* feat: multi-tenant company refactor (GNU-19) Introduce companies table, company_members, and user_preferences to support multiple companies per user. All data scoping changes from user_id to company_id across the entire codebase. Key changes: - Database migration: new tables, company_id on 40+ tables, backfill, RLS rewrite from user_id to company-member-based, updated RPCs - Types: Company, CompanyMember, CompanyRole, UserPreferences types; company_id added to all entity interfaces; companyId on all events - Engine: all 7 core functions take companyId; storno, period, year-end services updated; 16 report generators updated - Middleware: company context resolution (cookie → prefs → first company) - API routes: ~120 routes updated with requireCompanyId() - Frontend: CompanyProvider context, layout/dashboard/onboarding updated - Extensions: context factory, 9 extensions, all lib files updated - Tests: 1880 tests passing, all helpers updated with company_id defaults Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: add database migrations for multi-tenant company and team system (GNU-19) Adds company_invitations, company creation RPC, team_members, account deletion RPC, and teams table refactor migrations. Updates base multi-tenant migration with cascading FKs and onboarding_step column. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: add team types and update core infrastructure for multi-tenancy (GNU-19) Adds TeamRole, MemberSource, and Team types. Refactors Supabase service client to be stateless, updates middleware for team-aware routing, extends CompanyContext with team/role fields, and updates extension service types to accept companyId. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * refactor: thread company_id through business logic functions (GNU-19) Replaces user_id scoping with company_id across all lib modules: bookkeeping, documents, transactions, invoices, reconciliation, tax, deadlines, and import. Updates corresponding tests. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * refactor: thread company_id through API routes and extensions (GNU-19) Updates all existing API routes to extract and pass companyId. Updates enable-banking and arcim-migration extensions for company-scoped transaction ingestion and sync. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: add company and team management API routes (GNU-19) Adds CRUD endpoints for company members, company invitations, team members, and team invitations. Includes invite token utilities, email templates, and company switch server action. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * feat: add team/company UI components, pages, and dashboard updates (GNU-19) Adds CompanySwitcher, ConsultantEmptyState, Step0RoleChoice, company members and team management panels. Updates dashboard layout for team-aware routing, onboarding for multi-step role choice, and auth callback for team invite acceptance. Ignores supabase/.branches/. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add null guards for company in import page (GNU-19) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: move appUrl declaration to outer scope in invite route (GNU-19) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add optional chaining for company.name in members section (GNU-19) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add optional chaining for second company.name in members section (GNU-19) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: add null guards for company in extension components (GNU-19) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: pass companyId to executeSIEImport in arcim-migration extension (GNU-19) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: update tests to use companyId instead of userId and improve type handling --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
291 lines
9.7 KiB
TypeScript
291 lines
9.7 KiB
TypeScript
import { createServerClient } from '@supabase/ssr'
|
|
import { NextResponse } from 'next/server'
|
|
import { Webhook } from 'svix'
|
|
import { parseInboundPayload, extractAttachments, resolveUserFromEmail } from '@/extensions/general/invoice-inbox/lib/email-handler'
|
|
import { matchSupplier } from '@/extensions/general/invoice-inbox/lib/supplier-matcher'
|
|
import { analyzeDocument } from '@/lib/ai/document-analyzer'
|
|
import { processReceiptFromDocument } from '@/extensions/general/receipt-ocr/lib/receipt-pipeline'
|
|
import crypto from 'crypto'
|
|
|
|
function createServiceClient() {
|
|
return createServerClient(
|
|
process.env.NEXT_PUBLIC_SUPABASE_URL!,
|
|
process.env.SUPABASE_SERVICE_ROLE_KEY!,
|
|
{
|
|
cookies: {
|
|
getAll() { return [] },
|
|
setAll() { },
|
|
},
|
|
}
|
|
)
|
|
}
|
|
|
|
/**
|
|
* Build raw email payload for BFL 7 kap. 2§ archiving.
|
|
* Includes full email headers and body — excludes binary attachment content.
