Compare commits
38
Commits
d9f9e8a920
...
v1.0.1
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
121952fdc1 | ||
|
|
15f533b984 | ||
|
|
db2bd545a1 | ||
|
|
30dfc7dc3e | ||
|
|
d5ebb86cae | ||
|
|
19f03198d6 | ||
|
|
b2cdcbe2cd | ||
|
|
7e3b530174 | ||
|
|
1cba9bfc32 | ||
|
|
3ff56e6b72 | ||
|
|
27f04f1073 | ||
|
|
4ee7ec71f0 | ||
|
|
9ba5d2d09a | ||
|
|
c100dfa224 | ||
|
|
0bf97e6d2c | ||
|
|
7df928c3ab | ||
|
|
26a4faa33e | ||
|
|
159dcc4963 | ||
|
|
9b9ee201c9 | ||
|
|
6dbd4a319b | ||
|
|
f7ae0d5342 | ||
|
|
1b79b43a54 | ||
|
|
8802f08d4f | ||
|
|
921a47cbaa | ||
|
|
27b3bd9efc | ||
|
|
70911e7e62 | ||
|
|
afe2411c86 | ||
|
|
45afb824ef | ||
|
|
f1ef1c70b3 | ||
|
|
6ad0993a71 | ||
|
|
9dc7f26e02 | ||
|
|
0260b8110d | ||
|
|
7d9f59e51b | ||
|
|
548eeb5798 | ||
|
|
506f8ce684 | ||
|
|
7a46c30d9b | ||
|
|
12692a0af8 | ||
|
|
74e2ad8bcd |
@@ -0,0 +1,16 @@
|
||||
# Keep the build context small + deterministic. node_modules, build output, and
|
||||
# the migration venv are all recreated inside the image, never copied from host.
|
||||
**/node_modules
|
||||
**/dist
|
||||
**/.next
|
||||
**/.turbo
|
||||
apps/web/.next
|
||||
packages/database/generated
|
||||
migration/.venv
|
||||
migration/**/__pycache__
|
||||
**/*.log
|
||||
.git
|
||||
.idea
|
||||
.env
|
||||
.env.*
|
||||
!.env.example
|
||||
@@ -3,3 +3,24 @@ DATABASE_URL=mysql://jorgecuadros:jorgecuadros@localhost:3306/jorgecuadros
|
||||
SESSION_SECRET=change-me-to-a-random-string
|
||||
WEB_ORIGIN=http://localhost:3000
|
||||
NEXT_PUBLIC_API_ORIGIN=http://localhost:3001
|
||||
|
||||
# Login the "Operaciones" screen runs mysqldump/mysql as. Optional locally: when
|
||||
# unset it falls back to the DATABASE_URL credentials, which a dev MySQL usually
|
||||
# grants enough for. Required in any deployment, where the application user has
|
||||
# only ALL ON jorgecuadros.* and mysqldump --single-transaction needs the global
|
||||
# RELOAD privilege. Host/port/database always come from DATABASE_URL.
|
||||
OPS_DB_ADMIN_USER=
|
||||
OPS_DB_ADMIN_PASSWORD=
|
||||
|
||||
# Company info — printed in the header of every report (PDF + browser
|
||||
# print). Leave blank to use the placeholders. COMPANY_LOGO_PATH is
|
||||
# optional; when unset the API falls back to apps/api/assets/company_logo.png.
|
||||
COMPANY_NAME=Jorge Cuadros & Asociados
|
||||
COMPANY_ADDRESS_LINE1=
|
||||
COMPANY_ADDRESS_LINE2=
|
||||
COMPANY_CITY_STATE=
|
||||
COMPANY_PHONE=
|
||||
COMPANY_EMAIL=
|
||||
COMPANY_TAX_ID=
|
||||
COMPANY_WEBSITE=
|
||||
COMPANY_LOGO_PATH=
|
||||
|
||||
@@ -0,0 +1,91 @@
|
||||
# Build + push the API and web container images to the git.mancinas.io registry.
|
||||
#
|
||||
# Two images from this one repo:
|
||||
# git.mancinas.io/rmancinas/jorgecuadros-api
|
||||
# git.mancinas.io/rmancinas/jorgecuadros-web
|
||||
#
|
||||
# Comprehensive versioning (docker/metadata-action). Every build pushes a set
|
||||
# of tags so an image is addressable at several granularities:
|
||||
# - vX.Y.Z / vX.Y when the trigger is a git tag vX.Y.Z (releases)
|
||||
# - <branch> the branch that was pushed (e.g. master, feat-foo)
|
||||
# - sha-<short> immutable per-commit id, always present
|
||||
# - latest only on the default branch (master)
|
||||
# The same version string + commit + build date are baked into the image as
|
||||
# ARG/ENV (APP_VERSION / GIT_SHA / BUILD_DATE) and as OCI labels, so a running
|
||||
# container can report exactly what is deployed.
|
||||
#
|
||||
# Release flow: git tag v1.2.0 && git push origin v1.2.0 -> versioned images.
|
||||
|
||||
name: Build and Push Images
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [master]
|
||||
tags: ["v*"]
|
||||
paths:
|
||||
- "apps/**"
|
||||
- "packages/**"
|
||||
- "docker/**"
|
||||
- "package.json"
|
||||
- "pnpm-lock.yaml"
|
||||
- ".gitea/workflows/build.yml"
|
||||
workflow_dispatch:
|
||||
|
||||
env:
|
||||
REGISTRY: git.mancinas.io
|
||||
|
||||
jobs:
|
||||
build:
|
||||
name: Build ${{ matrix.image }}
|
||||
runs-on: docker
|
||||
container:
|
||||
image: docker:27-dind
|
||||
options: --privileged
|
||||
permissions:
|
||||
contents: read
|
||||
packages: write
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- image: jorgecuadros-api
|
||||
dockerfile: docker/api.Dockerfile
|
||||
- image: jorgecuadros-web
|
||||
dockerfile: docker/web.Dockerfile
|
||||
steps:
|
||||
- name: Install Node.js for actions
|
||||
run: apk add --no-cache nodejs npm
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- uses: docker/setup-buildx-action@v3
|
||||
|
||||
- uses: docker/login-action@v3
|
||||
with:
|
||||
registry: ${{ env.REGISTRY }}
|
||||
username: ${{ secrets.REGISTRY_USERNAME }}
|
||||
password: ${{ secrets.REGISTRY_PASSWORD }}
|
||||
|
||||
- id: meta
|
||||
uses: docker/metadata-action@v5
|
||||
with:
|
||||
images: ${{ env.REGISTRY }}/${{ github.repository_owner }}/${{ matrix.image }}
|
||||
tags: |
|
||||
type=semver,pattern={{version}}
|
||||
type=semver,pattern={{major}}.{{minor}}
|
||||
type=ref,event=branch
|
||||
type=sha,format=short,prefix=sha-
|
||||
type=raw,value=latest,enable={{is_default_branch}}
|
||||
|
||||
- uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: .
|
||||
file: ${{ matrix.dockerfile }}
|
||||
push: true
|
||||
tags: ${{ steps.meta.outputs.tags }}
|
||||
labels: ${{ steps.meta.outputs.labels }}
|
||||
platforms: linux/amd64
|
||||
build-args: |
|
||||
APP_VERSION=${{ steps.meta.outputs.version }}
|
||||
GIT_SHA=${{ github.sha }}
|
||||
BUILD_DATE=${{ fromJSON(steps.meta.outputs.json).labels['org.opencontainers.image.created'] }}
|
||||
@@ -0,0 +1,319 @@
|
||||
# Manual PROD deploy to galactus — the office server, Portainer endpoint 3.
|
||||
#
|
||||
# galactus is STANDALONE Docker (`swarm: inactive`), so this workflow applies
|
||||
# the compose files under deploy/galactus/, NOT the Swarm files in deploy/.
|
||||
# .gitea/workflows/deploy.yml is the cubex/Swarm equivalent; the two are kept
|
||||
# separate on purpose because plain compose silently ignores Swarm's `deploy:`
|
||||
# keys rather than failing on them.
|
||||
#
|
||||
# This does NOT build. build.yml already built + pushed both images from one
|
||||
# matrix run, so api and web at the same tag are always in step.
|
||||
#
|
||||
# Order of operations, and why:
|
||||
# 1. db + minio (scope=full only) — the API depends on both.
|
||||
# 2. pre-migrate backup dumped INSIDE the still-running OLD api container,
|
||||
# so the file lands in the volume the Operaciones
|
||||
# restore screen reads. Must precede the migration.
|
||||
# 3. prisma migrate deploy forward-only. Prisma has no down-migrations; see
|
||||
# docs/DEPLOY_AND_MIGRATIONS.md — expand/contract is
|
||||
# the rule, the backup is the emergency lever.
|
||||
# 4. app (api + web) the new images.
|
||||
# 5. verify ask the running API what it actually is.
|
||||
#
|
||||
# Rollback = re-dispatch with an older `tag`. That rolls back CODE only; the
|
||||
# schema stays forward. This is exactly why every schema change must be
|
||||
# backward-compatible with the previous release.
|
||||
#
|
||||
# Prereqs (once):
|
||||
# - Gitea repo secrets, galactus-specific (suffix _GALACTUS so the cubex
|
||||
# secrets keep working side by side):
|
||||
# PORTAINER_URL_GALACTUS https://100.103.77.46:9443
|
||||
# PORTAINER_API_KEY_GALACTUS Portainer access token for galactus
|
||||
# PORTAINER_ENDPOINT_ID_GALACTUS 3
|
||||
# PORTAINER_APP_STACK_NAME_GALACTUS e.g. jorgecuadros-prod-app
|
||||
# PORTAINER_DB_STACK_NAME_GALACTUS e.g. jorgecuadros-prod-db
|
||||
# PORTAINER_MINIO_STACK_NAME_GALACTUS e.g. jorgecuadros-prod-minio
|
||||
# DATABASE_URL_GALACTUS mysql://jorgecuadros:<pass>@<galactus>:3306/jorgecuadros
|
||||
# APP_API_ORIGIN_GALACTUS browser-facing API URL
|
||||
# APP_WEB_ORIGIN_GALACTUS web public origin (API CORS)
|
||||
# APP_S3_ENDPOINT_GALACTUS server-side minio URL
|
||||
# SESSION_SECRET_GALACTUS 64-hex (openssl rand -hex 32)
|
||||
# MINIO_ROOT_USER / MINIO_ROOT_PASSWORD
|
||||
# MYSQL_PASSWORD / MYSQL_ROOT_PASSWORD
|
||||
# - The runner (which lives on cubex) must be able to reach BOTH
|
||||
# galactus:9443 (Portainer) and galactus:3306 (MySQL, for migrate deploy).
|
||||
# If it cannot reach 3306, run the migration by hand from a host that can
|
||||
# and dispatch with skip_migrate=true.
|
||||
# - ONE-TIME, on a database that predates migration history (i.e. one built
|
||||
# with `prisma db push`): baseline it before the first run, or step 3 fails
|
||||
# with P3005 "database schema is not empty":
|
||||
# npx prisma@5 migrate resolve --applied 0000_init \
|
||||
# --schema packages/database/prisma/schema.prisma
|
||||
|
||||
name: Deploy to galactus
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
tag:
|
||||
description: "Image tag to deploy (1.2.3 — no leading v — or sha-<short>, or latest)"
|
||||
required: true
|
||||
default: "latest"
|
||||
scope:
|
||||
description: "What to deploy"
|
||||
type: choice
|
||||
required: true
|
||||
default: "app"
|
||||
options:
|
||||
- app
|
||||
- full
|
||||
bootstrap:
|
||||
description: "First-ever deploy: allow the pre-migrate backup to be skipped when no API container exists yet"
|
||||
type: boolean
|
||||
required: false
|
||||
default: false
|
||||
skip_migrate:
|
||||
description: "Skip prisma migrate deploy (use when the runner cannot reach MySQL and you migrated by hand)"
|
||||
type: boolean
|
||||
required: false
|
||||
default: false
|
||||
|
||||
env:
|
||||
REGISTRY: git.mancinas.io
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
name: Deploy ${{ github.event.inputs.tag }} (${{ github.event.inputs.scope }})
|
||||
runs-on: docker
|
||||
container:
|
||||
image: node:20-alpine
|
||||
steps:
|
||||
- name: Install tools
|
||||
# openssl: prisma's migration engine picks its musl/openssl build at
|
||||
# runtime and cannot resolve one without it.
|
||||
run: apk add --no-cache openssl ca-certificates git
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
# An unset secret arrives as an empty string, and the deploy action then
|
||||
# fails with "Input required and not supplied: token" — which names the
|
||||
# action's input, not the secret you forgot. Check them up front and say
|
||||
# exactly which ones are missing.
|
||||
- name: Preflight — required secrets
|
||||
env:
|
||||
PORTAINER_URL_GALACTUS: ${{ secrets.PORTAINER_URL_GALACTUS }}
|
||||
PORTAINER_API_KEY_GALACTUS: ${{ secrets.PORTAINER_API_KEY_GALACTUS }}
|
||||
PORTAINER_ENDPOINT_ID_GALACTUS: ${{ secrets.PORTAINER_ENDPOINT_ID_GALACTUS }}
|
||||
PORTAINER_APP_STACK_NAME_GALACTUS: ${{ secrets.PORTAINER_APP_STACK_NAME_GALACTUS }}
|
||||
PORTAINER_DB_STACK_NAME_GALACTUS: ${{ secrets.PORTAINER_DB_STACK_NAME_GALACTUS }}
|
||||
PORTAINER_MINIO_STACK_NAME_GALACTUS: ${{ secrets.PORTAINER_MINIO_STACK_NAME_GALACTUS }}
|
||||
DATABASE_URL_GALACTUS: ${{ secrets.DATABASE_URL_GALACTUS }}
|
||||
SESSION_SECRET_GALACTUS: ${{ secrets.SESSION_SECRET_GALACTUS }}
|
||||
APP_API_ORIGIN_GALACTUS: ${{ secrets.APP_API_ORIGIN_GALACTUS }}
|
||||
APP_WEB_ORIGIN_GALACTUS: ${{ secrets.APP_WEB_ORIGIN_GALACTUS }}
|
||||
APP_S3_ENDPOINT_GALACTUS: ${{ secrets.APP_S3_ENDPOINT_GALACTUS }}
|
||||
MINIO_ROOT_USER: ${{ secrets.MINIO_ROOT_USER }}
|
||||
MINIO_ROOT_PASSWORD: ${{ secrets.MINIO_ROOT_PASSWORD }}
|
||||
MYSQL_PASSWORD: ${{ secrets.MYSQL_PASSWORD }}
|
||||
MYSQL_ROOT_PASSWORD: ${{ secrets.MYSQL_ROOT_PASSWORD }}
|
||||
SCOPE: ${{ github.event.inputs.scope }}
|
||||
run: |
|
||||
REQUIRED="PORTAINER_URL_GALACTUS PORTAINER_API_KEY_GALACTUS
|
||||
PORTAINER_ENDPOINT_ID_GALACTUS PORTAINER_APP_STACK_NAME_GALACTUS
|
||||
DATABASE_URL_GALACTUS SESSION_SECRET_GALACTUS
|
||||
APP_API_ORIGIN_GALACTUS APP_WEB_ORIGIN_GALACTUS
|
||||
APP_S3_ENDPOINT_GALACTUS MINIO_ROOT_USER MINIO_ROOT_PASSWORD
|
||||
MYSQL_ROOT_PASSWORD"
|
||||
if [ "$SCOPE" = "full" ]; then
|
||||
REQUIRED="$REQUIRED PORTAINER_DB_STACK_NAME_GALACTUS
|
||||
PORTAINER_MINIO_STACK_NAME_GALACTUS MYSQL_PASSWORD"
|
||||
fi
|
||||
missing=""
|
||||
for name in $REQUIRED; do
|
||||
eval "value=\${$name}"
|
||||
[ -z "$value" ] && missing="$missing $name"
|
||||
done
|
||||
if [ -n "$missing" ]; then
|
||||
echo "::error::missing repo secrets:$missing"
|
||||
echo "::error::set them under Settings > Actions > Secrets"
|
||||
exit 1
|
||||
fi
|
||||
echo "all required secrets present for scope=$SCOPE"
|
||||
|
||||
# --- full only: database ---------------------------------------------
|
||||
- name: Deploy database stack
|
||||
if: ${{ github.event.inputs.scope == 'full' }}
|
||||
uses: cssnr/portainer-stack-deploy-action@v1
|
||||
with:
|
||||
url: ${{ secrets.PORTAINER_URL_GALACTUS }}
|
||||
token: ${{ secrets.PORTAINER_API_KEY_GALACTUS }}
|
||||
name: ${{ secrets.PORTAINER_DB_STACK_NAME_GALACTUS }}
|
||||
file: deploy/galactus/jorgecuadros-db.compose.yml
|
||||
type: file
|
||||
standalone: true
|
||||
endpoint: ${{ secrets.PORTAINER_ENDPOINT_ID_GALACTUS }}
|
||||
env_data: |
|
||||
{
|
||||
"MYSQL_SERVER_ID": "1",
|
||||
"MYSQL_PORT": "3306",
|
||||
"MYSQL_DATABASE": "jorgecuadros",
|
||||
"MYSQL_USER": "jorgecuadros",
|
||||
"MYSQL_PASSWORD": "${{ secrets.MYSQL_PASSWORD }}",
|
||||
"MYSQL_ROOT_PASSWORD": "${{ secrets.MYSQL_ROOT_PASSWORD }}"
|
||||
}
|
||||
|
||||
# --- full only: object storage ---------------------------------------
|
||||
- name: Deploy minio stack
|
||||
if: ${{ github.event.inputs.scope == 'full' }}
|
||||
uses: cssnr/portainer-stack-deploy-action@v1
|
||||
with:
|
||||
url: ${{ secrets.PORTAINER_URL_GALACTUS }}
|
||||
token: ${{ secrets.PORTAINER_API_KEY_GALACTUS }}
|
||||
name: ${{ secrets.PORTAINER_MINIO_STACK_NAME_GALACTUS }}
|
||||
file: deploy/galactus/jorgecuadros-minio.compose.yml
|
||||
type: file
|
||||
standalone: true
|
||||
endpoint: ${{ secrets.PORTAINER_ENDPOINT_ID_GALACTUS }}
|
||||
env_data: |
|
||||
{
|
||||
"MINIO_API_PORT": "9000",
|
||||
"MINIO_CONSOLE_PORT": "9001",
|
||||
"MINIO_ROOT_USER": "${{ secrets.MINIO_ROOT_USER }}",
|
||||
"MINIO_ROOT_PASSWORD": "${{ secrets.MINIO_ROOT_PASSWORD }}"
|
||||
}
|
||||
|
||||
# --- restore point, taken while the OLD api container is still up ------
|
||||
- name: Pre-migrate backup
|
||||
env:
