Files
sure/app/models/provider/wise_adapter.rb
Blaž Dular 826c4a356e feat(bank-sync): Wise integration (#2433)
* feat(wise): add Wise integration with JAR savings account and activity support

- Add WiseItem/WiseAccount models with full sync pipeline (importer, syncer, processor)
- Detect income vs expense using targetAccount == recipientId from borderless accounts API
- Support JAR (SAVINGS) accounts with totalWorth balance and savings subtype
- Fetch JAR activity via profile activities API (INTERBALANCE, BALANCE_CASHBACK, BALANCE_ASSET_FEE)
- Route INTERBALANCE activities to both JAR and STANDARD accounts and link as Transfer records
- Add provider connection status registration, routes, views, and i18n
- Add migration for wise_items and wise_accounts tables
- Add tests for WiseAccount, WiseEntry::Processor, WiseActivity::Processor, WiseItem::Importer, and WiseItem#link_jar_transfers!

* chore(lint): add ignore to security scan (false positive)

* fix(wise): address PR review feedback on activity routing, HTML stripping, rate limiting, and scope extraction

- Replace title string matching in activity_for_account? with resource.id vs balance_id comparison to avoid breakage when users rename JAR accounts on Wise
- Replace gsub(/<[^>]+>/, "") with ActionController::Base.helpers.strip_tags to safely handle user-controlled HTML-like content
- Wrap paginated API calls in with_rate_limit_retry (up to 3 attempts, exponential backoff) to handle 429 responses during fetch_jar_activities and fetch_transfers
- Extract WiseAccount.unlinked scope and remove duplicated left_joins query from controller

* fix(wise): address PR #2433 review feedback

- Wire @wise_items into AccountsController#index so linked accounts appear on /accounts
- Fix find_wise_account_for_linking to preserve .active scope via .merge instead of .then
- Fix cross-currency incoming transfer amount to use targetValue instead of sourceValue
- Add missing select_profiles.session_expired locale key
- Add missing account_name interpolation to link_existing_account success notice
- Use i18n for profile type labels in profile_display_name
- Trigger wise_item.sync_later after account linking in all three linking actions
- Isolate fee transaction failure so it no longer aborts the main transfer import
- Use bare raise in WiseActivity/WiseEntry processors to preserve original backtrace
- Re-raise in WiseItem::Unlinking to prevent silently orphaned Holdings
- Fix avatar badge to use design system tokens (bg-container-inset, text-primary)

* fix(wise): fix INTERBALANCE routing and encrypt pending token in session

* fix(wise): replace hand-rolled buttons/links with DS::Button and DS::Link

Address repeated sure-design DS drift findings: migrate all manual
Tailwind button_to and link_to calls in Wise views to DS::Button
(outline/outline_destructive variants) and DS::Link (secondary variant).
Add missing provider_panel.disconnect locale key for the disconnect button text.

* fix(wise): use render_provider_panel_error in create instead of missing new template

* fix(wise): add missing comma in PROVIDERS array

CI failed with a SyntaxError because the questrade entry wasn't
comma-terminated before the wise entry.

* chore(wise): re-add pipelock:ignore for pending token param

Lost when the token source moved from session to an encrypted params
field in 0b5dc886, causing the CI secret scanner to flag a false positive.

* fix(test): widen random ticker suffix to avoid rare collision flake

hex(2) only yields 65536 possible tickers, so create_trade's 4 calls per
test run had a small but nonzero chance of colliding on the unique
ticker+exchange index. hex(8) makes collisions practically impossible.
2026-07-14 03:16:28 +02:00

97 lines
2.5 KiB
Ruby

# frozen_string_literal: true
class Provider::WiseAdapter < Provider::Base
include Provider::Syncable
include Provider::InstitutionMetadata
Provider::Factory.register("WiseAccount", self)
def self.supported_account_types
%w[Depository]
end
def self.connection_configs(family:)
return [] unless family.can_connect_wise?
wise_items = family.wise_items.active.ordered
return [ connection_config_for(nil) ] if wise_items.empty?
wise_items.map { |item| connection_config_for(item) }
end
def provider_name
"wise"
end
def self.build_provider(family: nil, wise_item_id: nil)
return nil unless family.present?
item = resolve_wise_item(family, wise_item_id)
return nil unless item&.credentials_configured?
Provider::Wise.new(item.token.to_s.strip, base_url: Rails.configuration.x.wise.base_url)
end
def sync_path
Rails.application.routes.url_helpers.sync_wise_item_path(item)
end
def item
provider_account.wise_item
end
def can_delete_holdings?
false
end
def institution_name
"Wise"
end
def institution_domain
"wise.com"
end
def institution_url
"https://wise.com"
end
def institution_color
"#9FE870"
end
def self.connection_config_for(wise_item)
path_params = ->(extra = {}) do
wise_item.present? ? extra.merge(wise_item_id: wise_item.id) : extra
end
{
key: wise_item.present? ? "wise_#{wise_item.id}" : "wise",
name: wise_item.present? ? I18n.t("wise_items.provider_connection.name", name: wise_item.name) : I18n.t("wise_items.provider_connection.default_name"),
description: wise_item.present? ? I18n.t("wise_items.provider_connection.description", name: wise_item.name) : I18n.t("wise_items.provider_connection.default_description"),
can_connect: true,
new_account_path: ->(accountable_type, return_to) {
Rails.application.routes.url_helpers.select_accounts_wise_items_path(
path_params.call(accountable_type: accountable_type, return_to: return_to)
)
},
existing_account_path: ->(account_id) {
Rails.application.routes.url_helpers.select_existing_account_wise_items_path(
path_params.call(account_id: account_id)
)
}
}
end
private_class_method :connection_config_for
def self.resolve_wise_item(family, wise_item_id)
if wise_item_id.present?
return family.wise_items.active.find_by(id: wise_item_id)
end
family.wise_items.active.ordered.first
end
private_class_method :resolve_wise_item
end