Files
accounted/extensions/general/stripe/__tests__/sync.test.ts
T
Mattsson d840257c0c Add/stripe connect transactions (#1139)
* fix(mcp-oauth): allow ChatGPT connector callbacks and resume OAuth after login

Add chatgpt.com/connector/oauth/* (per-instance) and the legacy
chatgpt.com/connector_platform_oauth_redirect to the built-in OAuth
redirect allowlist so ChatGPT MCP connectors can register and authorize.

Fix the login page dropping the ?next= destination: an OAuth-initiated
visit that required login previously ended on the dashboard and the
connection flow silently died. Login now resumes to the sanitized next
path (hard navigation, since the consent page is route-handler HTML),
carries it through the MFA step-up as returnTo, and /mfa/verify
hard-navigates for /api/ destinations.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(transactions): dedup incoming feed rows against booked hand-entered twins

Users who bookkeep via MCP/chat first and connect their bank afterwards got
the same movement twice: the synced row's external_id lives in a different
namespace, the free-form manual title never text-bridges the bank's raw
string, and the cross-channel mirror deliberately excluded manual/mcp rows.

Extend the mirror with a booked-hand-entered track: an incoming feed row is
skipped when a BOOKED manual/mcp row shares its (date, ore) bucket count-
symmetrically. Gates beyond the feed-vs-feed mirror: stored row must be
booked (staged rows never consume an import), currencies must not contradict
(bucket key is date+ore only), the cash-account guard applies to the count
exactly as to consumption, and symmetry uses the Layer-1-unmatched incoming
count so an already-stored row cannot inflate it. Consumption stamps the
batch cash_account_id onto an account-unbound hand row, so one hand row can
never consume feed rows on other accounts in later syncs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(bookkeeping): inline verifikat rattelse (strike lines + text/date edit)

Second sanctioned correction track under BFL 5 kap 5/9 pp, Fortnox-style:
strike lines inside a posted verifikat with replacements in the same
voucher, and correct description/entry_date without an andringsverifikat.
Envelope: posted entries, open unlocked periods, company lock date,
same-period date moves, structural/FX/doc-linked lines excluded, and a
reconciliation guard preserving per-account net on bank/reskontra sides of
externally linked entries. Every rattelse writes an immutable who/when row
(journal_entry_rattelse_log, WORM, archived as rakenskapsinformation) and
struck originals render struck-through in the verifikat; list rows and the
detail header carry a Rattad marker. CLAUDE.md hard rule 1 and the
swedish-accounting-compliance skill are amended to state the two-track
rule. Staging carries the DDL; prod gets it on merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat: live saldo in booking form, prior-year window comparison, hideable assistant FAB

- Manual journal entry: saldo column now shows before -> after computed
  from the typed debit/credit amounts (direction feedback while booking)
- Resultatrapport: a narrowed date range now compares against the same
  window shifted one year back (#862), merged across fiscal periods for
  brutet rakenskapsar; P&L rows report window activity instead of
  rolled-forward YTD closing
- Assistant FAB: per-user hide toggle (user_preferences.hide_assistant_fab,
  settings > assistant), sidebar entry unaffected; collapsed sessions keep
  their reopen handle

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(stripe): sync balance transactions as a bank feed on 1686

Import the connected Stripe balance into the transactions inbox, opt-in
per connection (transaction_sync_enabled on stripe_connections):

- Balance transactions map to feed rows with the two-row gross+fee split
  and frozen external_id formats (stripe_{acct}_{txn} / _fee), dated on
  created, bound to a provisioned "Stripe-saldo" cash account on 1686 so
  booking settles against the clearing account by construction.
- Double-booking protection: settled payment-link charges import
  pre-linked to their settlement entry; payout rows import pre-linked to
  the payout entry; processPayoutPaidEvent claims the payout's fee rows
  at booking time (linkPayoutFeedRows, idempotent from both directions).
- Cursor last_balance_txn_synced_at with 24h overlap; first run
  backfills 90 days floored at the day after the company lock date.
- Nightly cron /api/extensions/stripe/transactions/cron (03:30),
  transaction-sync toggle route, "Synka nu" covers both feeds, settings
  panel toggle with last-synced/backfill note, sv+en strings.
- Migration 20260723200000 (applied to staging).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(transactions): offer match-to-voucher on unbooked history rows