|
||||
PORTAINER_URL: ${{ secrets.PORTAINER_URL_GALACTUS }}
|
||||
PORTAINER_API_KEY: ${{ secrets.PORTAINER_API_KEY_GALACTUS }}
|
||||
PORTAINER_ENDPOINT_ID: ${{ secrets.PORTAINER_ENDPOINT_ID_GALACTUS }}
|
||||
DATABASE_URL: ${{ secrets.DATABASE_URL_GALACTUS }}
|
||||
# The dump runs as root: --single-transaction issues FLUSH TABLES,
|
||||
# which needs the global RELOAD privilege the application user
|
||||
# deliberately does not have.
|
||||
MYSQL_ROOT_PASSWORD: ${{ secrets.MYSQL_ROOT_PASSWORD }}
|
||||
BACKUP_TAG: ${{ github.event.inputs.tag }}
|
||||
ALLOW_MISSING_CONTAINER: ${{ github.event.inputs.bootstrap }}
|
||||
# Portainer serves a self-signed certificate. Scoped to this step
|
||||
# only, which does nothing but talk to Portainer.
|
||||
NODE_TLS_REJECT_UNAUTHORIZED: "0"
|
||||
run: node deploy/scripts/pre-migrate-backup.mjs
|
||||
|
||||
# --- schema, forward-only ---------------------------------------------
|
||||
- name: Apply database migrations
|
||||
if: ${{ github.event.inputs.skip_migrate != 'true' }}
|
||||
env:
|
||||
DATABASE_URL: ${{ secrets.DATABASE_URL_GALACTUS }}
|
||||
run: |
|
||||
set -e
|
||||
SCHEMA=packages/database/prisma/schema.prisma
|
||||
npx --yes prisma@5 migrate status --schema "$SCHEMA" || true
|
||||
if ! npx --yes prisma@5 migrate deploy --schema "$SCHEMA"; then
|
||||
echo "::error::migrate deploy failed. If this is P3005 (schema not empty),"
|
||||
echo "::error::the database predates migration history — baseline it once with:"
|
||||
echo "::error:: npx prisma@5 migrate resolve --applied 0000_init --schema $SCHEMA"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# --- make sure the host actually has the images ------------------------
|
||||
# The deploy action's `pull: true` does not reliably refresh an already
|
||||
# cached moving tag. Pull explicitly, or a "successful" deploy can leave
|
||||
# the host serving an older build of the same tag.
|
||||
- name: Pull images
|
||||
env:
|
||||
PORTAINER_URL: ${{ secrets.PORTAINER_URL_GALACTUS }}
|
||||
PORTAINER_API_KEY: ${{ secrets.PORTAINER_API_KEY_GALACTUS }}
|
||||
PORTAINER_ENDPOINT_ID: ${{ secrets.PORTAINER_ENDPOINT_ID_GALACTUS }}
|
||||
REGISTRY: ${{ env.REGISTRY }}
|
||||
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
|
||||
REGISTRY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }}
|
||||
IMAGES: ${{ github.repository_owner }}/jorgecuadros-api,${{ github.repository_owner }}/jorgecuadros-web
|
||||
TAG: ${{ github.event.inputs.tag }}
|
||||
NODE_TLS_REJECT_UNAUTHORIZED: "0"
|
||||
run: node deploy/scripts/pull-images.mjs
|
||||
|
||||
# --- always: the app (web + api) -------------------------------------
|
||||
- name: Deploy app stack
|
||||
uses: cssnr/portainer-stack-deploy-action@v1
|
||||
with:
|
||||
url: ${{ secrets.PORTAINER_URL_GALACTUS }}
|
||||
token: ${{ secrets.PORTAINER_API_KEY_GALACTUS }}
|
||||
name: ${{ secrets.PORTAINER_APP_STACK_NAME_GALACTUS }}
|
||||
file: deploy/galactus/jorgecuadros-app.compose.yml
|
||||
type: file
|
||||
standalone: true
|
||||
pull: true
|
||||
endpoint: ${{ secrets.PORTAINER_ENDPOINT_ID_GALACTUS }}
|
||||
env_data: |
|
||||
{
|
||||
"APP_TAG": "${{ github.event.inputs.tag }}",
|
||||
"API_PORT": "3001",
|
||||
"WEB_PORT": "3000",
|
||||
"S3_BUCKET": "jorgecuadros-documents",
|
||||
"API_ORIGIN": "${{ secrets.APP_API_ORIGIN_GALACTUS }}",
|
||||
"WEB_ORIGIN": "${{ secrets.APP_WEB_ORIGIN_GALACTUS }}",
|
||||
"S3_ENDPOINT": "${{ secrets.APP_S3_ENDPOINT_GALACTUS }}",
|
||||
"DATABASE_URL": "${{ secrets.DATABASE_URL_GALACTUS }}",
|
||||
"SESSION_SECRET": "${{ secrets.SESSION_SECRET_GALACTUS }}",
|
||||
"SESSION_COOKIE_SECURE": "false",
|
||||
"OPS_DB_ADMIN_USER": "root",
|
||||
"OPS_DB_ADMIN_PASSWORD": "${{ secrets.MYSQL_ROOT_PASSWORD }}",
|
||||
"MINIO_ROOT_USER": "${{ secrets.MINIO_ROOT_USER }}",
|
||||
"MINIO_ROOT_PASSWORD": "${{ secrets.MINIO_ROOT_PASSWORD }}"
|
||||
}
|
||||
|
||||
# --- prove it ----------------------------------------------------------
|
||||
- name: Verify running version
|
||||
env:
|
||||
API_ORIGIN: ${{ secrets.APP_API_ORIGIN_GALACTUS }}
|
||||
WEB_ORIGIN: ${{ secrets.APP_WEB_ORIGIN_GALACTUS }}
|
||||
WANT: ${{ github.event.inputs.tag }}
|
||||
# A stack naming a tag is not proof the containers run it. Ask BOTH
|
||||
# tiers what they are, and require them to be the same commit: api and
|
||||
# web are built from one matrix run, so a difference can only mean one
|
||||
# of them did not actually get replaced.
|
||||
run: |
|
||||
set -e
|
||||
apk add --no-cache curl >/dev/null
|
||||
fetch_version() {
|
||||
for i in $(seq 1 30); do
|
||||
if curl -fsS "$1/version" > "$2"; then return 0; fi
|
||||
echo "waiting for $1 ($i/30)..."
|
||||
sleep 5
|
||||
done
|
||||
echo "::error::$1/version never answered"
|
||||
return 1
|
||||
}
|
||||
fetch_version "$API_ORIGIN" /tmp/api.json
|
||||
fetch_version "$WEB_ORIGIN" /tmp/web.json
|
||||
cat /tmp/api.json; echo; cat /tmp/web.json; echo
|
||||
|
||||
API_SHA=$(node -e 'console.log(require("/tmp/api.json").gitSha)')
|
||||
WEB_SHA=$(node -e 'console.log(require("/tmp/web.json").gitSha)')
|
||||
API_VER=$(node -e 'console.log(require("/tmp/api.json").version)')
|
||||
|
||||
# Compare the COMMIT, not the version string: on a branch build both
|
||||
# tiers report "master", so version equality proves nothing.
|
||||
if [ "$API_SHA" != "$WEB_SHA" ]; then
|
||||
echo "::error::api and web are different builds — api $API_SHA, web $WEB_SHA"
|
||||
echo "::error::one of the images was not replaced; check the Pull images step"
|
||||
exit 1
|
||||
fi
|
||||
echo "api and web agree: $API_SHA"
|
||||
|
||||
# A semver dispatch is additionally comparable to the tag itself:
|
||||
# metadata-action's {{version}} turns tag v1.2.3 into image 1.2.3,
|
||||
# while `latest` and `sha-*` report the branch or short sha instead.
|
||||
case "$WANT" in
|
||||
[0-9]*.[0-9]*.[0-9]*)
|
||||
if [ "$API_VER" != "$WANT" ]; then
|
||||
echo "::error::deployed $WANT but the API reports $API_VER"
|
||||
exit 1
|
||||
fi
|
||||
echo "verified: running $API_VER"
|
||||
;;
|
||||
*)
|
||||
echo "dispatched '$WANT'; tiers report '$API_VER' (not directly comparable)"
|
||||
;;
|
||||
esac
|
||||
@@ -0,0 +1,321 @@
|
||||
# Manual PROD deploy to Portainer.
|
||||
#
|
||||
# This does NOT build — build.yml already builds + pushes the api/web images.
|
||||
# This workflow (re)applies the deploy/*.stack.yml files to the Portainer Swarm.
|
||||
# Trigger it by hand from the Actions tab ("Run workflow") and choose:
|
||||
# - tag: which already-published image tag to ship (default: latest)
|
||||
# - scope: how much to deploy
|
||||
# app = web + api only (the usual app release) [default]
|
||||
# full = db + minio + web + api (bring up / update the whole platform)
|
||||
#
|
||||
# The `tag` input carries NO leading `v`: metadata-action's {{version}} turns
|
||||
# git tag v1.2.3 into image tag 1.2.3. Tag v1.2.3, dispatch 1.2.3.
|
||||
#
|
||||
# Order: db+minio (full only) -> pre-migrate backup -> prisma migrate deploy ->
|
||||
# app -> verify the API reports the version you asked for. Rollback = dispatch
|
||||
# an older tag; that rolls back CODE only, never the schema, which is why every
|
||||
# schema change must be expand/contract. See docs/DEPLOY_AND_MIGRATIONS.md.
|
||||
#
|
||||
# galactus (the office server) is standalone Docker, not this Swarm — it has its
|
||||
# own workflow, .gitea/workflows/deploy-galactus.yml.
|
||||
#
|
||||
# cssnr/portainer-stack-deploy-action creates each stack on first run and updates
|
||||
# it on every run, so no manual stack pre-creation in the Portainer UI. On a
|
||||
# `full` deploy the db + minio stacks are applied BEFORE the app (the API depends
|
||||
# on them). db + minio are stateful + pinned to node label jorgecuadros_db=true
|
||||
# (see their stack files) — re-applying them is idempotent and keeps their data.
|
||||
#
|
||||
# Prereqs (once):
|
||||
# - one swarm node labelled jorgecuadros_db=true (db + minio + api pin there).
|
||||
# - Gitea repo secrets set (Settings > Actions > Secrets):
|
||||
# # Portainer
|
||||
# PORTAINER_URL https://192.168.4.212:9443
|
||||
# PORTAINER_API_KEY Portainer access token
|
||||
# PORTAINER_ENDPOINT_ID 2 (the local Swarm endpoint)
|
||||
# PORTAINER_APP_STACK_NAME e.g. jorgecuadros-prod-app
|
||||
# PORTAINER_DB_STACK_NAME e.g. jorgecuadros-prod-db (full only)
|
||||
# PORTAINER_MINIO_STACK_NAME e.g. jorgecuadros-prod-minio (full only)
|
||||
# # App runtime
|
||||
# DATABASE_URL mysql://jorgecuadros:<pass>@192.168.4.212:3306/jorgecuadros
|
||||
# SESSION_SECRET 64-hex (openssl rand -hex 32)
|
||||
# APP_API_ORIGIN http://192.168.4.212:3001 (browser-facing API URL)
|
||||
# APP_WEB_ORIGIN http://192.168.4.212:3000 (web public origin, API CORS)
|
||||
# APP_S3_ENDPOINT http://192.168.4.212:9000 (server-side minio URL)
|
||||
# # Object storage (app + minio stack)
|
||||
# MINIO_ROOT_USER minio access key
|
||||
# MINIO_ROOT_PASSWORD minio secret key
|
||||
# # Database stack (full only)
|
||||
# MYSQL_PASSWORD app-user password (matches DATABASE_URL)
|
||||
# MYSQL_ROOT_PASSWORD mysql root password
|
||||
# - the runner must reach BOTH Portainer (9443) and MySQL (3306) — the
|
||||
# migration step connects to the database directly. If it cannot reach 3306,
|
||||
# migrate by hand and dispatch with skip_migrate=true.
|
||||
# - ONE-TIME on a database built with `prisma db push` (i.e. every database
|
||||
# that exists today): baseline it before the first run, or the migrate step
|
||||
# fails with P3005 "database schema is not empty":
|
||||
# npx prisma@5 migrate resolve --applied 0000_init \
|
||||
# --schema packages/database/prisma/schema.prisma
|
||||
|
||||
name: Deploy to Portainer
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
tag:
|
||||
description: "Image tag to deploy (latest, sha-<short>, or vX.Y.Z)"
|
||||
required: true
|
||||
default: "latest"
|
||||
scope:
|
||||
description: "What to deploy"
|
||||
type: choice
|
||||
required: true
|
||||
default: "app"
|
||||
options:
|
||||
- app
|
||||
- full
|
||||
bootstrap:
|
||||
description: "First-ever deploy: allow the pre-migrate backup to be skipped when no API container exists yet"
|
||||
type: boolean
|
||||
required: false
|
||||
default: false
|
||||
skip_migrate:
|
||||
description: "Skip prisma migrate deploy (use when the runner cannot reach MySQL and you migrated by hand)"
|
||||
type: boolean
|
||||
required: false
|
||||
default: false
|
||||
|
||||
env:
|
||||
REGISTRY: git.mancinas.io
|
||||
|
||||
jobs:
|
||||
deploy:
|
||||
name: Deploy (${{ github.event.inputs.scope }})
|
||||
runs-on: docker
|
||||
container:
|
||||
image: node:20-alpine
|
||||
steps:
|
||||
- name: Install tools
|
||||
# openssl: prisma's migration engine picks its musl/openssl build at
|
||||
# runtime and cannot resolve one without it.
|
||||
run: apk add --no-cache openssl ca-certificates git
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
# An unset secret arrives as an empty string, and the deploy action then
|
||||
# fails with "Input required and not supplied: token" — which names the
|
||||
# action's input, not the secret you forgot.
|
||||
- name: Preflight — required secrets
|
||||
env:
|
||||
PORTAINER_URL: ${{ secrets.PORTAINER_URL }}
|
||||
PORTAINER_API_KEY: ${{ secrets.PORTAINER_API_KEY }}
|
||||
PORTAINER_ENDPOINT_ID: ${{ secrets.PORTAINER_ENDPOINT_ID }}
|
||||
PORTAINER_APP_STACK_NAME: ${{ secrets.PORTAINER_APP_STACK_NAME }}
|
||||
PORTAINER_DB_STACK_NAME: ${{ secrets.PORTAINER_DB_STACK_NAME }}
|
||||
PORTAINER_MINIO_STACK_NAME: ${{ secrets.PORTAINER_MINIO_STACK_NAME }}
|
||||
DATABASE_URL: ${{ secrets.DATABASE_URL }}
|
||||
SESSION_SECRET: ${{ secrets.SESSION_SECRET }}
|
||||
APP_API_ORIGIN: ${{ secrets.APP_API_ORIGIN }}
|
||||
APP_WEB_ORIGIN: ${{ secrets.APP_WEB_ORIGIN }}
|
||||
APP_S3_ENDPOINT: ${{ secrets.APP_S3_ENDPOINT }}
|
||||
MINIO_ROOT_USER: ${{ secrets.MINIO_ROOT_USER }}
|
||||
MINIO_ROOT_PASSWORD: ${{ secrets.MINIO_ROOT_PASSWORD }}
|
||||
MYSQL_PASSWORD: ${{ secrets.MYSQL_PASSWORD }}
|
||||
MYSQL_ROOT_PASSWORD: ${{ secrets.MYSQL_ROOT_PASSWORD }}
|
||||
SCOPE: ${{ github.event.inputs.scope }}
|
||||
run: |
|
||||
REQUIRED="PORTAINER_URL PORTAINER_API_KEY PORTAINER_ENDPOINT_ID
|
||||
PORTAINER_APP_STACK_NAME DATABASE_URL SESSION_SECRET
|
||||
APP_API_ORIGIN APP_WEB_ORIGIN APP_S3_ENDPOINT
|
||||
MINIO_ROOT_USER MINIO_ROOT_PASSWORD MYSQL_ROOT_PASSWORD"
|
||||
if [ "$SCOPE" = "full" ]; then
|
||||
REQUIRED="$REQUIRED PORTAINER_DB_STACK_NAME PORTAINER_MINIO_STACK_NAME
|
||||
MYSQL_PASSWORD"
|
||||
fi
|
||||
missing=""
|
||||
for name in $REQUIRED; do
|
||||
eval "value=\${$name}"
|
||||
[ -z "$value" ] && missing="$missing $name"
|
||||
done
|
||||
if [ -n "$missing" ]; then
|
||||
echo "::error::missing repo secrets:$missing"
|
||||
echo "::error::set them under Settings > Actions > Secrets"
|
||||
exit 1
|
||||
fi
|
||||
echo "all required secrets present for scope=$SCOPE"
|
||||
|
||||
# --- full only: database ---------------------------------------------
|
||||
- name: Deploy database stack
|
||||
if: ${{ github.event.inputs.scope == 'full' }}
|
||||
uses: cssnr/portainer-stack-deploy-action@v1
|
||||
with:
|
||||
url: ${{ secrets.PORTAINER_URL }}
|
||||
token: ${{ secrets.PORTAINER_API_KEY }}
|
||||
name: ${{ secrets.PORTAINER_DB_STACK_NAME }}
|
||||
file: deploy/jorgecuadros-db.stack.yml
|
||||
type: file
|
||||
endpoint: ${{ secrets.PORTAINER_ENDPOINT_ID }}
|
||||
env_data: |
|
||||
{
|
||||
"MYSQL_SERVER_ID": "1",
|
||||
"MYSQL_PORT": "3306",
|
||||
"MYSQL_DATABASE": "jorgecuadros",
|
||||
"MYSQL_USER": "jorgecuadros",
|
||||
"MYSQL_PASSWORD": "${{ secrets.MYSQL_PASSWORD }}",
|
||||
"MYSQL_ROOT_PASSWORD": "${{ secrets.MYSQL_ROOT_PASSWORD }}"
|
||||
}
|
||||
|
||||
# --- full only: object storage ---------------------------------------
|
||||
- name: Deploy minio stack
|
||||
if: ${{ github.event.inputs.scope == 'full' }}
|
||||
uses: cssnr/portainer-stack-deploy-action@v1
|
||||
with:
|
||||
url: ${{ secrets.PORTAINER_URL }}
|
||||
token: ${{ secrets.PORTAINER_API_KEY }}
|
||||
name: ${{ secrets.PORTAINER_MINIO_STACK_NAME }}
|
||||
file: deploy/jorgecuadros-minio.stack.yml
|
||||
type: file
|
||||
endpoint: ${{ secrets.PORTAINER_ENDPOINT_ID }}
|
||||
env_data: |
|
||||
{
|
||||
"MINIO_API_PORT": "9000",
|
||||
"MINIO_CONSOLE_PORT": "9001",
|
||||
"MINIO_ROOT_USER": "${{ secrets.MINIO_ROOT_USER }}",
|
||||
"MINIO_ROOT_PASSWORD": "${{ secrets.MINIO_ROOT_PASSWORD }}"
