mirror of
https://github.com/we-promise/sure.git
synced 2026-07-26 19:52:15 +00:00
* Add native Questrade brokerage provider integration Adds a per-family Questrade provider so users can sync their Questrade investment accounts (TFSA, FHSA, RRSP, margin, etc.) directly via Questrade's free personal API, with no paid aggregator. - OAuth2 refresh-token flow with single-use token rotation, persisted under a row lock. Tokens self-renew on each sync; the connected panel lets users paste a fresh token if a connection goes stale (no need to disconnect and re-link). - Imports accounts, balances, positions and activities; multi-currency holdings with per-currency cash holdings; Norbert's Gambit journals. - New-account and link-existing-account flows, settings card with desktop-only setup steps, and connect/update/disconnect. - Restricted to Investment account types. Registered in the provider connection-status registry with a syncable scope so it participates in nightly family sync. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix: linting error * fix: refresh token encrypted The OAuth token exchange passed the single-use refresh token as a GET query parameter, so it could leak into URL-based logs (Sentry breadcrumbs, APM spans, debug output). Switch to POST with a form-encoded body (RFC 6749 3.2) so the credential stays out of URLs. Verified Questrade's token endpoint accepts POST (returns 400 for a bad token, not 405). Adds a test asserting the token travels in the body. * Address PR review: authz, data integrity, retries, logging Batch of fixes from the automated PR review: - Require admin for all mutating/linking Questrade actions, and gate existing-account linking through accessible_accounts + write permission (was only Current.family scoped). - Clear requires_update when a fresh token is accepted; use a real 302 redirect (not 422) on full-page failures. - Require refresh_token on all saves (not just create) unless the item is scheduled for deletion. - Migrations target Rails 7.2; questrade_items state columns are NOT NULL. - Background activity dedup keys on Questrade fields (matches the importer) so multiple activities no longer collapse to one. - Persist the normalized account payload; date-scope synthetic cash holdings so daily history is not overwritten. - Retry 429/5xx via a RetryableResponseError instead of hard-failing. - Route provider error bodies to DebugLogEntry instead of Rails.logger / exception messages, so payloads do not leak into application logs. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Address PR review: atomic linking, sync health, retry loop, USD cash - Wrap account creation + provider linking (+ sync_start_date) in a transaction in both link paths so a link failure rolls back the orphan account. - Surface per-account process/schedule failures in the item sync health instead of always reporting healthy. - Always stamp last_activities_sync once the background fetch completes, so legitimately empty accounts stop being re-queued every sync. - Treat only the account-currency (CAD) balance as primary cash; other currencies (e.g. USD) now surface as separate cash holdings instead of being hidden as primary. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Address PR review: serialize token exchange, real processor tests - Single-use token race: the SDK now wraps every token exchange (initial and 401 re-auth) in a model-supplied lock that reloads and spends the freshest persisted token (provided.rb#synchronize_exchange). Two concurrent syncs/jobs can no longer double-spend the same refresh token. Adds a test asserting the exchange runs inside the lock with the fresh token. - Replace the all-skipped QuestradeAccount processor test stubs with real fixture-backed tests covering balance anchoring, holdings import, and Buy-trade import (plus blank-symbol / blank-type guards). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Fix indentation of spliced Questrade schema blocks The manually added questrade_accounts/questrade_items create_table blocks sat at column 0 instead of the file 2-space indent, so rubocop flagged them as inconsistent. Re-indent to match the rest of the schema. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Include currency and type in the Questrade activity merge key Two activities that differ only by currency or type could collapse to a single row in merge_activities. Add both fields to activity_key in the importer and the background fetch job so multi-currency imports dedup correctly. