mirror of
https://github.com/we-promise/sure.git
synced 2026-09-05 06:41:08 +00:00
* feat(bills): the bills pages, calendar feed and in-page AI helpers Second of three chunks carved out of #3083, stacked on the schema and domain core. This is everything a user sees and clicks. The whole surface sits behind the preview flag, so it is unreachable until someone opts in. Pages, all under one nav entry: - the pay run, a month calendar, the full bills table, and the paycheck planner - a detail drawer per bill, with payment history, price changes and cost analytics - create and edit flows for bills, subscriptions, installment plans and income The overview marks pay periods inside the month, so a weekly paycheck no longer reads as one undifferentiated month of bills. Markers appear only when income actually subdivides the month, which means monthly and undeclared income render exactly as before and there is no new setting to configure. Navigation and design system: - one preview-gated nav item shared by the desktop rail and the mobile bar - DS::Sparkline for payment-history charts, replacing raw SVG in views - status badges render through DS::Pill rather than hand-rolled spans - the suggestions panel is a disclosure that remembers being collapsed, per device, the way privacy mode and the sidebar width already do - every surface reflows to phone widths without horizontal scroll Calendar feed: a signed ICS feed per family, served sessionless by token, with a reset that revokes previously shared URLs. In-page AI helpers: smart fill on the bill form and a smart configuration proposal on an existing bill, each reading a bounded slice of charge history. Provider-side prompt assembly sits behind the existing LlmConcept interface, with an implementation for each of the two providers. These belong here rather than with the assistant tools because they are buttons on these pages and lean on the provider suggester, not on the tool registry. Suite 7,776 runs green apart from the pre-existing passkey-session flake, which passes standalone. Rubocop clean, eager loading verified. The hosting guide for the feature ships here rather than with the schema, since its instructions walk pages this PR introduces. * Render the suggested strip through DS::Disclosure The hand-rolled details pair predates the component. The card_inset variant is the same shape, so the strip now inherits the design system chrome, and the persisted-disclosure controller rides along unchanged. * Route the remaining hand-rolled chips through the design system The subscription-state chips, rule-match chips and match-reason chips become DS::Pill, with the state chips extracted to one shared partial so the drawer and the summary tab stop carrying copy-pasted markup. The AI prompt chips become DS::Button and the bills-index filter becomes DS::SearchInput, both of which this PR already uses elsewhere for the same shapes. * Fix erb_lint whitespace offenses in bills views * Address the post-ready review round * Require a writable destination account and gate the feed on preview * Reject an unresolvable declared account out loud
129 lines
4.4 KiB
Ruby
129 lines
4.4 KiB
Ruby
require "test_helper"
|
|
|
|
class BillsFeedsControllerTest < ActionDispatch::IntegrationTest
|
|
setup do
|
|
@family = families(:dylan_family)
|
|
@user = users(:family_admin)
|
|
# The feed is preview-gated on the member the token names.
|
|
@user.update!(preferences: (@user.preferences || {}).merge("preview_features_enabled" => true))
|
|
@family.recurring_transactions.destroy_all
|
|
create_bill(name: "Rent", amount: 2150)
|
|
end
|
|
|
|
test "a member token serves the feed without a session" do
|
|
get bills_feed_url(token: @family.bills_feed_token_for(@user))
|
|
|
|
assert_response :success
|
|
assert_match "BEGIN:VCALENDAR", response.body
|
|
assert_match "Rent", response.body
|
|
end
|
|
|
|
test "an unknown token is not found" do
|
|
get bills_feed_url(token: "nonsense")
|
|
|
|
assert_response :not_found
|
|
end
|
|
|
|
# The old URLs carried a deterministic signed family id with no expiry and
|
|
# no revocation. Breaking them is the point of the change: every URL minted
|
|
# under the old scheme stops working.
|
|
test "an old-style signed token no longer works" do
|
|
signed = Rails.application.message_verifier("bills-ical-feed").generate(@family.id)
|
|
|
|
get bills_feed_url(token: signed)
|
|
|
|
assert_response :not_found
|
|
end
|
|
|
|
# The stored family secret is the revocation root, not a credential: putting
|
|
# it in a URL would hand every member the whole family's obligations.
|
|
test "the raw family secret is not itself a feed token" do
|
|
get bills_feed_url(token: @family.bills_feed_token!)