|
|
*/
|
|
function buildRawEmailPayload(body: Record<string, unknown>, payload: { from: string; to: string; subject: string; created_at: string }): Record<string, unknown> {
|
|
return {
|
|
from: payload.from,
|
|
to: payload.to,
|
|
subject: payload.subject,
|
|
created_at: payload.created_at,
|
|
text: body.text ?? null,
|
|
html: body.html ?? null,
|
|
headers: body.headers ?? null,
|
|
message_id: body.message_id ?? null,
|
|
in_reply_to: body.in_reply_to ?? null,
|
|
references: body.references ?? null,
|
|
archived_at: new Date().toISOString(),
|
|
}
|
|
}
|
|
|
|
export async function POST(request: Request) {
|
|
// Verify webhook signature
|
|
const webhookSecret = process.env.RESEND_WEBHOOK_SECRET
|
|
if (!webhookSecret) {
|
|
console.error('[document-inbox] RESEND_WEBHOOK_SECRET not configured')
|
|
return NextResponse.json({ error: 'Webhook not configured' }, { status: 500 })
|
|
}
|
|
|
|
const svixId = request.headers.get('svix-id')
|
|
const svixTimestamp = request.headers.get('svix-timestamp')
|
|
const svixSignature = request.headers.get('svix-signature')
|
|
|
|
if (!svixId || !svixTimestamp || !svixSignature) {
|
|
return NextResponse.json({ error: 'Missing webhook headers' }, { status: 400 })
|
|
}
|
|
|
|
const rawBody = await request.text()
|
|
|
|
try {
|
|
const wh = new Webhook(webhookSecret)
|
|
wh.verify(rawBody, {
|
|
'svix-id': svixId,
|
|
'svix-timestamp': svixTimestamp,
|
|
'svix-signature': svixSignature,
|
|
})
|
|
} catch {
|
|
return NextResponse.json({ error: 'Invalid signature' }, { status: 401 })
|
|
}
|
|
|
|
const body = JSON.parse(rawBody)
|
|
const payload = parseInboundPayload(body)
|
|
|
|
if (!payload) {
|
|
return NextResponse.json({ error: 'Invalid payload' }, { status: 400 })
|
|
}
|
|
|
|
const supabase = createServiceClient()
|
|
|
|
// Resolve user from recipient email
|
|
const resolved = await resolveUserFromEmail(payload.to, supabase)
|
|
|
|
if (!resolved) {
|
|
console.warn(`[document-inbox] No user found for email: ${payload.to}`)
|
|
return NextResponse.json({ error: 'User not found' }, { status: 404 })
|
|
}
|
|
|
|
const { userId, companyId } = resolved
|
|
|
|
// Build raw email payload for BFL 7:2 archiving (no binary attachment content)
|
|
const rawEmailPayload = buildRawEmailPayload(body, payload)
|
|
|
|
// Extract file attachments
|
|
const attachments = extractAttachments(payload)
|
|
|
|
if (attachments.length === 0) {
|
|
await supabase
|
|
.from('invoice_inbox_items')
|
|
.insert({
|
|
company_id: companyId,
|
|
user_id: userId,
|
|
status: 'error',
|
|
source: 'email',
|
|
email_from: payload.from,
|
|
email_subject: payload.subject,
|
|
email_received_at: payload.created_at,
|
|
error_message: 'No supported attachments found',
|
|
raw_email_payload: rawEmailPayload,
|
|
})
|
|
|
|
return NextResponse.json({ data: { processed: 0, message: 'No attachments' } })
|
|
}
|
|
|
|
const processed: string[] = []
|
|
|
|
for (const attachment of attachments) {
|
|
try {
|
|
const buffer = Buffer.from(attachment.content, 'base64')
|
|
const hash = crypto.createHash('sha256').update(buffer).digest('hex')
|
|
|
|
// Upload to storage
|
|
const storagePath = `documents/${userId}/inbox/${Date.now()}-${attachment.filename}`
|
|
const { error: uploadError } = await supabase.storage
|
|
.from('documents')
|
|
.upload(storagePath, buffer, { contentType: attachment.content_type })
|
|
|
|
if (uploadError) {
|
|
console.error('[document-inbox] Upload failed:', uploadError)
|
|
continue
|
|
}
|
|
|
|
// Create document attachment
|
|
const { data: document, error: docError } = await supabase
|
|
.from('document_attachments')
|
|
.insert({
|
|
company_id: companyId,
|
|
user_id: userId,
|
|
storage_path: storagePath,
|
|
file_name: attachment.filename,
|
|
file_size_bytes: buffer.length,
|
|
mime_type: attachment.content_type,
|
|
sha256_hash: hash,
|
|
upload_source: 'email',
|
|
})
|
|
.select()
|
|
.single()
|
|
|
|
if (docError || !document) continue
|
|
|
|
// Unified classify + extract in a single Claude call
|
|
let documentType: 'supplier_invoice' | 'receipt' | 'government_letter' | 'unknown' = 'supplier_invoice'