Unbooked transactions with is_business already set (e.g. left behind when
a voucher was removed without a full uncategorize) land in the history
list instead of the inbox, where the match-against-existing-voucher
action did not exist, leaving them with no path back to voucher
matching. Add the same menu item to the history list for unbooked rows.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(transactions): enhance ownership checks and error handling in journal entry routes

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 01:16:20 +02:00

332 lines
11 KiB
TypeScript

import { describe, it, expect, vi, beforeEach, afterEach } from 'vitest'
import { createQueuedMockSupabase, makeInvoice } from '@/tests/helpers'
import type { SupabaseClient } from '@supabase/supabase-js'
const eventsList = vi.fn()
vi.mock('@/lib/stripe/client', () => ({
getStripe: () => ({ events: { list: eventsList } }),
}))
vi.mock('@/lib/invoices/settle-invoice-payment', () => ({
settleInvoicePayment: vi.fn(),
}))
import { settleInvoicePayment } from '@/lib/invoices/settle-invoice-payment'
import { eventBus } from '@/lib/events/bus'
import { syncStripeConnection } from '../lib/sync'
import type { StripeConnection } from '../types'
const CONNECTION: StripeConnection = {
id: 'conn-1',
company_id: 'company-1',
user_id: 'user-1',
stripe_account_id: 'acct_1',
livemode: false,
status: 'active',
oauth_state: null,
display_name: 'Test AB',
last_event_created_at: null,
last_event_id: null,
transaction_sync_enabled: false,
last_balance_txn_synced_at: null,
error_message: null,
connected_at: '2026-07-01T00:00:00.000Z',
disconnected_at: null,
created_at: '2026-07-01T00:00:00.000Z',
updated_at: '2026-07-01T00:00:00.000Z',
}
function makeSession(overrides: Record<string, unknown> = {}) {
return {
id: 'cs_1',
payment_link: 'plink_1',
payment_intent: 'pi_1',
amount_total: 125000, // 1250.00 SEK in öre
currency: 'sek',
payment_status: 'paid',
livemode: false,
metadata: { invoice_id: 'inv-1', company_id: 'company-1' },
...overrides,
}
}
function makeEvent(session: Record<string, unknown>, overrides: Record<string, unknown> = {}) {
return {
id: 'evt_1',
type: 'checkout.session.completed',
created: 1_767_000_000,
data: { object: session },
...overrides,
}
}
function stubEvents(events: unknown[]) {
eventsList.mockReturnValue({
autoPagingToArray: vi.fn().mockResolvedValue(events),
})
}
function payableInvoice(overrides: Record<string, unknown> = {}) {
return {
...makeInvoice({
id: 'inv-1',
status: 'sent',
currency: 'SEK',
total: 1250,
}),
remaining_amount: 1250,
paid_amount: 0,
stripe_payment_link_id: 'plink_1',
customer: { name: 'Kund AB' },
items: [],
...overrides,
}
}
describe('syncStripeConnection', () => {
beforeEach(() => {
vi.clearAllMocks()
eventBus.clear()
vi.stubEnv('STRIPE_SECRET_KEY', 'sk_test_123')
vi.stubEnv('STRIPE_CONNECT_CLIENT_ID', 'ca_test_123')
vi.mocked(settleInvoicePayment).mockResolvedValue({
ok: true,
newStatus: 'paid',
newPaidAmount: 1250,
newRemaining: 0,
journalEntryId: 'je-9',
paidAt: '2026-07-12T00:00:00.000Z',
})
})
afterEach(() => {
vi.unstubAllEnvs()
})
it('settles a deterministic match against 1686 and advances the cursor', async () => {
stubEvents([makeEvent(makeSession())])
const { supabase, enqueue } = createQueuedMockSupabase()
enqueue({ data: [{ id: 'spe-1' }] }) // claim insert
enqueue({ data: payableInvoice() }) // invoice by payment link
enqueue({ data: { accounting_method: 'accrual', entity_type: 'aktiebolag' } })
enqueue({ data: null }) // event row finalize
enqueue({ data: null }) // cursor update
const summary = await syncStripeConnection(supabase as unknown as SupabaseClient, CONNECTION)
