* feat(agent): telemetry completeness + durability, CI gates, commit_method provenance
Quick wins from the "Building AI systems that ship" audit:
- mcp.tool_called gains errorMessage (message_sv, truncated 500 chars) on
all failure exits; new mcp.skill_loaded event on every gnubok_load_skill
(all tiers) so atom usage is finally measurable
- event_log: (event_type, created_at) index; cleanup cron keeps
mcp.*/agent.* telemetry 180 days (delivery events stay 30)
- CI: lint ratchet (npm run check:lint — 60 legacy errors baselined,
fails only on NEW errors) and a pg-real coverage gate (migrations
touching trigger/RPC/RLS/DEFERRABLE require a *.pg.test.ts change;
escape hatch: -- pg-test: covered-by/skip)
- journal_entries.commit_method CHECK widened with 'api_key'/'agent';
the MCP approve path records 'api_key' truthfully instead of
'user_accept' (agent_first_vision §8 P0-1). 'agent' is reserved — ALL
MCP traffic (incl. claude.ai OAuth, whose access_token is a minted
API key) authenticates as api_key today
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(import): derive opening balances from prior-year #UB when SIE lacks #IB (#675)
SIE files exported without #IB 0 rows (only #UB -1) previously imported
with zero opening balances. getEffectiveOpeningBalances() now derives IB
from prior-year UB for balance-sheet accounts when explicit #IB is
absent, surfaces the derivation as an info issue in the import preview,
and excludes share-capital vouchers from opening-balance detection.
Detection regexes are shared between parser and importer so the two
checks cannot drift. 507 lib/import tests pass.
(Authored in a parallel session in this checkout; included per request.)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(review): address PR #677 bot findings — RoPA entry, execFileSync, gate scope note
Triage of the compliance-swarm + Greptile findings:
Applied:
- .compliance/ropa.yaml: new mcp.telemetry processing activity declaring
the 180-day mcp.*/agent.* retention, lawful basis, data categories, and
the no-args/no-results minimisation (ISO A.8.10, GDPR Art.5(1)(c) —
the retention split is now formally documented, referenced from the cron)
- check-pg-test-coverage.mjs: execFileSync with argv array — no shell, so
a hostile base-ref can't inject (ASVS V13.2.1); verified an injection
attempt exits 2 without executing
- check-pg-test-coverage.mjs: documented the PR-level (not per-migration)
scope of the gate so reviewers know to check coverage per migration when
a PR carries several risky migrations (Greptile P2)
Acknowledged, no change:
- errorMessage PII risk: messages are domain-mapped strings; event_log
already persists far richer delivery payloads under the same RLS; now
declared in ropa.yaml
- cron error envelope: errorResponse maps to the canonical safe envelope
and the endpoint is CRON_SECRET-gated
- two-pass delete "partial state": TTL deletes are idempotent — the next
daily run sweeps whatever a failed pass left behind
- skill_loaded actorLabel/sessionId: mirrors the pre-existing
mcp.tool_called payload; sessionId is the join key the analytics exist for
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test: add real-Postgres smoke gate (pg-real)
Mocked Supabase tests cannot exercise triggers, RPCs, or RLS policies —
a migration that drops enforce_period_lock, mangles user_company_ids(),
or weakens an RLS policy ships green today. Closes that gap with a
small Vitest project `pg-real` running 5 smoke tests against a real
supabase/postgres:15 container in CI.
Covers: closed-period INSERT rejection, commit_journal_entry voucher
atomicity under concurrency, posted-entry immutability, RLS tenant
isolation on journal_entries, and audit_log UPDATE/DELETE rejection.
Also lands the bankid anonymization migration that was sitting
untracked from a prior task.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* test(pg-real): fix storage schema bootstrap + de-scope + PR review fixes
- Drop bankid anonymization migration from this PR. That change is
separate scope (and has open compliance questions flagged by the
Swedish review bot on #357); it will land in its own PR.
- Add tests/pg/bootstrap.sql to align storage.buckets/objects/foldername
with what migrations expect before the replay loop. The supabase/postgres
image ships only a partial storage schema; the rest comes from the
storage-api service at runtime, which CI does not run. First pg-real run
failed at migration 24 on "column public of relation buckets does not exist".
- Add concurrency group to the workflow so stacked PR commits cancel
in-progress runs instead of queueing.
- Gate the pg-real vitest project on DATABASE_URL so a bare `vitest run`
with no DB configured runs only the unit project. npm run test:pg is
the opt-in entry point.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* test(pg-real): widen JWT claim setup so auth.uid() resolves under RLS
The rls.pg test came back with 0 rows instead of 1 — user_company_ids()
returned empty because auth.uid() didn't resolve to the seeded user.
Two fixes:
- Set both request.jwt.claims (whole object) and request.jwt.claim.sub
(individual claim). Different Supabase auth.uid() versions read one or
the other.
- Assert auth.uid() = expected userId immediately after the context
switch, so the next failure points at the right layer instead of an
unrelated empty-result assertion.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>