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Address review: infer account currency, Encryptable, safer flag clear From @jjmata's review: - Currency: QuestradeAccount#upsert_from_questrade! no longer hardcodes CAD for every account. upsert_balances! now infers the home currency from the per-currency balances (the currency holding the cash wins, ties broken by total equity, default CAD) so USD-denominated accounts are labelled USD and match the right combinedBalances anchor. Adds tests for USD and CAD cases. - QuestradeItem now includes the shared Encryptable concern instead of reimplementing encryption_ready? inline. - QuestradeActivitiesFetchJob#clear_pending_flag is now best-effort so it can never mask (and swallow) the original error in perform's rescue. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Fix review issues: safe_return_to_path, DebugLogEntry, financial reset, turbo_prefetch, N+1 counts - Add safe_return_to_path to QuestradeItemsController (blocks //evil.com protocol-relative open redirect; same 3-check guard as PR #2591 Wise provider) - Pass return_to through select_accounts and complete_account_setup so users land back on the account they were linking from - Replace Rails.logger.error/warn with DebugLogEntry.capture in controller and unlinking concern (surface errors in the app debug log UI) - Add questrade_items to Family::FinancialDataReset::PROVIDER_ITEM_ASSOCIATIONS so Reset Financial Data actually removes Questrade data - Add when "questrade" case to load_provider_items in providers_controller so the settings panel lazy-load refresh works - Fix turbo_prefetch: false on non-lunchflow provider links in _method_selector.html.erb and select_provider.html.erb (prevents prefetch-cache blank-modal bug for all generic sync providers) - Preload questrade_accounts: :account_provider and build @questrade_account_counts_map in AccountsController; read from map in partial instead of calling .count on associations (eliminates N+1) - Localize default connection name via I18n.t(questrade_items.default_name) - Add default_name key to questrade_items locale Patterns and bugs surfaced during review of PR #2591 (Wise provider). * Cross-apply Wise learnings to Questrade provider Encryption (matched convention from Wise/jjmata review): - Add deterministic: true to QuestradeItem#refresh_token - Add encrypts :raw_payload + :raw_institution_payload to QuestradeItem - Add Encryptable + encrypts :raw_payload, :raw_holdings_payload, :raw_activities_payload, :raw_balances_payload to QuestradeAccount (brokerage-specific columns; matches MercuryAccount/UpAccount pattern) Bug fix: - Add missing RetryableResponseError class to Provider::Questrade (used in with_retries rescue clause but never defined — would cause NameError on any rate-limited or 5xx response) Logging: - Replace Rails.logger.error with DebugLogEntry.capture in QuestradeItem#import_latest_questrade_data, #process_accounts, and #schedule_account_syncs to surface errors in the support UI Consistency: - Extract update_sync_status(sync, key, **i18n_options) helper in QuestradeItem::Syncer, replacing 5 inline sync.update! guard calls - Use blank? instead of ||= for default name fallback in create action Tests: - Add QuestradeItemsControllerTest (18 tests: CRUD, sync, account linking/setup flows, admin guard enforcement) - Add questrade fixtures: questrade_items.yml, questrade_accounts.yml - Add retry/backoff tests to Provider::QuestradeTest (network error, 429, 5xx — all verify MAX_RETRIES exhaustion raises Error) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Signed-off-by: Jestin Palamuttam <34907800+jestinjoshi@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
235 lines
9.8 KiB
Ruby
235 lines
9.8 KiB
Ruby
module SettingsHelper
|
|
SETTINGS_ORDER = [
|
|
# General section
|
|
{ name: -> { t("settings.settings_nav.accounts_label") }, path: :accounts_path },
|
|
{ name: -> { t("settings.settings_nav.bank_sync_label") }, path: :settings_providers_path, condition: :admin_user? },
|
|
{ name: -> { t("settings.settings_nav.preferences_label") }, path: :settings_preferences_path },
|
|
{ name: -> { t("settings.settings_nav.appearance_label") }, path: :settings_appearance_path },
|
|
{ name: -> { t("settings.settings_nav.profile_label") }, path: :settings_profile_path },
|
|
{ name: -> { t("settings.settings_nav.security_label") }, path: :settings_security_path },
|
|
{ name: -> { t("settings.settings_nav.payment_label") }, path: :settings_payment_path, condition: :not_self_hosted? },
|
|
# Transactions section
|
|
{ name: -> { t("settings.settings_nav.categories_label") }, path: :categories_path },
|
|
{ name: -> { t("settings.settings_nav.tags_label") }, path: :tags_path },
|
|
{ name: -> { t("settings.settings_nav.rules_label") }, path: :rules_path },
