Files
accounted/lib/providers/wint/__tests__/client.test.ts
T
MattssonandClaude Fable 5 93f81f03e8 feat(providers): WINT migration provider behind WINT_MIGRATION_ENABLED (#1446)
* feat(providers): WINT migration provider behind WINT_MIGRATION_ENABLED

Adds WINT (wint.se) as a sixth migration provider, built against the
OpenAPI specs WINT's own API host serves publicly. Tier A scope: only the
partner-facing v1 endpoints are used; the general ledger is fetched as
vouchers/accounts and rendered as SIE 4E by our own sie-builder, with
opening balances for earlier years derived backward from the current-year
Ib anchor. Auth is the user's WINT login exchanged once for a JWT pair;
the password is never stored.

Ships dark: the wizard shows a disabled "Kommer snart" card, and the
server-side /connect gate rejects WINT until WINT_MIGRATION_ENABLED=true.
Live verification against a real WINT account is still outstanding.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(providers): harden WINT provider per PR #1446 review findings

Addresses CodeRabbit and Swedish accounting review feedback in one pass:

- Ib anchor selection now uses WINT's unfiltered fiscal-year list, so an
  active year outside the allowed import window can never silently anchor
  the wrong year; the voucher chain is extended through the anchor and a
  per-year fetch failure fails that year loudly instead of sinking the
  whole migration.
- Auth token exchange is strict: only LoginState Success with a complete
  access+refresh pair mints a consent (a pair without a refresh token is
  unrefreshable and would break days later).
- WintApiError no longer retains full response bodies (bounded 300-char
  diagnostic; bodies can carry customer data and errors get logged).
- sie-builder refuses to render structurally invalid vouchers (missing
  account number or booking date) and documents deleted-voucher gaps in a
  #PROSA record per BFL 5 kap 6-7 §.
- Account classification: 20xx is equity, 83xx is financial income.
- SIE validator accepts EUBAS97 as BAS-based (standard kontoplanstyp; it
  previously produced a false non-BAS warning on every WINT/Bollbok file).
- New tests: resolveConsent WINT refresh flow, credential upsert payload
  (no mail/password persisted), WINT fetch failure path, EUBAS97 warning
  regression, builder invalid-data rejection, vi.clearAllMocks hygiene.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(import): pin EUBAS97 acceptance to the exact SIE spec value

Review follow-up on PR #1446: match EUBAS97 exactly instead of any
EUBAS* prefix, so the non-BAS kontoplan warning stays pinned to the four
kontoplanstyp values the SIE 4B spec enumerates (BAS95, BAS96, EUBAS97,
NE2007) rather than silently accepting unknown future variants.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-07 11:07:14 +02:00

105 lines
3.8 KiB
TypeScript

import { describe, it, expect, vi, beforeEach, afterEach } from 'vitest';
import { WintClient, WintApiError } from '../client';
function jsonResponse(body: unknown, status = 200): Response {
return new Response(JSON.stringify(body), {
status,
headers: { 'Content-Type': 'application/json' },
});
}
function listResponse(items: unknown[], page: number, totalItems: number, numPerPage = 200): Response {
return jsonResponse({ Items: items, Page: page, NumPerPage: numPerPage, TotalItems: totalItems });
}
describe('WintClient', () => {
let fetchSpy: ReturnType<typeof vi.spyOn>;
beforeEach(() => {
fetchSpy = vi.spyOn(globalThis, 'fetch');
});
afterEach(() => {
fetchSpy.mockRestore();
});
describe('auth header', () => {
it('sends the JWT as a Bearer token', async () => {
fetchSpy.mockResolvedValueOnce(jsonResponse({}));
const client = new WintClient();
await client.get('jwt-abc', '/api/Auth');
const [, init] = fetchSpy.mock.calls[0];
expect((init as RequestInit).headers).toMatchObject({
Authorization: 'Bearer jwt-abc',
});
});
});
describe('pagination', () => {
it('getPaginated walks pages until TotalItems is reached', async () => {
fetchSpy
.mockResolvedValueOnce(listResponse([{ Id: 1 }, { Id: 2 }], 1, 3, 2))
.mockResolvedValueOnce(listResponse([{ Id: 3 }], 2, 3, 2));
const client = new WintClient();
const items = await client.getPaginated<{ Id: number }>('t', '/api/Customer', { pageSize: 2 });
expect(items.map((i) => i.Id)).toEqual([1, 2, 3]);
expect(fetchSpy).toHaveBeenCalledTimes(2);
expect(String(fetchSpy.mock.calls[0][0])).toContain('Page=1');
expect(String(fetchSpy.mock.calls[0][0])).toContain('NumPerPage=2');
expect(String(fetchSpy.mock.calls[1][0])).toContain('Page=2');
});
it('appends pagination params with & when the path already has a query', async () => {
fetchSpy.mockResolvedValueOnce(listResponse([], 1, 0));
const client = new WintClient();
await client.getPage('t', '/api/Voucher?IncludeTransactions=true', { page: 1 });
const url = String(fetchSpy.mock.calls[0][0]);
expect(url).toContain('/api/Voucher?IncludeTransactions=true&Page=1');
});
it('stops after a short page even when TotalItems overcounts', async () => {
fetchSpy.mockResolvedValueOnce(listResponse([{ Id: 1 }], 1, 99, 200));
const client = new WintClient();
const items = await client.getPaginated<{ Id: number }>('t', '/api/Customer');
expect(items).toHaveLength(1);
expect(fetchSpy).toHaveBeenCalledTimes(1);
});
it('throws when the server ignores the Page param (page-echo guard)', async () => {
// Both requests answer Page=1 with a FULL page: without the guard this
// would loop forever appending the same 200 items. Fresh Response per
// call: a Response body can only be consumed once.
fetchSpy.mockImplementation(async () =>
listResponse(Array.from({ length: 200 }, (_, i) => ({ Id: i })), 1, 400, 200),
);
const client = new WintClient();
const err = await client.getPaginated('t', '/api/Transaction').catch((e: unknown) => e);
expect(err).toBeInstanceOf(WintApiError);
expect((err as WintApiError).message).toContain('did not honor Page=2');
});
});
describe('errors', () => {
it('does NOT retry on 401 and carries the status code', async () => {
fetchSpy.mockResolvedValueOnce(new Response('unauthorized', { status: 401 }));
const client = new WintClient();
const err = await client.get('t', '/api/Auth').catch((e: unknown) => e);
expect(err).toBeInstanceOf(WintApiError);
expect((err as WintApiError).statusCode).toBe(401);
expect(fetchSpy).toHaveBeenCalledTimes(1);
});
});
});