bc61862e76
* feat(agent): telemetry completeness + durability, CI gates, commit_method provenance Quick wins from the "Building AI systems that ship" audit: - mcp.tool_called gains errorMessage (message_sv, truncated 500 chars) on all failure exits; new mcp.skill_loaded event on every gnubok_load_skill (all tiers) so atom usage is finally measurable - event_log: (event_type, created_at) index; cleanup cron keeps mcp.*/agent.* telemetry 180 days (delivery events stay 30) - CI: lint ratchet (npm run check:lint — 60 legacy errors baselined, fails only on NEW errors) and a pg-real coverage gate (migrations touching trigger/RPC/RLS/DEFERRABLE require a *.pg.test.ts change; escape hatch: -- pg-test: covered-by/skip) - journal_entries.commit_method CHECK widened with 'api_key'/'agent'; the MCP approve path records 'api_key' truthfully instead of 'user_accept' (agent_first_vision §8 P0-1). 'agent' is reserved — ALL MCP traffic (incl. claude.ai OAuth, whose access_token is a minted API key) authenticates as api_key today Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(import): derive opening balances from prior-year #UB when SIE lacks #IB (#675) SIE files exported without #IB 0 rows (only #UB -1) previously imported with zero opening balances. getEffectiveOpeningBalances() now derives IB from prior-year UB for balance-sheet accounts when explicit #IB is absent, surfaces the derivation as an info issue in the import preview, and excludes share-capital vouchers from opening-balance detection. Detection regexes are shared between parser and importer so the two checks cannot drift. 507 lib/import tests pass. (Authored in a parallel session in this checkout; included per request.) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(review): address PR #677 bot findings — RoPA entry, execFileSync, gate scope note Triage of the compliance-swarm + Greptile findings: Applied: - .compliance/ropa.yaml: new mcp.telemetry processing activity declaring the 180-day mcp.*/agent.* retention, lawful basis, data categories, and the no-args/no-results minimisation (ISO A.8.10, GDPR Art.5(1)(c) — the retention split is now formally documented, referenced from the cron) - check-pg-test-coverage.mjs: execFileSync with argv array — no shell, so a hostile base-ref can't inject (ASVS V13.2.1); verified an injection attempt exits 2 without executing - check-pg-test-coverage.mjs: documented the PR-level (not per-migration) scope of the gate so reviewers know to check coverage per migration when a PR carries several risky migrations (Greptile P2) Acknowledged, no change: - errorMessage PII risk: messages are domain-mapped strings; event_log already persists far richer delivery payloads under the same RLS; now declared in ropa.yaml - cron error envelope: errorResponse maps to the canonical safe envelope and the endpoint is CRON_SECRET-gated - two-pass delete "partial state": TTL deletes are idempotent — the next daily run sweeps whatever a failed pass left behind - skill_loaded actorLabel/sessionId: mirrors the pre-existing mcp.tool_called payload; sessionId is the join key the analytics exist for Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
64 lines
2.3 KiB
TypeScript
64 lines
2.3 KiB
TypeScript
import { describe, expect, it } from 'vitest'
|
|
import {
|
|
seedCompany,
|
|
insertDraftJournalEntry,
|
|
insertBalancedLines,
|
|
} from '@/tests/pg/fixtures'
|
|
import { getPool } from '@/tests/pg/setup'
|
|
|
|
/**
|
|
* Covers 20260618120001_commit_method_agent_provenance:
|
|
* - journal_entries.commit_method accepts the new 'agent' and 'api_key'
|
|
* values (MCP-relayed approvals — agent_first_vision.md §8 P0-1).
|
|
* - The pre-existing values are still accepted.
|
|
* - Unknown values are still rejected by the CHECK constraint.
|
|
* - Exactly one commit_method constraint exists (guards against the
|
|
* DROP CONSTRAINT IF EXISTS missing a differently-named original, which
|
|
* would leave the old, narrower CHECK in force).
|
|
*/
|
|
|
|
async function postWithCommitMethod(commitMethod: string): Promise<string> {
|
|
const { userId, companyId, fiscalPeriodId } = await seedCompany()
|
|
const entryId = await insertDraftJournalEntry({ userId, companyId, fiscalPeriodId })
|
|
await insertBalancedLines(entryId)
|
|
// draft → posted with commit metadata — same transition the commit RPC does.
|
|
await getPool().query(
|
|
`UPDATE public.journal_entries
|
|
SET status = 'posted', voucher_number = 1, commit_method = $2
|
|
WHERE id = $1`,
|
|
[entryId, commitMethod],
|
|
)
|
|
return entryId
|
|
}
|
|
|
|
describe('journal_entries.commit_method — agent provenance values', () => {
|
|
it.each(['agent', 'api_key', 'user_accept', 'bulk_accept'])(
|
|
'accepts commit_method=%s',
|
|
async (method) => {
|
|
const entryId = await postWithCommitMethod(method)
|
|
const { rows } = await getPool().query(
|
|
`SELECT commit_method, status FROM public.journal_entries WHERE id = $1`,
|
|
[entryId],
|
|
)
|
|
expect(rows[0]).toEqual({ commit_method: method, status: 'posted' })
|
|
},
|
|
)
|
|
|
|
it('rejects values outside the CHECK list', async () => {
|
|
await expect(postWithCommitMethod('robot')).rejects.toMatchObject({
|
|
// 23514 = check_violation
|
|
code: '23514',
|
|
})
|
|
})
|
|
|
|
it('exactly one commit_method CHECK constraint exists, under the canonical name', async () => {
|
|
const { rows } = await getPool().query(
|
|
`SELECT conname
|
|
FROM pg_constraint
|
|
WHERE conrelid = 'public.journal_entries'::regclass
|
|
AND conname LIKE '%commit_method%'`,
|
|
)
|
|
expect(rows.map((r) => r.conname)).toEqual(['journal_entries_commit_method_check'])
|
|
})
|
|
})
|