Files
accounted/app/api
MattssonandClaude Fable 5 b74b5e3c0d fix(company): revoke store connections when archiving a company (#2096)
* fix(company): revoke store connections when archiving a company

Archiving a company left its WooCommerce/Shopify/Stripe connection rows
at status 'active'. The store-uniqueness partial indexes (one active
company per store) then blocked reconnecting the same store from any new
company with 'Butiken är redan ansluten till ett företag', and since
user_company_ids() hides archived companies there was no user-reachable
disconnect. The archive flow now flips pending/active connections to
'revoked' and nulls their secrets, mirroring the manual disconnect paths.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016GTvGjEvpyqkepRmrtr5Vj

* fix(company): audit connection revocations and cover error path on archive

Review findings (compliance swarm A.8.15/A.8.29 + skeptic pass):
- write audit_log rows for each revoked store connection (the tables
  have no auto-audit trigger)
- revoke via .neq('status','revoked') so 'error'-state rows, which can
  also carry credentials, are cleared too
- test that the archive still succeeds when a connection revoke fails

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016GTvGjEvpyqkepRmrtr5Vj

* fix(company): literal payloads for connection revokes (phantom-column ceiling)

The spread/mapped payloads registered as unresolvable expressions in
tests/schema/no-phantom-columns.test.ts (392 > ceiling 391). Inline each
table's update as an object literal and insert audit rows one per row.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016GTvGjEvpyqkepRmrtr5Vj

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 11:12:12 +02:00
..
2026-07-25 22:56:17 +02:00
2026-07-23 16:16:55 +02:00
2026-07-05 03:05:09 +02:00
2026-07-08 09:54:46 +02:00