Files
accounted/lib/onboarding/__tests__/checklist.test.ts
T
Mattsson a80ce54b78 fix(mcp): eager-auth flag on the Grok connector links so Grok starts OAuth (#2167)
* fix(mcp): eager-auth flag on the Grok connector links so Grok starts OAuth

Live test after #2158: pasting the Grok URL into grok.com's custom
connector dialog listed all 150+ tools and never opened the sign-in. Grok
probes the URL without credentials, like claude.ai, and reads the lazy
200 on initialize as an authless server; only the 401 challenge starts
OAuth (#2159 fixed the same thing for the claude.ai link).

- lib/onboarding/checklist.ts: mcpServerUrl() builds the server URL with
  an optional eagerAuth flag; sideDoorServerUrl() gives the Grok side door
  auth=required and keeps ChatGPT lazy; claudeConnectorLink() reuses it.
  SIDE_DOORS / SideDoor move here from the component. Tests for all three.
- NewUserChecklist copies the door-specific URL (now with a client marker).
- ApiKeysPanel's Grok row copies the flagged URL, mirroring the Claude one.
- auth-mode.ts comment records the second consumer; registry entry's Grok
  step carries the flag; DECISIONS.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LhTJcwgzmN3TsLR8tVHwdi
Signed-off-by: Emil <emilmattsson14@gmail.com>

* docs(mcp): registry Claude.ai step carries auth=required too

Review pass on #2167: the registry entry flagged the Grok install URL
but left the Claude.ai step on the bare URL, which pre-fills "None" in
claude.ai's dialog (#2159). Same file, same flag, now consistent.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LhTJcwgzmN3TsLR8tVHwdi
Signed-off-by: Emil <emilmattsson14@gmail.com>

---------

Signed-off-by: Emil <emilmattsson14@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 16:55:23 +02:00