|
|
|
|
assert_response :not_found
|
|
end
|
|
|
|
# Sharing is per account, so the feed has to honor it: a member who cannot
|
|
# reach an account in the app must not receive its bills by calendar.
|
|
test "a member's feed carries only the bills that member can reach" do
|
|
member = users(:family_member)
|
|
member.update!(preferences: (member.preferences || {}).merge("preview_features_enabled" => true))
|
|
# The investment account is the admin's and was never shared.
|
|
create_bill(name: "Private Brokerage Fee", amount: 95, account: accounts(:investment))
|
|
create_bill(name: "Gym", amount: 30, account: nil)
|
|
|
|
get bills_feed_url(token: @family.bills_feed_token_for(member))
|
|
|
|
assert_response :success
|
|
assert_match "Gym", response.body
|
|
assert_no_match(/Private Brokerage Fee/, response.body)
|
|
|
|
get bills_feed_url(token: @family.bills_feed_token_for(@user))
|
|
|
|
assert_match "Gym", response.body
|
|
assert_match "Private Brokerage Fee", response.body
|
|
end
|
|
|
|
test "resetting the token revokes every member URL and freshly minted ones work" do
|
|
old_token = @family.bills_feed_token_for(@user)
|
|
@family.reset_bills_feed_token!
|
|
|
|
get bills_feed_url(token: old_token)
|
|
assert_response :not_found
|
|
|
|
get bills_feed_url(token: @family.reload.bills_feed_token_for(@user))
|
|
assert_response :success
|
|
assert_match "BEGIN:VCALENDAR", response.body
|
|
end
|
|
|
|
# The feed is sessionless, so the preview gate has to travel with the token:
|
|
# a retained calendar URL must die the moment its member opts out, not only
|
|
# after an explicit token reset.
|
|
test "a retained URL stops working when the member opts out of preview" do
|
|
token = @family.bills_feed_token_for(@user)
|
|
|
|
@user.update!(preferences: (@user.preferences || {}).merge("preview_features_enabled" => false))
|
|
get bills_feed_url(token: token)
|
|
assert_response :not_found
|
|
|
|
@user.update!(preferences: (@user.preferences || {}).merge("preview_features_enabled" => true))
|
|
get bills_feed_url(token: token)
|
|
assert_response :success
|
|
end
|
|
|
|
test "the feed honors the family recurring switch" do
|
|
token = @family.bills_feed_token_for(@user)
|
|
@family.update!(recurring_transactions_disabled: true)
|
|
|
|
get bills_feed_url(token: token)
|
|
|
|
assert_response :not_found
|
|
end
|
|
|
|
test "the family secret generates lazily exactly once" do
|
|
assert_nil @family.bills_feed_token
|
|
|
|
first = @family.bills_feed_token!
|
|
second = @family.bills_feed_token!
|
|
|
|
assert first.present?
|
|
assert_equal first, second
|
|
end
|
|
|
|
private
|
|
|
|
def create_bill(name:, amount:, account: accounts(:depository))
|
|
@family.recurring_transactions.create!(
|
|
account: account,
|
|
name: name,
|
|
amount: amount,
|
|
dedup_scope: amount.to_s,
|
|
currency: "USD",
|
|
expected_day_of_month: Date.current.day,
|
|
last_occurrence_date: 1.month.ago.to_date,
|
|
next_expected_date: Date.current,
|
|
status: "active"
|
|
)
|
|
end
|
|
end
|