Files
sure/app/views/settings/providers/_wise_panel.html.erb
Blaž Dular 826c4a356e feat(bank-sync): Wise integration (#2433)
* feat(wise): add Wise integration with JAR savings account and activity support

- Add WiseItem/WiseAccount models with full sync pipeline (importer, syncer, processor)
- Detect income vs expense using targetAccount == recipientId from borderless accounts API
- Support JAR (SAVINGS) accounts with totalWorth balance and savings subtype
- Fetch JAR activity via profile activities API (INTERBALANCE, BALANCE_CASHBACK, BALANCE_ASSET_FEE)
- Route INTERBALANCE activities to both JAR and STANDARD accounts and link as Transfer records
- Add provider connection status registration, routes, views, and i18n
- Add migration for wise_items and wise_accounts tables
- Add tests for WiseAccount, WiseEntry::Processor, WiseActivity::Processor, WiseItem::Importer, and WiseItem#link_jar_transfers!

* chore(lint): add ignore to security scan (false positive)

* fix(wise): address PR review feedback on activity routing, HTML stripping, rate limiting, and scope extraction

- Replace title string matching in activity_for_account? with resource.id vs balance_id comparison to avoid breakage when users rename JAR accounts on Wise
- Replace gsub(/<[^>]+>/, "") with ActionController::Base.helpers.strip_tags to safely handle user-controlled HTML-like content
- Wrap paginated API calls in with_rate_limit_retry (up to 3 attempts, exponential backoff) to handle 429 responses during fetch_jar_activities and fetch_transfers
- Extract WiseAccount.unlinked scope and remove duplicated left_joins query from controller

* fix(wise): address PR #2433 review feedback

- Wire @wise_items into AccountsController#index so linked accounts appear on /accounts
- Fix find_wise_account_for_linking to preserve .active scope via .merge instead of .then
- Fix cross-currency incoming transfer amount to use targetValue instead of sourceValue
- Add missing select_profiles.session_expired locale key
- Add missing account_name interpolation to link_existing_account success notice
- Use i18n for profile type labels in profile_display_name
- Trigger wise_item.sync_later after account linking in all three linking actions
- Isolate fee transaction failure so it no longer aborts the main transfer import
- Use bare raise in WiseActivity/WiseEntry processors to preserve original backtrace
- Re-raise in WiseItem::Unlinking to prevent silently orphaned Holdings
- Fix avatar badge to use design system tokens (bg-container-inset, text-primary)

* fix(wise): fix INTERBALANCE routing and encrypt pending token in session

* fix(wise): replace hand-rolled buttons/links with DS::Button and DS::Link

Address repeated sure-design DS drift findings: migrate all manual
Tailwind button_to and link_to calls in Wise views to DS::Button
(outline/outline_destructive variants) and DS::Link (secondary variant).
Add missing provider_panel.disconnect locale key for the disconnect button text.

* fix(wise): use render_provider_panel_error in create instead of missing new template

* fix(wise): add missing comma in PROVIDERS array

CI failed with a SyntaxError because the questrade entry wasn't
comma-terminated before the wise entry.

* chore(wise): re-add pipelock:ignore for pending token param

Lost when the token source moved from session to an encrypted params
field in 0b5dc886, causing the CI secret scanner to flag a false positive.

* fix(test): widen random ticker suffix to avoid rare collision flake

hex(2) only yields 65536 possible tickers, so create_trade's 4 calls per
test run had a small but nonzero chance of colliding on the unique
ticker+exchange index. hex(8) makes collisions practically impossible.
2026-07-14 03:16:28 +02:00

