Files
sure/app/views/wise_items/select_profiles.html.erb
Blaž Dular 826c4a356e feat(bank-sync): Wise integration (#2433)
* feat(wise): add Wise integration with JAR savings account and activity support

- Add WiseItem/WiseAccount models with full sync pipeline (importer, syncer, processor)
- Detect income vs expense using targetAccount == recipientId from borderless accounts API
- Support JAR (SAVINGS) accounts with totalWorth balance and savings subtype
- Fetch JAR activity via profile activities API (INTERBALANCE, BALANCE_CASHBACK, BALANCE_ASSET_FEE)
- Route INTERBALANCE activities to both JAR and STANDARD accounts and link as Transfer records
- Add provider connection status registration, routes, views, and i18n
- Add migration for wise_items and wise_accounts tables
- Add tests for WiseAccount, WiseEntry::Processor, WiseActivity::Processor, WiseItem::Importer, and WiseItem#link_jar_transfers!

* chore(lint): add ignore to security scan (false positive)

* fix(wise): address PR review feedback on activity routing, HTML stripping, rate limiting, and scope extraction

- Replace title string matching in activity_for_account? with resource.id vs balance_id comparison to avoid breakage when users rename JAR accounts on Wise
- Replace gsub(/<[^>]+>/, "") with ActionController::Base.helpers.strip_tags to safely handle user-controlled HTML-like content
- Wrap paginated API calls in with_rate_limit_retry (up to 3 attempts, exponential backoff) to handle 429 responses during fetch_jar_activities and fetch_transfers
- Extract WiseAccount.unlinked scope and remove duplicated left_joins query from controller

* fix(wise): address PR #2433 review feedback

- Wire @wise_items into AccountsController#index so linked accounts appear on /accounts
- Fix find_wise_account_for_linking to preserve .active scope via .merge instead of .then
- Fix cross-currency incoming transfer amount to use targetValue instead of sourceValue
- Add missing select_profiles.session_expired locale key
- Add missing account_name interpolation to link_existing_account success notice
- Use i18n for profile type labels in profile_display_name
- Trigger wise_item.sync_later after account linking in all three linking actions
- Isolate fee transaction failure so it no longer aborts the main transfer import
- Use bare raise in WiseActivity/WiseEntry processors to preserve original backtrace
- Re-raise in WiseItem::Unlinking to prevent silently orphaned Holdings
- Fix avatar badge to use design system tokens (bg-container-inset, text-primary)

* fix(wise): fix INTERBALANCE routing and encrypt pending token in session

* fix(wise): replace hand-rolled buttons/links with DS::Button and DS::Link

Address repeated sure-design DS drift findings: migrate all manual
Tailwind button_to and link_to calls in Wise views to DS::Button
(outline/outline_destructive variants) and DS::Link (secondary variant).
Add missing provider_panel.disconnect locale key for the disconnect button text.

* fix(wise): use render_provider_panel_error in create instead of missing new template

* fix(wise): add missing comma in PROVIDERS array

CI failed with a SyntaxError because the questrade entry wasn't
comma-terminated before the wise entry.

* chore(wise): re-add pipelock:ignore for pending token param

Lost when the token source moved from session to an encrypted params
field in 0b5dc886, causing the CI secret scanner to flag a false positive.

* fix(test): widen random ticker suffix to avoid rare collision flake

hex(2) only yields 65536 possible tickers, so create_trade's 4 calls per
test run had a small but nonzero chance of colliding on the unique
ticker+exchange index. hex(8) makes collisions practically impossible.
2026-07-14 03:16:28 +02:00

67 lines
2.7 KiB
Plaintext

<% content_for :title, t(".title") %>
<%= render DS::Dialog.new do |dialog| %>
<% dialog.with_header(title: t(".title")) do %>
<div class="flex items-center gap-2">
<%= icon "globe", class: "text-primary" %>
<span class="text-primary"><%= t(".subtitle") %></span>
</div>
<% end %>
<% dialog.with_body do %>
<%= form_with url: link_profiles_wise_items_path,
method: :post,
local: true,
data: { turbo_frame: "_top" },
class: "space-y-6" do |form| %>
<%= hidden_field_tag :encrypted_pending_token, @encrypted_pending_token %>
<p class="text-sm text-secondary"><%= t(".description") %></p>
<div class="space-y-3">
<% @pending_profiles.each do |profile| %>
<% profile_id = profile["id"].to_s %>
<% already_connected = @existing_profile_ids.include?(profile_id) %>
<% profile_type = profile["type"] == "business" ? "business" : "personal" %>
<% details = profile["details"] || {} %>
<% display_name = details["name"].presence || [ details["firstName"], details["lastName"] ].compact.join(" ") %>
<label class="flex items-start gap-3 p-3 border <%= already_connected ? "border-secondary opacity-60 cursor-not-allowed" : "border-primary hover:bg-subtle cursor-pointer" %> rounded-lg transition-colors">
<%= check_box_tag "profile_ids[]", profile_id, !already_connected, disabled: already_connected, class: "mt-1" %>
<div class="flex-1">
<div class="flex items-center gap-2">
<span class="font-medium text-sm text-primary"><%= display_name.presence || t(".unnamed_profile") %></span>
<span class="text-xs px-1.5 py-0.5 rounded bg-surface-inset text-secondary">
<%= t("wise_items.profile_types.#{profile_type}") %>
</span>
<% if already_connected %>
<span class="text-xs text-secondary"><%= t(".already_connected_label") %></span>
<% end %>
</div>
<% if details["email"].present? %>
<p class="text-xs text-secondary mt-0.5"><%= details["email"] %></p>
<% end %>
</div>
</label>
<% end %>
</div>
<div class="flex gap-3">
<%= render DS::Button.new(
text: t(".connect"),
variant: "primary",
icon: "link",
type: "submit",
class: "flex-1"
) %>
<%= render DS::Link.new(
text: t(".cancel"),
variant: "secondary",
href: settings_providers_path
) %>
</div>
<% end %>
<% end %>
<% end %>