Files
sure/app/views/settings/providers/_up_panel.html.erb
Jake dc2a565b6a feat(up): add Up Bank (AU) provider integration (#2391)
* feat(up): add Up Bank (AU) provider integration

Adds Up Bank as a per-family, token-based bank sync provider, modelled on
the existing Akahu integration. Up uses a JSON:API REST API with a personal
access token (Bearer), cursor pagination via links.next, and returns both
HELD (pending) and SETTLED transactions from one endpoint.

New:
- Provider::Up client (JSON:API unwrap, links.next pagination, retries,
  typed errors, /util/ping) + Provider::UpAdapter (Factory-registered,
  Depository + Loan).
- UpItem / UpAccount models with Provided, Unlinking, Syncer,
  SyncCompleteEvent, Importer, Processor, Transactions::Processor, and
  UpEntry::Processor (amount sign flip, HELD->pending, foreignAmount FX,
  merchant from description, stale-pending pruning).
- Family::UpConnectable, UpItemsController, routes, settings panel + connect
  flow views, accounts index wiring, initializer, en locale, and model tests.

Core wiring:
- "up" added to Transaction::PENDING_PROVIDERS, the three pending-match SQL
  blocks in Account::ProviderImportAdapter, Provider::Metadata::REGISTRY,
  ProviderMerchant/DataEnrichment source enums, ProviderConnectionStatus,
  settings provider panels, and financial data reset.

Migration create_up_items_and_accounts must be run before use. No external
API endpoints added (no OpenAPI changes).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(up): dump up tables to schema and make since filter TZ-safe

The feature commit added the up_items/up_accounts migration but never
re-dumped db/schema.rb, leaving the schema version and tables stale.
Add the two table definitions and foreign keys and bump the schema
version so a fresh DB load matches the migration.

Also format a bare Date `since` as UTC midnight instead of the server's
local zone, so `filter[since]` is deterministic regardless of where the
app runs (previously shifted by the local UTC offset).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(up): address code review feedback

Behavior/correctness:
- Persist skipped accounts via a new up_accounts.ignored flag and a
  needs_setup scope, so skipped accounts stop resurfacing as "needs
  setup" on every sync. Linking clears the flag.
- destroy now checks unlink_all! per-account results and aborts deletion
  (alert) if any unlink failed, instead of swallowing failures.
- render_provider_panel_error redirect uses :see_other (was an invalid
  4xx redirect status).
- Up provider adapter falls back to item institution name/url when
  institution_metadata is absent (early return previously blocked it).

Resilience/security:
- fetch_all_resources guards against an API repeating the same
  links.next cursor (Set#add?), preventing infinite pagination.
- HTTP client validates absolute URLs (from links.next) against Up's
  HTTPS host before sending the bearer token, preventing credential
  leakage to untrusted hosts.

Diagnostics:
- Route provider sync/import failures through DebugLogEntry.capture
  (controller, UpItem, syncer, unlinking) with family/account context.
  Low-level HTTP client and currency-normalization warnings keep
  Rails.logger to match existing provider conventions.

Data integrity:
- up_accounts.name and currency are NOT NULL (align with model presence
  validations); account_id stays nullable (allow_nil uniqueness).

Forms:
- select_existing_account radio is required; controller guards a blank/
  unknown up_account_id with a friendly alert instead of RecordNotFound.

Tests:
- Add UpAccount needs_setup scope test, pagination loop guard test,
  untrusted-host rejection test; tighten filter[since] assertion to the
  exact UTC timestamp.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(up): address second-round review feedback

- Capture sync/import failures via DebugLogEntry so swallowed errors in
  account/transaction fetching and transaction processing surface in
  /settings/debug instead of only Rails.logger.
- Gate UP_DEBUG_RAW raw payload dump to local envs to avoid leaking PII
  (merchant names, amounts, account IDs) in managed/production logs.
- Collapse linked/unlinked/total account counts into one memoized query
  instead of 3 separate COUNTs per rendered item.
- Rename "Set Up Up Accounts" locale title to "Link Up Accounts".

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs(up): add method docstrings and align failed_result keys

Add docstrings to all Up provider source files (controller, models,
providers, concerns) to satisfy the 80% docstring coverage threshold.

