(createMockRequest('/api/settings/peppol', { method: 'POST' }))
|
|
const body = await response.json()
|
|
expect(response.status).toBe(201)
|
|
expect(body.data.registration).toMatchObject({ status: 'registered', participant_scheme: '0007' })
|
|
expect(transport.registerRecipient).toHaveBeenCalledTimes(1)
|
|
})
|
|
|
|
it('POST maps a personnummer-based company to a 422 with the reason', async () => {
|
|
unregister = registerPeppolTransport(makeTransport())
|
|
enqueue({ data: { is_sandbox: false }, error: null })
|
|
enqueue({ data: { org_number: '800101-1234', company_name: 'Firma', vat_number: null, city: null, country: 'SE' }, error: null })
|
|
const response = await POST(createMockRequest('/api/settings/peppol', { method: 'POST' }))
|
|
expect(response.status).toBe(422)
|
|
expect((await response.json()).error.code).toBe('PEPPOL_REGISTRATION_PERSONAL_NUMBER')
|
|
})
|
|
|
|
it('DELETE withdraws the identifier and 404s when nothing is live', async () => {
|
|
const transport = makeTransport()
|
|
unregister = registerPeppolTransport(transport)
|
|
service.enqueue({ data: [registeredRow], error: null })
|
|
service.enqueue({ data: { ...registeredRow, status: 'deregistered', deregistered_at: '2026-08-21T17:00:00.000Z' }, error: null })
|
|
const ok = await DELETE(createMockRequest('/api/settings/peppol', { method: 'DELETE' }))
|
|
expect(ok.status).toBe(200)
|
|
expect((await ok.json()).data.registration.status).toBe('deregistered')
|
|
expect(transport.unregisterRecipient).toHaveBeenCalledWith({ scheme: '0007', identifier: '5595386219' })
|
|
|
|
service.enqueue({ data: [], error: null })
|
|
const missing = await DELETE(createMockRequest('/api/settings/peppol', { method: 'DELETE' }))
|
|
expect(missing.status).toBe(404)
|
|
})
|
|
})
|