* feat: cloud backup to Google Drive + full-archive all-scope Adds a cloud-backup extension that uploads a full-company backup ZIP to the user's own Google Drive via OAuth (drive.file scope only). Refresh tokens are AES-256-GCM encrypted before being stored in extension_data. The full-archive export gains a scope=all mode for whole-company backups (per-period SIE under sie/, per-period rapporter/ subfolders, flat dokument/ manifest tagged with fiscal_period_id). An 80 MB size guard short-circuits generation before the platform response limit. Also fixes a latent bug in lib/core/audit/audit-service.ts where the parameter was named userId while the query filtered by company_id; the audit-trail API route was passing user.id so audit queries returned empty unless user and company shared a UUID. Drive-by: scope the dashboard "fresh start" localStorage key per companyId so dismissing the setup checklist in one company no longer carries over to others. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: address review comments on cloud backup + archive export - Extend audit trail to_date to end-of-day so last-day entries aren't silently excluded from period-scoped archives. - Apply 413 size-limit guard regardless of include_documents, using the overhead-only figure when documents are excluded. - Use crypto.randomUUID() for Drive multipart boundary to eliminate any collision risk with ZIP payload bytes. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: migrate legacy setup-gate localStorage keys on dashboard Users who previously dismissed the setup checklist via the old global erp_setup_fresh_start or erp_checklist_dismissed keys were re-gated after the switch to a company-scoped key. Fall back to the legacy keys on read and migrate them to the scoped key on first hit. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: update customer email handling and anonymization rules in supportmail-to-ticket skill * test: update audit trail to_date expectation for end-of-day timestamp Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
104 lines
3.0 KiB
TypeScript
104 lines
3.0 KiB
TypeScript
import { createClient } from '@/lib/supabase/server'
|
|
import { NextResponse } from 'next/server'
|
|
import {
|
|
generateFullArchive,
|
|
estimateArchiveSize,
|
|
type ArchiveScope,
|
|
} from '@/lib/reports/full-archive-export'
|
|
import { requireCompanyId } from '@/lib/company/context'
|
|
|
|
export const runtime = 'nodejs'
|
|
export const maxDuration = 300
|
|
|
|
const SIZE_LIMIT_BYTES = 80 * 1024 * 1024
|
|
|
|
export async function GET(request: Request) {
|
|
const supabase = await createClient()
|
|
const { data: { user } } = await supabase.auth.getUser()
|
|
|
|
if (!user) {
|
|
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
|
|
}
|
|
|
|
const companyId = await requireCompanyId(supabase, user.id)
|
|
|
|
const { searchParams } = new URL(request.url)
|
|
const scopeParam = searchParams.get('scope')
|
|
const periodId = searchParams.get('period_id')
|
|
const estimateOnly = searchParams.get('estimate') === '1'
|
|
const includeDocuments = searchParams.get('include_documents') !== 'false'
|
|
|
|
// Backward compat: a bare `period_id` without `scope` is treated as scope=period.
|
|
const scope: ArchiveScope =
|
|
scopeParam === 'period' || (!scopeParam && periodId) ? 'period' : 'all'
|
|
|
|
if (scope === 'period' && !periodId) {
|
|
return NextResponse.json(
|
|
{ error: 'period_id is required when scope=period' },
|
|
{ status: 400 }
|
|
)
|
|
}
|
|
|
|
try {
|
|
const estimate = await estimateArchiveSize(
|
|
supabase,
|
|
companyId,
|
|
scope,
|
|
scope === 'period' ? periodId! : undefined
|
|
)
|
|
|
|
if (estimateOnly) {
|
|
return NextResponse.json({
|
|
data: {
|
|
...estimate,
|
|
size_limit_bytes: SIZE_LIMIT_BYTES,
|
|
within_limit: estimate.total_bytes <= SIZE_LIMIT_BYTES,
|
|
},
|
|
})
|
|
}
|
|
|
|
if (includeDocuments && estimate.total_bytes > SIZE_LIMIT_BYTES) {
|
|
return NextResponse.json(
|
|
{
|
|
error: 'archive_too_large',
|
|
size_bytes: estimate.total_bytes,
|
|
size_limit_bytes: SIZE_LIMIT_BYTES,
|
|
},
|
|
{ status: 413 }
|
|
)
|
|
}
|
|
|
|
const zipBuffer = await generateFullArchive(
|
|
supabase,
|
|
companyId,
|
|
scope === 'period'
|
|
? { scope: 'period', period_id: periodId!, include_documents: includeDocuments }
|
|
: { scope: 'all', include_documents: includeDocuments }
|
|
)
|
|
|
|
const filename =
|
|
scope === 'period'
|
|
? `arkiv_${periodId}.zip`
|
|
: `arkiv_full_${companyId}_${formatDateStamp(new Date())}.zip`
|
|
|
|
return new NextResponse(zipBuffer, {
|
|
status: 200,
|
|
headers: {
|
|
'Content-Type': 'application/zip',
|
|
'Content-Disposition': `attachment; filename="${filename}"`,
|
|
},
|
|
})
|
|
} catch (err) {
|
|
const message = err instanceof Error ? err.message : 'Failed to generate archive'
|
|
const status = message.includes('not found') ? 404 : 500
|
|
return NextResponse.json({ error: message }, { status })
|
|
}
|
|
}
|
|
|
|
function formatDateStamp(d: Date): string {
|
|
const y = d.getUTCFullYear()
|
|
const m = String(d.getUTCMonth() + 1).padStart(2, '0')
|
|
const day = String(d.getUTCDate()).padStart(2, '0')
|
|
return `${y}${m}${day}`
|
|
}
|