Third-round review: failed_result now mirrors import's result shape
(accounts_updated/created/failed, transactions_imported/failed) instead
of the stale accounts_imported key, so failure results stay consistent.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-20 20:33:09 +02:00

124 lines
5.2 KiB
Plaintext

<div id="up-providers-panel" class="space-y-4">
<% active_items = local_assigns[:up_items] || @up_items || Current.family.up_items.active.ordered %>
<%= render "settings/providers/setup_steps",
steps: [
t("settings.providers.up_panel.step_1_html", link: link_to(t("providers.up.name"), "https://api.up.com.au", target: "_blank", rel: "noopener noreferrer", class: "text-primary font-medium underline")),
t("settings.providers.up_panel.step_2"),
t("settings.providers.up_panel.step_3")
] %>
<% error_msg = local_assigns[:error_message] || @error_message %>
<% if error_msg.present? %>
<%= render DS::Alert.new(message: error_msg, variant: :error) %>
<% end %>
<% if active_items.any? %>
<div class="space-y-3">
<% active_items.each do |item| %>
<%= render DS::Disclosure.new(variant: :card) do |disclosure| %>
<% disclosure.with_summary_content do %>
<div class="flex items-center justify-between gap-2 w-full">
<div class="flex items-center gap-3">
<div class="flex items-center justify-center h-8 w-8 bg-surface rounded-full">
<p class="text-primary text-xs font-medium"><%= item.name.to_s.first.to_s.upcase %></p>
</div>
<div>
<p class="font-medium text-primary"><%= item.name %></p>
<p class="text-xs text-secondary"><%= item.sync_status_summary %></p>
</div>
</div>
</div>
<% end %>
<div class="mt-4 space-y-4">
<div class="flex items-center gap-2">
<%= render DS::Button.new(
text: t("up_items.provider_panel.sync"),
icon: "refresh-cw",
variant: :outline,
size: :sm,
href: sync_up_item_path(item),
method: :post,
disabled: item.syncing?
) %>
<%= render DS::Button.new(
text: t("up_items.provider_panel.disconnect"),
icon: "trash-2",
variant: :outline_destructive,
size: :sm,
href: up_item_path(item),
method: :delete,
data: { turbo_confirm: t("up_items.provider_panel.disconnect_confirm", name: item.name) }
) %>
</div>
<%= styled_form_with model: item,
url: up_item_path(item),
scope: :up_item,
method: :patch,
data: { turbo: true },
class: "space-y-3" do |form| %>
<%= form.text_field :name,
label: t("up_items.provider_panel.connection_name_label"),
placeholder: t("up_items.provider_panel.connection_name_placeholder") %>
<%= form.text_field :access_token,
label: t("up_items.provider_panel.access_token_label"),
placeholder: t("up_items.provider_panel.keep_access_token_placeholder"),
type: :password,
value: nil %>
<div class="flex flex-wrap justify-end gap-2">
<%= render DS::Link.new(
text: t("up_items.provider_panel.setup_accounts"),
icon: "settings",
variant: "secondary",
href: setup_accounts_up_item_path(item),
frame: :modal
) %>
<%= render DS::Button.new(
text: t("up_items.provider_panel.update_connection"),
type: "submit"
) %>
</div>
<% end %>
</div>
<% end %>
<% end %>
</div>
<% end %>
<% up_item = Current.family.up_items.build(name: t("up_items.provider_panel.default_connection_name")) %>
<% if active_items.any? %>
<h3 class="flex items-center gap-2 text-sm font-medium text-primary mt-4">
<%= icon "plus", size: "sm" %>
<%= t("up_items.provider_panel.add_connection") %>
</h3>
<% end %>
<%= styled_form_with model: up_item,
url: up_items_path,
scope: :up_item,
method: :post,
data: { turbo: true },
class: "space-y-3" do |form| %>
<%= form.text_field :name,
label: t("up_items.provider_panel.connection_name_label"),
placeholder: t("up_items.provider_panel.connection_name_placeholder") %>
<%= form.text_field :access_token,
label: t("up_items.provider_panel.access_token_label"),
placeholder: t("up_items.provider_panel.access_token_placeholder"),
type: :password,
value: nil %>
<div class="flex justify-end">
<%= render DS::Button.new(
text: t("up_items.provider_panel.add_connection"),
type: "submit"
) %>
</div>
<% end %>
</div>