mirror of
https://github.com/we-promise/sure.git
synced 2026-07-20 00:35:22 +00:00
* feat(up): add Up Bank (AU) provider integration Adds Up Bank as a per-family, token-based bank sync provider, modelled on the existing Akahu integration. Up uses a JSON:API REST API with a personal access token (Bearer), cursor pagination via links.next, and returns both HELD (pending) and SETTLED transactions from one endpoint. New: - Provider::Up client (JSON:API unwrap, links.next pagination, retries, typed errors, /util/ping) + Provider::UpAdapter (Factory-registered, Depository + Loan). - UpItem / UpAccount models with Provided, Unlinking, Syncer, SyncCompleteEvent, Importer, Processor, Transactions::Processor, and UpEntry::Processor (amount sign flip, HELD->pending, foreignAmount FX, merchant from description, stale-pending pruning). - Family::UpConnectable, UpItemsController, routes, settings panel + connect flow views, accounts index wiring, initializer, en locale, and model tests. Core wiring: - "up" added to Transaction::PENDING_PROVIDERS, the three pending-match SQL blocks in Account::ProviderImportAdapter, Provider::Metadata::REGISTRY, ProviderMerchant/DataEnrichment source enums, ProviderConnectionStatus, settings provider panels, and financial data reset. Migration create_up_items_and_accounts must be run before use. No external API endpoints added (no OpenAPI changes). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(up): dump up tables to schema and make since filter TZ-safe The feature commit added the up_items/up_accounts migration but never re-dumped db/schema.rb, leaving the schema version and tables stale. Add the two table definitions and foreign keys and bump the schema version so a fresh DB load matches the migration. Also format a bare Date `since` as UTC midnight instead of the server's local zone, so `filter[since]` is deterministic regardless of where the app runs (previously shifted by the local UTC offset). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(up): address code review feedback Behavior/correctness: - Persist skipped accounts via a new up_accounts.ignored flag and a needs_setup scope, so skipped accounts stop resurfacing as "needs setup" on every sync. Linking clears the flag. - destroy now checks unlink_all! per-account results and aborts deletion (alert) if any unlink failed, instead of swallowing failures. - render_provider_panel_error redirect uses :see_other (was an invalid 4xx redirect status). - Up provider adapter falls back to item institution name/url when institution_metadata is absent (early return previously blocked it). Resilience/security: - fetch_all_resources guards against an API repeating the same links.next cursor (Set#add?), preventing infinite pagination. - HTTP client validates absolute URLs (from links.next) against Up's HTTPS host before sending the bearer token, preventing credential leakage to untrusted hosts. Diagnostics: - Route provider sync/import failures through DebugLogEntry.capture (controller, UpItem, syncer, unlinking) with family/account context. Low-level HTTP client and currency-normalization warnings keep Rails.logger to match existing provider conventions. Data integrity: - up_accounts.name and currency are NOT NULL (align with model presence validations); account_id stays nullable (allow_nil uniqueness). Forms: - select_existing_account radio is required; controller guards a blank/ unknown up_account_id with a friendly alert instead of RecordNotFound. Tests: - Add UpAccount needs_setup scope test, pagination loop guard test, untrusted-host rejection test; tighten filter[since] assertion to the exact UTC timestamp. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(up): address second-round review feedback - Capture sync/import failures via DebugLogEntry so swallowed errors in account/transaction fetching and transaction processing surface in /settings/debug instead of only Rails.logger. - Gate UP_DEBUG_RAW raw payload dump to local envs to avoid leaking PII (merchant names, amounts, account IDs) in managed/production logs. - Collapse linked/unlinked/total account counts into one memoized query instead of 3 separate COUNTs per rendered item. - Rename "Set Up Up Accounts" locale title to "Link Up Accounts". Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs(up): add method docstrings and align failed_result keys Add docstrings to all Up provider source files (controller, models, providers, concerns) to satisfy the 80% docstring coverage threshold. Third-round review: failed_result now mirrors import's result shape (accounts_updated/created/failed, transactions_imported/failed) instead of the stale accounts_imported key, so failure results stay consistent. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
68 lines
2.8 KiB
Ruby
68 lines
2.8 KiB
Ruby
class ProviderMerchant < Merchant
|
|
enum :source, { plaid: "plaid", simplefin: "simplefin", lunchflow: "lunchflow", akahu: "akahu", up: "up", synth: "synth", ai: "ai", enable_banking: "enable_banking", coinstats: "coinstats", mercury: "mercury", brex: "brex", indexa_capital: "indexa_capital", sophtron: "sophtron" }
|
|
|
|
validates :name, uniqueness: { scope: [ :source ] }
|
|
validates :source, presence: true
|
|
|
|
# Convert this ProviderMerchant to a FamilyMerchant for a specific family.
|
|
# Only affects transactions belonging to that family.
|
|
# Returns the newly created FamilyMerchant.
|
|
def convert_to_family_merchant_for(family, attributes = {})
|
|
transaction do
|
|
family_merchant = family.merchants.create!(
|
|
name: attributes[:name].presence || name,
|
|
color: attributes[:color].presence || FamilyMerchant::COLORS.sample,
|
|
website_url: attributes[:website_url].presence || website_url
|
|
)
|
|
|
|
scope = family.transactions.where(merchant_id: id)
|
|
|
|
# Protect the manual reassignment from being reverted on the next
|
|
# provider sync (issue #1977). Must run before the merchant_id update.
|
|
Entry.mark_user_modified_for_transactions!(scope)
|
|
|
|
# Update only this family's transactions to point to new merchant
|
|
scope.update_all(merchant_id: family_merchant.id)
|
|
|
|
family_merchant
|
|
end
|
|
end
|
|
|
|
# Generate logo URL from website_url using BrandFetch, if configured.
|
|
def generate_logo_url_from_website!
|
|
if website_url.present? && Setting.brand_fetch_client_id.present?
|
|
domain = extract_domain(website_url)
|
|
size = Setting.brand_fetch_logo_size
|
|
update!(logo_url: "https://cdn.brandfetch.io/#{domain}/icon/fallback/lettermark/w/#{size}/h/#{size}?c=#{Setting.brand_fetch_client_id}")
|
|
elsif website_url.blank?
|
|
update!(logo_url: nil)
|
|
end
|
|
end
|
|
|
|
# Unlink from family's transactions (set merchant_id to null).
|
|
# Does NOT delete the ProviderMerchant since it may be used by other families.
|
|
# Tracks the unlink in FamilyMerchantAssociation so it shows as "recently unlinked".
|
|
def unlink_from_family(family)
|
|
scope = family.transactions.where(merchant_id: id)
|
|
|
|
# Protect the manual unlink from being reverted on the next provider sync
|
|
# (issue #1977). Must run before the merchant_id is nulled.
|
|
Entry.mark_user_modified_for_transactions!(scope)
|
|
|
|
scope.update_all(merchant_id: nil)
|
|
|
|
# Track that this merchant was unlinked from this family
|
|
association = FamilyMerchantAssociation.find_or_initialize_by(family: family, merchant: self)
|
|
association.update!(unlinked_at: Time.current)
|
|
end
|
|
|
|
private
|
|
|
|
def extract_domain(url)
|
|
normalized_url = url.start_with?("http://", "https://") ? url : "https://#{url}"
|
|
URI.parse(normalized_url).host&.sub(/\Awww\./, "")
|
|
rescue URI::InvalidURIError
|
|
url.sub(/\Awww\./, "")
|
|
end
|
|
end
|