Nightly cloud-backup syncs kept retrying Google connections whose
refresh token is permanently dead (Google returns 400 invalid_grant;
3 of 12 prod connections are in this state), and the settings card
showed the raw English error string while presenting the account as
connected.
- refreshAccessToken now throws a typed GoogleTokenRefreshError
carrying status + body, with an isInvalidGrant discriminator.
- performSync catches the invalid_grant case, persists
status: 'needs_reauth' (+ needs_reauth_at) on the connection JSON in
extension_data (no migration needed), and returns a needs_reauth
failure instead of throwing. Transient failures (5xx, network, other
400s) still throw and stay retried.
- The nightly cron loads connections for due companies and skips
needs_reauth ones (reported as skipped in the summary) instead of
retrying the dead token every night. A successful refresh clears a
stale flag; reconnecting via OAuth writes a fresh connection.
- CloudBackupCard shows a reconnect callout (Swedish-first, sv+en
strings) wired to the existing connect action, and replaces the raw
error string on the schedule row with a short reconnect notice.
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat: cloud backup to Google Drive + full-archive all-scope
Adds a cloud-backup extension that uploads a full-company backup ZIP to
the user's own Google Drive via OAuth (drive.file scope only). Refresh
tokens are AES-256-GCM encrypted before being stored in extension_data.
The full-archive export gains a scope=all mode for whole-company
backups (per-period SIE under sie/, per-period rapporter/ subfolders,
flat dokument/ manifest tagged with fiscal_period_id). An 80 MB size
guard short-circuits generation before the platform response limit.
Also fixes a latent bug in lib/core/audit/audit-service.ts where the
parameter was named userId while the query filtered by company_id; the
audit-trail API route was passing user.id so audit queries returned
empty unless user and company shared a UUID.
Drive-by: scope the dashboard "fresh start" localStorage key per
companyId so dismissing the setup checklist in one company no longer
carries over to others.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix: address review comments on cloud backup + archive export
- Extend audit trail to_date to end-of-day so last-day entries aren't
silently excluded from period-scoped archives.
- Apply 413 size-limit guard regardless of include_documents, using the
overhead-only figure when documents are excluded.
- Use crypto.randomUUID() for Drive multipart boundary to eliminate any
collision risk with ZIP payload bytes.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix: migrate legacy setup-gate localStorage keys on dashboard
Users who previously dismissed the setup checklist via the old global
erp_setup_fresh_start or erp_checklist_dismissed keys were re-gated after
the switch to a company-scoped key. Fall back to the legacy keys on read
and migrate them to the scoped key on first hit.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix: update customer email handling and anonymization rules in supportmail-to-ticket skill
* test: update audit trail to_date expectation for end-of-day timestamp
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>