* feat(onboarding): company setup from the conversation and POST /api/v1/companies Third PR of agent-first onboarding (#1814). Once connected, the agent can now set up a company end to end without the web wizard, and partner platforms can provision companies over REST. - create_company_for_user: service-role-only SECURITY DEFINER twin of create_company_with_owner taking the owner explicitly (service clients have no auth.uid()). pg-real test covers creation, role gating, unknown owner and foreign team. - lib/company/create-company.ts: the wizard's creation sequence (org number, TIC snapshot, BAS chart, settings, first fiscal period, tax deadlines, rollback) extracted into createCompanyCore; the Server Action delegates to it, behaviour unchanged. - lib/company/onboarding-input.ts: one Zod schema + planner for the agent/API paths; a VAT-registered company without moms_period is refused (a missing period silently yields zero VAT deadlines). - MCP: gnubok_create_company (two-phase: preview, then confirm=true; companies:write, company-independent), gnubok_connect_bank and gnubok_connect_skatteverket (status + the browser link, gated on bank_sync / skatteverket, search-only in the catalog), the "onboarding" skill, and initialize instructions pointing at it. - Consent page pre-ticks companies:write for an account with no company yet, so the setup does not dead-end on insufficient scope after signup. - POST /api/v1/companies (companies:write, dry-run aware) on the same core; scope map, registry, spec snapshot and the generated API skill updated. - tools/list payload ceiling raised 59.95K -> 60.4K for the one new default-catalog tool (documented in the guard). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * fix(onboarding): explicit f_skatt, org number when VAT-registered, EF first year ends 31 Dec Review findings on #1864 (Swedish compliance review): - f_skatt is required, never defaulted to approved (SE-R-005 risk). - org_number is required when vat_registered: the invoice momsregistreringsnummer derives from it (ML 17 kap 24 §). - An enskild firma's first fiscal year must end on 31 December and its start month is forced to 1 even with first_fiscal_year set, mirroring the wizard's own rule text (BFL 3 kap. 1 §). - POST /api/v1/companies no longer claims Idempotency-Key support (the wrapper only honours it on company-scoped routes). - pg-real: createCompanyCore's chart seed runs under the real service_role, which the unit tests could not prove. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * test(pg): starter chart has 41 accounts, assert non-empty The service_role chart-seed proof passed the part that mattered (no 42501 from seed_chart_of_accounts) and failed on a wrong row-count guess: the seeded chart is a curated starter set, not the full BAS list. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * fix(migrations): move create_company_for_user to 20260825120000 main gained 20260824170000_bulk_book_transactions_service_actor.sql with the same version while this branch was open; two files on one version abort every Supabase branch apply and the prod auto-apply. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * chore(api): refresh spec snapshot and generated skill after rebasing onto main Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 * fix(mcp): flat create_company result, refuse localhost connect links, test hygiene CodeRabbit on #1864: the confirmed-create result was wrapped in the { data, next } envelope while its outputSchema promised top-level fields; it now returns the fields with next as a sibling. The two connect-link tools refuse to build a link when NEXT_PUBLIC_APP_URL is unset instead of handing a remote user a localhost URL. Tests clear mocks and the event bus in beforeEach. Not changed: the rollback already survives user_preferences.active_company_id (that FK is ON DELETE SET NULL since 20260331010000), and v1 error details stay in the surface's English developer convention. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
98 lines
3.5 KiB
PL/PgSQL
98 lines
3.5 KiB
PL/PgSQL
-- Migration: create_company_for_user (service-role company creation)
|
|
--
|
|
-- Agent-first onboarding (issue #1814 PR 3): the MCP tool gnubok_create_company
|
|
-- and POST /api/v1/companies create companies on behalf of the API key's
|
|
-- user. Both run with a service-role client, where auth.uid() is NULL, so
|
|
-- create_company_with_owner (which derives the owner from auth.uid()) cannot
|
|
-- be used. This variant takes the owner explicitly and is callable by
|
|
-- service_role ONLY: an authenticated or anonymous caller must never be able
|
|
-- to create a company for someone else.
