Files
accounted/extensions/general/stripe/index.ts
T
MattssonandClaude Opus 4.8 53e343ee92 Bug/invalid imports (#1146)
* feat: add Accounted MCP namespace

* fix(bookkeeping): stop flagging verifikat whose underlag lives on a referenced supplier invoice

The missing-underlag surfaces only accepted a document directly linked to
the entry, so payment verifikat for supplier invoices (doc on the
registration entry per design) and entries whose doc was pinned to the
bank transaction before matching were falsely flagged; opening the entry
showed the referenced doc and cleared the warning client-side, and it
came back on reload.

- verifikat_without_documents + transactions_without_documents now treat
  an entry as covered when a supplier invoice referencing it (registration
  or payment FK, or a supplier_invoice_payments row) carries a document
  anchored to a journal entry (BFL 5 kap 7 paragraf hänvisning till
  underlag; anchoring required because the WORM deletion guards key on
  document_attachments.journal_entry_id)
- match-supplier-invoice routes (dashboard + v1) propagate the
  transaction's pinned document onto the payment verifikat, mirroring the
  categorize route; migration backfills rows already written (open
  unlocked periods, company-guarded, never steals a linked doc)
- /api/documents/counts, the transactions-page badges, the bulk "Inget
  underlag krävs" count and the push-notification scheduler share the
  same reference-aware predicate, so every surface agrees with the RPC
- counts route validates journal_entry_ids as UUIDs (they are
  interpolated into a PostgREST or-filter)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(transactions): align table columns flush with page edges

Collapse the checkbox gutter column to zero width and hang the
hover-revealed checkbox/expand chevron in the page margins, drop the
outer padding so DATUM sits flush left and STATUS flush right, and
tuck the overflow-menu dots under the middle of the STATUS header.
Applied to both the inbox and history tables so they stay identical.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(arsredovisning): tie anlaggningstillgangar note to booked depreciation

The ARL 5:8 roll-forward note recomputed depreciation from its own
day-based linear formula (365.25/12 month length, non-inclusive day
count, linear only), drifting ~20 kr per year per asset from the
ledger-driven resultat- and balansrakning and misstating non-linear
methods entirely. Note figures now come from posted
depreciation_schedules rows (the same source disposeAsset reverses),
falling back to the engine's computeAnnualDepreciation when nothing is
posted; pre-onboarding opening balances iterate prior years through
the engine. Adds a note-vs-trial-balance tie-out warning (accounts
1000-1299, over 1 kr) surfaced before download.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(stripe): move connect and sync surface from settings to import page

Stripe's transaction feed is a continuous import source in the same
category as the PSD2 bank connection, so its connect/sync surface now
lives on the import page as a source card (mode=stripe), gated
"kommer snart" on hosted like before; self-hosted keeps the full panel.

- Import page: Stripe card after Koppla bank, renders the existing
  StripeSettingsPanel via the settings-panel registry
- OAuth callback and panel cleanup return to /import?mode=stripe
- Settings > Betalningar retired: nav item removed, route redirects,
  PaymentsSettingsContent deleted, legacy ?tab=payments mapped
- New import.stripe_* strings in sv+en; dead settings_nav.payments removed

Crons and sync logic unchanged; payment-link settings stay in the
invoicing section.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(underlag): paginate missing-underlag cron and harden doc-surface queries

Resolve PR review findings on bug/invalid-imports:
- notification-scheduler: fetchAllRows on all 5 global reads; past 1000 rows
  the capped reads produced false "saknade underlag" notifications
- bulk-missing: LOOKUP_CHUNK 300->150 so the twice-embedded .or() id list
  stays under the PostgREST URL limit
- bulk-missing + transactions page: UUID-guard the .or()-interpolated id
  lists, matching documents/counts
- match-supplier-invoice (dashboard + v1): log documentId/journalEntryId on
  the non-fatal doc-link warning
- well-known/oauth-protected-resource: document the tool_namespace allow-list
- messages/en: reword stripe_description
- DECISIONS.md: record the asset ibAck tie-out and Tailwind !important calls

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(tic): convert registrationDate from Unix seconds to millisecond epoch in lookup and profile tests