|
||||
}
|
||||
|
||||
# --- restore point, taken while the OLD api container is still up ------
|
||||
# Dumped INSIDE the running api container so the file lands in the volume
|
||||
# the "Operaciones" restore screen reads — a dump on the runner would be
|
||||
# unreachable by the only restore path this platform has.
|
||||
- name: Pre-migrate backup
|
||||
env:
|
||||
PORTAINER_URL: ${{ secrets.PORTAINER_URL }}
|
||||
PORTAINER_API_KEY: ${{ secrets.PORTAINER_API_KEY }}
|
||||
PORTAINER_ENDPOINT_ID: ${{ secrets.PORTAINER_ENDPOINT_ID }}
|
||||
DATABASE_URL: ${{ secrets.DATABASE_URL }}
|
||||
# The dump runs as root: --single-transaction issues FLUSH TABLES,
|
||||
# which needs the global RELOAD privilege the application user
|
||||
# deliberately does not have.
|
||||
MYSQL_ROOT_PASSWORD: ${{ secrets.MYSQL_ROOT_PASSWORD }}
|
||||
BACKUP_TAG: ${{ github.event.inputs.tag }}
|
||||
ALLOW_MISSING_CONTAINER: ${{ github.event.inputs.bootstrap }}
|
||||
# Portainer serves a self-signed certificate. Scoped to this step
|
||||
# only, which does nothing but talk to Portainer.
|
||||
NODE_TLS_REJECT_UNAUTHORIZED: "0"
|
||||
run: node deploy/scripts/pre-migrate-backup.mjs
|
||||
|
||||
# --- schema, forward-only ---------------------------------------------
|
||||
# Prisma has no down-migrations: a code rollback does NOT roll the schema
|
||||
# back. See docs/DEPLOY_AND_MIGRATIONS.md — every change must be
|
||||
# expand/contract so the previous release still runs against the new
|
||||
# schema. Run as a deploy STEP, never as the container CMD: N replicas
|
||||
# would race each other applying the same migration.
|
||||
- name: Apply database migrations
|
||||
if: ${{ github.event.inputs.skip_migrate != 'true' }}
|
||||
env:
|
||||
DATABASE_URL: ${{ secrets.DATABASE_URL }}
|
||||
run: |
|
||||
set -e
|
||||
SCHEMA=packages/database/prisma/schema.prisma
|
||||
npx --yes prisma@5 migrate status --schema "$SCHEMA" || true
|
||||
if ! npx --yes prisma@5 migrate deploy --schema "$SCHEMA"; then
|
||||
echo "::error::migrate deploy failed. If this is P3005 (schema not empty),"
|
||||
echo "::error::the database predates migration history — baseline it once with:"
|
||||
echo "::error:: npx prisma@5 migrate resolve --applied 0000_init --schema $SCHEMA"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# --- make sure the host actually has the images ------------------------
|
||||
# The deploy action's `pull: true` does not reliably refresh an already
|
||||
# cached moving tag; without this a "successful" deploy can leave the host
|
||||
# serving an older build of the same tag.
|
||||
- name: Pull images
|
||||
env:
|
||||
PORTAINER_URL: ${{ secrets.PORTAINER_URL }}
|
||||
PORTAINER_API_KEY: ${{ secrets.PORTAINER_API_KEY }}
|
||||
PORTAINER_ENDPOINT_ID: ${{ secrets.PORTAINER_ENDPOINT_ID }}
|
||||
REGISTRY: ${{ env.REGISTRY }}
|
||||
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
|
||||
REGISTRY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }}
|
||||
IMAGES: ${{ github.repository_owner }}/jorgecuadros-api,${{ github.repository_owner }}/jorgecuadros-web
|
||||
TAG: ${{ github.event.inputs.tag }}
|
||||
NODE_TLS_REJECT_UNAUTHORIZED: "0"
|
||||
run: node deploy/scripts/pull-images.mjs
|
||||
|
||||
# --- always: the app (web + api) -------------------------------------
|
||||
- name: Deploy app stack
|
||||
uses: cssnr/portainer-stack-deploy-action@v1
|
||||
with:
|
||||
url: ${{ secrets.PORTAINER_URL }}
|
||||
token: ${{ secrets.PORTAINER_API_KEY }}
|
||||
name: ${{ secrets.PORTAINER_APP_STACK_NAME }}
|
||||
file: deploy/jorgecuadros-app.stack.yml
|
||||
type: file
|
||||
pull: true
|
||||
endpoint: ${{ secrets.PORTAINER_ENDPOINT_ID }}
|
||||
env_data: |
|
||||
{
|
||||
"APP_TAG": "${{ github.event.inputs.tag }}",
|
||||
"API_PORT": "3001",
|
||||
"WEB_PORT": "3000",
|
||||
"S3_BUCKET": "jorgecuadros-documents",
|
||||
"API_ORIGIN": "${{ secrets.APP_API_ORIGIN }}",
|
||||
"WEB_ORIGIN": "${{ secrets.APP_WEB_ORIGIN }}",
|
||||
"S3_ENDPOINT": "${{ secrets.APP_S3_ENDPOINT }}",
|
||||
"DATABASE_URL": "${{ secrets.DATABASE_URL }}",
|
||||
"SESSION_SECRET": "${{ secrets.SESSION_SECRET }}",
|
||||
"OPS_DB_ADMIN_USER": "root",
|
||||
"OPS_DB_ADMIN_PASSWORD": "${{ secrets.MYSQL_ROOT_PASSWORD }}",
|
||||
"MINIO_ROOT_USER": "${{ secrets.MINIO_ROOT_USER }}",
|
||||
"MINIO_ROOT_PASSWORD": "${{ secrets.MINIO_ROOT_PASSWORD }}"
|
||||
}
|
||||
|
||||
# --- prove it ----------------------------------------------------------
|
||||
# A stack naming a tag is not proof the container is running it — a
|
||||
# skipped pull leaves the old code up. Ask the API what it actually is.
|
||||
- name: Verify running version
|
||||
env:
|
||||
API_ORIGIN: ${{ secrets.APP_API_ORIGIN }}
|
||||
WEB_ORIGIN: ${{ secrets.APP_WEB_ORIGIN }}
|
||||
WANT: ${{ github.event.inputs.tag }}
|
||||
run: |
|
||||
set -e
|
||||
apk add --no-cache curl >/dev/null
|
||||
fetch_version() {
|
||||
for i in $(seq 1 30); do
|
||||
if curl -fsS "$1/version" > "$2"; then return 0; fi
|
||||
echo "waiting for $1 ($i/30)..."
|
||||
sleep 5
|
||||
done
|
||||
echo "::error::$1/version never answered"
|
||||
return 1
|
||||
}
|
||||
fetch_version "$API_ORIGIN" /tmp/api.json
|
||||
fetch_version "$WEB_ORIGIN" /tmp/web.json
|
||||
cat /tmp/api.json; echo; cat /tmp/web.json; echo
|
||||
|
||||
API_SHA=$(node -e 'console.log(require("/tmp/api.json").gitSha)')
|
||||
WEB_SHA=$(node -e 'console.log(require("/tmp/web.json").gitSha)')
|
||||
API_VER=$(node -e 'console.log(require("/tmp/api.json").version)')
|
||||
|
||||
# Compare the COMMIT, not the version string: on a branch build both
|
||||
# tiers report "master", so version equality proves nothing.
|
||||
if [ "$API_SHA" != "$WEB_SHA" ]; then
|
||||
echo "::error::api and web are different builds — api $API_SHA, web $WEB_SHA"
|
||||
echo "::error::one of the images was not replaced; check the Pull images step"
|
||||
exit 1
|
||||
fi
|
||||
echo "api and web agree: $API_SHA"
|
||||
|
||||
case "$WANT" in
|
||||
[0-9]*.[0-9]*.[0-9]*)
|
||||
if [ "$API_VER" != "$WANT" ]; then
|
||||
echo "::error::deployed $WANT but the API reports $API_VER"
|
||||
exit 1
|
||||
fi
|
||||
echo "verified: running $API_VER"
|
||||
;;
|
||||
*)
|
||||
echo "dispatched '$WANT'; tiers report '$API_VER' (not directly comparable)"
|
||||
;;
|
||||
esac
|
||||
@@ -8,6 +8,8 @@ build/
|
||||
*.log
|
||||
migration/output/
|
||||
migration/.venv/
|
||||
migration/ingest/
|
||||
migration/backups/
|
||||
__pycache__/
|
||||
*.pyc
|
||||
packages/database/generated/
|
||||
|
||||
@@ -128,8 +128,26 @@ Given the amount of near-duplicate/overlapping data across snapshot tables (mult
|
||||
6. Shared billing/statements module (the payoff: one statement per customer spanning both utility and insurance transactions) — **DONE**. `apps/api/src/billing/` + web `/estado-cuenta` and `/estado-cuenta/[id]`. Two questions, two views: a per-customer **balances worklist** (who owes what) and a cross-customer **movement browser** (every charge and credit, filterable by line, concept, origin table and date range, with totals for the whole filtered set). The detail page is the actual statement: balance per currency, the same balance split by business line, charges broken out by concept, and the full movement list with a running balance. **Design constraint that shapes the whole module: balances are reported per currency and never collapsed into one number.** 912 of the 1,269 customers with a ledger move in both MXN and USD, the charge side is MXN-only while receipts arrive in both, and the legacy data never stored the exchange rate applied to a movement — so a single "total balance" would be a figure that never existed in the books.
|
||||
7. Bank register module (`bank_transactions`/`business_line_categories` from SCOTHIA) — small, self-contained, and has no customer FK, so it can slot in independently once the core migration pipeline exists; low risk, low priority relative to the customer-facing modules.
|
||||
8. VPS provisioning + Tailscale + MySQL replication setup. `utility_dbo`'s schema is now available (full dump on disk — 55 tables; see Status), so the exact replicated table/column set and inbox-table shape can be finalized against the real portal DB and the portal PHP code (`my-jorgecuadros-web`) that reads/writes it.
|
||||
9. Sync worker (push replicated tables' relevant subset, poll inbox tables for payment/propane submissions) — depends on step 8. Portal write points confirmed present in `utility_dbo`: `peticion_gas` (propane requests), PayPal payment writes, `notifications_settings`, `verification_codes` — these define the VPS→internal inbox set.
|
||||
9. Sync worker (push replicated tables' relevant subset, poll inbox tables for payment/propane submissions) — depends on step 8. **The separate Phase B Access additive sync is implemented:** `migration/run_all.py --sync` and the admin `SYNC` job upsert legacy-owned rows without truncating the database or touching manual rows. Portal write points confirmed present in `utility_dbo`: `peticion_gas` (propane requests), PayPal payment writes, `notifications_settings`, `verification_codes` — these define the VPS→internal inbox set.
|
||||
10. Reports/email campaigns/admin — parity with old app's `reports.php`/`emailCampaigns.php` intent, rebuilt properly.
|
||||
11. **Receipt capture ("Editor") completion + three net-new ops features — NOT STARTED, spec written.** Full design in [`docs/RECEIPT_CAPTURE_SPEC.md`](docs/RECEIPT_CAPTURE_SPEC.md), from the 2026-07-25/26 meeting with Jorge:
|
||||
- **Receipt capture module — DONE** (2026-07-27). The legacy "Editor" replacement, built on the single-movement capture from step 6. Wires up the previously-unused `Transaction.outstanding` (NOPAGO): capture flag on `POST /billing`, `?outstanding=` list filter, `POST /billing/:id/resolve-outstanding` (gated `ledger:create`, not `ledger:void` — resolving *completes* a capture), and exclusion from every balance aggregate exactly as the legacy `SALDOS ULTIMO 0`'s `HAVING NOPAGO = 0` did. Adds `POST /billing/batch` (one `$transaction`, check-level fields shared, per-line customer/amount) and `GET /billing/by-check`, plus the `cheque-count` report replacing `REPORTE CHEQUE COUNT` / `REPORTE POR CHEQUE` / `EDITA CHEQUE ALF|COUNT|NUM` — print/PDF/CSV/XLSX come free from the existing `/reportes/:slug` machinery. Web: `/estado-cuenta/lote` (the actual "Editor" screen, with live reconciliation against the physical check amount), plus an "Estado de pago" filter, a "sin fondos" row tag and a Resolver dialog on `/estado-cuenta`. No new abilities. Verified end-to-end against dev, API + browser.
|
||||
**Two pre-existing bugs found and fixed while building it:** (a) `statement()` filtered `legacySourceTable: { notIn: [...] }`, which compiles to SQL `NOT IN` — and `NULL NOT IN (…)` is NULL, so **every app-captured movement was invisible on the customer statement** (438 rows in the movement browser vs 392 on the statement) while still appearing everywhere else. This would have made the whole receipt-capture feature look broken to staff. Now NULL-safe. (b) The balances *count* query omitted the void filter its own page query applied, so the row count disagreed with the rows.
|
||||
**OCR seam:** `BillingService.createBatch(dto, opts)` is the single multi-row write path and carries three contract guarantees for the step-11 OCR module to post through — `items[i]` maps to `lines[i]` (so `StatementDocument.postedTransactionId` can be zipped back on), `opts.refs[i]` stamps `captureRef` with a duplicate-post guard that a *voided* row deliberately does not block, and `opts.source` is service-level only so an HTTP client cannot label hand-keyed rows as machine-captured. Backed by a new `TransactionCaptureSource` enum (MANUAL/BATCH/OCR) + `captureRef`, both nullable so the 40,136 migrated rows stay NULL rather than being mislabelled.
|
||||
- **PDF/OCR auto-capture** — ingest→split→OCR→match→review pipeline for the 300+/month/service-provider statements staff currently key in by hand. Posts through the capture module above. Matching logic was checked field-by-field against `migration/transform_properties.py`'s actual output and found three real gaps to close first: no `TELEPHONE` service kind exists yet, `PROPERTY_TAX.accountNumber` was migrated from `PREDIAL` not `CLAVE` (needs verification against a real predial statement), and `GAS.meterNumber` was never populated by the migration at all.
|
||||
- **Multi-bank chequera — DONE** (2026-07-27). `Bank`/`BankAccount` models so Seguros (US bank) and Utilities (Mexican bank, currently SCOTHIA) can each have their own register. `bank_transactions` gained a **required** `bankAccountId` (plus an `(bankAccountId, transactionDate)` index, since every read is now filtered by account and ordered by date), and all 22,669 existing rows were backfilled onto a seeded "Utilities — Scotiabank (MXN)" account by `migration/backfill_bank_accounts.py` — a standalone step because `prisma db push` cannot add a required column to a populated table. It is idempotent and now runs inside `run_all.py` (both normal and `--sync`) ahead of `transform_bank.py`, which fails fast if the account is missing. Every read path in `bank.service.ts` is account-scoped, including `facets()` (which had no filter at all) and *both* raw-SQL rollups in `summary()`. API: `?bankAccountId=` is required on `list`/`stats`/`facets`/`summary` — **not** optional-with-an-all-accounts-default, since summing an MXN and a USD register repeats exactly the currency-collapsing mistake the billing module exists to prevent — plus a new `bank/accounts` + `bank/banks` sub-resource under a MANAGER `bank:manage-accounts` ability. Web: `/banco` gained an account picker (remembered per browser) and reads every figure in the selected account's currency, `/banco/cuentas` manages banks and accounts, and `/inicio`'s chequera card names the account it is showing instead of implying one register. An account's `currency` is immutable after creation by design — its booked movements are denominated in it. Verified against dev + browser: a second USD account showed full read/write isolation from the MXN register, whose totals were unchanged.
|
||||
- **Customer-number recycling** — promotes the legacy `NUM id` (currently only inside `customer_legacy_refs`) into a first-class, reusable `Customer.customerNumber`, automates *finding* candidates for reuse (cancelled / 1-year-inactive), and auto-assigns the lowest free number at creation — the search is automated, the release/reuse decision stays a human action. Backfill needs care: ~140 utilities rows and all insurance-only customers have no real legacy number (synthetic `rownum_N`/`insrow_N` placeholders in `transform_customers.py`, not real `NUM id`s).
|
||||
|
||||
Several open questions block parts of this (OCR provider/budget, the Seguros bank's identity, the clave-catastral-vs-predial mismatch, exact recycling triggers, and whether "recycling" should ever mean true data purge vs. archive-and-reuse-the-number) — see the spec's collected open-questions section.
|
||||
12. **Insurance features — NOT STARTED, spec written.** Full design in [`docs/INSURANCE_FEATURES_SPEC.md`](docs/INSURANCE_FEATURES_SPEC.md), the insurance half of the same 2026-07-25/26 meeting with Jorge that produced step 11:
|
||||
- **Renewal notification emails** — a daily `@nestjs/schedule` sweep that mails the customer 30 days before expiry, 15 days before, and 7 days after, mapping onto `RenewalNotice.generation` 1/2/3 with **no schema change**. Sending is **Amazon SES** (`@aws-sdk/client-sesv2`, mirroring `StorageService`'s optional-client/degrade-don't-crash pattern) — the office already runs SES, so provider and budget are settled, not open. The letter body is the *existing* `aviso-renovacion` report (`reports.registry.ts:623-799`); `@@unique([policyId, generation])` is already-in-place idempotency, so a re-run cannot double-send. Volume ≈260 mails/month, and **815 of the 893 policyholders (91%) have an email**. Also adds the manual mark-as-sent mutation the report's own comment anticipates, so the report's permanently-zero `enviadas` total becomes real. Smallest useful piece — do first.
