* fix(company): revoke store connections when archiving a company
Archiving a company left its WooCommerce/Shopify/Stripe connection rows
at status 'active'. The store-uniqueness partial indexes (one active
company per store) then blocked reconnecting the same store from any new
company with 'Butiken är redan ansluten till ett företag', and since
user_company_ids() hides archived companies there was no user-reachable
disconnect. The archive flow now flips pending/active connections to
'revoked' and nulls their secrets, mirroring the manual disconnect paths.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016GTvGjEvpyqkepRmrtr5Vj
* fix(company): audit connection revocations and cover error path on archive
Review findings (compliance swarm A.8.15/A.8.29 + skeptic pass):
- write audit_log rows for each revoked store connection (the tables
have no auto-audit trigger)
- revoke via .neq('status','revoked') so 'error'-state rows, which can
also carry credentials, are cleared too
- test that the archive still succeeds when a connection revoke fails
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016GTvGjEvpyqkepRmrtr5Vj
* fix(company): literal payloads for connection revokes (phantom-column ceiling)
The spread/mapped payloads registered as unresolvable expressions in
tests/schema/no-phantom-columns.test.ts (392 > ceiling 391). Inline each
table's update as an object literal and insert audit rows one per row.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016GTvGjEvpyqkepRmrtr5Vj
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>