8d2ff61599
* feat(bookkeeping): agent attribution into the immutable ledger layer Close the three attribution gaps left after 20260618120001 (which made commit_method record 'api_key' for MCP-relayed approvals): - journal_entries gains nullable committed_actor_type/committed_actor_label, stamped by commit_journal_entry in the same draft->posted UPDATE that writes commit_method. The RPC gains p_actor_type/p_actor_label (DEFAULT NULL; prior signature dropped first to avoid PostgREST overload ambiguity, same technique as 20260421140000). - write_audit_log now populates audit_log.actor_type/actor_label from transaction-local gnubok.actor_* GUCs set by the RPC (the established gnubok.allow_delete pattern). Unset GUCs COALESCE to 'user' — byte- identical to the column's previous effective DEFAULT for every pre-existing write path. - commitPendingOperation accepts opts.actor and runs the entire executor inside an AsyncLocalStorage runWithActor() scope read by commitEntry(), so EVERY journal commit an operation makes is attributed — closing the documented "commitMethod only reaches create_voucher" gap. MCP approve passes the api_key actor + key label; web single/bulk approve pass the user + email. Known limitation (documented): reverseEntry posts reversal vouchers via direct PostgREST writes, not the commit RPC — reversals keep NULL attribution until that path is RPC-ified (follow-up). pg-real coverage: lib/bookkeeping/__tests__/commit-actor.pg.test.ts (RPC param stamping, audit GUC read, transaction-locality, CHECK rejection, immutability of the new columns, single-signature guard). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bookkeeping): split actor-context so client bundles never see node:async_hooks CI core-only build failed: engine.ts is reachable from client component bundles (invoices/[id] page), and the static node:async_hooks import in actor-context.ts cannot be chunked for the browser. Split the module: - actor-context.ts (isomorphic): CommitActor type + a storage registry + getActor(). In a client bundle the registry stays empty and getActor() returns undefined — identical to the server-side no-scope default. - actor-context-node.ts (server-only): owns the AsyncLocalStorage, binds it into the registry on import, exports runWithActor(). Imported only by the approval paths (commit.ts), which are never client-reachable. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
41 lines
1.7 KiB
TypeScript
41 lines
1.7 KiB
TypeScript
/**
|
|
* Transaction-scoped actor context for journal-entry commits — isomorphic half.
|
|
*
|
|
* Carries WHO is relaying a commit (api_key | user | agent_chat | …) from the
|
|
* approval entry points down to commitEntry() without threading a parameter
|
|
* through every pending-operation executor and entry-generator in between.
|
|
* commitEntry() reads it as a fallback and forwards it to the
|
|
* commit_journal_entry RPC, which stamps journal_entries.committed_actor_* and
|
|
* the audit_log COMMIT row (migration 20260619120000).
|
|
*
|
|
* engine.ts is reachable from client component bundles (e.g. the invoice
|
|
* detail page), and client chunks cannot load node:async_hooks — so this
|
|
* module holds only the type + a storage registry, and the AsyncLocalStorage
|
|
* implementation lives in ./actor-context-node (server-only, imported by the
|
|
* approval paths). In a client bundle the registry stays empty and getActor()
|
|
* returns undefined — the same no-attribution default as a server call
|
|
* outside a runWithActor() scope.
|
|
*/
|
|
export interface CommitActor {
|
|
/** Matches the journal_entries.committed_actor_type CHECK constraint. */
|
|
type: 'user' | 'api_key' | 'mcp_oauth' | 'cron' | 'system' | 'agent_chat'
|
|
/** Human-readable credential label, e.g. the API key name. */
|
|
label?: string
|
|
}
|
|
|
|
export interface ActorStore {
|
|
getStore(): CommitActor | undefined
|
|
}
|
|
|
|
let store: ActorStore | null = null
|
|
|
|
/** Bind the server-side AsyncLocalStorage. Called by ./actor-context-node. */
|
|
export function bindActorStore(s: ActorStore): void {
|
|
store = s
|
|
}
|
|
|
|
/** The actor for the current async execution scope, if any. */
|
|
export function getActor(): CommitActor | undefined {
|
|
return store?.getStore()
|
|
}
|