|
||||
- **Liquidación batch workflow** — ~70% already built (`liquidated`/`liquidationNumber`/`liquidationDate` are wired through DTOs, list filter, stats, form and detail page); only the *batch* print-and-mark step is missing, against a live pending set of 226 policies. Adds a ramo-parameterized pending report plus `POST /policies/liquidate-batch` under a new MANAGER `policy:liquidate` ability. Parameterized by ramo, not MULT-only — legacy `TABLA LIQUIDA MF` served `MULT`, `INCENDIO` and `M EMPR` alike.
|
||||
- **Certificate / "Solicitud Atlas"** — renders from the same `format: "letter"` machinery `aviso-renovacion` uses, then reaches customers as an extension of the step-8/9 replication (PDF generated here, pushed to MinIO, pointer replicated), **not** as a new public surface in this repo. Half-blocked: "Solicitud" has zero referent in the legacy system and normally means an *application form*, a different artifact from a certificate.
|
||||
- **Carrier API integration (ANA Seguros + GMX)** — shape only (`CarrierConnector` + an import-review queue rather than direct `Policy` writes, matching how step 11's OCR results are routed). Carrier research done 2026-07-27: **the two carriers are one company** — both belong to **Grupo Valore** (ANA writes autos, GMX writes daños, which is exactly this database's `AUTO`/`LICENCIAS` vs `MULT`/`INCENDIO`/`M_EMPR` split), so it is one commercial relationship, not two. **ANA has a real live SOAP service** (`server.anaseguros.com.mx/ananetws/service.asmx`, ASP.NET `.asmx`) with a published operation list — catalogs, `CalculaValor`/`CalculaMSI`, `ValidaSerie`, `RecuperaCotizacion`, `Transaccion`. **GMX publishes no machine interface at all**, only human agent portals. ⚠️ **Critical mismatch:** every ANA operation serves *new-business quoting/issuance*, not "list the policies where I am agent of record" — so if the ask is inbound portfolio sync, no evidence exists that either carrier sells it. Blocked on one phone call to Grupo Valore ((55) 5480-4000) for credentials + a direction answer, not on further research. ("GDMX" in the meeting notes was a typo for `GMX` — confirmed 2026-07-27.)
|
||||
|
||||
**Two pre-existing defects were found while verifying this spec and should be fixed as part of the liquidación work:** (a) `policy_types` is missing its `INCENDIO` and `M_EMPR` rows and, because `policies_policyTypeId_fkey` is `ON DELETE SET NULL`, 5 `m_empr` policies silently lost their ramo — 4 of them are pending liquidación and are invisible to every ramo-filtered query; (b) the legacy settlement slots don't match what the target model assumed — `MULT`/`INCENDIO` carry two and `M EMPR` carries four, while `Policy` collapses to one, so ≤41 MULT second settlements were dropped in migration. Spec recommends moving settlement onto `PolicyPaymentInstallment` rather than adding a second slot.
|
||||
|
||||
**One long-standing open question is closed by this spec:** `DATGRAL.[NUM UTIL]` is authoritative for Utilities↔Seguros reconciliation and **`UTILSEG` must not be used** — its numbers resolve to unrelated people under every reading tested (name match 58/1,024 vs. 298/563 for `NUM UTIL`), and where the two sources overlap they contradict each other on 170 of 218 shared ids. This matters to step 11's customer-number recycling, which touches the same identity space.
|
||||
|
||||
## Status
|
||||
|
||||
@@ -139,6 +157,10 @@ Repo scaffolded at `jorgecuadros-platform/`: npm workspaces, NestJS API with a r
|
||||
|
||||
**Portal live DB now in hand.** `utility_dbo.sql` (1.3 GB, 55 tables) and the portal codebase `my-jorgecuadros-web` (PHP/`mysqli`, Gitea repo, themed classic/modern, ~397 PHP files, core in `scripts/functions.php`) are both on disk — resolving the long-standing "`utility_dbo` schema unknown" blocker. Sync-relevant tables identified: statements/money (`utility_bills`, `accounting`, `email_alert_log`), customer/property (`home_owners`, `home_index`, `condominium`, `management`, `hoa_management`, `trust_assist`), portal-facing policy views (`fm2`/`fm3`/`fmt`, `full_coverage`, `mx_liability`, `usa_liability`), and portal write points (`peticion_gas`, PayPal payments, `notifications_settings`, `verification_codes`). A second dump, `jorgecuadros.sql` (38 MB, 11 tables — `pagos`/`pagosemail`/`PROPANO`/`TRUSTVENCE`/etc.), appears to be an older/partial export, not the portal live DB.
|
||||
|
||||
**Step 11 spec written, not built.** `docs/RECEIPT_CAPTURE_SPEC.md` covers the receipt-capture ("Editor") completion plus the three net-new ops features (OCR auto-capture, multi-bank chequera, customer-number recycling) — see Build sequencing step 11 above for the summary. Written from the 2026-07-25/26 meeting notes and verified against the real migration scripts and current API code, not just designed from the meeting notes alone.
|
||||
|
||||
**Step 12 spec written, not built.** `docs/INSURANCE_FEATURES_SPEC.md` covers the insurance half of the same meeting (renewal emails, liquidación batch, certificate + portal delivery, carrier APIs) — see Build sequencing step 12 above. Verified the same way, plus a live query of the dev DB for the counts it quotes (email coverage, pending liquidación, installment fill rates) and of the staged Parquet for the legacy settlement-slot usage. Two of the four features are much smaller than they sound: the renewal-notice table, its idempotency key and the letter body already exist, and the per-policy liquidación fields are already wired end to end.
|
||||
|
||||
## Decisions (locked)
|
||||
|
||||
- **Stack:** Next.js + NestJS + Prisma + **MySQL** (locked earlier — see engine rationale above).
|
||||
@@ -146,15 +168,43 @@ Repo scaffolded at `jorgecuadros-platform/`: npm workspaces, NestJS API with a r
|
||||
- **i18n:** **Spanish-first** UI — matches the source data and staff usage.
|
||||
- **CI/CD:** **Gitea Actions** on `git.mancinas.io` — build image, push to the git.mancinas.io container registry, deploy to Portainer (mirrors the `portainer-gitea-deploy` pattern already used on this LAN). Jenkins/`git.freakma.com` dropped.
|
||||
- **`utility_dbo`:** resolved — full dump + portal code available (see Status).
|
||||
- **Phase B Access additive sync:** implemented in `migration/run_all.py --sync` and the admin
|
||||
`SYNC` job. It preserves manual rows and stable legacy-owned primary keys; end-to-end database
|
||||
validation remains before production use.
|
||||
|
||||
## Open items (ops, not design)
|
||||
|
||||
- **VPS provisioning:** provider (Hetzner vs DigitalOcean), size, and Tailscale + MySQL replica setup on it — an ops task, still pending. Design is settled; only the box is missing.
|
||||
- **Old external-DB credential** (hardcoded plaintext MySQL password in the old repo's `dbConnection.php`, in git history) — rotate it regardless, since it's already exposed.
|
||||
|
||||
## Open design questions (steps 11 & 12 — need Jorge before/while building)
|
||||
|
||||
Unlike the ops items above, these block design decisions, not just infrastructure. Full detail in each section of `docs/RECEIPT_CAPTURE_SPEC.md` (step 11) and `docs/INSURANCE_FEATURES_SPEC.md` (step 12):
|
||||
|
||||
**Step 11 — utilities/ops side:**
|
||||
|
||||
- OCR provider/budget for the statement auto-capture pipeline (self-hosted vs. a paid per-page API, given 300+ statements/month/service provider).
|
||||
- Whether `PROPERTY_TAX.accountNumber` (migrated from `DATMEX.PREDIAL`) is actually the same number as "Clave Catastral" (`DATMEX.CLAVE`) — blocks OCR matching for predial statements until confirmed against a real bill.
|
||||
- The actual bank name/currency/details for the Seguros USD account, and whether any historical Seguros bank register exists to migrate. (Multi-bank support itself is **built** — this is now only the missing content: staff can open the account in `/banco/cuentas` the moment the answer arrives, and it starts empty unless a historical register turns up.)
|
||||
- The exact "1 year inactivity" / "cancelled" triggers for customer-number recycling eligibility.
|
||||
- Whether customer-number recycling should ever include true PII purge (matching the office's paper-world habit) or archive-and-reuse-the-number is sufficient — recommended default is archive-only, consistent with this project's existing never-hard-delete convention.
|
||||
|
||||
**Step 12 — insurance side:**
|
||||
|
||||
- Which SES region + verified sending identity/configuration set the renewal mail goes out under, and whether it reuses the existing IAM credentials or gets its own scoped `ses:SendEmail` user. (Provider and budget are *not* open — SES is settled.)
|
||||
- What to do with the 78 policyholders who have no email on file: skip silently, or produce a print worklist? Recommended: the worklist, since `aviso-renovacion` already renders exactly those letters.
|
||||
- Whether renewal notices go out in Spanish or English — `Customer` carries no language preference.
|
||||
- What "garantías" refers to — it has zero referent in the legacy data, and it blocks the liquidación batch's exclusion filter.
|
||||
- Whether policy settlement should move onto `PolicyPaymentInstallment` (recommended) or gain a second slot on `Policy`, and whether to backfill the ≤41 MULT second settlements lost in migration.
|
||||
- Whether batch liquidación warrants a new MANAGER-level `policy:liquidate` ability (recommended) or should reuse the existing STAFF-level `policy:update`.
|
||||
- **What "Solicitud Atlas" actually is** — an application form or a certificate. These are different artifacts with different data and timing; this blocks the whole certificate feature.
|
||||
- **Carrier integration direction** — outbound quote/issue (which ANA's SOAP service supports today) or inbound sync of the office's existing book (which nothing found suggests either carrier offers)? This decides whether the feature is buildable at all. Bundle with the other three carrier questions into one call to Grupo Valore ((55) 5480-4000): WSDL + credentials for the ANA service, whether a cartera/portfolio download exists for an agent's own book, whether GMX daños has any machine interface, and whether one credential spans both carriers. ("GDMX" is resolved — it was a typo for `GMX`.)
|
||||
|
||||
## Verification
|
||||
|
||||
- Migration: automated row-count/sum reconciliation between `staging` and final schema per table group (see step 5 above), run as part of the migration script, not a manual spot-check.
|
||||
- App: standard NestJS unit/integration tests per module (auth guards, Prisma queries), Playwright/Cypress e2e for the core "look up a customer, see their unified policies + services + statement" flow — the thing the whole project exists to deliver.
|
||||
- Sync: once the VPS replica and inbox tables exist, verify replication lag stays low (a few seconds to low minutes) and that a payment/propane submission on the portal reliably shows up in the internal app within one polling interval, before relying on it operationally.
|
||||
- **Sync:** Phase B Access additive sync now has automated CLI/admin wiring, but must be verified
|
||||
against a disposable DB with stable-PK, manual-row, update, and source-delete cases. The
|
||||
separate VPS/portal sync still requires VPS provisioning and inbox-table implementation.
|
||||
- Before cutover: run the new app against migrated data side-by-side with the live Access files for a period, comparing balances/statements for a sample of active customers to catch migration logic errors before the Access files are retired.
|
||||
|
||||
@@ -0,0 +1,204 @@
|
||||
# Jorge Cuadros & Asociados — Platform
|
||||
|
||||
Internal platform for a Baja California insurance brokerage and property-services
|
||||
firm: a single expedient joining each client's **properties/services**,
|
||||
**insurance policies**, **account statement**, and the firm's **checkbook**.
|
||||
It replaces a legacy PHP/Access app (see `RESUME.md` and `PLAN.md` for the full
|
||||
history and rebuild rationale).
|
||||
|
||||
The UI is Spanish-first; the codebase and this document are in English.
|
||||
|
||||
---
|
||||
|
||||
## Stack
|
||||
|
||||
| Layer | Tech | Port |
|
||||
| --------- | -------------------------------------------------------------- | ---- |
|
||||
| Web | Next.js 14 (App Router, React 18) | 3000 |
|
||||
| API | NestJS 10 · Passport local + `express-session` · Argon2 | 3001 |
|
||||
| Database | MySQL 8 via Prisma 5 (`@jorgecuadros/database` workspace pkg) | 3306 |
|
||||
| Migration | Python 3 pipeline (legacy Access → staging → transforms) | — |
|
||||
|
||||
Monorepo managed with **pnpm workspaces**. Node **>= 20**.
|
||||
|
||||
---
|
||||
|
||||
## Repository layout
|
||||
|
||||
```
|
||||
apps/
|
||||
web/ Next.js frontend (@jorgecuadros/web)
|
||||
api/ NestJS backend (@jorgecuadros/api)
|
||||
scripts/seed-user.mjs idempotent admin seeder
|
||||
packages/
|
||||
database/ Prisma schema + generated client (@jorgecuadros/database)
|
||||
prisma/schema.prisma
|
||||
migration/ One-off Python ETL from the legacy Access DB (run_all.py)
|
||||
docker/ Dockerfiles for api + web
|
||||
docker-compose.yml mysql + api + web
|
||||
.env.example copy to .env
|
||||
```
|
||||
|
||||
API feature modules: `auth`, `users`, `customers`, `policies`, `properties`,
|
||||
`billing`, `bank`. Web routes: `/clientes`, `/polizas`, `/servicios`,
|
||||
`/estado-cuenta`, `/banco` (chequera), `/catalogos`, `/usuarios`, `/login`.
|
||||
|
||||
---
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Node.js >= 20 and **pnpm** (`npm i -g pnpm`)
|
||||
- Docker (for MySQL, or bring your own MySQL 8)
|
||||
- Python 3 — only if you run the legacy data migration
|
||||
|
||||
---
|
||||
|
||||
## Run it locally (development)
|
||||
|
||||
### 1. Install
|
||||
|
||||
```bash
|
||||
pnpm install
|
||||
```
|
||||
|
||||
pnpm blocks postinstall build scripts by default; the trusted ones
|
||||
(`argon2`, `prisma`, `@prisma/client`, `@prisma/engines`, `@nestjs/core`) are
|
||||
allowlisted in `pnpm-workspace.yaml`, so the native builds run automatically.
|
||||
|
||||
### 2. Configure environment
|
||||
|
||||
```bash
|
||||
cp .env.example .env
|
||||
```
|
||||
|
||||
Then edit `.env`. For the Docker MySQL below the defaults already line up;
|
||||
just set a real `SESSION_SECRET`:
|
||||
|
||||
```env
|
||||
DATABASE_URL=mysql://jorgecuadros:jorgecuadros@localhost:3306/jorgecuadros
|
||||
SESSION_SECRET=<any long random string>
|
||||
WEB_ORIGIN=http://localhost:3000
|
||||
NEXT_PUBLIC_API_ORIGIN=http://localhost:3001
|
||||
```
|
||||
|
||||
The API loads `DATABASE_URL`, `SESSION_SECRET`, `WEB_ORIGIN`, and optional
|
||||
`PORT` (default `3001`). The web app only needs `NEXT_PUBLIC_API_ORIGIN`.
|
||||
|
||||
### 3. Start MySQL
|
||||
|
||||
```bash
|
||||
docker compose up -d mysql
|
||||
```
|
||||
|
||||
(Or point `DATABASE_URL` at an existing MySQL 8 instance.)
|
||||
|
||||
### 4. Create the schema + generate the Prisma client
|
||||
|
||||
The schema is managed with `prisma db push` (no migration history committed):
|
||||
|
||||
```bash
|
||||
pnpm --filter @jorgecuadros/database exec prisma db push
|
||||
pnpm --filter @jorgecuadros/database generate
|
||||
```
|
||||
|
||||
### 5. Seed a sign-in user
|
||||
|
||||
```bash
|
||||
node apps/api/scripts/seed-user.mjs
|
||||
```
|
||||
|
||||
Idempotent (upsert by email). Defaults — override with `SEED_EMAIL`,
|
||||
`SEED_PASSWORD`, `SEED_NAME`:
|
||||
|
||||
- email: `admin@jorgecuadros.local`
|
||||
- password: `ChangeMe!2026`
|
||||
- role: `ADMIN`
|
||||
|
||||
### 6. Run the apps (two terminals)
|
||||
|
||||
```bash
|
||||
# API → http://localhost:3001
|
||||
pnpm --filter @jorgecuadros/api start:dev
|
||||
|
||||
# Web → http://localhost:3000
|
||||
pnpm --filter @jorgecuadros/web dev
|
||||
```
|
||||
|
||||
Root shortcuts also exist: `pnpm dev:api`, `pnpm dev:web`.
|
||||
|
||||
### 7. Log in
|
||||
|
||||
Open http://localhost:3000, sign in with the seeded credentials.
|
||||
Sessions are cookie-based and last 8 hours.
|
||||
|
||||
---
|
||||
|
||||
## Run it with Docker (full stack)
|
||||
|
||||
Builds MySQL + API + web from `docker-compose.yml`:
|
||||
|
||||
```bash
|
||||
export SESSION_SECRET=$(openssl rand -hex 32)
|
||||
docker compose up --build
|
||||
```
|
||||
|
||||
Web on http://localhost:3000, API on http://localhost:3001. `SESSION_SECRET`
|
||||
is required (compose fails without it). After first boot, push the schema and
|
||||
seed a user against the container DB:
|
||||
|
||||
```bash
|
||||
docker compose exec api node apps/api/scripts/seed-user.mjs
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Common commands
|
||||
|
||||
| Task | Command |
|
||||
| ------------------------ | -------------------------------------------------------------- |
|
||||
| Install | `pnpm install` |
|
||||
| Dev — API | `pnpm dev:api` |
|
||||
| Dev — Web | `pnpm dev:web` |
|
||||
| Build all | `pnpm build` |
|
||||
| Generate Prisma client | `pnpm prisma:generate` |
|
||||
| Push schema (dev) | `pnpm --filter @jorgecuadros/database exec prisma db push` |
|
||||
| Prisma Studio | `pnpm prisma:studio` |
|
||||
| API tests | `pnpm --filter @jorgecuadros/api test` |
|
||||
| Lint (web / api) | `pnpm --filter @jorgecuadros/web lint` · `... /api lint` |
|
||||
| Seed admin user | `node apps/api/scripts/seed-user.mjs` |
|
||||
|
||||
---
|
||||
|
||||
## Auth & roles
|
||||
|
||||
Session auth via Passport local strategy; passwords hashed with Argon2 (no
|
||||
plaintext, unlike the legacy app). Roles gate the UI and API — e.g. managing
|
||||
`/catalogos` and `/usuarios` requires the appropriate ability (`ADMIN` /
|
||||
`MANAGER`). New users are created by an admin in `/usuarios`; the first admin
|
||||
comes from the seed script above.