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 15:03:50 +02:00

468 lines
17 KiB
TypeScript

import type { Extension, ExtensionContext } from '@/lib/extensions/types'
import { NextResponse } from 'next/server'
import { checkRateLimit } from '@/lib/auth/rate-limit-http'
import { requireCapability } from '@/lib/entitlements/has-capability'
import { CAPABILITY } from '@/lib/entitlements/keys'
import { guardSandbox, sandboxBlockedResponse } from '@/lib/sandbox/guard'
import {
buildAuthorizeUrl,
deauthorizeAccount,
isStripeConnectConfigured,
isLiveMode,
} from './lib/connect'
import {
createInvoicePaymentLink,
handleCreditNoteCreated,
handleInvoicePaid,
} from './lib/payment-links'
import { syncStripeConnection } from './lib/sync'
import { syncStripeBalanceTransactions } from './lib/transaction-sync'
import { createServiceClientNoCookies } from '@/lib/auth/api-keys'
import type { StripeConnection, StripeStatusResponse } from './types'
// Per-user limits: connect/disconnect are outward-facing OAuth operations,
// sync hits the Stripe API.
const RATE_LIMIT_CONNECT = { maxRequests: 10, windowMs: 60_000 }
const RATE_LIMIT_DISCONNECT = { maxRequests: 10, windowMs: 60_000 }
const RATE_LIMIT_SYNC = { maxRequests: 10, windowMs: 60_000 }
// A pending row younger than this blocks a second connect attempt so a
// double-click cannot start two OAuth round-trips (only one state would
// survive, stranding the other at the callback).
const PENDING_FRESH_MS = 60_000
const NOT_CONFIGURED_MESSAGE =
'Stripe-integrationen är inte konfigurerad på den här installationen.'
/**
* Stripe Connect extension
*
* Connects a company's Stripe account via Connect OAuth (Standard accounts).
* Auto-creates a Stripe Payment Link when an invoice is sent, marks invoices
* paid from Stripe checkout events, and books payouts (gross/fees/net) against
* the 1686 clearing account.
*
* Required environment variables:
* - STRIPE_SECRET_KEY (the platform account key, shared with billing)
* - STRIPE_CONNECT_CLIENT_ID (ca_... from the platform's Connect settings)
*/
export const stripeExtension: Extension = {
id: 'stripe',
name: 'Stripe-betalningar',
version: '1.0.0',
settingsPanel: {
label: 'Betalningar (Stripe)',
path: '/import?mode=stripe',
},
// Core-callable services, resolved via the extension registry (core never
// imports extension code). The send routes use this to auto-fill
// invoices.payment_link_url before the email/PDF render.
services: {
createInvoicePaymentLink,
},
eventHandlers: [
// A settled or credited invoice must stop accepting money through its link.
{ eventType: 'invoice.paid', handler: handleInvoicePaid },
{ eventType: 'credit_note.created', handler: handleCreditNoteCreated },
],
apiRoutes: [
{
method: 'GET',
path: '/status',
handler: async (_request: Request, ctx?: ExtensionContext) => {
const supabase = ctx?.supabase ?? await (await import('@/lib/supabase/server')).createClient()
const { data: { user } } = await supabase.auth.getUser()
if (!user) {
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
}
if (!ctx?.companyId) {
return NextResponse.json({ error: 'Company context required' }, { status: 400 })
}
// Prefer the active connection; otherwise surface the most recent row
// so the panel can show pending/error/revoked states.
const { data: rows } = await supabase
.from('stripe_connections')
.select(
'id, status, stripe_account_id, livemode, display_name, error_message, connected_at, last_event_created_at, transaction_sync_enabled, last_balance_txn_synced_at',
)
.eq('company_id', ctx.companyId)
.order('created_at', { ascending: false })
.limit(10)
const connection =
rows?.find((r) => r.status === 'active') ?? rows?.[0] ?? null
// Events + payouts the deterministic matcher refused to auto-apply.
// Members can read both ledgers under RLS; the panel lists them for
// manual handling.
const { data: reviewRows, count: reviewCount } = await supabase
.from('stripe_payment_events')
.select('id, reason, amount, currency, invoice_id, event_created_at', {
count: 'exact',
})
.eq('company_id', ctx.companyId)
.eq('status', 'needs_review')
.order('event_created_at', { ascending: false })
.limit(5)
const { data: payoutRows, count: payoutCount } = await supabase
.from('stripe_payouts')
.select('id, reason, amount, currency, event_created_at', { count: 'exact' })
.eq('company_id', ctx.companyId)
.eq('status', 'needs_review')
.order('event_created_at', { ascending: false })
.limit(5)
const payload: StripeStatusResponse = {
configured: isStripeConnectConfigured(),
connection,
needs_review_count: (reviewCount ?? 0) + (payoutCount ?? 0),
needs_review: [
...(reviewRows ?? []),
...(payoutRows ?? []).map((p) => ({ ...p, invoice_id: null })),
],
}
return NextResponse.json(payload)
