Files
accounted/lib/providers/visma/oauth.ts
T
f266c386f3 chore: repo-wide bloat sweep, remove dead code and fold duplicate helpers (#2150)
* chore: repo-wide bloat sweep, remove dead code and fold duplicate helpers

Remove 33 dead files, ~270 unreferenced exports/types, 13 dead i18n
namespaces and 4 unused dependencies; fold byte-identical helper copies
into one canonical home each (lib/utils chunk/sleep/utcDateStamp,
lib/dates/iso, lib/invariants/uuid, lib/xml/escape, lib/reports/sru/format,
lib/pdf/number-text, lib/browser/panel-request, lib/api/v1/body +
v1ValidationError rolled out to ~55 v1 routes, booking-template schemas).

No behaviour change: v1 bodies and status codes, MCP tool schemas, DB
writes and money math are untouched. Naive ore rounding was deliberately
not swapped for roundOre; see DECISIONS.md 2026-09-02 for the full list
of things left alone on purpose.

tsc, lint, 19588 unit tests and check:guards green; antipattern baseline
ratcheted (naive-ore-round 622 -> 620, hand-rolled-invariant 115 -> 113).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(transactions): import RawTransaction from @/types after the ingest re-export removal

CI's type ratchet (check:types, full tsconfig) caught the one test file
that still imported the type through lib/transactions/ingest.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 11:51:16 +02:00

107 lines
2.9 KiB
TypeScript

import { VISMA_AUTH_URL, VISMA_TOKEN_URL } from './config';
import type { OAuthConfig, TokenResponse } from '../types';
import {
fetchWithTimeout,
OAUTH_TIMEOUT_MS,
} from '@/lib/http/fetch-with-timeout';
const DEFAULT_SCOPES = [
'ea:api',
'offline_access',
'ea:sales',
'ea:accounting',
'ea:purchase',
];
const EACCOUNTING_ACR_VALUE = 'service:44643EB1-3F76-4C1C-A672-402AE8085934';
const ALLOWED_PROMPT_VALUES = new Set(['none', 'login', 'consent', 'select_account']);
export function buildVismaAuthUrl(
config: OAuthConfig,
options?: { scopes?: string[]; state?: string; acrValues?: string; prompt?: string },
): string {
const promptCandidate = options?.prompt ?? 'select_account';
const prompt = ALLOWED_PROMPT_VALUES.has(promptCandidate) ? promptCandidate : 'select_account';
const params = new URLSearchParams({
client_id: config.clientId,
redirect_uri: config.redirectUri,
response_type: 'code',
prompt,
acr_values: options?.acrValues ?? EACCOUNTING_ACR_VALUE,
});
const scopes = options?.scopes?.length ? options.scopes : DEFAULT_SCOPES;
params.set('scope', scopes.join(' '));
if (options?.state) {
params.set('state', options.state);
}
return `${VISMA_AUTH_URL}?${params.toString()}`;
}
function basicAuthHeader(config: OAuthConfig): string {
const encoded = btoa(`${config.clientId}:${config.clientSecret}`);
return `Basic ${encoded}`;
}
export async function exchangeVismaCode(
config: OAuthConfig,
code: string,
): Promise<TokenResponse> {
const response = await fetchWithTimeout(
VISMA_TOKEN_URL,
{
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded',
Authorization: basicAuthHeader(config),
},
body: new URLSearchParams({
grant_type: 'authorization_code',
code,
redirect_uri: config.redirectUri,
}).toString(),
},
{ timeoutMs: OAUTH_TIMEOUT_MS, description: 'Visma token exchange' },
);
if (!response.ok) {
const body = await response.text().catch(() => '');
throw new Error(`Visma token exchange failed: ${response.status} ${body}`);
}
return response.json() as Promise<TokenResponse>;
}
export async function refreshVismaToken(
config: OAuthConfig,
refreshToken: string,
): Promise<TokenResponse> {
const response = await fetchWithTimeout(
VISMA_TOKEN_URL,
{
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded',
Authorization: basicAuthHeader(config),
},
body: new URLSearchParams({
grant_type: 'refresh_token',
refresh_token: refreshToken,
}).toString(),
},
{ timeoutMs: OAUTH_TIMEOUT_MS, description: 'Visma token refresh' },
);
if (!response.ok) {
const body = await response.text().catch(() => '');
throw new Error(`Visma token refresh failed: ${response.status} ${body}`);
}
return response.json() as Promise<TokenResponse>;
}