Files
Jakob Wennberg 05c3c6ebd9 feat(peppol): Qvalia access-point adapter, send flow and delivery webhook (#1780)
* feat(peppol): Qvalia access-point adapter, send flow and delivery webhook

Qvalia is the contracted Peppol Access Point (signed 2026-08-21). This fills
the provider-neutral PeppolTransport seam from #1595 with a real adapter and
turns the disabled "Skicka via Peppol" menu item into a working send flow.

Adapter (lib/invoices/transports/qvalia.ts): partner-scoped recipient lookup,
XML submission to /invoices/outgoing with integrationId correlation, 409
recovery only when the stored copy carries the same seller endpoint, tolerant
mapping of Qvalia's free-text webhook statuses onto the 11-state lifecycle,
constant-time shared-secret webhook verification (Qvalia does not sign
webhooks), and evidence retrieval of the message-log status plus Qvalia's
stored XML copy. Registered from the environment in lib/init.ts; switched on
per deployment with PEPPOL_TRANSPORT_PROVIDER=qvalia.

POST /api/invoices/[id]/peppol/send: stage the exact XML, look up the
recipient, record recipient_verified and submitting, submit, record
submission_accepted, then issue a draft with the mark-sent semantics
(issueAndBookInvoice) only after the network accepted it. A sync rejection is
a terminal failed event so the identical document is never re-sent; an
operational failure is retryable; an already-submitted XML replays
idempotently.

POST /api/webhooks/peppol/qvalia resolves the delivery by integrationId,
persists the verified event via the service-role RPC and stores evidence
best-effort; unknown submissions answer 200, our own persistence failures 500.

UI: the send item is availability-driven with a confirm dialog, the invoice
page shows the latest Peppol status, and drafts can be sent (the number is
assigned server-side). Probe script for the first sandbox contact under
scripts/peppol/qvalia-probe.ts.

Refs #546

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TqFpxeWqbpR7bcwUJLRERQ

* fix(peppol): Qvalia sandbox facts from first live contact: bare-key auth, api-test host, SMP-URL document types

The onboarding mail and a live probe against the sandbox (partner
SE5595386219) corrected three assumptions from the public docs: the key is
accepted bare in the Authorization header (the ApiKey prefix answers 401), the
sandbox host is api-test.qvalia.com, and the recipient lookup returns document
types as SMP service URLs, so capabilities are now normalized to bare Peppol
document type ids before comparison.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TqFpxeWqbpR7bcwUJLRERQ

* feat(peppol): probe commands to inspect and configure the Qvalia webhook subscription

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TqFpxeWqbpR7bcwUJLRERQ

* fix(peppol): decode UBL entities in one pass (CodeQL js/double-escaping)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TqFpxeWqbpR7bcwUJLRERQ

---------

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-21 12:45:11 +02:00

107 lines
4.3 KiB
TypeScript

import { loadExtensions } from '@/lib/extensions/loader'
import { setContextFactory } from '@/lib/extensions/registry'
import { createExtensionContext } from '@/lib/extensions/context-factory'
import { registerSupplierInvoiceHandler } from '@/lib/bookkeeping/handlers/supplier-invoice-handler'
import { registerEventLogHandler } from '@/lib/events/handlers/event-log-handler'
import { registerWebhookHandler } from '@/lib/webhooks/handler'
import { registerConfiguredPeppolTransports } from '@/lib/invoices/transports'
import { registerObservabilitySink } from '@/lib/observability'
import { postHogSink } from '@/lib/analytics/posthog-observability'
import { isAnalyticsEnabled } from '@/lib/analytics/enabled'
import { createLogger } from '@/lib/logger'
const log = createLogger('init')
let initialized = false
const REQUIRED_CORE_VARS = [
'NEXT_PUBLIC_SUPABASE_URL',
'NEXT_PUBLIC_SUPABASE_ANON_KEY',
'SUPABASE_SERVICE_ROLE_KEY',
'NEXT_PUBLIC_APP_URL',
'CRON_SECRET',
] as const
// Each entry is one logical requirement; if multiple names are listed, the
// requirement is satisfied when ANY of them is set. Mirrors the runtime
// fallback in extensions/general/enable-banking/lib/jwt.ts (_PRODUCTION ||
// base) so Vercel prod (which only sets the _PRODUCTION variants) doesn't
// warn on every cold start.
// AI features run Claude via AWS Bedrock (see lib/agent/composer/client.ts and
// extensions/general/invoice-inbox/lib/extract-invoice-fields.ts), so the
// static AWS keys are what actually gates them. The assistant's client can
// fall back to the AWS credential provider chain (instance profile, IRSA),
// but document extraction requires both static keys, so this log-only warning
// stays useful even on AWS infrastructure.
const REQUIRED_EXTENSION_VARS: ReadonlyArray<readonly string[]> = [
['ENABLE_BANKING_APP_ID_PRODUCTION', 'ENABLE_BANKING_APP_ID'],
['ENABLE_BANKING_PRIVATE_KEY_PRODUCTION', 'ENABLE_BANKING_PRIVATE_KEY'],
['AWS_ACCESS_KEY_ID'],
['AWS_SECRET_ACCESS_KEY'],
// whatsapp-inbox extension (Meta Cloud API + phone PII at rest)
['WHATSAPP_ACCESS_TOKEN'],
['WHATSAPP_PHONE_NUMBER_ID'],
['WHATSAPP_APP_SECRET'],
['WHATSAPP_VERIFY_TOKEN'],
['WHATSAPP_PHONE_HASH_KEY'],
['WHATSAPP_PHONE_ENCRYPTION_KEY'],
] as const
function validateEnvironment(): void {
// During builds (CI, Docker, Vercel), env vars may be absent or set to
// placeholder sentinels. Skip validation so Next.js page collection
// doesn't fail: real validation happens at runtime.
const supabaseUrl = process.env.NEXT_PUBLIC_SUPABASE_URL
if (!supabaseUrl || supabaseUrl.startsWith('__')) return
const missing: string[] = []
for (const v of REQUIRED_CORE_VARS) {
if (!process.env[v]) missing.push(v)
}
if (missing.length > 0) {
throw new Error(`Missing required environment variables: ${missing.join(', ')}`)
}
const missingExt: string[] = []
for (const aliases of REQUIRED_EXTENSION_VARS) {
if (!aliases.some((v) => !!process.env[v])) {
missingExt.push(aliases.join(' or '))
}
}
if (missingExt.length > 0) {
log.warn(`Missing extension environment variables (extensions needing them may not work): ${missingExt.join(', ')}`)
}
}
/**
* Ensure the system is initialized (extensions loaded, context factory wired,
* core event handlers registered).
* Called from API routes that emit events.
* Idempotent: safe to call multiple times.
*/
export function ensureInitialized(): void {
if (initialized) return
validateEnvironment()
setContextFactory(createExtensionContext)
// Turns lib/observability from a no-op into PostHog Error Tracking. Gated,
// so with no token (core, CI, self-hosted) the sink stays the no-op and
// PostHog is never constructed and never contacted. Note the SDK is still
// BUNDLED in those builds: the imports are static, so the bytes ship even
// though nothing initialises. Making that a true zero would mean dynamic
// imports at every posthog call site, which is a deliberate non-goal here.
if (isAnalyticsEnabled()) registerObservabilitySink(postHogSink)
registerSupplierInvoiceHandler()
registerEventLogHandler()
registerWebhookHandler()
// Peppol Access Point adapters are registered from the environment here so
// every route that reports transport availability sees the same answer.
registerConfiguredPeppolTransports()
loadExtensions()
initialized = true
}