Files
sure/app/models/wise_activity/processor.rb
Blaž Dular 826c4a356e feat(bank-sync): Wise integration (#2433)
* feat(wise): add Wise integration with JAR savings account and activity support

- Add WiseItem/WiseAccount models with full sync pipeline (importer, syncer, processor)
- Detect income vs expense using targetAccount == recipientId from borderless accounts API
- Support JAR (SAVINGS) accounts with totalWorth balance and savings subtype
- Fetch JAR activity via profile activities API (INTERBALANCE, BALANCE_CASHBACK, BALANCE_ASSET_FEE)
- Route INTERBALANCE activities to both JAR and STANDARD accounts and link as Transfer records
- Add provider connection status registration, routes, views, and i18n
- Add migration for wise_items and wise_accounts tables
- Add tests for WiseAccount, WiseEntry::Processor, WiseActivity::Processor, WiseItem::Importer, and WiseItem#link_jar_transfers!

* chore(lint): add ignore to security scan (false positive)

* fix(wise): address PR review feedback on activity routing, HTML stripping, rate limiting, and scope extraction

- Replace title string matching in activity_for_account? with resource.id vs balance_id comparison to avoid breakage when users rename JAR accounts on Wise
- Replace gsub(/<[^>]+>/, "") with ActionController::Base.helpers.strip_tags to safely handle user-controlled HTML-like content
- Wrap paginated API calls in with_rate_limit_retry (up to 3 attempts, exponential backoff) to handle 429 responses during fetch_jar_activities and fetch_transfers
- Extract WiseAccount.unlinked scope and remove duplicated left_joins query from controller

* fix(wise): address PR #2433 review feedback

- Wire @wise_items into AccountsController#index so linked accounts appear on /accounts
- Fix find_wise_account_for_linking to preserve .active scope via .merge instead of .then
- Fix cross-currency incoming transfer amount to use targetValue instead of sourceValue
- Add missing select_profiles.session_expired locale key
- Add missing account_name interpolation to link_existing_account success notice
- Use i18n for profile type labels in profile_display_name
- Trigger wise_item.sync_later after account linking in all three linking actions
- Isolate fee transaction failure so it no longer aborts the main transfer import
- Use bare raise in WiseActivity/WiseEntry processors to preserve original backtrace
- Re-raise in WiseItem::Unlinking to prevent silently orphaned Holdings
- Fix avatar badge to use design system tokens (bg-container-inset, text-primary)

* fix(wise): fix INTERBALANCE routing and encrypt pending token in session

* fix(wise): replace hand-rolled buttons/links with DS::Button and DS::Link

Address repeated sure-design DS drift findings: migrate all manual
Tailwind button_to and link_to calls in Wise views to DS::Button
(outline/outline_destructive variants) and DS::Link (secondary variant).
Add missing provider_panel.disconnect locale key for the disconnect button text.

* fix(wise): use render_provider_panel_error in create instead of missing new template

* fix(wise): add missing comma in PROVIDERS array

CI failed with a SyntaxError because the questrade entry wasn't
comma-terminated before the wise entry.

* chore(wise): re-add pipelock:ignore for pending token param

Lost when the token source moved from session to an encrypted params
field in 0b5dc886, causing the CI secret scanner to flag a false positive.

* fix(test): widen random ticker suffix to avoid rare collision flake

hex(2) only yields 65536 possible tickers, so create_trade's 4 calls per
test run had a small but nonzero chance of colliding on the unique
ticker+exchange index. hex(8) makes collisions practically impossible.
2026-07-14 03:16:28 +02:00