|
|
{ name: -> { t("settings.settings_nav.merchants_label") }, path: :family_merchants_path },
|
|
{ name: -> { t("settings.settings_nav.recurring_transactions_label") }, path: :recurring_transactions_path },
|
|
{ name: -> { t("settings.settings_nav.statement_vault_label") }, path: :account_statements_path, condition: :admin_user? },
|
|
# Advanced section
|
|
{ name: -> { t("settings.settings_nav.ai_prompts_label") }, path: :settings_ai_prompts_path, condition: :admin_user? },
|
|
{ name: -> { t("settings.settings_nav.llm_usage_label") }, path: :settings_llm_usage_path, condition: :admin_user? },
|
|
{ name: -> { t("settings.settings_nav.api_key_label") }, path: :settings_api_keys_path, condition: :admin_user? },
|
|
{ name: -> { t("settings.settings_nav.self_hosting_label") }, path: :settings_hosting_path, condition: :self_hosted_and_admin? },
|
|
{ name: -> { t("settings.settings_nav.imports_label") }, path: :imports_path, condition: :admin_user? },
|
|
{ name: -> { t("settings.settings_nav.exports_label") }, path: :family_exports_path, condition: :admin_user? },
|
|
# More section
|
|
{ name: -> { t("settings.settings_nav.guides_label") }, path: :settings_guides_path },
|
|
{ name: -> { t("settings.settings_nav.whats_new_label") }, path: :changelog_path },
|
|
{ name: -> { t("settings.settings_nav.feedback_label") }, path: :feedback_path }
|
|
]
|
|
|
|
def adjacent_setting(current_path, offset)
|
|
visible_settings = SETTINGS_ORDER.select { |setting| setting[:condition].nil? || send(setting[:condition]) }
|
|
current_index = visible_settings.index { |setting| send(setting[:path]) == current_path }
|
|
return nil unless current_index
|
|
|
|
adjacent_index = current_index + offset
|
|
return nil if adjacent_index < 0 || adjacent_index >= visible_settings.size
|
|
|
|
adjacent = visible_settings[adjacent_index]
|
|
|
|
render partial: "settings/settings_nav_link_large", locals: {
|
|
path: send(adjacent[:path]),
|
|
direction: offset > 0 ? "next" : "previous",
|
|
title: setting_name(adjacent)
|
|
}
|
|
end
|
|
|
|
def settings_section(title: nil, subtitle: nil, collapsible: false, open: true, auto_open_param: nil, status: nil, meta: nil, actions: nil, badge: nil, &block)
|
|
content = capture(&block)
|
|
render partial: "settings/section", locals: { title: title, subtitle: subtitle, content: content, collapsible: collapsible, open: open, auto_open_param: auto_open_param, status: status, meta: meta, actions: actions, badge: badge }
|
|
end
|
|
|
|
def provider_summary(provider_key)
|
|
key = provider_key.to_s.downcase
|
|
|
|
case key
|
|
when "plaid", "plaid_eu"
|
|
configured = @provider_configurations&.find { |c| c.provider_key.to_s.casecmp(key).zero? }&.configured?
|
|
configured ? { status: :ok } : { status: :off }
|
|
when "akahu"
|
|
return { status: :off } unless @akahu_items&.any?
|
|
sync_based_summary(key)
|
|
when "up"
|
|
return { status: :off } unless @up_items&.any?
|
|
sync_based_summary(key)
|
|
when "simplefin"
|
|
return { status: :off } unless @simplefin_items&.any?
|
|
sync_based_summary(key)
|
|
when "lunchflow"
|
|
return { status: :off } unless @lunchflow_items&.any?
|
|
sync_based_summary(key)
|
|
when "enable_banking"
|
|
return { status: :off } unless @enable_banking_items&.any?
|
|
enable_banking_summary
|
|
when "coinstats"
|
|
return { status: :off } unless @coinstats_items&.any?
|
|
sync_based_summary(key)
|
|
when "mercury"
|
|
return { status: :off } unless @mercury_items&.any?
|
|
sync_based_summary(key)
|
|
when "brex"
|
|
return { status: :off } unless @brex_items&.any?
|
|
sync_based_summary(key)
|
|
when "coinbase"
|
|
return { status: :off } unless @coinbase_items&.any?
|
|
sync_based_summary(key)
|
|
when "binance"
|
|
return { status: :off } unless @binance_items&.any?
|
|
sync_based_summary(key)
|
|
when "kraken"
|
|
return { status: :off } unless @kraken_items&.any?
|
|
sync_based_summary(key)
|
|
when "snaptrade"
|
|
configured_item = @snaptrade_items&.find { |item| item.credentials_configured? || item.oauth_configured? }
|
|
return { status: :off } unless configured_item
|
|
|
|
unless configured_item.user_registered?
|
|
return { status: :warn, meta: t("settings.providers.meta.registration_needed") }
|
|
end
|
|
sync_based_summary(key)
|
|
when "ibkr"
|
|
return { status: :off } unless @ibkr_items&.any?
|
|
sync_based_summary(key)
|
|
when "indexa_capital"
|
|
return { status: :off } unless @indexa_capital_items&.any?
|
|
sync_based_summary(key)
|
|
when "sophtron"
|
|
return { status: :off } unless @sophtron_items&.any?
|
|
sync_based_summary(key)
|
|
when "questrade"
|
|
return { status: :off } unless @questrade_items&.any?