169 lines
6.4 KiB
TypeScript

import { describe, expect, it } from 'vitest'
import {
checklistNumbers,
claudeConnectorLink,
mcpServerUrl,
sideDoorServerUrl,
SIDE_DOORS,
claudeStepDone,
completionPatchBody,
vatDeadlineLine,
} from '../checklist'
describe('vatDeadlineLine', () => {
it('returns null when the company is not VAT-registered', () => {
expect(
vatDeadlineLine({ vatRegistered: false, momsPeriod: 'quarterly', nextVatDueDate: '2026-11-12' })
).toBeNull()
expect(
vatDeadlineLine({ vatRegistered: null, momsPeriod: null, nextVatDueDate: null })
).toBeNull()
})
it('flags the silent zero-deadline misconfiguration when moms_period is unset', () => {
expect(
vatDeadlineLine({ vatRegistered: true, momsPeriod: null, nextVatDueDate: null })
).toEqual({ kind: 'missing_period' })
// Even with a stray row, an unset period is still a misconfiguration to surface.
expect(
vatDeadlineLine({ vatRegistered: true, momsPeriod: undefined, nextVatDueDate: '2026-11-12' })
).toEqual({ kind: 'missing_period' })
})
it('returns the due date when registered with a period and an upcoming row', () => {
expect(
vatDeadlineLine({ vatRegistered: true, momsPeriod: 'quarterly', nextVatDueDate: '2026-11-12' })
).toEqual({ kind: 'date', dueDate: '2026-11-12' })
})
it('says nothing when a period is set but no upcoming row surfaced', () => {
expect(
vatDeadlineLine({ vatRegistered: true, momsPeriod: 'yearly', nextVatDueDate: null })
).toBeNull()
})
})
describe('checklistNumbers', () => {
it('numbers all five steps when both extensions are on', () => {
expect(checklistNumbers({ hasSkatteverket: true, hasInbox: true })).toEqual({
count: 5,
skv: 3,
receipts: 4,
assistant: 5,
})
})
it('collapses to four steps without the inbox extension', () => {
expect(checklistNumbers({ hasSkatteverket: true, hasInbox: false })).toEqual({
count: 4,
skv: 3,
receipts: 4,
assistant: 4,
})
})
it('collapses to four steps without the skatteverket extension', () => {
expect(checklistNumbers({ hasSkatteverket: false, hasInbox: true })).toEqual({
count: 4,
skv: 3,
receipts: 3,
assistant: 4,
})
})
it('collapses to three steps with neither extension', () => {
expect(checklistNumbers({ hasSkatteverket: false, hasInbox: false })).toEqual({
count: 3,
skv: 3,
receipts: 3,
assistant: 3,
})
})
})
describe('completionPatchBody', () => {
it('keeps a recorded path out of the body', () => {
expect(completionPatchBody('bank')).toEqual({ completed: true })
expect(completionPatchBody('fresh')).toEqual({ completed: true })
})
it('records migration when no path was chosen, so the route accepts completion', () => {
// Skipped the books question, then imported: step 1 is only done via an
// import in that state. Without a path the route answers 400 and the
// completion effect used to retry it forever.
expect(completionPatchBody(null)).toEqual({ completed: true, path: 'migration' })
})
})
describe('claudeStepDone', () => {
it('is done once an OAuth-minted MCP key row exists', () => {
expect(claudeStepDone({ oauthKeyCount: 1 })).toBe(true)
expect(claudeStepDone({ oauthKeyCount: 3 })).toBe(true)
})
it('stays open without a key row, including a null head count', () => {
expect(claudeStepDone({ oauthKeyCount: 0 })).toBe(false)
expect(claudeStepDone({ oauthKeyCount: null })).toBe(false)
expect(claudeStepDone({ oauthKeyCount: undefined })).toBe(false)
})
})
describe('mcpServerUrl', () => {
it('builds the namespaced URL with the client marker and no auth flag by default', () => {
expect(mcpServerUrl({ origin: 'https://app.testbrand.example', client: 'cursor' })).toBe(
'https://app.testbrand.example/api/extensions/ext/mcp-server/mcp?tool_namespace=accounted&client=cursor',
)
})
it('appends auth=required when eagerAuth is set', () => {
const url = new URL(mcpServerUrl({ origin: 'http://localhost:3000', client: 'grok', eagerAuth: true }))
expect(url.searchParams.get('tool_namespace')).toBe('accounted')
expect(url.searchParams.get('client')).toBe('grok')
expect(url.searchParams.get('auth')).toBe('required')
})
})
describe('sideDoorServerUrl', () => {
it('lists chatgpt then grok', () => {
expect(SIDE_DOORS).toEqual(['chatgpt', 'grok'])
})
it('gives Grok the eager-auth flag: its dialog reads a 200 probe as "no auth" and never starts OAuth', () => {
const url = new URL(sideDoorServerUrl({ origin: 'https://app.testbrand.example', door: 'grok' }))
expect(url.searchParams.get('client')).toBe('grok')
expect(url.searchParams.get('auth')).toBe('required')
})
it('keeps ChatGPT on the lazy URL', () => {
const url = new URL(sideDoorServerUrl({ origin: 'https://app.testbrand.example', door: 'chatgpt' }))
expect(url.searchParams.get('client')).toBe('chatgpt')
expect(url.searchParams.get('auth')).toBeNull()
})
})
describe('claudeConnectorLink', () => {
it('builds the claude.ai deep link with namespace, client marker and eager-auth flag, from the page origin', () => {
const link = claudeConnectorLink({ origin: 'https://app.testbrand.example', appName: 'Testbrand' })
expect(link).toBe(
'https://claude.ai/customize/connectors?modal=add-custom-connector' +
'&connectorName=Testbrand' +
'&connectorUrl=https%3A%2F%2Fapp.testbrand.example%2Fapi%2Fextensions%2Fext%2Fmcp-server%2Fmcp%3Ftool_namespace%3Daccounted%26client%3Dclaude-connector%26auth%3Drequired',
)
})
it('matches the Settings → API & MCP button shape (tool_namespace + client=claude-connector + auth=required)', () => {
const link = claudeConnectorLink({ origin: 'http://localhost:3000', appName: 'Bokföring AB' })
const url = new URL(link)
expect(url.searchParams.get('connectorName')).toBe('Bokföring AB')
const server = new URL(url.searchParams.get('connectorUrl') ?? '')
expect(server.origin).toBe('http://localhost:3000')
expect(server.pathname).toBe('/api/extensions/ext/mcp-server/mcp')
expect(server.searchParams.get('tool_namespace')).toBe('accounted')
expect(server.searchParams.get('client')).toBe('claude-connector')
// Without this flag claude.ai's Add-custom-connector dialog pre-fills
// Authentication "None" (the lazy handshake answers 200) and the sign-in
// never opens.
expect(server.searchParams.get('auth')).toBe('required')
})
})