|
||||
|
||||
---
|
||||
|
||||
## Legacy data migration (optional)
|
||||
|
||||
`migration/` holds the one-off Python ETL that lifts data out of the old
|
||||
Microsoft Access database into MySQL.
|
||||
|
||||
```bash
|
||||
pip install -r migration/requirements.txt
|
||||
python migration/run_all.py
|
||||
```
|
||||
|
||||
> ⚠️ `run_all.py` truncates and reloads **all** downstream tables. Never run an
|
||||
> individual `transform_*.py` in isolation — it orphans dependent tables. See
|
||||
> `migration/RECONCILIATION.md` for details.
|
||||
|
||||
---
|
||||
|
||||
## Production notes
|
||||
|
||||
- Use `pnpm --filter @jorgecuadros/database exec prisma migrate deploy` if/when
|
||||
a committed migration history is adopted; today dev uses `db push`.
|
||||
- Set a strong `SESSION_SECRET` and a locked-down `DATABASE_URL`.
|
||||
- The API expects `WEB_ORIGIN` to match the browser origin for session cookies.
|
||||
- Documents are stored in MinIO in the deployed environment (see `RESUME.md`).
|
||||
@@ -127,8 +127,14 @@ To rerun (from `migration/`, venv at `migration/.venv`):
|
||||
```bash
|
||||
./.venv/bin/python load_staging.py --output-dir ./output # re-extract from Access (needs mdbtools + the source files)
|
||||
./.venv/bin/python run_all.py --env dev # full transform+load; add --stage to re-extract first
|
||||
./.venv/bin/python run_all.py --env dev --sync # additive sync: upsert legacy by provenance, keep manual rows, prune legacy empties
|
||||
```
|
||||
|
||||
`--sync` mode (Phase B) upserts legacy-owned rows by their provenance keys and preserves
|
||||
manual rows (`legacyId IS NULL`); every transform reuses each row's existing PK, rebuilds
|
||||
legacy-owned children by scoped delete + reinsert, and drops legacy rows gone from source.
|
||||
Verified end-to-end against dev 2026-07-24 — see §6 item 6.
|
||||
|
||||
## 5. Infrastructure & sync architecture (designed, not yet built)
|
||||
|
||||
- **Internal server** — on-prem, private IP `192.168.1.xx`, no inbound internet exposure. Runs the platform + canonical MySQL (source of truth).
|
||||
@@ -162,6 +168,30 @@ the reconciliation pass (done, then corrected) are all closed. See §3 and §8.
|
||||
5. **`TRASPASOS PAYPAL` is a clearing account, not a customer** — carries -7.03M MXN over
|
||||
309 movements and therefore tops the adeudo worklist. Deliberately not special-cased in
|
||||
code; needs a business decision on how to model it.
|
||||
6. **DB Operations — Phase B (additive sync) — VERIFIED END-TO-END against dev DB 2026-07-24.**
|
||||
Phase A provides the admin-only `/operaciones` page + `ops` API module (ability `db:manage`,
|
||||
ADMIN), ingest folder, backup, restore, and destructive re-import. Phase B enables `SYNC`:
|
||||
`OpsService` creates a safety backup and runs `run_all.py --sync`; transforms upsert
|
||||
legacy-owned rows by provenance keys while preserving existing PKs and rows whose
|
||||
`legacyId IS NULL` (manual). Prisma enforces provenance uniqueness for properties, policies,
|
||||
transactions, and bank transactions (the vehicle unique was **removed** — one legacy policy
|
||||
row carries up to 3 vehicles that share a `legacyId`, so provenance is not unique per
|
||||
vehicle; vehicles are rebuilt by scoped delete + reinsert). Sync skips blob extraction, and
|
||||
runs a **manual-safe prune** (`prune_empty_customers.py --sync` — only prunes empties that
|
||||
carry a legacy ref, never manually-added customers) because the customer upsert otherwise
|
||||
re-creates every previously-pruned empty from Parquet.
|
||||
|
||||
**The as-written sync was broken and had never been run; a batch of bugs were fixed on
|
||||
2026-07-24 before it passed** (fresh-uuid child FKs in policies/properties, unconditional
|
||||
child inserts, a `zip(customers, refs)` mispairing in transform_customers, invalid vehicle
|
||||
unique, lookup tables built with fresh uuids but never upserted, a `updatedAt=NOW()` on a
|
||||
table with no such column, and report crashes on NULL `legacySourceTable` for manual rows).
|
||||
Verified with `migration/` `verify_sync.py`-style harness: two consecutive `run_all.py --sync`
|
||||
runs both exit 0 and pass 32/32 assertions (stable PKs, manual-row preservation, changed-row
|
||||
updates, legacy-delete, no child duplication, zero FK orphans), idempotent (customers stable
|
||||
at 1537). Schema pushed to dev, Prisma client regenerated, API build clean. Migration/web
|
||||
changes uncommitted as of this update. Still open before production: run the same sync from
|
||||
the `/operaciones` UI (OpsService path) and against a prod-shaped DB.
|
||||
|
||||
## 7. Environment notes (current macOS machine)
|
||||
|
||||
@@ -170,9 +200,12 @@ the reconciliation pass (done, then corrected) are all closed. See §3 and §8.
|
||||
- **`npm` is pnpm-aliased**, and pnpm ignores the `workspaces` field. Consequences:
|
||||
- there is **no root `node_modules/.bin`**. Binaries live per-app: `apps/api/node_modules/.bin/nest`, `apps/web/node_modules/.bin/next`.
|
||||
- Prisma CLI is run as `npx prisma@5`.
|
||||
- **Dev servers** (both must be up to use the UI):
|
||||
- API `cd apps/api && ./node_modules/.bin/nest start --watch` → `:3001`
|
||||
- Web `cd apps/web && ./node_modules/.bin/next dev` → `:3000`
|
||||
- **Dev servers** (both must be up to use the UI). ⚠️ **Ports come from the env files, not the
|
||||
framework defaults** — `apps/api/.env` sets `PORT=4501` and `WEB_ORIGIN=http://localhost:4500`,
|
||||
and `apps/web/.env.local` points at `NEXT_PUBLIC_API_ORIGIN=http://localhost:4501`. This doc
|
||||
said `:3001`/`:3000` until 2026-07-27; that was wrong and cost a debugging detour.
|
||||
- API `cd apps/api && ./node_modules/.bin/nest start --watch` → **`:4501`**
|
||||
- Web `cd apps/web && ./node_modules/.bin/next dev -p 4500` → **`:4500`**
|
||||
- Dev login: `admin@jorgecuadros.local`, password from `apps/api/scripts/seed-user.mjs` (`SEED_PASSWORD` env overrides the default).
|
||||
- **Dev DB**: `192.168.4.212:3307` (cubex Swarm stack `jorgecuadros-dev-db`). Credentials in gitignored `deploy/.env.dev`. **MinIO** for documents: `192.168.4.212:9100`, bucket `jorgecuadros-documents`.
|
||||
|
||||
@@ -348,9 +381,18 @@ for what's actually next.
|
||||
insurance/servicios/fideicomiso split the migration comment implied. A
|
||||
classifier would invent data, so `categoryId` stays null and the module does
|
||||
not filter on it. Register is browsable by date/payee/amount/cheque instead.
|
||||
(c) **Single currency (MXN).** `bank_transactions` has no currency column and
|
||||
every `amountInWords` is spelled out in PESOS — so, unlike the customer
|
||||
ledger, everything here is one currency and not split per-currency.
|
||||
(c) ~~**Single currency (MXN).**~~ **SUPERSEDED 2026-07-27 by the multi-bank
|
||||
chequera** (step 11, `docs/RECEIPT_CAPTURE_SPEC.md` §3). The office keeps
|
||||
more than one register, so `bank_transactions` now carries a **required**
|
||||
`bankAccountId` and every read in the module is scoped to exactly one
|
||||
`BankAccount`, whose `currency` the movements inherit — there is still no
|
||||
currency column on the movement itself, because a real bank account doesn't
|
||||
mix currencies. All 22,669 migrated rows are the Utilities/Scotiabank MXN
|
||||
account (backfilled by `migration/backfill_bank_accounts.py`, which
|
||||
`run_all.py` runs before `transform_bank.py`), which is why every
|
||||
`amountInWords` is still spelled out in PESOS. There is deliberately no
|
||||
"all accounts" option: summing an MXN and a USD register would repeat the
|
||||
currency-collapsing mistake the billing module warns against.
|
||||
(d) **The "acumulado" is net movement since the register opened, not a bank
|
||||
balance** — SCOTHIA carries no opening balance (its `ban` table holds only the
|
||||
bank's name), so the running total starts at 0 in 2013. Labelled as such in
|
||||
@@ -358,9 +400,18 @@ for what's actually next.
|
||||
(e) Sign convention (from `transform_bank.py`): positive = ingreso,
|
||||
negative = egreso, exactly zero = a cancelled/void cheque (787 of 791 say
|
||||
CANCELADO/VOID) — voids are excluded from both the income and expense sides.
|
||||
(f) **Multi-account since 2026-07-27.** `/banco` opens on an account picker
|
||||
(the last account is remembered per browser) and reads every figure in that
|
||||
account's currency; `/banco/cuentas` manages banks and accounts under a new
|
||||
MANAGER `bank:manage-accounts` ability. Accounts are never deleted — the
|
||||
`bankAccountId` FK is required, so a used account can only be *closed*
|
||||
(`active: false`), which hides it from new captures but keeps its history
|
||||
readable. An account's currency is immutable after creation, since its
|
||||
booked movements are denominated in it.
|
||||
- Full pipeline reproducible in one command: `run_all.py --env <env>` runs customers →
|
||||
properties → policies → transactions → prune → bank → blobs in order (all idempotent);
|
||||
add `--stage` to re-extract from the Access files first. Verified end-to-end against dev.
|
||||
properties → policies → transactions → prune → bank accounts → bank → blobs in order
|
||||
(all idempotent); add `--stage` to re-extract from the Access files first. Verified
|
||||
end-to-end against dev.
|
||||
|
||||
5. **Infra** — **DONE.** Dev MySQL deployed to the cubex Swarm via the Portainer API as stack
|
||||
`jorgecuadros-dev-db` (MySQL 8.4, `192.168.4.212:3307`, node `cubex` labeled
|
||||
@@ -374,12 +425,20 @@ for what's actually next.
|
||||
|
||||
---
|
||||
|
||||
⏭ **NEXT — where to pick up:**
|
||||
|
||||
- **Plan step 8–9: VPS + sync worker.** Blocked on VPS provisioning (§6.1) — the only real
|
||||
external dependency left. Pure ops: provider, size, Tailscale, MySQL replica.
|
||||
- **Plan step 10: reports / email campaigns / admin.**
|
||||
- **Sync implementation — DONE + VALIDATED end-to-end against dev 2026-07-24.** `run_all.py
|
||||
--sync` performs the non-destructive legacy upsert path for customers, properties, policies,
|
||||
transactions, and bank rows, plus a manual-safe empty-customer prune. It preserves manual rows
|
||||
and stable legacy-owned primary keys; the admin SYNC job auto-creates a pre-sync backup. The
|
||||
as-written code was broken and had never been run — a batch of bugs was fixed before it passed
|
||||
(see §6 item 6). Two consecutive syncs both exit 0 and pass 32/32 assertions (added, changed,
|
||||
removed, and manually-created rows), idempotent. Remaining: exercise the same path from the
|
||||
`/operaciones` admin UI and against a prod-shaped DB.
|
||||
- **Plan step 9: portal sync worker** remains separate and blocked on VPS provisioning. This
|
||||
Phase B feature synchronizes Access source files into the internal platform; it does not yet
|
||||
poll `utility_dbo` inbox tables or replicate portal-facing data to a VPS.
|
||||
- **Small / open:** (a) `TRASPASOS PAYPAL` clearing account still tops the adeudo worklist
|
||||
(§6.4d) — a business modelling call, not code. (b) Credential rotation on the old repo's
|
||||
exposed MySQL password. (c) The `/estado-cuenta` browser visual pass — `/banco` was verified
|
||||
in-browser this session; `/estado-cuenta` still worth a look.
|
||||
exposed MySQL password. (c) ~~The `/estado-cuenta` browser visual pass.~~ **DONE 2026-07-24** —
|
||||
verified vs dev: Anular buttons admin-gated, voided rows struck + excluded from totals,
|
||||
clicking Anular voids end-to-end (note: it uses a blocking `window.confirm`). Customer-detail
|
||||
mini tx list now also strikes voided rows ("(anulado)" tag) — was the last void-UI gap.
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 110 KiB |
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "@jorgecuadros/api",
|
||||
"version": "0.1.0",
|
||||
"version": "1.0.1",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "nest build",
|
||||
@@ -11,6 +11,7 @@
|
||||
"test": "jest"
|
||||
},
|
||||
"dependencies": {
|
||||
"@aws-sdk/client-s3": "^3.665.0",
|
||||
"@jorgecuadros/database": "workspace:*",
|
||||
"@nestjs/common": "^10.4.4",
|
||||
"@nestjs/config": "^3.3.0",
|
||||
@@ -20,7 +21,9 @@
|
||||
"argon2": "^0.41.1",
|
||||
"class-transformer": "^0.5.1",
|
||||
"class-validator": "^0.14.1",
|
||||
"exceljs": "^4.4.0",
|
||||
"express-session": "^1.18.0",
|
||||
"pdfkit": "^0.15.1",
|
||||
"passport": "^0.7.0",
|
||||
"passport-local": "^1.0.0",
|
||||
"reflect-metadata": "^0.2.2",
|
||||
@@ -31,6 +34,7 @@
|
||||
"@nestjs/testing": "^10.4.4",
|
||||
"@types/express": "^4.17.21",
|
||||
"@types/express-session": "^1.18.0",
|
||||
"@types/pdfkit": "^0.13.5",
|
||||
"@types/jest": "^29.5.13",
|
||||
"@types/node": "^20.16.11",
|
||||
"@types/passport": "^1.0.17",
|
||||
|
||||
@@ -6,4 +6,25 @@ export class AppController {
|
||||
health() {
|
||||
return { status: "ok" };
|
||||
}
|
||||
|
||||
/**
|
||||
* What is actually running. The three values are baked into the image at
|
||||
* build time by .gitea/workflows/build.yml (see docker/api.Dockerfile) and
|
||||
* are the only way to confirm a deploy — or a rollback — landed: the tag you
|
||||
* dispatched and the code inside the container can disagree if a stack was
|
||||
* applied without pulling, or if the app stack still names an older tag.
|
||||
*
|
||||
* Deliberately unauthenticated, same as /health: the deploy workflow has to
|
||||
* read it with no session, and it exposes nothing an attacker could not
|
||||
* already infer from the repo.
|
||||
*/
|
||||
@Get("version")
|
||||
version() {
|
||||
return {
|
||||
service: "api",
|
||||
version: process.env.APP_VERSION ?? "dev",
|
||||
gitSha: process.env.GIT_SHA ?? "unknown",
|
||||
buildDate: process.env.BUILD_DATE ?? "unknown",
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
import { Module } from "@nestjs/common";
|
||||
import { ConfigModule } from "@nestjs/config";
|
||||
import { PrismaModule } from "./prisma/prisma.module";
|
||||
import { StorageModule } from "./storage/storage.module";
|
||||
import { CommonModule } from "./common/common.module";
|
||||
import { UsersModule } from "./users/users.module";
|
||||
import { AuthModule } from "./auth/auth.module";
|
||||
import { CustomersModule } from "./customers/customers.module";
|
||||
@@ -8,12 +10,16 @@ import { PoliciesModule } from "./policies/policies.module";
|
||||
import { PropertiesModule } from "./properties/properties.module";
|
||||
import { BillingModule } from "./billing/billing.module";
|
||||
import { BankModule } from "./bank/bank.module";
|
||||
import { OpsModule } from "./ops/ops.module";
|
||||
import { ReportsModule } from "./reports/reports.module";
|
||||
import { AppController } from "./app.controller";
|
||||
|
||||
@Module({
|
||||
imports: [
|
||||
ConfigModule.forRoot({ isGlobal: true }),
|
||||
PrismaModule,
|
||||
StorageModule,
|
||||
CommonModule,
|
||||
UsersModule,
|
||||
AuthModule,
|
||||
CustomersModule,
|
||||
@@ -21,6 +27,8 @@ import { AppController } from "./app.controller";
|
||||
PropertiesModule,
|
||||
BillingModule,
|
||||
BankModule,
|
||||
OpsModule,
|
||||
ReportsModule,
|
||||
],
|
||||
controllers: [AppController],
|
||||
})
|
||||
|
||||
@@ -0,0 +1,73 @@
|
||||
// Server-authoritative permission matrix. Roles form an ordered rank
|
||||
// (ADMIN > MANAGER > STAFF > VIEWER — this is the "level" concept); every
|
||||
// write action carries a minimum rank. VIEWER holds rank 0 and is the
|
||||
// read-only role. Reads are not listed here — they stay on AuthenticatedGuard
|
||||
// alone, so any logged-in user (including VIEWER) can read.
|
||||
//
|
||||
// This is the single source of truth: the API enforces it via AbilityGuard and
|
||||
// ships the resolved per-user map to the web through /auth/me, so the UI never
|
||||
// keeps its own copy of the rules.
