Files
accounted/lib/bookkeeping/__tests__/actor-context.test.ts
T
Jakob Wennberg 8d2ff61599 feat(bookkeeping): agent attribution into the immutable ledger layer (P0-1) (#678)
* feat(bookkeeping): agent attribution into the immutable ledger layer

Close the three attribution gaps left after 20260618120001 (which made
commit_method record 'api_key' for MCP-relayed approvals):

- journal_entries gains nullable committed_actor_type/committed_actor_label,
  stamped by commit_journal_entry in the same draft->posted UPDATE that
  writes commit_method. The RPC gains p_actor_type/p_actor_label
  (DEFAULT NULL; prior signature dropped first to avoid PostgREST overload
  ambiguity, same technique as 20260421140000).
- write_audit_log now populates audit_log.actor_type/actor_label from
  transaction-local gnubok.actor_* GUCs set by the RPC (the established
  gnubok.allow_delete pattern). Unset GUCs COALESCE to 'user' — byte-
  identical to the column's previous effective DEFAULT for every
  pre-existing write path.
- commitPendingOperation accepts opts.actor and runs the entire executor
  inside an AsyncLocalStorage runWithActor() scope read by commitEntry(),
  so EVERY journal commit an operation makes is attributed — closing the
  documented "commitMethod only reaches create_voucher" gap. MCP approve
  passes the api_key actor + key label; web single/bulk approve pass the
  user + email.

Known limitation (documented): reverseEntry posts reversal vouchers via
direct PostgREST writes, not the commit RPC — reversals keep NULL
attribution until that path is RPC-ified (follow-up).

pg-real coverage: lib/bookkeeping/__tests__/commit-actor.pg.test.ts
(RPC param stamping, audit GUC read, transaction-locality, CHECK
rejection, immutability of the new columns, single-signature guard).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(bookkeeping): split actor-context so client bundles never see node:async_hooks

CI core-only build failed: engine.ts is reachable from client component
bundles (invoices/[id] page), and the static node:async_hooks import in
actor-context.ts cannot be chunked for the browser. Split the module:

- actor-context.ts (isomorphic): CommitActor type + a storage registry +
  getActor(). In a client bundle the registry stays empty and getActor()
  returns undefined — identical to the server-side no-scope default.
- actor-context-node.ts (server-only): owns the AsyncLocalStorage, binds it
  into the registry on import, exports runWithActor(). Imported only by the
  approval paths (commit.ts), which are never client-reachable.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-06 10:05:48 +02:00

44 lines
1.5 KiB
TypeScript

import { describe, it, expect } from 'vitest'
import { runWithActor } from '../actor-context-node'
import { getActor } from '../actor-context'
describe('actor-context (AsyncLocalStorage commit attribution)', () => {
it('returns undefined outside a runWithActor scope', () => {
expect(getActor()).toBeUndefined()
})
it('exposes the actor inside the scope, across awaits', async () => {
const seen: Array<ReturnType<typeof getActor>> = []
await runWithActor({ type: 'api_key', label: 'Test Key' }, async () => {
seen.push(getActor())
await new Promise((resolve) => setTimeout(resolve, 0))
seen.push(getActor())
})
expect(seen).toEqual([
{ type: 'api_key', label: 'Test Key' },
{ type: 'api_key', label: 'Test Key' },
])
expect(getActor()).toBeUndefined()
})
it('keeps concurrent scopes isolated', async () => {
const results = await Promise.all([
runWithActor({ type: 'api_key', label: 'A' }, async () => {
await new Promise((resolve) => setTimeout(resolve, 5))
return getActor()?.label
}),
runWithActor({ type: 'user', label: 'B' }, async () => {
return getActor()?.label
}),
])
expect(results).toEqual(['A', 'B'])
})
it('propagates into nested calls without parameter threading', async () => {
const deepRead = async () => getActor()
const middle = async () => deepRead()
const actor = await runWithActor({ type: 'agent_chat' }, middle)
expect(actor).toEqual({ type: 'agent_chat' })
})
})