8d2ff61599
* feat(bookkeeping): agent attribution into the immutable ledger layer Close the three attribution gaps left after 20260618120001 (which made commit_method record 'api_key' for MCP-relayed approvals): - journal_entries gains nullable committed_actor_type/committed_actor_label, stamped by commit_journal_entry in the same draft->posted UPDATE that writes commit_method. The RPC gains p_actor_type/p_actor_label (DEFAULT NULL; prior signature dropped first to avoid PostgREST overload ambiguity, same technique as 20260421140000). - write_audit_log now populates audit_log.actor_type/actor_label from transaction-local gnubok.actor_* GUCs set by the RPC (the established gnubok.allow_delete pattern). Unset GUCs COALESCE to 'user' — byte- identical to the column's previous effective DEFAULT for every pre-existing write path. - commitPendingOperation accepts opts.actor and runs the entire executor inside an AsyncLocalStorage runWithActor() scope read by commitEntry(), so EVERY journal commit an operation makes is attributed — closing the documented "commitMethod only reaches create_voucher" gap. MCP approve passes the api_key actor + key label; web single/bulk approve pass the user + email. Known limitation (documented): reverseEntry posts reversal vouchers via direct PostgREST writes, not the commit RPC — reversals keep NULL attribution until that path is RPC-ified (follow-up). pg-real coverage: lib/bookkeeping/__tests__/commit-actor.pg.test.ts (RPC param stamping, audit GUC read, transaction-locality, CHECK rejection, immutability of the new columns, single-signature guard). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bookkeeping): split actor-context so client bundles never see node:async_hooks CI core-only build failed: engine.ts is reachable from client component bundles (invoices/[id] page), and the static node:async_hooks import in actor-context.ts cannot be chunked for the browser. Split the module: - actor-context.ts (isomorphic): CommitActor type + a storage registry + getActor(). In a client bundle the registry stays empty and getActor() returns undefined — identical to the server-side no-scope default. - actor-context-node.ts (server-only): owns the AsyncLocalStorage, binds it into the registry on import, exports runWithActor(). Imported only by the approval paths (commit.ts), which are never client-reachable. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
92 lines
3.0 KiB
TypeScript
92 lines
3.0 KiB
TypeScript
import { createClient } from '@/lib/supabase/server'
|
|
import { NextResponse } from 'next/server'
|
|
import { ensureInitialized } from '@/lib/init'
|
|
import { requireCompanyId } from '@/lib/company/context'
|
|
import { requireWritePermission } from '@/lib/auth/require-write'
|
|
import { validateBody } from '@/lib/api/validate'
|
|
import { PendingOperationsBulkSchema } from '@/lib/api/schemas'
|
|
import { commitPendingOperation } from '@/lib/pending-operations/commit'
|
|
import type { PendingOperation } from '@/types'
|
|
|
|
ensureInitialized()
|
|
|
|
interface BulkCommitItemResult {
|
|
id: string
|
|
status: 'committed' | 'failed' | 'skipped' | 'rejected'
|
|
error?: string
|
|
}
|
|
|
|
export async function POST(request: Request) {
|
|
const supabase = await createClient()
|
|
|
|
const { data: { user } } = await supabase.auth.getUser()
|
|
if (!user) {
|
|
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
|
|
}
|
|
|
|
const writeCheck = await requireWritePermission(supabase, user.id)
|
|
if (!writeCheck.ok) return writeCheck.response
|
|
|
|
const validated = await validateBody(request, PendingOperationsBulkSchema)
|
|
if (!validated.success) return validated.response
|
|
const { ids } = validated.data
|
|
|
|
const companyId = await requireCompanyId(supabase, user.id)
|
|
|
|
const { data: ops, error: fetchError } = await supabase
|
|
.from('pending_operations')
|
|
.select('*')
|
|
.in('id', ids)
|
|
.eq('company_id', companyId)
|
|
|
|
if (fetchError) {
|
|
return NextResponse.json({ error: fetchError.message }, { status: 500 })
|
|
}
|
|
|
|
const opsById = new Map((ops ?? []).map((op) => [op.id, op as PendingOperation]))
|
|
const results: BulkCommitItemResult[] = []
|
|
|
|
for (const id of ids) {
|
|
const op = opsById.get(id)
|
|
if (!op) {
|
|
results.push({ id, status: 'failed', error: 'Operation not found' })
|
|
continue
|
|
}
|
|
if (op.status !== 'pending') {
|
|
results.push({ id, status: 'skipped', error: `Already ${op.status}` })
|
|
continue
|
|
}
|
|
if (op.risk_level === 'high') {
|
|
results.push({
|
|
id,
|
|
status: 'skipped',
|
|
error: 'Hög risk — kräver individuellt godkännande',
|
|
})
|
|
continue
|
|
}
|
|
|
|
const result = await commitPendingOperation(supabase, user.id, companyId, op, {
|
|
userEmail: user.email,
|
|
commitMethod: 'bulk_accept',
|
|
actor: { type: 'user', ...(user.email ? { label: user.email } : {}) },
|
|
})
|
|
if (result.status === 'committed') {
|
|
results.push({ id, status: 'committed' })
|
|
} else if (result.status === 'rejected' && result.auto_rejected) {
|
|
results.push({ id, status: 'rejected', error: result.error ?? 'Avvisad' })
|
|
} else {
|
|
results.push({ id, status: 'failed', error: result.error ?? 'Misslyckades' })
|
|
}
|
|
}
|
|
|
|
const summary = {
|
|
total: results.length,
|
|
committed: results.filter((r) => r.status === 'committed').length,
|
|
failed: results.filter((r) => r.status === 'failed').length,
|
|
skipped: results.filter((r) => r.status === 'skipped').length,
|
|
rejected: results.filter((r) => r.status === 'rejected').length,
|
|
}
|
|
|
|
return NextResponse.json({ data: { results, summary } })
|
|
}
|