expect(summary).toMatchObject({ fetched: 1, settled: 1, needsReview: 0, ignored: 0 })
expect(vi.mocked(settleInvoicePayment)).toHaveBeenCalledWith(
expect.anything(),
'company-1',
'user-1',
expect.objectContaining({
paymentAmountInInvoiceCurrency: 1250,
settlementAccountNumber: '1686',
accountingMethod: 'accrual',
entityType: 'aktiebolag',
paymentDate: new Date(1_767_000_000 * 1000).toISOString().split('T')[0],
}),
)
})
it('records amount drift as needs_review and never settles', async () => {
stubEvents([makeEvent(makeSession({ amount_total: 100000 }))]) // 1000 vs 1250 remaining
const { supabase, enqueue } = createQueuedMockSupabase()
enqueue({ data: [{ id: 'spe-1' }] })
enqueue({ data: payableInvoice() })
enqueue({ data: null }) // event row finalize
enqueue({ data: null }) // cursor update
const summary = await syncStripeConnection(supabase as unknown as SupabaseClient, CONNECTION)
expect(summary).toMatchObject({ settled: 0, needsReview: 1 })
expect(vi.mocked(settleInvoicePayment)).not.toHaveBeenCalled()
})
it('records an already-paid invoice as needs_review (double payment)', async () => {
stubEvents([makeEvent(makeSession())])
const { supabase, enqueue } = createQueuedMockSupabase()
enqueue({ data: [{ id: 'spe-1' }] })
enqueue({ data: payableInvoice({ status: 'paid' }) })
enqueue({ data: null })
enqueue({ data: null })
const summary = await syncStripeConnection(supabase as unknown as SupabaseClient, CONNECTION)
expect(summary.needsReview).toBe(1)
expect(vi.mocked(settleInvoicePayment)).not.toHaveBeenCalled()
})
it('records non-SEK invoices as needs_review (v1 automation scope)', async () => {
stubEvents([makeEvent(makeSession({ currency: 'eur', amount_total: 50000 }))])
const { supabase, enqueue } = createQueuedMockSupabase()
enqueue({ data: [{ id: 'spe-1' }] })
enqueue({
data: payableInvoice({ currency: 'EUR', total: 500, remaining_amount: 500 }),
})
enqueue({ data: null })
enqueue({ data: null })
const summary = await syncStripeConnection(supabase as unknown as SupabaseClient, CONNECTION)
expect(summary.needsReview).toBe(1)
expect(vi.mocked(settleInvoicePayment)).not.toHaveBeenCalled()
})
it('ignores test-mode events on a live-mode connection', async () => {
stubEvents([makeEvent(makeSession({ livemode: false }))])
const { supabase, enqueue } = createQueuedMockSupabase()
enqueue({ data: [{ id: 'spe-1' }] })
enqueue({ data: null }) // event row finalize
enqueue({ data: null }) // cursor update
const summary = await syncStripeConnection(
supabase as unknown as SupabaseClient,
{ ...CONNECTION, livemode: true },
)
expect(summary).toMatchObject({ settled: 0, needsReview: 0, ignored: 1 })
})
it('skips events already claimed by an earlier run', async () => {
stubEvents([makeEvent(makeSession())])
const { supabase, enqueue } = createQueuedMockSupabase()
enqueue({ data: [] }) // claim conflict
enqueue({ data: [] }) // reclaim: not stale
enqueue({ data: null }) // cursor update
const summary = await syncStripeConnection(supabase as unknown as SupabaseClient, CONNECTION)
expect(summary).toMatchObject({ alreadyProcessed: 1, settled: 0 })
expect(vi.mocked(settleInvoicePayment)).not.toHaveBeenCalled()
})
it('marks the connection revoked when Stripe reports severed access', async () => {
eventsList.mockReturnValue({
autoPagingToArray: vi
.fn()
.mockRejectedValue(
Object.assign(new Error('The account acct_1 is not connected to your platform'), {
type: 'StripePermissionError',
}),
),
})
const disconnected = vi.fn()
eventBus.on('stripe.disconnected', disconnected)
const { supabase, enqueue } = createQueuedMockSupabase()
enqueue({ data: null }) // connection status update