|
|
let unifiedResult: Awaited<ReturnType<typeof analyzeDocument>> | null = null
|
|
try {
|
|
unifiedResult = await analyzeDocument(attachment.content, attachment.content_type)
|
|
documentType = unifiedResult.classification.type
|
|
console.log(`[document-inbox] Classified as ${documentType} (confidence: ${unifiedResult.classification.confidence})`)
|
|
} catch (classifyErr) {
|
|
console.error('[document-inbox] Classification failed, defaulting to supplier_invoice:', classifyErr)
|
|
}
|
|
|
|
// Create inbox item with document type and raw email payload
|
|
const { data: inboxItem, error: itemError } = await supabase
|
|
.from('invoice_inbox_items')
|
|
.insert({
|
|
company_id: companyId,
|
|
user_id: userId,
|
|
status: 'processing',
|
|
source: 'email',
|
|
email_from: payload.from,
|
|
email_subject: payload.subject,
|
|
email_received_at: payload.created_at,
|
|
document_id: document.id,
|
|
document_type: documentType,
|
|
raw_email_payload: rawEmailPayload,
|
|
})
|
|
.select()
|
|
.single()
|
|
|
|
if (itemError || !inboxItem) continue
|
|
|
|
// Route based on document type
|
|
try {
|
|
switch (documentType) {
|
|
case 'supplier_invoice': {
|
|
// Use pre-extracted invoice data from unified call
|
|
const extraction = unifiedResult?.invoice
|
|
if (!extraction) {
|
|
throw new Error('No invoice extraction available')
|
|
}
|
|
|
|
const isReverseCharge = unifiedResult?.classification.isReverseCharge ?? false
|
|
|
|
// Store reverse charge flag in extracted data
|
|
const extractedData = {
|
|
...(extraction as unknown as Record<string, unknown>),
|
|
isReverseCharge,
|
|
}
|
|
|
|
// Supplier matching
|
|
let matchedSupplierId: string | null = null
|
|
const { data: suppliers } = await supabase
|
|
.from('suppliers')
|
|
.select('*')
|
|
.eq('company_id', companyId)
|
|
|
|
if (suppliers && suppliers.length > 0) {
|
|
const match = matchSupplier(extraction, suppliers)
|
|
if (match && match.confidence >= 0.7) {
|
|
matchedSupplierId = match.supplierId
|
|
}
|
|
}
|
|
|
|
await supabase
|
|
.from('invoice_inbox_items')
|
|
.update({
|
|
status: 'ready',
|
|
extracted_data: extractedData,
|
|
confidence: extraction.confidence,
|
|
matched_supplier_id: matchedSupplierId,
|
|
})
|
|
.eq('id', inboxItem.id)
|
|
break
|
|
}
|
|
|
|
case 'receipt': {
|
|
// Use pre-extracted receipt data from unified call
|
|
const { data: urlData } = supabase.storage.from('documents').getPublicUrl(storagePath)
|
|
|
|
const result = await processReceiptFromDocument(supabase, userId, companyId, attachment.content, attachment.content_type, {
|
|
documentId: document.id,
|
|
source: 'email',
|
|
emailFrom: payload.from,
|
|
storageUrl: urlData.publicUrl,
|
|
preExtracted: unifiedResult?.receipt ?? undefined,
|
|
})
|
|
|
|
await supabase
|
|
.from('invoice_inbox_items')
|
|
.update({
|
|
status: 'ready',
|
|
linked_receipt_id: result.receipt.id,
|
|
confidence: result.receipt.extraction_confidence,
|
|
})
|
|
.eq('id', inboxItem.id)
|
|
break
|
|
}
|
|
|
|
case 'government_letter': {
|
|
// Store with status ready for manual review
|
|
await supabase
|
|
.from('invoice_inbox_items')
|
|
.update({
|
|
status: 'ready',
|
|
extracted_data: {
|
|
sender: payload.from,
|
|
subject: payload.subject,
|
|
body: typeof body.text === 'string' ? body.text : null,
|
|
},
|
|
})
|
|
.eq('id', inboxItem.id)
|
|
break
|
|
}
|
|
|
|
case 'unknown':
|
|
default: {
|
|
// Store with status ready for manual handling
|
|
await supabase
|
|
.from('invoice_inbox_items')
|
|
.update({ status: 'ready' })
|
|
.eq('id', inboxItem.id)
|
|
break
|
|
}
|
|
}
|
|
} catch (err) {
|
|
const message = err instanceof Error ? err.message : 'Processing failed'
|
|
await supabase
|
|
.from('invoice_inbox_items')
|
|
.update({ status: 'error', error_message: message })
|
|
.eq('id', inboxItem.id)
|
|
}
|
|
|
|
processed.push(inboxItem.id)
|
|
} catch (err) {
|
|
console.error('[document-inbox] Processing attachment failed:', err)
|
|
}
|
|
}
|
|
|
|
return NextResponse.json({ data: { processed: processed.length, ids: processed } })
|
|
}
|