|
||||
|
||||
export type Role = "ADMIN" | "MANAGER" | "STAFF" | "VIEWER";
|
||||
|
||||
export const ROLE_RANK: Record<Role, number> = {
|
||||
VIEWER: 0,
|
||||
STAFF: 1,
|
||||
MANAGER: 2,
|
||||
ADMIN: 3,
|
||||
};
|
||||
|
||||
export type Ability =
|
||||
| "customer:create"
|
||||
| "customer:update"
|
||||
| "customer:delete"
|
||||
| "policy:create"
|
||||
| "policy:update"
|
||||
| "policy:delete"
|
||||
| "property:create"
|
||||
| "property:update"
|
||||
| "property:delete"
|
||||
| "ledger:create"
|
||||
| "ledger:void"
|
||||
| "bank:create"
|
||||
| "bank:void"
|
||||
| "bank:manage-accounts"
|
||||
| "lookup:manage"
|
||||
| "user:manage"
|
||||
| "db:manage";
|
||||
|
||||
/** Minimum role required for each ability. */
|
||||
export const ABILITY_MIN: Record<Ability, Role> = {
|
||||
"customer:create": "STAFF",
|
||||
"customer:update": "STAFF",
|
||||
"customer:delete": "ADMIN",
|
||||
"policy:create": "STAFF",
|
||||
"policy:update": "STAFF",
|
||||
"policy:delete": "MANAGER",
|
||||
"property:create": "STAFF",
|
||||
"property:update": "STAFF",
|
||||
"property:delete": "MANAGER",
|
||||
"ledger:create": "STAFF",
|
||||
"ledger:void": "MANAGER",
|
||||
"bank:create": "STAFF",
|
||||
"bank:void": "MANAGER",
|
||||
// Opening or renaming a chequera is rarer and higher-stakes than posting a
|
||||
// movement into one — a wrong account silently mixes two sets of books.
|
||||
"bank:manage-accounts": "MANAGER",
|
||||
"lookup:manage": "MANAGER",
|
||||
"user:manage": "ADMIN",
|
||||
"db:manage": "ADMIN",
|
||||
};
|
||||
|
||||
export const ALL_ABILITIES = Object.keys(ABILITY_MIN) as Ability[];
|
||||
|
||||
export function can(role: Role, ability: Ability): boolean {
|
||||
return ROLE_RANK[role] >= ROLE_RANK[ABILITY_MIN[ability]];
|
||||
}
|
||||
|
||||
/** Resolved {ability: boolean} map for a role — sent to the web via /auth/me. */
|
||||
export function abilitiesFor(role: Role): Record<Ability, boolean> {
|
||||
return Object.fromEntries(
|
||||
ALL_ABILITIES.map((a) => [a, can(role, a)]),
|
||||
) as Record<Ability, boolean>;
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
import {
|
||||
CanActivate,
|
||||
ExecutionContext,
|
||||
ForbiddenException,
|
||||
Injectable,
|
||||
} from "@nestjs/common";
|
||||
import { Reflector } from "@nestjs/core";
|
||||
import { Request } from "express";
|
||||
import { ABILITY_KEY } from "./require-ability.decorator";
|
||||
import { Ability, Role, can } from "./abilities";
|
||||
|
||||
/**
|
||||
* Enforces the ability matrix (abilities.ts) against req.user.role. A route
|
||||
* with no @RequireAbility passes through untouched — this guard only gates the
|
||||
* routes that declare one. It does NOT check authentication; always list it
|
||||
* after AuthenticatedGuard so an unauthenticated request is rejected first.
|
||||
*/
|
||||
@Injectable()
|
||||
export class AbilityGuard implements CanActivate {
|
||||
constructor(private readonly reflector: Reflector) {}
|
||||
|
||||
canActivate(context: ExecutionContext): boolean {
|
||||
const ability = this.reflector.getAllAndOverride<Ability | undefined>(
|
||||
ABILITY_KEY,
|
||||
[context.getHandler(), context.getClass()],
|
||||
);
|
||||
if (!ability) return true;
|
||||
|
||||
const req = context.switchToHttp().getRequest<Request>();
|
||||
const user = req.user as { role?: Role } | undefined;
|
||||
if (!user?.role || !can(user.role, ability)) {
|
||||
throw new ForbiddenException("No tiene permisos para esta acción");
|
||||
}
|
||||
return true;
|
||||
}
|
||||
}
|
||||
@@ -1,11 +1,33 @@
|
||||
import { Controller, Get, HttpCode, Post, Req, Res, UseGuards } from "@nestjs/common";
|
||||
import {
|
||||
Body,
|
||||
Controller,
|
||||
Get,
|
||||
HttpCode,
|
||||
Patch,
|
||||
Post,
|
||||
Req,
|
||||
Res,
|
||||
UseGuards,
|
||||
} from "@nestjs/common";
|
||||
import { Request, Response } from "express";
|
||||
import { LocalAuthGuard } from "./local-auth.guard";
|
||||
import { AuthenticatedGuard } from "./authenticated.guard";
|
||||
import { LoginDto } from "./login.dto";
|
||||
import { UpdatePreferencesDto } from "./update-preferences.dto";
|
||||
import { abilitiesFor, Role } from "./abilities";
|
||||
import { UsersService } from "../users/users.service";
|
||||
|
||||
/** Attach the resolved ability map so the web can gate its UI off one payload. */
|
||||
function withAbilities(user: unknown) {
|
||||
const u = user as { role?: Role } | undefined;
|
||||
if (!u?.role) return u;
|
||||
return { ...u, abilities: abilitiesFor(u.role) };
|
||||
}
|
||||
|
||||
@Controller("auth")
|
||||
export class AuthController {
|
||||
constructor(private readonly users: UsersService) {}
|
||||
|
||||
// LoginDto is only used for request-shape documentation/validation here —
|
||||
// the actual credential check happens inside LocalStrategy via Passport,
|
||||
// which populates req.user before this handler runs.
|
||||
@@ -13,13 +35,26 @@ export class AuthController {
|
||||
@Post("login")
|
||||
@HttpCode(200)
|
||||
login(@Req() req: Request, @Res({ passthrough: true }) _res: Response, _body?: LoginDto) {
|
||||
return req.user;
|
||||
return withAbilities(req.user);
|
||||
}
|
||||
|
||||
@UseGuards(AuthenticatedGuard)
|
||||
@Get("me")
|
||||
me(@Req() req: Request) {
|
||||
return req.user;
|
||||
return withAbilities(req.user);
|
||||
}
|
||||
|
||||
/**
|
||||
* Update the caller's own UI preferences. Deliberately not on /users/:id —
|
||||
* that controller is ADMIN-only, and this has to work for every role. The
|
||||
* target is always the session's own user id, never a body parameter.
|
||||
*/
|
||||
@UseGuards(AuthenticatedGuard)
|
||||
@Patch("preferences")
|
||||
async updatePreferences(@Req() req: Request, @Body() dto: UpdatePreferencesDto) {
|
||||
const id = (req.user as { id: string }).id;
|
||||
const user = await this.users.updatePreferences(id, dto.uiScale);
|
||||
return withAbilities(user);
|
||||
}
|
||||
|
||||
@Post("logout")
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
import { SetMetadata } from "@nestjs/common";
|
||||
import type { Ability } from "./abilities";
|
||||
|
||||
export const ABILITY_KEY = "required_ability";
|
||||
|
||||
/**
|
||||
* Tags a write route with the ability it requires. Pair with
|
||||
* `@UseGuards(AuthenticatedGuard, AbilityGuard)` — AuthenticatedGuard proves
|
||||
* the session, AbilityGuard checks this ability against the user's role.
|
||||
*/
|
||||
export const RequireAbility = (ability: Ability) =>
|
||||
SetMetadata(ABILITY_KEY, ability);
|
||||
@@ -0,0 +1,17 @@
|
||||
import { IsNumber, Max, Min } from "class-validator";
|
||||
|
||||
/**
|
||||
* Self-service UI preferences — any authenticated user may set these on their
|
||||
* own account, including VIEWER. No ability gate: it changes nothing but how
|
||||
* the app looks to that one person.
|
||||
*
|
||||
* The bounds mirror MIN_UI_SCALE/MAX_UI_SCALE in apps/web/src/lib/ui-scale.ts;
|
||||
* keep them in sync. The API clamps rather than trusting the client because
|
||||
* this endpoint is reachable outside the UI.
|
||||
*/
|
||||
export class UpdatePreferencesDto {
|
||||
@IsNumber()
|
||||
@Min(0.9)
|
||||
@Max(1.5)
|
||||
uiScale!: number;
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
import {
|
||||
IsBoolean,
|
||||
IsIn,
|
||||
IsOptional,
|
||||
IsString,
|
||||
MinLength,
|
||||
} from "class-validator";
|
||||
|
||||
/** Mirrors the Prisma `Currency` enum; a chequera's is fixed at creation. */
|
||||
export const BANK_CURRENCIES = ["MXN", "USD"] as const;
|
||||
export type BankAccountCurrency = (typeof BANK_CURRENCIES)[number];
|
||||
|
||||
/** Mirrors `TransactionDomain`. A soft hint on the account, never enforced. */
|
||||
export const BANK_BUSINESS_LINES = ["UTILITY", "INSURANCE", "TRUST"] as const;
|
||||
export type BankBusinessLine = (typeof BANK_BUSINESS_LINES)[number];
|
||||
|
||||
export class CreateBankDto {
|
||||
@IsString() @MinLength(1) name!: string;
|
||||
/** "MX" | "US" — free text, informational only. */
|
||||
@IsOptional() @IsString() country?: string;
|
||||
}
|
||||
|
||||
export class UpdateBankDto {
|
||||
@IsOptional() @IsString() @MinLength(1) name?: string;
|
||||
@IsOptional() @IsString() country?: string;
|
||||
}
|
||||
|
||||
export class CreateBankAccountDto {
|
||||
@IsString() @MinLength(1) bankId!: string;
|
||||
@IsString() @MinLength(1) label!: string;
|
||||
/**
|
||||
* Immutable after creation (no field for it on the update DTO): every
|
||||
* movement already booked into the account is denominated in it, so
|
||||
* changing it would silently re-denominate history.
|
||||
*/
|
||||
@IsIn(BANK_CURRENCIES) currency!: BankAccountCurrency;
|
||||
@IsOptional() @IsIn(BANK_BUSINESS_LINES) businessLine?: BankBusinessLine;
|
||||
@IsOptional() @IsBoolean() active?: boolean;
|
||||
}
|
||||
|
||||
export class UpdateBankAccountDto {
|
||||
@IsOptional() @IsString() @MinLength(1) bankId?: string;
|
||||
@IsOptional() @IsString() @MinLength(1) label?: string;
|
||||
@IsOptional() @IsIn(BANK_BUSINESS_LINES) businessLine?: BankBusinessLine;
|
||||
/** Closing an account hides it from the picker; its movements stay readable. */
|
||||
@IsOptional() @IsBoolean() active?: boolean;
|
||||
}
|
||||
@@ -0,0 +1,23 @@
|
||||
import { IsBoolean, IsNumber, IsOptional, IsString, MinLength } from "class-validator";
|
||||
|
||||
/**
|
||||
* A new bank-register movement. `amount` is signed: positive = ingreso,
|
||||
* negative = egreso (the module's sign convention). The currency is the
|
||||
* account's, not the movement's — `bankAccountId` decides it.
|
||||
* Booked rows are never edited — a mistake is corrected by voiding + re-capture.
|
||||
*/
|
||||
export class CreateBankMovementDto {
|
||||
/** Which chequera this lands in. Required — see BankAccount in the schema. */
|
||||
@IsString() @MinLength(1) bankAccountId!: string;
|
||||
|
||||
@IsNumber() amount!: number;
|
||||
@IsString() @MinLength(1) transactionDate!: string;
|
||||
|
||||
@IsOptional() @IsString() concept?: string;
|
||||
@IsOptional() @IsString() reference?: string;
|
||||
@IsOptional() @IsString() transactionType?: string;
|
||||
@IsOptional() @IsBoolean() cleared?: boolean;
|
||||
@IsOptional() @IsBoolean() transferred?: boolean;
|
||||
@IsOptional() @IsString() notes?: string;
|
||||
@IsOptional() @IsString() amountInWords?: string;
|
||||
}
|
||||
@@ -1,11 +1,32 @@
|
||||
import { Controller, Get, Query, UseGuards } from "@nestjs/common";
|
||||
import {
|
||||
Body,
|
||||
Controller,
|
||||
Get,
|
||||
Param,
|
||||
Patch,
|
||||
Post,
|
||||
Query,
|
||||
Req,
|
||||
UseGuards,
|
||||
} from "@nestjs/common";
|
||||
import { Request } from "express";
|
||||
import { AuthenticatedGuard } from "../auth/authenticated.guard";
|
||||
import { AbilityGuard } from "../auth/ability.guard";
|
||||
import { RequireAbility } from "../auth/require-ability.decorator";
|
||||
import { AuditService } from "../common/audit.service";
|
||||
import {
|
||||
BankCleared,
|
||||
BankDirection,
|
||||
BankService,
|
||||
BankSort,
|
||||
} from "./bank.service";
|
||||
import { CreateBankMovementDto } from "./bank-movement.dto";
|
||||
import {
|
||||
CreateBankAccountDto,
|
||||
CreateBankDto,
|
||||
UpdateBankAccountDto,
|
||||
UpdateBankDto,
|
||||
} from "./bank-account.dto";
|
||||
|
||||
const DIRECTIONS: BankDirection[] = ["income", "expense", "void"];
|
||||
const CLEARED: BankCleared[] = ["cleared", "pending"];
|
||||
@@ -28,33 +49,120 @@ function parseDate(v: string | undefined, endOfDay = false): Date | undefined {
|
||||
return Number.isNaN(d.getTime()) ? undefined : d;
|
||||
}
|
||||
|
||||
@UseGuards(AuthenticatedGuard)
|
||||
@UseGuards(AuthenticatedGuard, AbilityGuard)
|
||||
@Controller("bank")
|
||||
export class BankController {
|
||||
constructor(private readonly bank: BankService) {}
|
||||
constructor(
|
||||
private readonly bank: BankService,
|
||||
private readonly audit: AuditService,
|
||||
) {}
|
||||
|
||||
private actingId(req: Request): string {
|
||||
return (req.user as { id: string }).id;
|
||||
}
|
||||
|
||||
// --- accounts -------------------------------------------------------------
|
||||
// Declared before the parameterised routes below so `/bank/accounts` can
|
||||
// never be swallowed by a `:id`-shaped path.
|
||||
|
||||
/**
|
||||
* The account picker. Readable by any authenticated user, VIEWER included —
|
||||
* nothing else on this page can render until an account is chosen.
|
||||
*/
|
||||
@Get("accounts")
|
||||
accounts() {
|
||||
return this.bank.listAccounts();
|
||||
}
|
||||
|
||||
@Get("banks")
|
||||
banks() {
|
||||
return this.bank.listBanks();
|
||||
}
|
||||
|
||||
@Post("banks")
|
||||
@RequireAbility("bank:manage-accounts")
|
||||
async createBank(@Body() dto: CreateBankDto, @Req() req: Request) {
|
||||
const row = await this.bank.createBank(dto);
|
||||
void this.audit.log(this.actingId(req), "bank.bank.create", {
|
||||
bankId: row.id,
|
||||
name: row.name,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
|
||||
@Patch("banks/:id")
|
||||
@RequireAbility("bank:manage-accounts")
|
||||
async updateBank(
|
||||
@Param("id") id: string,
|
||||
@Body() dto: UpdateBankDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const row = await this.bank.updateBank(id, dto);
|
||||
void this.audit.log(this.actingId(req), "bank.bank.update", { bankId: id });
|
||||
return row;
|
||||
}
|
||||
|
||||
@Post("accounts")
|
||||
@RequireAbility("bank:manage-accounts")
|
||||
async createAccount(
|
||||
@Body() dto: CreateBankAccountDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const row = await this.bank.createAccount(dto);
|
||||
void this.audit.log(this.actingId(req), "bank.account.create", {
|
||||
bankAccountId: row.id,
|
||||
label: row.label,
|
||||
currency: row.currency,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
|
||||
@Patch("accounts/:id")
|
||||
@RequireAbility("bank:manage-accounts")
|
||||
async updateAccount(
|
||||
@Param("id") id: string,
|
||||
@Body() dto: UpdateBankAccountDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const row = await this.bank.updateAccount(id, dto);
|
||||
void this.audit.log(this.actingId(req), "bank.account.update", {
|
||||
bankAccountId: id,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
|
||||
// --- register reads (all scoped to one account) ---------------------------
|
||||
|
||||
@Get("stats")
|
||||
stats() {
|
||||
return this.bank.stats();
|
||||
async stats(@Query("bankAccountId") bankAccountId?: string) {
|
||||
const account = await this.bank.requireAccount(bankAccountId);
|
||||
return this.bank.stats(account.id);
|
||||
}
|
||||
|
||||
@Get("facets")
|
||||
facets() {
|
||||
return this.bank.facets();
|
||||
async facets(@Query("bankAccountId") bankAccountId?: string) {
|
||||
const account = await this.bank.requireAccount(bankAccountId);
|
||||
return this.bank.facets(account.id);
|
||||
}
|
||||
|
||||
/** Year and month rollups with a running net-movement figure. */
|
||||
@Get("summary")
|
||||
summary(@Query("year") year?: string) {
|
||||
async summary(
|
||||
@Query("bankAccountId") bankAccountId?: string,
|
||||
@Query("year") year?: string,
|
||||
) {
|
||||
const account = await this.bank.requireAccount(bankAccountId);
|
||||
const y = Number(year);
|
||||
return this.bank.summary(
|
||||
account.id,
|
||||
Number.isInteger(y) && y >= 1900 && y <= 2999 ? y : undefined,
|
||||
);
|
||||
}
|
||||
|
||||
/** The register browser. */
|
||||
@Get()
|
||||
list(
|
||||
async list(
|
||||
@Query("bankAccountId") bankAccountId?: string,
|
||||
@Query("query") query?: string,
|
||||
@Query("page") page?: string,
|
||||
@Query("pageSize") pageSize?: string,
|
||||
@@ -64,7 +172,9 @@ export class BankController {
|
||||
@Query("to") to?: string,
|
||||
@Query("sort") sort?: string,
|
||||
) {
|
||||
const account = await this.bank.requireAccount(bankAccountId);
|
||||
return this.bank.list({
|
||||
bankAccountId: account.id,
|
||||
query,
|
||||
page: Math.max(1, Number(page) || 1),
|
||||
pageSize: Math.min(100, Math.max(1, Number(pageSize) || 25)),
|
||||
@@ -75,4 +185,26 @@ export class BankController {
|
||||
sort: one(SORTS, sort) ?? "date_desc",
|
||||
});
|
||||
}
|
||||
|
||||
// --- writes ---------------------------------------------------------------
|
||||
|
||||
@Post()
|
||||
@RequireAbility("bank:create")
|
||||
async create(@Body() dto: CreateBankMovementDto, @Req() req: Request) {
|
||||
const row = await this.bank.createMovement(dto);
|
||||
void this.audit.log(this.actingId(req), "bank.create", {
|
||||
bankTransactionId: row.id,
|
||||
bankAccountId: row.bankAccountId,
|
||||
amount: dto.amount,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
|
||||
@Post(":id/void")
|
||||
@RequireAbility("bank:void")
|
||||
async void(@Param("id") id: string, @Req() req: Request) {
|
||||
const row = await this.bank.voidMovement(id, this.actingId(req));
|
||||
void this.audit.log(this.actingId(req), "bank.void", { bankTransactionId: id });
|
||||
return row;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,6 +1,21 @@
|
||||
import { Injectable } from "@nestjs/common";
|
||||
import { BadRequestException, Injectable, NotFoundException } from "@nestjs/common";
|
||||
import { Prisma } from "@jorgecuadros/database";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
import { CreateBankMovementDto } from "./bank-movement.dto";
|
||||
import {
|
||||
CreateBankAccountDto,
|
||||
CreateBankDto,
|
||||
UpdateBankAccountDto,
|
||||
UpdateBankDto,
|
||||
} from "./bank-account.dto";
|
||||
|
||||
/**
|
||||
* App-voided rows (voidedAt set) are reversed and must leave every
|
||||
* income/expense/net total. This is distinct from the legacy zero-amount
|
||||
* "void" cheques, which stay as amount-0 rows. List views still show voided
|
||||
* rows struck-through.
