b9a2ce522b
* chore: post-bankid redirect, recapt feedback, TIC SPAR enrichment - BankID login + register now redirect to /select-company so the picker shows freshly enriched CompanyRoles from the current session. - New lib/support/submit-feedback util prefers window.recapt feedback widget when present, falls back to /api/support/contact. SupportLink uses it and hides itself in sandbox companies via new isSandbox flag on CompanyContext (+ useCompanyOptional hook). - TIC enrichment re-requests SPAR alongside CompanyRoles now that both types are enabled on the tenant; enrichment shape logged PII-free (booleans/counts only). Tests cover the SPAR+CompanyRoles path. - Skatteverket api-client: 15s AbortSignal timeout on outbound requests. - Swedish compliance review CI: bump REVIEW_MODEL to claude-opus-4-7. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore: keep compliance review model on sonnet-4-6 Reverts the opus-4-7 bump from the previous commit per request. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(tic): don't persist SPAR PII to extension_data The previous commit started requesting SPAR alongside CompanyRoles and wrote the full enrichment payload (incl. personnummer, full name, home address, birth date, gender) verbatim to extension_data.value — a plain JSON column. Personnummer is already hashed + encrypted in bankid_identities, so the extension_data row was an unencrypted PII duplicate exposed to anyone with read access to the table. No consumer (middleware, /select-company, createCompanyFromTicRole) reads any SPAR field today; they only read companyRoles. Persist a sanitized blob of { companyRoles, enrichedAtUtc } instead. SPAR is still requested from TIC (and its shape logged PII-free) so enrichment completes; if address pre-fill ships later, those fields should be encrypted before storage. Also drop the dead `null` branch from SubmitFeedbackResult.channel — every code path returns 'recapt' or 'email'. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
105 lines
3.0 KiB
TypeScript
105 lines
3.0 KiB
TypeScript
import { describe, it, expect, vi, beforeEach, afterEach } from 'vitest'
|
|
import { submitFeedback } from '@/lib/support/submit-feedback'
|
|
|
|
describe('submitFeedback', () => {
|
|
beforeEach(() => {
|
|
vi.unstubAllGlobals()
|
|
vi.restoreAllMocks()
|
|
})
|
|
|
|
afterEach(() => {
|
|
vi.unstubAllGlobals()
|
|
})
|
|
|
|
function stubRecapt(impl: (...args: unknown[]) => void) {
|
|
vi.stubGlobal('window', { recapt: impl })
|
|
}
|
|
|
|
function stubNoRecapt() {
|
|
vi.stubGlobal('window', {})
|
|
}
|
|
|
|
it('uses Recapt when SDK is present and prepends subject', async () => {
|
|
const recapt = vi.fn()
|
|
stubRecapt(recapt)
|
|
const fetchSpy = vi.fn()
|
|
vi.stubGlobal('fetch', fetchSpy)
|
|
|
|
const result = await submitFeedback({ subject: 'Hjälpsida', message: 'Hjälp tack' })
|
|
|
|
expect(result).toEqual({ ok: true, channel: 'recapt' })
|
|
expect(recapt).toHaveBeenCalledWith('feedback', { message: '[Hjälpsida]\n\nHjälp tack' })
|
|
expect(fetchSpy).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('uses Recapt without subject prefix when subject omitted', async () => {
|
|
const recapt = vi.fn()
|
|
stubRecapt(recapt)
|
|
|
|
await submitFeedback({ message: 'plain' })
|
|
|
|
expect(recapt).toHaveBeenCalledWith('feedback', { message: 'plain' })
|
|
})
|
|
|
|
it('falls back to email when Recapt throws', async () => {
|
|
stubRecapt(() => {
|
|
throw new Error('boom')
|
|
})
|
|
const fetchSpy = vi.fn().mockResolvedValue({
|
|
ok: true,
|
|
json: async () => ({}),
|
|
})
|
|
vi.stubGlobal('fetch', fetchSpy)
|
|
|
|
const result = await submitFeedback({ subject: 'X', message: 'msg' })
|
|
|
|
expect(result).toEqual({ ok: true, channel: 'email' })
|
|
expect(fetchSpy).toHaveBeenCalledWith(
|
|
'/api/support/contact',
|
|
expect.objectContaining({
|
|
method: 'POST',
|
|
body: JSON.stringify({ subject: 'X', message: 'msg' }),
|
|
})
|
|
)
|
|
})
|
|
|
|
it('falls back to email when Recapt SDK is absent', async () => {
|
|
stubNoRecapt()
|
|
const fetchSpy = vi.fn().mockResolvedValue({
|
|
ok: true,
|
|
json: async () => ({}),
|
|
})
|
|
vi.stubGlobal('fetch', fetchSpy)
|
|
|
|
const result = await submitFeedback({ message: 'msg' })
|
|
|
|
expect(result).toEqual({ ok: true, channel: 'email' })
|
|
expect(fetchSpy).toHaveBeenCalledOnce()
|
|
})
|
|
|
|
it('returns failure with error from email when fetch returns non-ok', async () => {
|
|
stubNoRecapt()
|
|
const fetchSpy = vi.fn().mockResolvedValue({
|
|
ok: false,
|
|
json: async () => ({ error: 'Mailtjänsten är inte konfigurerad' }),
|
|
})
|
|
vi.stubGlobal('fetch', fetchSpy)
|
|
|
|
const result = await submitFeedback({ message: 'msg' })
|
|
|
|
expect(result.ok).toBe(false)
|
|
expect(result.channel).toBe('email')
|
|
expect(result.error).toBe('Mailtjänsten är inte konfigurerad')
|
|
})
|
|
|
|
it('returns failure when fetch itself throws', async () => {
|
|
stubNoRecapt()
|
|
vi.stubGlobal('fetch', vi.fn().mockRejectedValue(new Error('Network down')))
|
|
|
|
const result = await submitFeedback({ message: 'msg' })
|
|
|
|
expect(result.ok).toBe(false)
|
|
expect(result.error).toBe('Network down')
|
|
})
|
|
})
|