},
},
{
method: 'POST',
path: '/sync',
handler: async (_request: Request, ctx?: ExtensionContext) => {
const log = ctx?.log ?? console
const supabase = ctx?.supabase ?? await (await import('@/lib/supabase/server')).createClient()
const { data: { user } } = await supabase.auth.getUser()
if (!user) {
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
}
if (!ctx?.companyId) {
return NextResponse.json({ error: 'Company context required' }, { status: 400 })
}
const companyId = ctx.companyId
const capabilityBlocked = await requireCapability(
supabase,
companyId,
CAPABILITY.stripe_payments,
)
if (capabilityBlocked) return capabilityBlocked
const rl = await checkRateLimit({
prefix: 'stripe:sync',
identifier: user.id,
...RATE_LIMIT_SYNC,
})
if (!rl.ok) return rl.response!
// Membership-scoped lookup via the user client; the sync itself runs
// on the service client because the event ledger is service-write-only.
const { data: connection } = await supabase
.from('stripe_connections')
.select('*')
.eq('company_id', companyId)
.eq('status', 'active')
.maybeSingle()
if (!connection) {
return NextResponse.json({ error: 'Inget anslutet Stripe-konto.' }, { status: 404 })
}
try {
const serviceClient = createServiceClientNoCookies()
const typedConnection = connection as StripeConnection
const summary = await syncStripeConnection(serviceClient, typedConnection)
// The manual button covers both feeds: when the balance-transaction
// feed is enabled, "Synka nu" also pulls it (same module as the
// nightly cron, no separate rate limit needed: one user action).
const transactions = typedConnection.transaction_sync_enabled
? await syncStripeBalanceTransactions(serviceClient, typedConnection)
: undefined
return NextResponse.json({ success: true, ...summary, transactions })
} catch (error) {
log.error('[stripe] Manual sync failed', {
message: error instanceof Error ? error.message : String(error),
connection_id: connection.id,
})
return NextResponse.json(
{ error: 'Synkroniseringen misslyckades. Försök igen.' },
{ status: 502 },
)
}
},
},
{
method: 'POST',
path: '/transaction-sync',
handler: async (request: Request, ctx?: ExtensionContext) => {
const supabase = ctx?.supabase ?? await (await import('@/lib/supabase/server')).createClient()
const { data: { user } } = await supabase.auth.getUser()
if (!user) {
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
}
if (!ctx?.companyId) {
return NextResponse.json({ error: 'Company context required' }, { status: 400 })
}
const companyId = ctx.companyId
const capabilityBlocked = await requireCapability(
supabase,
companyId,
CAPABILITY.stripe_payments,
)
if (capabilityBlocked) return capabilityBlocked
const rl = await checkRateLimit({
prefix: 'stripe:transaction-sync-toggle',
identifier: user.id,
...RATE_LIMIT_SYNC,
})
if (!rl.ok) return rl.response!
const body = (await request.json().catch(() => ({}))) as { enabled?: unknown }
if (typeof body.enabled !== 'boolean') {
return NextResponse.json(
{ error: 'enabled (boolean) krävs.' },
{ status: 400 },
)
}
const { data: updated, error: updateError } = await supabase
.from('stripe_connections')
.update({ transaction_sync_enabled: body.enabled })
.eq('company_id', companyId)
.eq('status', 'active')
.select('id')
if (updateError) {
return NextResponse.json(
{ error: 'Kunde inte spara inställningen. Försök igen.' },
{ status: 500 },
)
}
if (!updated || updated.length === 0) {
return NextResponse.json({ error: 'Inget anslutet Stripe-konto.' }, { status: 404 })
}
return NextResponse.json({ success: true, enabled: body.enabled })
},
},
{
method: 'POST',
path: '/connect',
handler: async (_request: Request, ctx?: ExtensionContext) => {
const log = ctx?.log ?? console
const supabase = ctx?.supabase ?? await (await import('@/lib/supabase/server')).createClient()
const { data: { user } } = await supabase.auth.getUser()
if (!user) {
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
}
if (!ctx?.companyId) {
return NextResponse.json({ error: 'Company context required' }, { status: 400 })
}
const companyId = ctx.companyId
// Anonymous/sandbox users must never reach Stripe (same doctrine as
// billing checkout: the sandbox never talks to external services).
// The anon check is identity truth and runs first (no DB round trip).
if (user.is_anonymous) return sandboxBlockedResponse()
const sandboxBlocked = await guardSandbox(supabase, companyId)
if (sandboxBlocked) return sandboxBlocked
const capabilityBlocked = await requireCapability(
supabase,
companyId,
CAPABILITY.stripe_payments,
)
if (capabilityBlocked) return capabilityBlocked
const rl = await checkRateLimit({
prefix: 'stripe:connect',
identifier: user.id,
...RATE_LIMIT_CONNECT,
})
if (!rl.ok) return rl.response!
if (!isStripeConnectConfigured()) {