|
||||
*/
|
||||
const NOT_VOIDED: Prisma.BankTransactionWhereInput = { voidedAt: null };
|
||||
|
||||
/**
|
||||
* Bank register (chequera) module — plan step 7.
|
||||
@@ -19,9 +34,18 @@ import { PrismaService } from "../prisma/prisma.service";
|
||||
* expense and are excluded from both sides, the way the ~193 zero rows are
|
||||
* in the customer ledger.
|
||||
*
|
||||
* SINGLE CURRENCY. Unlike the customer ledger there is no currency column here:
|
||||
* `bank_transactions` has none, and every `amountInWords` on the egreso side is
|
||||
* spelled out in PESOS. All figures in this module are MXN.
|
||||
* ONE ACCOUNT AT A TIME, CURRENCY FROM THE ACCOUNT. The office now keeps more
|
||||
* than one chequera (Utilities banks in MXN, Seguros in USD), so every read
|
||||
* path here is scoped to exactly one `bankAccountId` — never "all accounts".
|
||||
* There is deliberately no currency column on `bank_transactions`: a movement
|
||||
* inherits its account's, the way a real bank account doesn't mix currencies.
|
||||
* Callers must therefore pass an account id; an unscoped total would sum MXN
|
||||
* and USD into a figure that never existed, the same mistake the billing
|
||||
* module's per-currency rule exists to prevent.
|
||||
*
|
||||
* The 22,669 migrated rows are all SCOTHIA = the Utilities MXN account
|
||||
* (backfilled by `migration/backfill_bank_accounts.py`), and their
|
||||
* `amountInWords` on the egreso side is spelled out in PESOS accordingly.
|
||||
*
|
||||
* NO CATEGORY DIMENSION. `bank_transactions.categoryId` is NULL on all 22,354
|
||||
* rows and this module does not filter or group by it, because the data cannot
|
||||
@@ -55,6 +79,8 @@ export type BankSort =
|
||||
| "reference";
|
||||
|
||||
export interface BankListParams {
|
||||
/** Which chequera to read. Required — see the module header. */
|
||||
bankAccountId: string;
|
||||
query?: string;
|
||||
page: number;
|
||||
pageSize: number;
|
||||
@@ -89,7 +115,9 @@ export class BankService {
|
||||
constructor(private readonly prisma: PrismaService) {}
|
||||
|
||||
private where(p: BankListParams): Prisma.BankTransactionWhereInput {
|
||||
const and: Prisma.BankTransactionWhereInput[] = [];
|
||||
const and: Prisma.BankTransactionWhereInput[] = [
|
||||
{ bankAccountId: p.bankAccountId },
|
||||
];
|
||||
|
||||
if (p.query && p.query.trim()) {
|
||||
const q = p.query.trim();
|
||||
@@ -115,7 +143,9 @@ export class BankService {
|
||||
});
|
||||
}
|
||||
|
||||
return and.length ? { AND: and } : {};
|
||||
// Never empty: the account clause above is always present, so no read can
|
||||
// accidentally span every chequera.
|
||||
return { AND: and };
|
||||
}
|
||||
|
||||
private orderBy(
|
||||
@@ -160,6 +190,7 @@ export class BankService {
|
||||
notes: true,
|
||||
amountInWords: true,
|
||||
legacySourceTable: true,
|
||||
voidedAt: true,
|
||||
},
|
||||
}),
|
||||
]);
|
||||
@@ -182,6 +213,7 @@ export class BankService {
|
||||
notes: r.notes,
|
||||
amountInWords: r.amountInWords,
|
||||
source: r.legacySourceTable,
|
||||
voided: r.voidedAt != null,
|
||||
})),
|
||||
total,
|
||||
page: params.page,
|
||||
@@ -195,17 +227,17 @@ export class BankService {
|
||||
private async totalsFor(where: Prisma.BankTransactionWhereInput) {
|
||||
const [income, expense, voided] = await Promise.all([
|
||||
this.prisma.bankTransaction.aggregate({
|
||||
where: { AND: [where, { amount: { gt: 0 } }] },
|
||||
where: { AND: [where, { amount: { gt: 0 } }, NOT_VOIDED] },
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
}),
|
||||
this.prisma.bankTransaction.aggregate({
|
||||
where: { AND: [where, { amount: { lt: 0 } }] },
|
||||
where: { AND: [where, { amount: { lt: 0 } }, NOT_VOIDED] },
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
}),
|
||||
this.prisma.bankTransaction.count({
|
||||
where: { AND: [where, { amount: 0 }] },
|
||||
where: { AND: [where, { amount: 0 }, NOT_VOIDED] },
|
||||
}),
|
||||
]);
|
||||
|
||||
@@ -222,17 +254,25 @@ export class BankService {
|
||||
};
|
||||
}
|
||||
|
||||
/** Top-line figures for the bank page header. */
|
||||
async stats() {
|
||||
/** Top-line figures for the bank page header, for one chequera. */
|
||||
async stats(bankAccountId: string) {
|
||||
const account = { bankAccountId };
|
||||
const [count, bounds, pending, transferred, totals] = await Promise.all([
|
||||
this.prisma.bankTransaction.count(),
|
||||
this.prisma.bankTransaction.count({
|
||||
where: { AND: [account, NOT_VOIDED] },
|
||||
}),
|
||||
this.prisma.bankTransaction.aggregate({
|
||||
where: { AND: [account, NOT_VOIDED] },
|
||||
_min: { transactionDate: true },
|
||||
_max: { transactionDate: true },
|
||||
}),
|
||||
this.prisma.bankTransaction.count({ where: { cleared: false } }),
|
||||
this.prisma.bankTransaction.count({ where: { transferred: true } }),
|
||||
this.totalsFor({}),
|
||||
this.prisma.bankTransaction.count({
|
||||
where: { AND: [account, { cleared: false }, NOT_VOIDED] },
|
||||
}),
|
||||
this.prisma.bankTransaction.count({
|
||||
where: { AND: [account, { transferred: true }, NOT_VOIDED] },
|
||||
}),
|
||||
this.totalsFor(account),
|
||||
]);
|
||||
|
||||
return {
|
||||
@@ -245,13 +285,16 @@ export class BankService {
|
||||
};
|
||||
}
|
||||
|
||||
/** Year list for the period filter, newest first. */
|
||||
async facets() {
|
||||
/** Year list for the period filter, newest first, for one chequera. */
|
||||
async facets(bankAccountId: string) {
|
||||
// Tagged-template `$queryRaw`: the interpolation below is a bound
|
||||
// parameter, not string concatenation.
|
||||
const years = await this.prisma.$queryRaw<
|
||||
{ year: number; count: bigint | number | string }[]
|
||||
>`
|
||||
SELECT YEAR(transactionDate) AS year, COUNT(*) AS count
|
||||
FROM bank_transactions
|
||||
WHERE voidedAt IS NULL AND bankAccountId = ${bankAccountId}
|
||||
GROUP BY year
|
||||
ORDER BY year DESC
|
||||
`;
|
||||
@@ -270,8 +313,12 @@ export class BankService {
|
||||
* `BAN` table holds only the bank's name), so the register starts at zero on
|
||||
* its first row in 2013 and the running figure is the net movement since
|
||||
* then. Labelled as such in the UI so it is never read as a statement balance.
|
||||
*
|
||||
* Both rollups take the SAME `bankAccountId`. Scoping only one of them would
|
||||
* leave the year list and its month drill-down describing different books —
|
||||
* wrong in a way that still looks right.
|
||||
*/
|
||||
async summary(year?: number) {
|
||||
async summary(bankAccountId: string, year?: number) {
|
||||
const years = await this.prisma.$queryRaw<PeriodRow[]>`
|
||||
SELECT
|
||||
YEAR(transactionDate) AS period,
|
||||
@@ -280,6 +327,7 @@ export class BankService {
|
||||
SUM(CASE WHEN amount < 0 THEN amount ELSE 0 END) AS expense,
|
||||
SUM(amount) AS net
|
||||
FROM bank_transactions
|
||||
WHERE voidedAt IS NULL AND bankAccountId = ${bankAccountId}
|
||||
GROUP BY period
|
||||
ORDER BY period ASC
|
||||
`;
|
||||
@@ -294,6 +342,8 @@ export class BankService {
|
||||
SUM(amount) AS net
|
||||
FROM bank_transactions
|
||||
WHERE YEAR(transactionDate) = ${year}
|
||||
AND voidedAt IS NULL
|
||||
AND bankAccountId = ${bankAccountId}
|
||||
GROUP BY period
|
||||
ORDER BY period ASC
|
||||
`
|
||||
@@ -346,6 +396,161 @@ export class BankService {
|
||||
opening: opening.toFixed(2),
|
||||
};
|
||||
}
|
||||
|
||||
// --- accounts -------------------------------------------------------------
|
||||
|
||||
/**
|
||||
* Every chequera, closed ones included — a closed account still has to be
|
||||
* selectable to read its history, it just isn't offered for new captures.
|
||||
*/
|
||||
async listAccounts() {
|
||||
const rows = await this.prisma.bankAccount.findMany({
|
||||
orderBy: [{ active: "desc" }, { label: "asc" }],
|
||||
select: {
|
||||
id: true,
|
||||
label: true,
|
||||
currency: true,
|
||||
businessLine: true,
|
||||
active: true,
|
||||
bank: { select: { id: true, name: true, country: true } },
|
||||
},
|
||||
});
|
||||
return rows.map((a) => ({
|
||||
id: a.id,
|
||||
label: a.label,
|
||||
currency: a.currency,
|
||||
businessLine: a.businessLine,
|
||||
active: a.active,
|
||||
bankId: a.bank.id,
|
||||
bankName: a.bank.name,
|
||||
bankCountry: a.bank.country,
|
||||
}));
|
||||
}
|
||||
|
||||
async listBanks() {
|
||||
return this.prisma.bank.findMany({
|
||||
orderBy: { name: "asc" },
|
||||
select: { id: true, name: true, country: true },
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve an account id from a request, or reject. Every read route funnels
|
||||
* through this so a bad/missing id is a 400 rather than a silently empty
|
||||
* register that reads as "this account has no movements".
|
||||
*/
|
||||
async requireAccount(bankAccountId: string | undefined) {
|
||||
if (!bankAccountId || !bankAccountId.trim())
|
||||
throw new BadRequestException("Falta la cuenta bancaria (bankAccountId)");
|
||||
const account = await this.prisma.bankAccount.findUnique({
|
||||
where: { id: bankAccountId },
|
||||
select: { id: true, label: true, currency: true, active: true },
|
||||
});
|
||||
if (!account)
|
||||
throw new NotFoundException(`Cuenta bancaria ${bankAccountId} no existe`);
|
||||
return account;
|
||||
}
|
||||
|
||||
async createBank(dto: CreateBankDto) {
|
||||
return this.prisma.bank.create({
|
||||
data: { name: dto.name.trim(), country: dto.country?.trim() || null },
|
||||
});
|
||||
}
|
||||
|
||||
async updateBank(id: string, dto: UpdateBankDto) {
|
||||
await this.getBankOr404(id);
|
||||
return this.prisma.bank.update({
|
||||
where: { id },
|
||||
data: {
|
||||
...(dto.name !== undefined ? { name: dto.name.trim() } : {}),
|
||||
...(dto.country !== undefined
|
||||
? { country: dto.country.trim() || null }
|
||||
: {}),
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
private async getBankOr404(id: string) {
|
||||
const bank = await this.prisma.bank.findUnique({
|
||||
where: { id },
|
||||
select: { id: true },
|
||||
});
|
||||
if (!bank) throw new NotFoundException(`Banco ${id} no existe`);
|
||||
return bank;
|
||||
}
|
||||
|
||||
async createAccount(dto: CreateBankAccountDto) {
|
||||
await this.getBankOr404(dto.bankId);
|
||||
return this.prisma.bankAccount.create({
|
||||
data: {
|
||||
bankId: dto.bankId,
|
||||
label: dto.label.trim(),
|
||||
currency: dto.currency,
|
||||
businessLine: dto.businessLine ?? null,
|
||||
active: dto.active ?? true,
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* `currency` is intentionally absent from the update DTO: the movements
|
||||
* already booked in this account are denominated in it, so changing it would
|
||||
* silently re-denominate history rather than convert it.
|
||||
*/
|
||||
async updateAccount(id: string, dto: UpdateBankAccountDto) {
|
||||
await this.requireAccount(id);
|
||||
if (dto.bankId !== undefined) await this.getBankOr404(dto.bankId);
|
||||
return this.prisma.bankAccount.update({
|
||||
where: { id },
|
||||
data: {
|
||||
...(dto.bankId !== undefined ? { bankId: dto.bankId } : {}),
|
||||
...(dto.label !== undefined ? { label: dto.label.trim() } : {}),
|
||||
...(dto.businessLine !== undefined
|
||||
? { businessLine: dto.businessLine }
|
||||
: {}),
|
||||
...(dto.active !== undefined ? { active: dto.active } : {}),
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
// --- writes (append + void) -----------------------------------------------
|
||||
|
||||
async createMovement(dto: CreateBankMovementDto) {
|
||||
const date = new Date(dto.transactionDate);
|
||||
if (isNaN(date.getTime())) throw new BadRequestException("Fecha inválida");
|
||||
const account = await this.requireAccount(dto.bankAccountId);
|
||||
if (!account.active)
|
||||
throw new BadRequestException(
|
||||
`La cuenta "${account.label}" está cerrada; no admite movimientos nuevos.`,
|
||||
);
|
||||
return this.prisma.bankTransaction.create({
|
||||
data: {
|
||||
bankAccountId: account.id,
|
||||
amount: dto.amount,
|
||||
transactionDate: date,
|
||||
concept: dto.concept,
|
||||
reference: dto.reference,
|
||||
transactionType: dto.transactionType,
|
||||
cleared: dto.cleared ?? false,
|
||||
transferred: dto.transferred ?? false,
|
||||
notes: dto.notes,
|
||||
amountInWords: dto.amountInWords,
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
async voidMovement(id: string, userId: string) {
|
||||
const row = await this.prisma.bankTransaction.findUnique({
|
||||
where: { id },
|
||||
select: { id: true, voidedAt: true },
|
||||
});
|
||||
if (!row) throw new NotFoundException(`Bank transaction ${id} not found`);
|
||||
if (row.voidedAt) throw new BadRequestException("El movimiento ya está anulado");
|
||||
return this.prisma.bankTransaction.update({
|
||||
where: { id },
|
||||
data: { voidedAt: new Date(), voidedById: userId },
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
function directionOf(amount: Prisma.Decimal): BankDirection {
|
||||
|
||||
@@ -1,6 +1,20 @@
|
||||
import { Controller, Get, Param, Query, UseGuards } from "@nestjs/common";
|
||||
import {
|
||||
BadRequestException,
|
||||
Body,
|
||||
Controller,
|
||||
Get,
|
||||
Param,
|
||||
Post,
|
||||
Query,
|
||||
Req,
|
||||
UseGuards,
|
||||
} from "@nestjs/common";
|
||||
import { TransactionDomain } from "@jorgecuadros/database";
|
||||
import { Request } from "express";
|
||||
import { AuthenticatedGuard } from "../auth/authenticated.guard";
|
||||
import { AbilityGuard } from "../auth/ability.guard";
|
||||
import { RequireAbility } from "../auth/require-ability.decorator";
|
||||
import { AuditService } from "../common/audit.service";
|
||||
import {
|
||||
BalanceFilter,
|
||||
BalanceSort,
|
||||
@@ -9,6 +23,11 @@ import {
|
||||
LedgerDirection,
|
||||
MovementSort,
|
||||
} from "./billing.service";
|
||||
import {
|
||||
BatchCreateDto,
|
||||
CreateMovementDto,
|
||||
ResolveOutstandingDto,
|
||||
} from "./movement.dto";
|
||||
|
||||
const DOMAINS: TransactionDomain[] = ["UTILITY", "INSURANCE", "TRUST"];
|
||||
const CURRENCIES: LedgerCurrency[] = ["MXN", "USD"];
|
||||
@@ -32,6 +51,11 @@ function one<T>(allowed: T[], value: string | undefined): T | undefined {
|
||||
return allowed.includes(value as T) ? (value as T) : undefined;
|
||||
}
|
||||
|
||||
/** Tri-state query flag: "true"/"false" filter, anything else means no filter. */
|
||||
function flag(v: string | undefined): boolean | undefined {
|
||||
return v === "true" ? true : v === "false" ? false : undefined;
|
||||
}
|
||||
|
||||
/** A `YYYY-MM-DD` bound; anything unparseable is treated as absent. */
|
||||
function parseDate(v: string | undefined, endOfDay = false): Date | undefined {
|
||||
if (!v) return undefined;
|
||||
@@ -39,10 +63,17 @@ function parseDate(v: string | undefined, endOfDay = false): Date | undefined {
|
||||
return Number.isNaN(d.getTime()) ? undefined : d;
|
||||
}
|
||||
|
||||
@UseGuards(AuthenticatedGuard)
|
||||
@UseGuards(AuthenticatedGuard, AbilityGuard)
|
||||
@Controller("billing")
|
||||
export class BillingController {
|
||||
constructor(private readonly billing: BillingService) {}
|
||||
constructor(
|
||||
private readonly billing: BillingService,
|
||||
private readonly audit: AuditService,
|
||||
) {}
|
||||
|
||||
private actingId(req: Request): string {
|
||||
return (req.user as { id: string }).id;
|
||||
}
|
||||
|
||||
@Get("stats")
|
||||
stats() {
|
||||
@@ -76,6 +107,18 @@ export class BillingController {
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Every movement cut against one check, with its total — the reconciliation
|
||||
* view replacing the legacy REPORTE CHEQUE COUNT. Declared before the
|
||||
* `customers/:id` and `:id`-shaped routes so the literal path wins.
