* feat(settings): per-company opt-in for data analysis of bookkeeping outcomes (#1346) Adds company_settings.data_analysis_opt_in (default false, no grandfathering) and gates every path that reads bookkeeping outcomes across companies on it: POST /api/agent/categorize/outcome stops writing calibration samples for companies that have not opted in, and the backtest / calibration-fit scripts filter to opted-in company ids. One helper (lib/company/data-analysis.ts) is the single gate for future analysis paths. A toggle on Inställningar > Företag states plainly what is analysed (proposed vs booked account, amount, confidence; no free text, no personal data) in sv and en. The flag is UI-only by design: consent is a human action, so it is absent from the v1 REST / MCP settings pick lists. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nAd8XJ2RPCmG2eKoLBdna * fix(settings): make data-analysis consent copy true for the backtest path (#1346) Addresses adversarial review findings on PR #2007: - Findings 1-3 (consent narrower than the gated processing): the flag also gates scripts/backtest-categorize.ts, which re-runs transaction descriptions, merchant names and matched underlag through the model. The sv/en toggle help and disclosure now state that explicitly as "evaluation runs" and no longer claim that free text or underlag are excluded. The migration header and COMMENT, the lib/company/data-analysis.ts docstring, the backtest script header and the DECISIONS line say the same. Kept the gate (un-gating would put the script back to reading every company with no consent at all). A test pins that both locales name those inputs and contain no "no free text / no underlag" denial. - Finding 4 (member sees an active switch that RLS rejects): the toggle is now enabled only for owner/admin, matching the company_settings update policy; the disclosure says only administrators can change the choice. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nAd8XJ2RPCmG2eKoLBdna * fix(scripts): address round-2 review findings (#1346) 1. [minor] Opted-in company filter was an unbounded PostgREST `in` list in the URL (scripts/fit-categorize-calibration.ts, scripts/backtest-categorize.ts). Both scripts now read the opted-in ids through a shared, paginated helper (listDataAnalysisOptedInCompanyIds, fetchAllRows so the pre-fetch no longer caps at 1000) and query per chunk of 100 ids (chunkCompanyIds). The fit script pages each chunk on the id PK; the backtest merges per-chunk results and re-cuts to the N most recent overall. Early exit on zero opt-ins is kept. Pinned with tests in lib/company/__tests__/data-analysis.test.ts. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nAd8XJ2RPCmG2eKoLBdna * fix(scripts): coerce a null transaction description in the backtest (#1346) The typed row from the chunked consent query made description nullable, which TransactionForSelect does not accept; fall back to the original description or an empty string, as the untyped row did implicitly before. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nAd8XJ2RPCmG2eKoLBdna --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
90 lines
3.4 KiB
TypeScript
90 lines
3.4 KiB
TypeScript
import { NextResponse } from 'next/server'
|
|
import { z } from 'zod'
|
|
import { requireAuth } from '@/lib/auth/require-auth'
|
|
import { getActiveCompanyId } from '@/lib/company/context'
|
|
import { isDataAnalysisOptedIn } from '@/lib/company/data-analysis'
|
|
import { guardSandbox } from '@/lib/sandbox/guard'
|
|
|
|
/**
|
|
* POST /api/agent/categorize/outcome: log one calibration sample.
|
|
*
|
|
* Called (fire-and-forget) after a user books an AI proposal: it records the
|
|
* confidence the model reported and whether the proposed account was the one
|
|
* actually booked. That corpus is what lib/agent/categorize/calibration.ts
|
|
* later fits an isotonic calibrator on, so "säker" can be made to mean ~right.
|
|
*
|
|
* Telemetry only: it never posts anything and is gated on auth + membership.
|
|
* Sandbox bookings run on seed data, so they are silently skipped (a 204) to
|
|
* keep the corpus clean. The corpus is read across companies, so it only
|
|
* collects from companies that opted in to data analysis
|
|
* (company_settings.data_analysis_opt_in, #1346): everyone else gets the same
|
|
* silent 204 and no row.
|
|
*/
|
|
|
|
const Schema = z.object({
|
|
company_id: z.string().uuid().optional(),
|
|
confidence: z.number().min(0).max(1),
|
|
proposed_account: z.string().max(20).nullable().optional(),
|
|
booked_account: z.string().min(1).max(20),
|
|
agreement: z.number().min(0).max(1).nullable().optional(),
|
|
model_confidence: z.enum(['high', 'medium', 'low']).nullable().optional(),
|
|
source: z.string().max(40).nullable().optional(),
|
|
amount: z.number().nullable().optional(),
|
|
})
|
|
|
|
const noContent = () => new Response(null, { status: 204 })
|
|
|
|
export async function POST(request: Request): Promise<Response> {
|
|
const { user, supabase, error } = await requireAuth()
|
|
if (error) return error
|
|
|
|
let body: unknown
|
|
try {
|
|
body = await request.json()
|
|
} catch {
|
|
return NextResponse.json({ error: 'Invalid JSON' }, { status: 400 })
|
|
}
|
|
const parsed = Schema.safeParse(body)
|
|
if (!parsed.success) return NextResponse.json({ error: 'Invalid body' }, { status: 400 })
|
|
|
|
const companyId = parsed.data.company_id ?? (await getActiveCompanyId(supabase, user.id))
|
|
if (!companyId) return noContent()
|
|
|
|
const { data: membership } = await supabase
|
|
.from('company_members')
|
|
.select('user_id')
|
|
.eq('company_id', companyId)
|
|
.eq('user_id', user.id)
|
|
.maybeSingle()
|
|
if (!membership) return NextResponse.json({ error: 'Forbidden' }, { status: 403 })
|
|
|
|
// Sandbox bookings are seed data: don't pollute the calibration corpus.
|
|
const blocked = await guardSandbox(supabase, companyId)
|
|
if (blocked) return noContent()
|
|
|
|
// Consent gate: the corpus is analysed across companies, so a company that
|
|
// has not opted in contributes nothing (default false, no grandfathering).
|
|
if (!(await isDataAnalysisOptedIn(supabase, companyId))) return noContent()
|
|
|
|
const proposed = parsed.data.proposed_account ?? null
|
|
|
|
// Best-effort: a failed telemetry insert must never surface to the user.
|
|
try {
|
|
await supabase.from('categorize_calibration_samples').insert({
|
|
company_id: companyId,
|
|
confidence: parsed.data.confidence,
|
|
agreement: parsed.data.agreement ?? null,
|
|
model_confidence: parsed.data.model_confidence ?? null,
|
|
source: parsed.data.source ?? null,
|
|
proposed_account: proposed,
|
|
booked_account: parsed.data.booked_account,
|
|
was_correct: proposed !== null && proposed === parsed.data.booked_account,
|
|
amount: parsed.data.amount ?? null,
|
|
})
|
|
} catch {
|
|
// swallow
|
|
}
|
|
|
|
return noContent()
|
|
}
|