144 lines
6.3 KiB
Plaintext

<div id="wise-providers-panel" class="space-y-4">
<% active_items = local_assigns[:wise_items] || @wise_items || Current.family.wise_items.active.ordered %>
<div class="prose prose-sm text-secondary">
<p class="text-primary font-medium"><%= t("wise_items.provider_panel.setup_title") %></p>
<ol>
<li><%= t("wise_items.provider_panel.instructions.sign_in_html", link: link_to("Wise", "https://wise.com", target: "_blank", rel: "noopener noreferrer", class: "link")).html_safe %></li>
<li><%= t("wise_items.provider_panel.instructions.open_tokens") %></li>
<li><%= t("wise_items.provider_panel.instructions.create_token") %></li>
<li><%= t("wise_items.provider_panel.instructions.copy_token_html").html_safe %></li>
</ol>
</div>
<% unless WiseItem.encryption_ready? %>
<div class="p-3 rounded-md bg-warning/10 text-warning text-sm">
<div class="flex items-start gap-2">
<%= icon "shield-alert", size: "sm", class: "mt-0.5 shrink-0" %>
<div>
<p class="font-medium"><%= t("wise_items.provider_panel.encryption_warning.title") %></p>
<p class="mt-1"><%= t("wise_items.provider_panel.encryption_warning.message") %></p>
</div>
</div>
</div>
<% end %>
<% error_msg = local_assigns[:error_message] || @error_message %>
<% if error_msg.present? %>
<div class="p-2 rounded-md bg-destructive/10 text-destructive text-sm overflow-hidden">
<p class="line-clamp-3" title="<%= error_msg %>"><%= error_msg %></p>
</div>
<% end %>
<% if active_items.any? %>
<div class="space-y-3">
<% active_items.each do |item| %>
<%= render DS::Disclosure.new(variant: :card) do |disclosure| %>
<% disclosure.with_summary_content do %>
<div class="flex items-center justify-between gap-2 w-full">
<div class="flex items-center gap-3">
<div class="flex items-center justify-center h-8 w-8 bg-container-inset rounded-full">
<p class="text-primary text-xs font-medium">WI</p>
</div>
<div>
<p class="font-medium text-primary"><%= item.name %></p>
<p class="text-xs text-secondary"><%= item.sync_status_summary %></p>
</div>
</div>
</div>
<% end %>
<div class="mt-4 space-y-4">
<div class="flex items-center gap-2">
<%= render DS::Button.new(
text: t("wise_items.provider_panel.sync"),
icon: "refresh-cw",
variant: :outline,
size: :sm,
href: sync_wise_item_path(item),
method: :post,
disabled: item.syncing?
) %>
<%= render DS::Button.new(
text: t("wise_items.provider_panel.disconnect"),
icon: "trash-2",
variant: :outline_destructive,
size: :sm,
href: wise_item_path(item),
method: :delete,
aria: { label: t("wise_items.provider_panel.disconnect_label", name: item.name) },
confirm: t("wise_items.provider_panel.disconnect_confirm", name: item.name)
) %>
</div>
<%= styled_form_with model: item,
url: wise_item_path(item),
scope: :wise_item,
method: :patch,
data: { turbo: true },
class: "space-y-3" do |form| %>
<%= form.text_field :name,
label: t("wise_items.provider_panel.connection_name_label"),
placeholder: t("wise_items.provider_panel.connection_name_placeholder") %>
<%= form.text_field :token,
label: t("wise_items.provider_panel.token_label"),
placeholder: t("wise_items.provider_panel.keep_token_placeholder"),
type: :password,
value: nil %>
<div class="flex flex-wrap justify-end gap-2">
<%= render DS::Link.new(
text: t("wise_items.provider_panel.setup_accounts"),
icon: "settings",
variant: "secondary",
href: setup_accounts_wise_item_path(item),
frame: :modal
) %>
<%= form.submit t("wise_items.provider_panel.update_connection") %>
</div>
<% end %>
</div>
<% end %>
<% end %>
</div>
<% end %>
<%= render DS::Disclosure.new(variant: :card, open: active_items.none?) do |disclosure| %>
<% disclosure.with_summary_content do %>
<div class="flex items-center gap-2 text-sm font-medium text-primary">
<%= icon "plus" %>
<%= t("wise_items.provider_panel.add_connection") %>
</div>
<% end %>
<%= styled_form_with url: wise_items_path,
scope: :wise_item,
method: :post,
data: { turbo: true },
class: "space-y-3 mt-4" do |form| %>
<%= form.text_field :token,
label: t("wise_items.provider_panel.token_label"),
placeholder: t("wise_items.provider_panel.token_placeholder"),
type: :password,
value: nil %>
<p class="text-xs text-secondary px-1 -mt-1"><%= t("wise_items.provider_panel.sandbox_note_html").html_safe %></p>
<div class="flex justify-end">
<%= form.submit t("wise_items.provider_panel.connect") %>
</div>
<% end %>
<% end %>
<div class="flex items-center gap-2">
<% if active_items.any? %>
<div class="w-2 h-2 bg-success rounded-full"></div>
<p class="text-sm text-secondary"><%= t("wise_items.provider_panel.configured_html", accounts_link: link_to(t("wise_items.provider_panel.accounts_link"), accounts_path, class: "link")).html_safe %></p>
<% else %>
<div class="w-2 h-2 bg-surface-inset rounded-full"></div>
<p class="text-sm text-secondary"><%= t("wise_items.provider_panel.not_configured") %></p>
<% end %>
</div>
</div>