Files
accounted/lib/providers/oauth-config.ts
T
MattssonandClaude Fable 5 93f81f03e8 feat(providers): WINT migration provider behind WINT_MIGRATION_ENABLED (#1446)
* feat(providers): WINT migration provider behind WINT_MIGRATION_ENABLED

Adds WINT (wint.se) as a sixth migration provider, built against the
OpenAPI specs WINT's own API host serves publicly. Tier A scope: only the
partner-facing v1 endpoints are used; the general ledger is fetched as
vouchers/accounts and rendered as SIE 4E by our own sie-builder, with
opening balances for earlier years derived backward from the current-year
Ib anchor. Auth is the user's WINT login exchanged once for a JWT pair;
the password is never stored.

Ships dark: the wizard shows a disabled "Kommer snart" card, and the
server-side /connect gate rejects WINT until WINT_MIGRATION_ENABLED=true.
Live verification against a real WINT account is still outstanding.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(providers): harden WINT provider per PR #1446 review findings

Addresses CodeRabbit and Swedish accounting review feedback in one pass:

- Ib anchor selection now uses WINT's unfiltered fiscal-year list, so an
  active year outside the allowed import window can never silently anchor
  the wrong year; the voucher chain is extended through the anchor and a
  per-year fetch failure fails that year loudly instead of sinking the
  whole migration.
- Auth token exchange is strict: only LoginState Success with a complete
  access+refresh pair mints a consent (a pair without a refresh token is
  unrefreshable and would break days later).
- WintApiError no longer retains full response bodies (bounded 300-char
  diagnostic; bodies can carry customer data and errors get logged).
- sie-builder refuses to render structurally invalid vouchers (missing
  account number or booking date) and documents deleted-voucher gaps in a
  #PROSA record per BFL 5 kap 6-7 §.
- Account classification: 20xx is equity, 83xx is financial income.
- SIE validator accepts EUBAS97 as BAS-based (standard kontoplanstyp; it
  previously produced a false non-BAS warning on every WINT/Bollbok file).
- New tests: resolveConsent WINT refresh flow, credential upsert payload
  (no mail/password persisted), WINT fetch failure path, EUBAS97 warning
  regression, builder invalid-data rejection, vi.clearAllMocks hygiene.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(import): pin EUBAS97 acceptance to the exact SIE spec value

Review follow-up on PR #1446: match EUBAS97 exactly instead of any
EUBAS* prefix, so the non-BAS kontoplan warning stays pinned to the four
kontoplanstyp values the SIE 4B spec enumerates (BAS95, BAS96, EUBAS97,
NE2007) rather than silently accepting unknown future variants.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-07 11:07:14 +02:00

56 lines
1.7 KiB
TypeScript

import type { OAuthConfig } from './types';
export function getOAuthConfig(provider: string): OAuthConfig {
if (provider === 'fortnox') {
return {
clientId: process.env.FORTNOX_CLIENT_ID ?? '',
clientSecret: process.env.FORTNOX_CLIENT_SECRET ?? '',
redirectUri: process.env.FORTNOX_REDIRECT_URI ?? '',
};
}
if (provider === 'visma') {
return {
clientId: process.env.VISMA_CLIENT_ID ?? '',
clientSecret: process.env.VISMA_CLIENT_SECRET ?? '',
redirectUri: process.env.VISMA_REDIRECT_URI ?? '',
};
}
if (provider === 'briox') {
// No app-level credentials: the user's account ID + application token are
// exchanged per consent (exchangeBrioxCode). No env vars needed.
return {
clientId: '',
clientSecret: '',
redirectUri: '',
};
}
if (provider === 'bokio') {
return {
clientId: '',
clientSecret: '',
redirectUri: '',
};
}
if (provider === 'bjornlunden') {
return {
clientId: process.env.BJORN_LUNDEN_CLIENT_ID ?? '',
clientSecret: process.env.BJORN_LUNDEN_CLIENT_SECRET ?? '',
redirectUri: '',
};
}
if (provider === 'wint') {
// No app-level credentials: WINT has no OAuth. The user's login is
// exchanged once for a token pair at submit (loginWint). No env vars.
return {
clientId: '',
clientSecret: '',
redirectUri: '',
};
}
throw new Error(`Unknown provider: ${provider}`);
}
export function validateProvider(provider: string): boolean {
return provider === 'fortnox' || provider === 'visma' || provider === 'briox' || provider === 'bokio' || provider === 'bjornlunden' || provider === 'wint';
}