|
|
sync_based_summary(key)
|
|
else
|
|
{ status: :off }
|
|
end
|
|
end
|
|
|
|
def settings_nav_footer
|
|
previous_setting = adjacent_setting(request.path, -1)
|
|
next_setting = adjacent_setting(request.path, 1)
|
|
|
|
content_tag :div, class: "hidden md:flex flex-row justify-between gap-4" do
|
|
concat(previous_setting)
|
|
concat(next_setting)
|
|
end
|
|
end
|
|
|
|
def settings_nav_footer_mobile
|
|
previous_setting = adjacent_setting(request.path, -1)
|
|
next_setting = adjacent_setting(request.path, 1)
|
|
|
|
content_tag :div, class: "md:hidden flex flex-col gap-4 pb-[env(safe-area-inset-bottom)]" do
|
|
concat(previous_setting)
|
|
concat(next_setting)
|
|
end
|
|
end
|
|
|
|
# Below this many synced accounts, the per-row pills already give the user
|
|
# enough at-a-glance signal and the strip is redundant chrome.
|
|
HEALTH_STRIP_MIN_ACCOUNTS = 10
|
|
|
|
# Slim health-strip data for the providers index. Pulls counts from the
|
|
# already-resolved entry summaries plus the family's distinct synced-account
|
|
# count for the trailing stat. Returns a hash consumed by the
|
|
# `settings/providers/_health_strip` partial, or nil when the family has
|
|
# fewer than HEALTH_STRIP_MIN_ACCOUNTS connected accounts.
|
|
def provider_health_strip(connected:, needs_attention:)
|
|
accounts_count = Current.family.accounts.joins(:account_providers).distinct.count
|
|
return nil if accounts_count < HEALTH_STRIP_MIN_ACCOUNTS
|
|
|
|
active_entries = connected + needs_attention
|
|
last_synced_at = active_entries.map { |e| e[:summary][:last_synced_at] }.compact.max
|
|
|
|
{
|
|
connected: active_entries.size,
|
|
needs_attention: needs_attention.size,
|
|
accounts_syncing: accounts_count,
|
|
last_synced_at: last_synced_at
|
|
}
|
|
end
|
|
|
|
# Strips the leading "about " from `time_ago_in_words` so copy reads as
|
|
# "Synced 6 hours ago" instead of "Synced about 6 hours ago".
|
|
def concise_time_ago(time)
|
|
time_ago_in_words(time).sub(/\Aabout /, "")
|
|
end
|
|
|
|
private
|
|
def sync_based_summary(provider_key)
|
|
health = @provider_sync_health&.dig(provider_key) || {}
|
|
last_synced_at = health[:last_synced_at]
|
|
|
|
base = if health[:error]
|
|
{ status: :err, meta: t("settings.providers.meta.sync_error") }
|
|
elsif health[:stale]
|
|
{ status: :warn, meta: t("settings.providers.meta.no_recent_sync") }
|
|
elsif last_synced_at.present?
|
|
{ status: :ok, meta: t("settings.providers.meta.last_synced", time: concise_time_ago(last_synced_at)) }
|
|
else
|
|
{ status: :ok }
|
|
end
|
|
|
|
base.merge(last_synced_at: last_synced_at)
|
|
end
|
|
|
|
def enable_banking_summary
|
|
health = @provider_sync_health&.dig("enable_banking") || {}
|
|
last_synced_at = health[:last_synced_at]
|
|
|
|
return { status: :err, meta: t("settings.providers.meta.sync_error"), last_synced_at: nil } if health[:error]
|
|
|
|
valid_items = @enable_banking_items&.select(&:session_valid?) || []
|
|
|
|
# All items have expired/missing sessions — need re-authorization
|
|
if valid_items.empty?
|
|
return { status: :warn, meta: t("settings.providers.meta.reconsent_required"), last_synced_at: last_synced_at }
|
|
end
|
|
|
|
expiring = valid_items.find do |item|
|
|
item.session_expires_at.present? && item.session_expires_at < 7.days.from_now
|
|
end
|
|
|
|
if expiring
|
|
days = [ ((expiring.session_expires_at - Time.current) / 1.day).ceil, 1 ].max
|
|
return { status: :warn, meta: t("settings.providers.meta.reconsent_needed", count: days), last_synced_at: last_synced_at }
|
|
end
|
|
|
|
return { status: :warn, meta: t("settings.providers.meta.no_recent_sync"), last_synced_at: last_synced_at } if health[:stale]
|
|
|
|
if last_synced_at.present?
|
|
{ status: :ok, meta: t("settings.providers.meta.last_synced", time: concise_time_ago(last_synced_at)), last_synced_at: last_synced_at }
|
|
else
|
|
{ status: :ok, last_synced_at: nil }
|
|
end
|
|
end
|
|
|
|
def not_self_hosted?
|
|
!self_hosted?
|
|
end
|
|
|
|
def setting_name(setting)
|
|
name = setting[:name]
|
|
name.respond_to?(:call) ? instance_exec(&name) : name
|
|
end
|
|
|
|
# Helper used by SETTINGS_ORDER conditions
|
|
def admin_user?
|
|
Current.user&.admin?
|
|
end
|
|
|
|
def self_hosted_and_admin?
|
|
self_hosted? && admin_user?
|
|
end
|
|
end
|