157 lines
4.6 KiB
Ruby

# frozen_string_literal: true
class WiseActivity::Processor
JAR_ACTIVITY_TYPES = %w[INTERBALANCE BALANCE_CASHBACK BALANCE_ASSET_FEE].freeze
def initialize(activity, wise_account:)
@activity = activity.with_indifferent_access
@wise_account = wise_account
end
def process
unless account.present?
Rails.logger.warn "WiseActivity::Processor - No linked account for wise_account #{wise_account.id}, skipping #{safe_id}"
return :skipped
end
import_adapter.import_transaction(
external_id: external_id,
amount: amount,
currency: currency,
date: date,
name: name,
source: "wise",
extra: extra
)
rescue ArgumentError => e
Rails.logger.error "WiseActivity::Processor - Validation error for activity #{safe_id}: #{e.message}"
raise
rescue => e
Rails.logger.error "WiseActivity::Processor - Error for activity #{safe_id}: #{e.class} - #{e.message}"
raise
end
private
attr_reader :activity, :wise_account
def import_adapter
@import_adapter ||= Account::ProviderImportAdapter.new(account)
end
def account
@account ||= wise_account.current_account
end
# INTERBALANCE uses resource_id so both sides can be matched for Transfer linking.
# Other activity types use the opaque activity id.
def external_id
if activity_type == "INTERBALANCE"
side = wise_account.jar? ? "inflow" : "outflow"
"wise_interbalance_#{resource_id}_#{side}"
else
"wise_activity_#{activity[:id]}"
end
end
def safe_id
activity[:id].presence || "unknown"
end
def activity_type
activity[:type].to_s
end
def resource_id
activity.dig(:resource, :id).to_s
end
# Expenses (outflow) → positive in Sure.
# Incomes (inflow / interest) → negative in Sure.
def amount
raw = parse_amount
case activity_type
when "BALANCE_ASSET_FEE"
raw.abs # fee = outflow = positive (expense)
when "INTERBALANCE"
if wise_account.jar?
# JAR perspective: "To Jar" = deposit (income, negative)
deposit_direction? ? -raw.abs : raw.abs
else
# STANDARD perspective: "To Jar" = outflow (expense, positive)
deposit_direction? ? raw.abs : -raw.abs
end
else
-raw.abs # BALANCE_CASHBACK / interest → income (negative)
end
end
# True when the activity title indicates money flowing INTO the JAR.
def deposit_direction?
title = strip_html(activity[:title]).downcase
title.start_with?("to") || title.include?("received") || title.include?("added")
end
def currency
parse_currency || wise_account.currency
end
def name
jar_name = wise_account.jar? ? (wise_account.raw_payload&.dig("name") || "Jar") : nil
case activity_type
when "INTERBALANCE"
if wise_account.jar?
deposit_direction? ? I18n.t("wise_items.activities.jar_deposit") : I18n.t("wise_items.activities.jar_withdrawal")
else
deposit_direction? ? I18n.t("wise_items.activities.transfer_to_jar", jar: jar_name_for_standard) : I18n.t("wise_items.activities.transfer_from_jar", jar: jar_name_for_standard)
end
when "BALANCE_CASHBACK"
I18n.t("wise_items.activities.interest")
when "BALANCE_ASSET_FEE"
I18n.t("wise_items.activities.asset_fee")
else
strip_html(activity[:title]).strip.presence ||
I18n.t("wise_items.activities.default_name")
end
end
def jar_name_for_standard
activity[:title].to_s.scan(/<strong>([^<]+)<\/strong>/).flatten.last || "Jar"
end
def date
raw = activity[:createdOn].presence
raise ArgumentError, "Activity missing createdOn" unless raw
DateTime.parse(raw).to_date
end
def extra
{
wise: {
activity_id: activity[:id],
activity_type: activity_type,
resource_type: activity.dig(:resource, :type),
resource_id: resource_id.presence
}.compact
}
end
# Parses the numeric amount from strings like:
# "1,000 EUR" → 1000.0
# "<positive>+ 1.12 EUR</positive>" → 1.12
# "0.83 EUR" → 0.83
def parse_amount
stripped = strip_html(activity[:primaryAmount]).strip
stripped.scan(/[\d,]+\.?\d*/).first.to_s.delete(",").to_d
end
def parse_currency
activity[:primaryAmount].to_s.scan(/\b[A-Z]{3}\b/).first
end
def strip_html(str)
ActionController::Base.helpers.strip_tags(str.to_s)
end
end