|
|
--
|
|
-- Body mirrors create_company_with_owner (20260519180000) step for step:
|
|
-- entity_type whitelist, team-membership authorization for p_team_id, the
|
|
-- companies + company_members inserts, the 1930 SEK cash account seed, the
|
|
-- active-company preference, and team sync. The trial capability grant is
|
|
-- minted by the AFTER INSERT trigger on companies, same as every other path.
|
|
|
|
CREATE OR REPLACE FUNCTION public.create_company_for_user(
|
|
p_user_id uuid,
|
|
p_name text,
|
|
p_entity_type text,
|
|
p_team_id uuid DEFAULT NULL
|
|
)
|
|
RETURNS uuid
|
|
LANGUAGE plpgsql
|
|
SECURITY DEFINER
|
|
SET search_path = public
|
|
AS $$
|
|
DECLARE
|
|
v_company_id uuid;
|
|
BEGIN
|
|
IF p_user_id IS NULL THEN
|
|
RAISE EXCEPTION 'p_user_id is required';
|
|
END IF;
|
|
|
|
IF NOT EXISTS (SELECT 1 FROM auth.users WHERE id = p_user_id) THEN
|
|
RAISE EXCEPTION 'Unknown user %', p_user_id
|
|
USING ERRCODE = '23503'; -- foreign_key_violation
|
|
END IF;
|
|
|
|
IF p_entity_type NOT IN ('enskild_firma', 'aktiebolag') THEN
|
|
RAISE EXCEPTION 'Invalid entity_type: %', p_entity_type;
|
|
END IF;
|
|
|
|
IF p_name IS NULL OR length(btrim(p_name)) = 0 THEN
|
|
RAISE EXCEPTION 'p_name is required';
|
|
END IF;
|
|
|
|
-- Same authorization as create_company_with_owner, against the explicit
|
|
-- owner: SECURITY DEFINER bypasses RLS, so team membership is checked here.
|
|
IF p_team_id IS NOT NULL THEN
|
|
IF NOT EXISTS (
|
|
SELECT 1
|
|
FROM public.team_members
|
|
WHERE team_id = p_team_id
|
|
AND user_id = p_user_id
|
|
) THEN
|
|
RAISE EXCEPTION 'Not a member of team %', p_team_id
|
|
USING ERRCODE = '42501'; -- insufficient_privilege
|
|
END IF;
|
|
END IF;
|
|
|
|
INSERT INTO public.companies (name, entity_type, created_by, team_id)
|
|
VALUES (btrim(p_name), p_entity_type, p_user_id, p_team_id)
|
|
RETURNING id INTO v_company_id;
|
|
|
|
INSERT INTO public.company_members (company_id, user_id, role)
|
|
VALUES (v_company_id, p_user_id, 'owner');
|
|
|
|
INSERT INTO public.cash_accounts (
|
|
company_id, ledger_account, currency, name, enabled, is_primary, source
|
|
)
|
|
VALUES (
|
|
v_company_id, '1930', 'SEK', 'Företagskonto (SEK)', true, true, 'manual'
|
|
)
|
|
ON CONFLICT (company_id, ledger_account) DO NOTHING;
|
|
|
|
INSERT INTO public.user_preferences (user_id, active_company_id)
|
|
VALUES (p_user_id, v_company_id)
|
|
ON CONFLICT (user_id)
|
|
DO UPDATE SET active_company_id = EXCLUDED.active_company_id;
|
|
|
|
IF p_team_id IS NOT NULL THEN
|
|
PERFORM public.sync_team_to_company(v_company_id, p_team_id);
|
|
END IF;
|
|
|
|
RETURN v_company_id;
|
|
END;
|
|
$$;
|
|
|
|
-- Service role only. PostgREST exposes functions to every role by default
|
|
-- (PUBLIC grant), so revoke first, then grant the one role that may call it.
|
|
REVOKE ALL ON FUNCTION public.create_company_for_user(uuid, text, text, uuid) FROM PUBLIC;
|
|
REVOKE ALL ON FUNCTION public.create_company_for_user(uuid, text, text, uuid) FROM anon;
|
|
REVOKE ALL ON FUNCTION public.create_company_for_user(uuid, text, text, uuid) FROM authenticated;
|
|
GRANT EXECUTE ON FUNCTION public.create_company_for_user(uuid, text, text, uuid) TO service_role;
|
|
|
|
NOTIFY pgrst, 'reload schema';
|