Files
Jakob Wennberg 4c6feea64d feat(connect): bank sync through the connector operation, with a per-company canary (#2205)
* feat(connect): bank sync through the connector operation, with a per-company canary

In connector mode the enable-banking sync no longer pages Enable Banking on
the instance: it calls POST /api/connect/bank/sync on the hosted service with
the session id it holds and the account, and receives booked, normalized
rows plus the raw provider pages to archive. Everything downstream is shared
with the direct path (stored external ids computed here from booking_date,
amount and the account scope; ingest; archive; balance refresh), so a company
that moves to the connector produces byte-identical keys. A 410 from the
service maps onto the same SessionExpiredError the direct path throws.

bankConnectorMode(companyId) gains CONNECT_BANK_CANARY_COMPANIES: listed
companies use the connector even while the installation has its own Enable
Banking credentials, which is how hosted Accounted moves its bank sync to
Connect a few companies at a time before dropping its keys. The contract
package gains the bank sync request/response schemas (2026-09-03).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>

* fix(connect): calendar-valid dates, body read inside the timeout, service origin as the default

Review follow-ups on #2205. The contract validates date_from, date_to and
booking_date with z.iso.date() (2026-02-30 and an empty booking date are
refused; the installation derives its stored keys from booking_date). The
connector sync reads the response body inside the timeout window so a
service that stalls the body cannot hold the sync open. DEFAULT_CONNECT_BASE_URL
now names the connector service (connect.accounted.se), which is where the
sync operation exists; the hosted app's copy of the connector routes is
legacy and hosted Accounted itself sets GNUBOK_CONNECT_URL explicitly.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>

---------

Signed-off-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-03 11:06:47 +02:00

26 lines
1.1 KiB
TypeScript

/**
* The wire contract between a self-hosted Accounted instance and the hosted
* connector service (connect.accounted.se/api/connect/*). The definitions live in
* the MIT package packages/connect-contract (published as
* @accounted/connect-contract) so that either side can be implemented outside
* this repository; this module re-exports them for in-repo callers.
*
* Background: a self-hosted instance runs everything itself except the
* services only Accounted can operate (bank sync via our PSD2/AISP
* credentials, the Skatteverket API client, TIC org lookup, the migration
* gateway). A connector key (`gnubok_ck_...`) is the subscription token for
* those; this is the Nabu Casa model: everything local is free AGPL, the key
* buys access to the hosted connectors, and enforcement is key auth at the
* hosted proxy, never a licence check inside the instance.
*/
export {
CONNECTOR_KEY_PREFIX,
CONNECTOR_KEY_HEADER,
CONNECTOR_ENTITLEMENTS_PATH,
DEFAULT_CONNECT_BASE_URL,
type ConnectorKeyStatus,
type ConnectorEntitlements,
type ConnectorSyncReport,
} from '@accounted/connect-contract'