mirror of
https://github.com/we-promise/sure.git
synced 2026-07-20 16:55:25 +00:00
* Add send_email_notification rule action Adds a new rule action that emails a digest of transactions matching a rule. Re-syncs re-apply every active rule to all in-window matches, so a notification_deliveries table (unique on rule_id + transaction_id) backs deduplication and a per-rule watermark: - Rule::ActionExecutor::SendEmailNotification plucks candidate ids, drops ones already in notification_deliveries, records the remainder BEFORE enqueuing (fail-safe: a crash suppresses rather than double-sends), and returns the count of newly-notified transactions. - RuleEmailNotificationJob loads the rule + transactions and delivers the digest via RuleNotificationMailer. - Creating the action pre-seeds all currently-matching transactions as already-delivered (after_create_commit), so the rule only emails about transactions appearing after the action exists. Dedup keys on the DB row id, not provider identity, so a re-ingested transaction (new id) may re-notify; accepted as benign. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Add view transactions link to rule notification digest email Include a "View transactions" CTA (APP_DOMAIN/transactions) in both the HTML and text versions of the rule notification digest email. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Address review feedback on rule email notifications - Restrict digest delivery to family admins only (drop non-admin fallback) - Make NotificationDelivery.record_for return only inserted ids and enqueue off that result, preventing duplicate digests under concurrent rule runs - Seed the notification baseline when an existing action is changed to send_email_notification, so historical matches are not emailed - Strengthen tests: assert the transactions CTA/link in the digest and the enqueued job's transaction-id args Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Include super_admin owner as rule digest recipient The admin-only recipient lookup used find_by(role: :admin), which excluded super_admin owners. A self-hosted family is commonly a single super_admin, so the digest was silently skipped (NullMail no-op) and no email was sent. Match the recipient on %w[admin super_admin] (the same pattern used elsewhere, and consistent with User#admin?), while still excluding regular members/guests. Add tests for the super_admin recipient and the no-admin skip path. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Add mixed-role digest recipient test Cover the case where a family has both an admin and a super_admin. The recipient lookup uses find_by(role: %w[admin super_admin]) with no ORDER BY, so which one is returned is non-deterministic; the contract is only that the recipient is an admin-level user (never a member). Assert recipient.admin? rather than a brittle precedence between the two roles. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Deliver rule digest via deliver_later and order in DB Use deliver_later so a slow/flaky SMTP connection doesn't tie up the Sidekiq worker, and push the entry-date sort into the query instead of materializing and sorting the result set in Ruby. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Replace raw hex colors with email-safe design tokens in digest template The rule digest email hardcoded Tailwind slate-100/200 hex values for table borders, which aren't part of this project's design system. Resolve to the actual border-primary/border-secondary token values and centralize them as a reusable .email-table class in the mailer layout. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
31 lines
1.5 KiB
Ruby
31 lines
1.5 KiB
Ruby
class Rule::ActionExecutor::SendEmailNotification < Rule::ActionExecutor
|
|
def label
|
|
"Send email notification"
|
|
end
|
|
|
|
# rule_run is accepted for interface compatibility but unused: the digest email
|
|
# is fire-and-forget and is not tracked as part of RuleRun accounting.
|
|
def execute(transaction_scope, value: nil, ignore_attribute_locks: false, rule_run: nil)
|
|
candidate_ids = transaction_scope.pluck(:id)
|
|
|
|
# record_for atomically inserts and returns ONLY the ids this run actually
|
|
# claimed. We enqueue off that result (not the pre-insert candidate list) so
|
|
# two concurrent runs over the same matches never enqueue duplicate digests:
|
|
# whichever loses the unique-index race gets those ids back as empty.
|
|
#
|
|
# Recording is the dedup boundary, since re-syncs re-apply every active rule
|
|
# to all in-window matches (not just newly ingested transactions). If the
|
|
# process crashes after recording but before delivery, the next run suppresses
|
|
# these ids rather than re-sending — we would rather miss a digest than spam.
|
|
new_transaction_ids = NotificationDelivery.record_for(rule_id: rule.id, transaction_ids: candidate_ids)
|
|
|
|
return 0 if new_transaction_ids.empty?
|
|
|
|
RuleEmailNotificationJob.perform_later(rule.id, new_transaction_ids)
|
|
|
|
# Synchronous count of newly-notified transactions. The email itself is
|
|
# delivered out-of-band by the job and is not part of RuleRun accounting.
|
|
new_transaction_ids.size
|
|
end
|
|
end
|