707d597b2e
* feat(woocommerce): store order/refund feed extension Connect a WooCommerce store via the wc-auth key handshake (manual key fallback) with per-store consumer key/secret AES-256-GCM encrypted at rest, and import paid orders and refunds into the transactions inbox as a bank-style feed on the 1680 cash account. Feed-only: nothing auto-books, gateway fees/payouts are out of scope (core wc/v3 does not expose them). Sync is cursor-paginated on modified_after (offset pages only inside same-second date_modified ties), terminates on an empty page, holds the cursor below failed refund fetches / ingest errors / deadline-skipped work, checks the time budget between refund fetches, and drops rows dated on or before bookkeeping_locked_through on every run. Nightly cron gated on the extension registry + new paid capability woocommerce_sync (backfilled to existing bank_sync grant holders). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(migrations): move woocommerce migrations past main's 20260806090000 origin/main gained 20260806090000_recurring_schedule_interval_months while this branch was in flight; identical version timestamps abort the Supabase apply, so the two new migrations move to 20260806170000/20260806170100. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(woocommerce): resolve CodeRabbit review findings - callback 503s early when WOOCOMMERCE_CREDENTIALS_ENCRYPTION_KEY is unset: encryptCredential would otherwise throw after the probe and strand the pending row without error_message - disconnect and upstream-revoke clear the encrypted consumer key/secret: nothing reads them after revoke and keeping decryptable dead credentials is unnecessary retention - manual sync gets a 240s time budget and the panel reports a truncated run as 'partial, sync again' instead of a normal completion - listOrderRefunds terminates on an empty batch (hosts may cap per_page), dedupes by id against hosts that ignore page, and caps total pages - unparseable money strings count as errors and log instead of being silently identical to a zero total - pg test uses per-run unique store URLs so committed rows cannot hit the store_url partial unique index across pg-real runs Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(woocommerce): resolve CodeRabbit cycle-2 findings - listOrderRefunds throws when the page cap is exhausted with data still flowing, instead of returning a silently partial list the sync cursor would advance past; the error routes into the existing held-cursor refund-retry path - partial sync results keep the row-error count, and the partial toast string surfaces it (ICU plural, hidden at zero) in both locales Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * chore: retrigger CI after dropped push event Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
185 lines
6.7 KiB
TypeScript
185 lines
6.7 KiB
TypeScript
import { NextResponse } from 'next/server'
|
|
import { createServiceClient } from '@/lib/supabase/server'
|
|
import { ensureInitialized } from '@/lib/init'
|
|
import { eventBus } from '@/lib/events/bus'
|
|
import { loadExtensions } from '@/lib/extensions/loader'
|
|
import { extensionRegistry } from '@/lib/extensions/registry'
|
|
import { createLogger } from '@/lib/logger'
|
|
import {
|
|
encryptCredential,
|
|
isWooCommerceConfigured,
|
|
} from '@/extensions/general/woocommerce/lib/credentials'
|
|
import { testConnectionAndFetchStoreInfo } from '@/extensions/general/woocommerce/lib/api-client'
|
|
|
|
// This route emits woocommerce.connected (audit trail). ensureInitialized()
|
|
// must run at module load so the event_log handler has subscribed before the
|
|
// first emit on a cold instance.
|
|
ensureInitialized()
|
|
|
|
const log = createLogger('woocommerce/callback')
|
|
|
|
// The credential probe talks to an arbitrary (often slow) WooCommerce host.
|
|
export const maxDuration = 60
|
|
|
|
/**
|
|
* POST /api/extensions/woocommerce/callback
|
|
*
|
|
* Server-to-server delivery of the wc-auth handshake result: WooCommerce
|
|
* POSTs { key_id, user_id, consumer_key, consumer_secret, key_permissions }
|
|
* here after the merchant approves. Must be a real Next.js route (not an
|
|
* extension dispatcher handler) because the store calls it directly,
|
|
* unauthenticated: the single-use oauth_state riding in user_id locates the
|
|
* pending row, and the received keys are verified against that row's stored
|
|
* store_url before anything is persisted.
|
|
*/
|
|
export async function POST(request: Request) {
|
|
loadExtensions()
|
|
if (!extensionRegistry.get('woocommerce')) {
|
|
return NextResponse.json(
|
|
{ error: 'WooCommerce extension is not enabled', code: 'EXTENSION_DISABLED' },
|
|
{ status: 503 },
|
|
)
|
|
}
|
|
// The registry does not check manifest requiredEnvVars, so this route can be
|
|
// live without the encryption key; without this guard encryptCredential()
|
|
// would throw AFTER the probe, escaping the markError path entirely.
