Files
sure/lib/active_record_encryption_config.rb
ghost 95f6451b39 feat(sync): add Brex provider connections (#1752)
* feat(sync): add Brex provider schema

Adds Brex item and account tables with per-family credentials, scoped upstream account uniqueness, encrypted token storage, and sanitized provider payload columns.

* feat(sync): add Brex provider core

Adds Brex item/account models, provider client and adapter support, family connection helpers, and provider enum registration for read-only Brex cash and card data.

* feat(sync): add Brex import pipeline

Adds Brex account discovery, linked-account sync, cash/card balance processors, transaction import, sanitized metadata handling, and idempotent provider entry processing.

* feat(sync): add Brex connection flows

Adds Mercury-style Brex connection management, explicit item-scoped account selection and linking, settings provider UI, account index visibility, localized copy, and per-item cache handling.

* test(sync): cover Brex provider workflows

Adds targeted coverage for Brex provider requests, adapter config, item/account guards, importer behavior, entry processing, and Mercury-style controller flows.

* fix(sync): align Brex API edge cases

Tightens Brex account fetching against the official card-account response shape, sends transaction start filters as RFC3339 date-times, and keeps provider error bodies out of user-facing messages while expanding provider client guard coverage.

* fix(sync): harden Brex provider integration

Restrict Brex API base URLs to official hosts, tighten account-selection UI behavior, and add tests for invalid credentials, cache scoping, and provider setup edge cases.

* test(sync): avoid Brex secret-shaped fixtures

* refactor(sync): extract Brex account flows

* fix(sync): address Brex provider review feedback

* fix(sync): address Brex review follow-ups

Move remaining Brex review cleanup into focused model behavior, tighten link/setup edge cases, localize summaries, and add regression coverage from CodeRabbit feedback.

Also records the security-review pass as no-findings after diff-scoped inspection and Brakeman validation.

* refactor(sync): split Brex account flow controllers

Route Brex account selection and setup actions through small namespaced controllers while keeping existing URLs and helpers stable.

Business flow remains in BrexItem::AccountFlow; the main Brex item controller now only handles connection CRUD, provider-panel rendering, destroy, and sync.

* fix(sync): address Brex CodeRabbit review

* fix(sync): address Brex follow-up review

* fix(sync): address Brex review follow-ups

* fix(sync): address Brex sync review findings

* fix(sync): polish Brex review copy and errors

* fix(sync): register Brex provider health

* fix(sync): polish Brex bank sync presentation

* fix(sync): address Brex review follow-ups

* fix(sync): tighten Brex setup params

* test(api): stabilize usage rate-limit window

* fix(sync): polish Brex setup flow nits

* fix(sync): harden Brex setup params

* fix(sync): finalize Brex review cleanup

---------

Signed-off-by: Juan José Mata <juanjo.mata@gmail.com>
Co-authored-by: Juan José Mata <juanjo.mata@gmail.com>
2026-05-13 18:13:48 +02:00

59 lines
1.4 KiB
Ruby

# frozen_string_literal: true
module ActiveRecordEncryptionConfig
ENV_KEYS = %w[
ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY
ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY
ACTIVE_RECORD_ENCRYPTION_KEY_DERIVATION_SALT
].freeze
CONFIG_KEYS = %i[
primary_key
deterministic_key
key_derivation_salt
].freeze
module_function
def complete_env?(env = ENV)
ENV_KEYS.all? { |key| env_value_present?(env, key) }
end
def partial_env?(env = ENV)
present_count = ENV_KEYS.count { |key| env_value_present?(env, key) }
present_count.positive? && present_count < ENV_KEYS.count
end
def missing_env_keys(env = ENV)
ENV_KEYS.reject { |key| env_value_present?(env, key) }
end
def partial_env_message(env = ENV)
"Active Record encryption environment variables are partially configured. Missing: #{missing_env_keys(env).join(', ')}"
end
def credentials_configured?(credentials = Rails.application.credentials)
credentials.active_record_encryption.present?
rescue NoMethodError
false
end
def runtime_configured?(config = Rails.application.config.active_record.encryption)
CONFIG_KEYS.all? { |key| config.public_send(key).present? }
rescue NoMethodError
false
end
def explicitly_configured?
complete_env? || credentials_configured?
end
def ready?
explicitly_configured? || runtime_configured?
end
def env_value_present?(env, key)
env[key].present?
end
end