const summary = await syncStripeConnection(supabase as unknown as SupabaseClient, CONNECTION)
expect(summary.revoked).toBe(true)
expect(summary.settled).toBe(0)
// Auto-detected revocation must reach the audit trail, mirroring the
// user-initiated disconnect emission.
expect(disconnected).toHaveBeenCalledWith({
connectionId: 'conn-1',
stripeAccountId: 'acct_1',
reason: 'revoked_upstream',
userId: 'user-1',
companyId: 'company-1',
})
})
it('falls back to accrual/enskild_firma when the company has no settings row', async () => {
stubEvents([makeEvent(makeSession())])
const { supabase, enqueue } = createQueuedMockSupabase()
enqueue({ data: [{ id: 'spe-1' }] }) // claim insert
enqueue({ data: payableInvoice() }) // invoice by payment link
enqueue({ data: null }) // company_settings: no row (maybeSingle -> null, no error)
enqueue({ data: null }) // event row finalize
enqueue({ data: null }) // cursor update
const summary = await syncStripeConnection(supabase as unknown as SupabaseClient, CONNECTION)
expect(summary.settled).toBe(1)
expect(vi.mocked(settleInvoicePayment)).toHaveBeenCalledWith(
expect.anything(),
'company-1',
'user-1',
expect.objectContaining({
accountingMethod: 'accrual',
entityType: 'enskild_firma',
}),
)
})
it('stops mid-batch at the deadline and persists the cursor only over processed events', async () => {
let now = 1_000
const nowSpy = vi.spyOn(Date, 'now').mockImplementation(() => now)
try {
// Settling the first event burns the remaining time budget.
vi.mocked(settleInvoicePayment).mockImplementation(async () => {
now = 10_000
return {
ok: true,
newStatus: 'paid',
newPaidAmount: 1250,
newRemaining: 0,
journalEntryId: 'je-9',
paidAt: '2026-07-12T00:00:00.000Z',
}
})
stubEvents([
makeEvent(makeSession()),
makeEvent(makeSession({ id: 'cs_2' }), { id: 'evt_2', created: 1_767_000_100 }),
])
const { supabase, enqueue } = createQueuedMockSupabase()
enqueue({ data: [{ id: 'spe-1' }] }) // claim insert (evt_1)
enqueue({ data: payableInvoice() }) // invoice by payment link
enqueue({ data: { accounting_method: 'accrual', entity_type: 'aktiebolag' } })
enqueue({ data: null }) // event row finalize (evt_1)
enqueue({ data: null }) // cursor update
const summary = await syncStripeConnection(
supabase as unknown as SupabaseClient,
CONNECTION,
undefined,
5_000, // deadline passes between the first and second event
)
expect(summary).toMatchObject({
fetched: 2,
settled: 1,
needsReview: 0,
deadlineReached: true,
})
expect(vi.mocked(settleInvoicePayment)).toHaveBeenCalledTimes(1)
// evt_2 was never claimed and the cursor advanced only over evt_1, so
// the next run refetches evt_2 (cursor overlap) and processes it then.
expect(vi.mocked(supabase.from).mock.calls.map((c) => c[0])).toEqual([
'stripe_payment_events', // claim evt_1
'invoices',
'company_settings',
'stripe_payment_events', // finalize evt_1
'stripe_connections', // cursor persisted up to evt_1
])
} finally {
nowSpy.mockRestore()
}
})
it('records a settle failure (e.g. locked period) as needs_review', async () => {
vi.mocked(settleInvoicePayment).mockResolvedValue({
ok: false,
code: 'BOOKKEEPING_ERROR',
error: new Error('Cannot write to locked/closed fiscal period'),
})
stubEvents([makeEvent(makeSession())])
const { supabase, enqueue } = createQueuedMockSupabase()
enqueue({ data: [{ id: 'spe-1' }] })
enqueue({ data: payableInvoice() })
enqueue({ data: { accounting_method: 'accrual', entity_type: 'aktiebolag' } })
enqueue({ data: null })
enqueue({ data: null })
const summary = await syncStripeConnection(supabase as unknown as SupabaseClient, CONNECTION)
expect(summary.needsReview).toBe(1)
})
})