|
|
if (!isWooCommerceConfigured()) {
|
|
return NextResponse.json(
|
|
{ error: 'WooCommerce integration is not configured', code: 'NOT_CONFIGURED' },
|
|
{ status: 503 },
|
|
)
|
|
}
|
|
|
|
let body: {
|
|
user_id?: unknown
|
|
consumer_key?: unknown
|
|
consumer_secret?: unknown
|
|
key_permissions?: unknown
|
|
}
|
|
try {
|
|
body = await request.json()
|
|
} catch {
|
|
return NextResponse.json({ error: 'Invalid JSON body' }, { status: 400 })
|
|
}
|
|
|
|
const state = typeof body.user_id === 'string' ? body.user_id : null
|
|
const consumerKey = typeof body.consumer_key === 'string' ? body.consumer_key : null
|
|
const consumerSecret = typeof body.consumer_secret === 'string' ? body.consumer_secret : null
|
|
const keyPermissions =
|
|
typeof body.key_permissions === 'string' ? body.key_permissions : null
|
|
// The state is a UUID we generated; reject anything else before it reaches
|
|
// the DB (the column is typed uuid and would error opaquely).
|
|
const isUuid =
|
|
state !== null &&
|
|
/^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$/i.test(state)
|
|
if (!isUuid || !consumerKey || !consumerSecret) {
|
|
return NextResponse.json({ error: 'Missing parameters' }, { status: 400 })
|
|
}
|
|
|
|
const supabase = await createServiceClient()
|
|
|
|
const { data: pending, error: findError } = await supabase
|
|
.from('woocommerce_connections')
|
|
.select('id, company_id, user_id, store_url')
|
|
.eq('oauth_state', state)
|
|
.eq('status', 'pending')
|
|
.single()
|
|
|
|
if (findError || !pending) {
|
|
log.warn('no pending connection for handshake state', {
|
|
hasRow: Boolean(pending),
|
|
code: findError?.code,
|
|
})
|
|
return NextResponse.json({ error: 'Unknown or expired state' }, { status: 404 })
|
|
}
|
|
|
|
const markError = (message: string) =>
|
|
supabase
|
|
.from('woocommerce_connections')
|
|
.update({ status: 'error', error_message: message, oauth_state: null })
|
|
.eq('id', pending.id)
|
|
.eq('status', 'pending')
|
|
|
|
// Authenticity check: the keys must actually work against the store URL the
|
|
// user asked to connect. A forged callback with someone else's (or made-up)
|
|
// keys fails here and never gets stored.
|
|
let storeInfo
|
|
try {
|
|
storeInfo = await testConnectionAndFetchStoreInfo({
|
|
storeUrl: pending.store_url,
|
|
consumerKey,
|
|
consumerSecret,
|
|
})
|
|
} catch (probeError) {
|
|
log.error('credential probe failed during handshake', {
|
|
connectionId: pending.id,
|
|
message: probeError instanceof Error ? probeError.message : String(probeError),
|
|
})
|
|
await markError('Nycklarna kunde inte verifieras mot butiken.')
|
|
return NextResponse.json({ error: 'Credential verification failed' }, { status: 502 })
|
|
}
|
|
|
|
const { data: activated, error: updateError } = await supabase
|
|
.from('woocommerce_connections')
|
|
.update({
|
|
consumer_key_encrypted: encryptCredential(consumerKey),
|
|
consumer_secret_encrypted: encryptCredential(consumerSecret),
|
|
key_permissions: keyPermissions,
|
|
store_name: storeInfo.name,
|
|
currency: storeInfo.currency,
|
|
prices_include_tax: storeInfo.prices_include_tax,
|
|
wc_version: storeInfo.wc_version,
|
|
status: 'active',
|
|
connected_at: new Date().toISOString(),
|
|
error_message: null,
|
|
oauth_state: null, // Clear to prevent replay
|
|
// Feed-only product: connecting the store means fetching its orders, so
|
|
// the nightly feed starts on by default; the panel toggle is the opt-out.
|
|
transaction_sync_enabled: true,
|
|
})
|
|
.eq('id', pending.id)
|
|
.eq('status', 'pending')
|
|
.select('id, company_id, user_id, store_url')
|
|
.single()
|
|
|
|
if (updateError || !activated) {
|
|
// 23505 = a partial unique index: the store is already actively connected
|
|
// (to this or another company), or the company connected in a parallel tab.
|
|
const isConflict = updateError?.code === '23505'
|
|
log.error('failed to activate connection', {
|
|
connectionId: pending.id,
|
|
code: updateError?.code,
|
|
message: updateError?.message,
|
|
})
|
|
await markError(
|
|
isConflict
|
|
? 'Butiken är redan ansluten till ett företag.'
|
|
: 'Anslutningen kunde inte slutföras.',
|
|
)
|
|
return NextResponse.json(
|
|
{ error: isConflict ? 'Store already connected' : 'Activation failed' },
|
|
{ status: isConflict ? 409 : 500 },
|
|
)
|
|
}
|
|
|
|
try {
|
|
await eventBus.emit({
|
|
type: 'woocommerce.connected',
|
|
payload: {
|
|
connectionId: activated.id,
|
|
storeUrl: activated.store_url,
|
|
userId: activated.user_id,
|
|
companyId: activated.company_id,
|
|
},
|
|
})
|
|
} catch (emitError) {
|
|
// Non-fatal: the DB state (source of truth) is already committed.
|
|
log.error('failed to emit woocommerce.connected', {
|
|
connectionId: activated.id,
|
|
message: emitError instanceof Error ? emitError.message : String(emitError),
|
|
})
|
|
}
|
|
|
|
return NextResponse.json({ success: true })
|
|
}
|