return NextResponse.json({ error: NOT_CONFIGURED_MESSAGE }, { status: 503 })
}
const { data: existing } = await supabase
.from('stripe_connections')
.select('id, status, created_at')
.eq('company_id', companyId)
.in('status', ['active', 'pending'])
.order('created_at', { ascending: false })
if (existing?.some((c) => c.status === 'active')) {
return NextResponse.json(
{ error: 'Företaget har redan ett anslutet Stripe-konto. Koppla från det först.' },
{ status: 409 },
)
}
const pending = existing?.filter((c) => c.status === 'pending') ?? []
const freshPending = pending.find(
(c) => Date.now() - new Date(c.created_at).getTime() < PENDING_FRESH_MS,
)
if (freshPending) {
return NextResponse.json(
{ error: 'En anslutning pågår redan. Vänta och försök igen.' },
{ status: 409 },
)
}
if (pending.length > 0) {
// Supersede stale pending attempts so their oauth_state can never
// complete a callback after this new round-trip starts.
await supabase
.from('stripe_connections')
.update({
status: 'error',
error_message: 'Superseded by new connection attempt',
oauth_state: null,
})
.eq('company_id', companyId)
.eq('status', 'pending')
}
// Persist the CSRF state BEFORE handing the user to Stripe: the
// callback locates the row by oauth_state alone, so the row must
// exist before Stripe can ever redirect back with that state.
const oauthState = crypto.randomUUID()
const { data: created, error: insertError } = await supabase
.from('stripe_connections')
.insert({
company_id: companyId,
user_id: user.id,
status: 'pending',
oauth_state: oauthState,
livemode: isLiveMode(),
})
.select('id')
.single()
if (insertError || !created) {
log.error('[stripe] Failed to stage pending connection', {
message: insertError?.message,
code: insertError?.code,
companyId,
})
return NextResponse.json(
{ error: 'Kunde inte starta anslutningen. Försök igen.' },
{ status: 500 },
)
}
log.info('[stripe] Starting Connect OAuth', {
connection_id: created.id,
company_id: companyId,
livemode: isLiveMode(),
})
return NextResponse.json({ url: buildAuthorizeUrl(oauthState) })
},
},
{
method: 'DELETE',
path: '/disconnect',
handler: async (request: Request, ctx?: ExtensionContext) => {
const log = ctx?.log ?? console
const supabase = ctx?.supabase ?? await (await import('@/lib/supabase/server')).createClient()
const { data: { user } } = await supabase.auth.getUser()
if (!user) {
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
}
if (!ctx?.companyId) {
return NextResponse.json({ error: 'Company context required' }, { status: 400 })
}
const companyId = ctx.companyId
const rl = await checkRateLimit({
prefix: 'stripe:disconnect',
identifier: user.id,
...RATE_LIMIT_DISCONNECT,
})
if (!rl.ok) return rl.response!
const body = (await request.json().catch(() => ({}))) as { connection_id?: string }
const base = supabase
.from('stripe_connections')
.select('id, status, stripe_account_id')
.eq('company_id', companyId)
const query = body.connection_id
? base.eq('id', body.connection_id).limit(1)
: base.neq('status', 'revoked').order('created_at', { ascending: false }).limit(1)
const { data: rows, error: findError } = await query
const connection = rows?.[0] as
| Pick<StripeConnection, 'id' | 'status' | 'stripe_account_id'>
| undefined
if (findError || !connection) {
return NextResponse.json({ error: 'Connection not found' }, { status: 404 })
}
// Best-effort revoke at Stripe: an already-severed connection throws,
// which is fine (the goal state is reached either way). Logged at WARN
// so a systematic revoke failure stays visible to monitoring.
if (connection.status === 'active' && connection.stripe_account_id) {
try {
await deauthorizeAccount(connection.stripe_account_id)
} catch (revokeError) {
log.warn('[stripe] Deauthorize skipped (likely already revoked)', {
message: revokeError instanceof Error ? revokeError.message : String(revokeError),
connection_id: connection.id,
})
}
}
const { error: updateError } = await supabase
.from('stripe_connections')
.update({
status: 'revoked',
oauth_state: null,
disconnected_at: new Date().toISOString(),
})
.eq('id', connection.id)
.eq('company_id', companyId)
if (updateError) {
log.error('[stripe] Failed to mark connection revoked', {
message: updateError.message,
connection_id: connection.id,
})
return NextResponse.json(
{ error: 'Kunde inte koppla från. Försök igen.' },
{ status: 500 },
)
}
if (ctx?.emit) {
try {
await ctx.emit({
type: 'stripe.disconnected',
payload: {
connectionId: connection.id,
stripeAccountId: connection.stripe_account_id,
reason: 'user',
userId: user.id,
companyId,
},
})
} catch {
// Audit event failure must not block the disconnect itself.
}
}
return NextResponse.json({ success: true })
},
},
],
}
export default stripeExtension