|
||||
*/
|
||||
@Get("by-check")
|
||||
byCheck(@Query("checkNumber") checkNumber?: string) {
|
||||
const n = checkNumber?.trim();
|
||||
if (!n) throw new BadRequestException("checkNumber es obligatorio");
|
||||
return this.billing.byCheck(n);
|
||||
}
|
||||
|
||||
/** One customer's full statement across both business lines. */
|
||||
@Get("customers/:id")
|
||||
statement(@Param("id") id: string) {
|
||||
@@ -94,6 +137,8 @@ export class BillingController {
|
||||
@Query("typeId") typeId?: string,
|
||||
@Query("source") source?: string,
|
||||
@Query("customerId") customerId?: string,
|
||||
@Query("outstanding") outstanding?: string,
|
||||
@Query("checkNumber") checkNumber?: string,
|
||||
@Query("from") from?: string,
|
||||
@Query("to") to?: string,
|
||||
@Query("sort") sort?: string,
|
||||
@@ -108,9 +153,70 @@ export class BillingController {
|
||||
typeId: typeId || undefined,
|
||||
source: source || undefined,
|
||||
customerId: customerId || undefined,
|
||||
outstanding: flag(outstanding),
|
||||
checkNumber: checkNumber?.trim() || undefined,
|
||||
from: parseDate(from),
|
||||
to: parseDate(to, true),
|
||||
sort: one(MOVEMENT_SORTS, sort) ?? "date_desc",
|
||||
});
|
||||
}
|
||||
|
||||
// --- writes ---------------------------------------------------------------
|
||||
|
||||
@Post()
|
||||
@RequireAbility("ledger:create")
|
||||
async create(@Body() dto: CreateMovementDto, @Req() req: Request) {
|
||||
const tx = await this.billing.createMovement(dto);
|
||||
void this.audit.log(this.actingId(req), "ledger.create", {
|
||||
transactionId: tx.id,
|
||||
customerId: dto.customerId,
|
||||
amount: dto.amount,
|
||||
currency: tx.currency,
|
||||
});
|
||||
return tx;
|
||||
}
|
||||
|
||||
/**
|
||||
* Batch capture: many customers' receipts against one physical check.
|
||||
* Same ability as single capture — batching is still capturing.
|
||||
*/
|
||||
@Post("batch")
|
||||
@RequireAbility("ledger:create")
|
||||
async createBatch(@Body() dto: BatchCreateDto, @Req() req: Request) {
|
||||
const result = await this.billing.createBatch(dto);
|
||||
void this.audit.log(this.actingId(req), "ledger.batch", {
|
||||
checkNumber: dto.checkNumber,
|
||||
count: result.count,
|
||||
total: result.total,
|
||||
currency: result.currency,
|
||||
});
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve an outstanding (NOPAGO) row — `ledger:create`, not `ledger:void`:
|
||||
* resolving completes a capture, it doesn't reverse one.
|
||||
*/
|
||||
@Post(":id/resolve-outstanding")
|
||||
@RequireAbility("ledger:create")
|
||||
async resolveOutstanding(
|
||||
@Param("id") id: string,
|
||||
@Body() dto: ResolveOutstandingDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const tx = await this.billing.resolveOutstanding(id, dto);
|
||||
void this.audit.log(this.actingId(req), "ledger.resolve-outstanding", {
|
||||
transactionId: id,
|
||||
checkNumber: dto.checkNumber,
|
||||
});
|
||||
return tx;
|
||||
}
|
||||
|
||||
@Post(":id/void")
|
||||
@RequireAbility("ledger:void")
|
||||
async void(@Param("id") id: string, @Req() req: Request) {
|
||||
const tx = await this.billing.voidMovement(id, this.actingId(req));
|
||||
void this.audit.log(this.actingId(req), "ledger.void", { transactionId: id });
|
||||
return tx;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,6 +1,15 @@
|
||||
import { Injectable, NotFoundException } from "@nestjs/common";
|
||||
import { Prisma, TransactionDomain } from "@jorgecuadros/database";
|
||||
import { BadRequestException, Injectable, NotFoundException } from "@nestjs/common";
|
||||
import {
|
||||
Prisma,
|
||||
TransactionCaptureSource,
|
||||
TransactionDomain,
|
||||
} from "@jorgecuadros/database";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
import {
|
||||
BatchCreateDto,
|
||||
CreateMovementDto,
|
||||
ResolveOutstandingDto,
|
||||
} from "./movement.dto";
|
||||
|
||||
/**
|
||||
* Shared billing / statements module — plan step 6.
|
||||
@@ -53,12 +62,29 @@ export interface MovementParams {
|
||||
typeId?: string;
|
||||
source?: string;
|
||||
customerId?: string;
|
||||
/** Restrict to captured-but-unpaid rows (the legacy NOPAGO worklist). */
|
||||
outstanding?: boolean;
|
||||
/** Groups a capture batch: every row cut against one physical check. */
|
||||
checkNumber?: string;
|
||||
/** Inclusive ISO date bounds on `transactionDate`. */
|
||||
from?: Date;
|
||||
to?: Date;
|
||||
sort: MovementSort;
|
||||
}
|
||||
|
||||
/**
|
||||
* Non-client-supplied options for a capture. Kept out of the DTO on purpose:
|
||||
* these are set by the calling *module*, never by an HTTP body, so a client
|
||||
* can't label its own rows as machine-captured or forge a capture ref.
|
||||
* See `BillingService.createBatch` for the seam contract.
|
||||
*/
|
||||
export interface CaptureOptions {
|
||||
/** Defaults to BATCH for the HTTP path; the OCR pipeline passes OCR. */
|
||||
source?: TransactionCaptureSource;
|
||||
/** Per-line artifact ids, positionally parallel to `dto.lines`. */
|
||||
refs?: (string | undefined)[];
|
||||
}
|
||||
|
||||
export interface BalanceParams {
|
||||
query?: string;
|
||||
page: number;
|
||||
@@ -104,6 +130,48 @@ function dec(v: Prisma.Decimal | null | undefined): string {
|
||||
return (v ?? new Prisma.Decimal(0)).toFixed(2);
|
||||
}
|
||||
|
||||
/**
|
||||
* Every aggregate (SUM/count/groupBy and the raw balance SQL) must exclude
|
||||
* voided rows, or a reversed movement keeps affecting the books. List views
|
||||
* still show voided rows struck-through — only totals drop them.
|
||||
*/
|
||||
const NOT_VOIDED: Prisma.TransactionWhereInput = { voidedAt: null };
|
||||
|
||||
/**
|
||||
* Outstanding ("NOPAGO") rows are captured but unpaid — the office recorded the
|
||||
* bill without funds to cover it. They are excluded from every *balance*
|
||||
* aggregate, exactly as the legacy `SALDOS ULTIMO 0` query did with its
|
||||
* `HAVING NOPAGO = 0`: the office hasn't paid the bill, so it isn't yet owed by
|
||||
* the customer. Resolving one (POST /billing/:id/resolve-outstanding) clears the
|
||||
* flag and the amount starts counting.
|
||||
*
|
||||
* This is deliberately narrower than NOT_VOIDED. Voided rows are excluded
|
||||
* everywhere; outstanding rows are excluded only from balances — the movement
|
||||
* browser still totals them, because "how much water did we capture in April"
|
||||
* means every captured row regardless of whether the check cleared.
|
||||
*/
|
||||
const NOT_OUTSTANDING: Prisma.TransactionWhereInput = { outstanding: false };
|
||||
|
||||
/**
|
||||
* Source tables excluded from the customer-facing statement.
|
||||
*
|
||||
* The legacy portal's `datosfreak` table was materialized from DATOS2 only
|
||||
* (`objects.json:1358`), so the customer's "current balance" never saw
|
||||
* EFECTIVO / EFECTIVO FM3 / CHEQUE FM3 / EFECTIVO_BACKUP cash receipts, nor
|
||||
* the IVA 2015 snapshot. The unified `transactions` table has all of them, so
|
||||
* the statement must drop them to match the legacy number the customer has
|
||||
* been quoted for years. The staff-facing balances worklist and movement
|
||||
* browser keep them — they're real money, just tracked separately
|
||||
* (FM3 = visa fee stream, EFECTIVO = cash receipt stream).
|
||||
*/
|
||||
const STATEMENT_EXCLUDED_SOURCE_TABLES: readonly string[] = [
|
||||
"EFECTIVO",
|
||||
"EFECTIVO_BACKUP",
|
||||
"EFECTIVO FM3",
|
||||
"CHEQUE FM3",
|
||||
"IVA 2015",
|
||||
];
|
||||
|
||||
@Injectable()
|
||||
export class BillingService {
|
||||
constructor(private readonly prisma: PrismaService) {}
|
||||
@@ -132,6 +200,10 @@ export class BillingService {
|
||||
if (p.typeId) and.push({ typeId: p.typeId });
|
||||
if (p.source) and.push({ legacySourceTable: p.source });
|
||||
if (p.customerId) and.push({ customerId: p.customerId });
|
||||
if (p.outstanding !== undefined) and.push({ outstanding: p.outstanding });
|
||||
// Exact match, not `contains`: this is the by-check reconciliation lookup,
|
||||
// where "1234" must not drag in "51234".
|
||||
if (p.checkNumber) and.push({ checkNumber: p.checkNumber });
|
||||
if (p.from || p.to) {
|
||||
and.push({
|
||||
transactionDate: {
|
||||
@@ -187,6 +259,8 @@ export class BillingService {
|
||||
checkNumber: true,
|
||||
message: true,
|
||||
legacySourceTable: true,
|
||||
voidedAt: true,
|
||||
outstanding: true,
|
||||
type: { select: { nameEn: true, nameEs: true } },
|
||||
customer: {
|
||||
select: { id: true, name: true, nameSource: true, city: true },
|
||||
@@ -200,19 +274,19 @@ export class BillingService {
|
||||
// cover everything the filter matched.
|
||||
const totals = await this.prisma.transaction.groupBy({
|
||||
by: ["currency"],
|
||||
where,
|
||||
where: { AND: [where, NOT_VOIDED] },
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
});
|
||||
const charges = await this.prisma.transaction.groupBy({
|
||||
by: ["currency"],
|
||||
where: { AND: [where, { amount: { lt: 0 } }] },
|
||||
where: { AND: [where, { amount: { lt: 0 } }, NOT_VOIDED] },
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
});
|
||||
const credits = await this.prisma.transaction.groupBy({
|
||||
by: ["currency"],
|
||||
where: { AND: [where, { amount: { gt: 0 } }] },
|
||||
where: { AND: [where, { amount: { gt: 0 } }, NOT_VOIDED] },
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
});
|
||||
@@ -233,6 +307,8 @@ export class BillingService {
|
||||
message: r.message,
|
||||
source: r.legacySourceTable,
|
||||
type: r.type,
|
||||
voided: r.voidedAt != null,
|
||||
outstanding: r.outstanding,
|
||||
customerId: r.customer.id,
|
||||
customerName: r.customer.name,
|
||||
customerNameSource: r.customer.nameSource,
|
||||
@@ -326,7 +402,7 @@ export class BillingService {
|
||||
MAX(t.transactionDate) AS lastMovement
|
||||
FROM customers c
|
||||
JOIN transactions t ON t.customerId = c.id
|
||||
WHERE 1 = 1 ${nameFilter} ${txFilter}
|
||||
WHERE t.voidedAt IS NULL AND t.outstanding = 0 ${nameFilter} ${txFilter}
|
||||
GROUP BY c.id, c.name, c.nameSource, c.nameMissing, c.city, c.state
|
||||
${having}
|
||||
${orderBy}
|
||||
@@ -338,7 +414,10 @@ export class BillingService {
|
||||
SELECT c.id
|
||||
FROM customers c
|
||||
JOIN transactions t ON t.customerId = c.id
|
||||
WHERE 1 = 1 ${nameFilter} ${txFilter}
|
||||
-- Must match the page query's filters exactly, or the total disagrees
|
||||
-- with the rows. (The void exclusion was missing here before the
|
||||
-- outstanding work; a voided-only customer inflated the count.)
|
||||
WHERE t.voidedAt IS NULL AND t.outstanding = 0 ${nameFilter} ${txFilter}
|
||||
GROUP BY c.id
|
||||
${having}
|
||||
) x
|
||||
@@ -382,17 +461,23 @@ export class BillingService {
|
||||
/** Top-line figures for the billing page header. */
|
||||
async stats() {
|
||||
const [movements, ledgerCustomers, byCurrency, byDomain] = await Promise.all([
|
||||
this.prisma.transaction.count(),
|
||||
this.prisma.transaction.count({ where: NOT_VOIDED }),
|
||||
this.prisma.transaction
|
||||
.findMany({ distinct: ["customerId"], select: { customerId: true } })
|
||||
.findMany({
|
||||
where: NOT_VOIDED,
|
||||
distinct: ["customerId"],
|
||||
select: { customerId: true },
|
||||
})
|
||||
.then((r) => r.length),
|
||||
this.prisma.transaction.groupBy({
|
||||
by: ["currency"],
|
||||
where: NOT_VOIDED,
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
}),
|
||||
this.prisma.transaction.groupBy({
|
||||
by: ["domain", "currency"],
|
||||
where: NOT_VOIDED,
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
}),
|
||||
@@ -400,13 +485,13 @@ export class BillingService {
|
||||
|
||||
const charges = await this.prisma.transaction.groupBy({
|
||||
by: ["currency"],
|
||||
where: { amount: { lt: 0 } },
|
||||
where: { AND: [{ amount: { lt: 0 } }, NOT_VOIDED] },
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
});
|
||||
const credits = await this.prisma.transaction.groupBy({
|
||||
by: ["currency"],
|
||||
where: { amount: { gt: 0 } },
|
||||
where: { AND: [{ amount: { gt: 0 } }, NOT_VOIDED] },
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
});
|
||||
@@ -428,7 +513,7 @@ export class BillingService {
|
||||
SUM(bal > 0.005) AS inCredit
|
||||
FROM (
|
||||
SELECT customerId, currency, SUM(amount) AS bal
|
||||
FROM transactions GROUP BY customerId, currency
|
||||
FROM transactions WHERE voidedAt IS NULL GROUP BY customerId, currency
|
||||
) x
|
||||
GROUP BY currency
|
||||
`;
|
||||
@@ -436,10 +521,12 @@ export class BillingService {
|
||||
|
||||
const [firstRow, lastRow] = await Promise.all([
|
||||
this.prisma.transaction.findFirst({
|
||||
where: NOT_VOIDED,
|
||||
orderBy: { transactionDate: "asc" },
|
||||
select: { transactionDate: true },
|
||||
}),
|
||||
this.prisma.transaction.findFirst({
|
||||
where: NOT_VOIDED,
|
||||
orderBy: { transactionDate: "desc" },
|
||||
select: { transactionDate: true },
|
||||
}),
|
||||
@@ -449,7 +536,7 @@ export class BillingService {
|
||||
// module is one view instead of two.
|
||||
const crossLine = await this.prisma.$queryRaw<{ n: bigint | number | string }[]>`
|
||||
SELECT COUNT(*) AS n FROM (
|
||||
SELECT customerId FROM transactions
|
||||
SELECT customerId FROM transactions WHERE voidedAt IS NULL
|
||||
GROUP BY customerId HAVING COUNT(DISTINCT domain) > 1
|
||||
) x
|
||||
`;
|
||||
@@ -484,7 +571,7 @@ export class BillingService {
|
||||
async facets() {
|
||||
const types = await this.prisma.transaction.groupBy({
|
||||
by: ["typeId"],
|
||||
where: { typeId: { not: null } },
|
||||
where: { AND: [{ typeId: { not: null } }, NOT_VOIDED] },
|
||||
_count: { _all: true },
|
||||
orderBy: { _count: { typeId: "desc" } },
|
||||
});
|
||||
@@ -496,6 +583,7 @@ export class BillingService {
|
||||
|
||||
const sources = await this.prisma.transaction.groupBy({
|
||||
by: ["legacySourceTable"],
|
||||
where: NOT_VOIDED,
|
||||
_count: { _all: true },
|
||||
orderBy: { _count: { legacySourceTable: "desc" } },
|
||||
});
|
||||
@@ -504,7 +592,7 @@ export class BillingService {
|
||||
{ year: number; count: bigint | number | string }[]
|
||||
>`
|
||||
SELECT YEAR(transactionDate) AS year, COUNT(*) AS count
|
||||
FROM transactions GROUP BY year ORDER BY year DESC
|
||||
FROM transactions WHERE voidedAt IS NULL GROUP BY year ORDER BY year DESC
|
||||
`;
|
||||
|
||||
return {
|
||||
@@ -560,7 +648,23 @@ export class BillingService {
|
||||
}
|
||||
|
||||
const rows = await this.prisma.transaction.findMany({
|
||||
where: { customerId },
|
||||
where: {
|
||||
customerId,
|
||||
// NULL-safe exclusion. `notIn` alone compiles to SQL `NOT IN`, and
|
||||
// `NULL NOT IN (...)` is NULL, not true — so every app-captured row
|
||||
// (which has no legacySourceTable) silently vanished from the
|
||||
// statement while still showing in the movement browser. Rows the app
|
||||
// books must appear on the customer's statement, so the null case is
|
||||
// spelled out.
|
||||
OR: [
|
||||
{ legacySourceTable: null },
|
||||
{
|
||||
legacySourceTable: {
|
||||
notIn: STATEMENT_EXCLUDED_SOURCE_TABLES as string[],
|
||||
},
|
||||
},
|
||||
],
|
||||
},
|
||||
orderBy: [{ transactionDate: "asc" }, { id: "asc" }],
|
||||
select: {
|
||||
id: true,
|
||||
@@ -573,14 +677,20 @@ export class BillingService {
|
||||
checkNumber: true,
|
||||
message: true,
|
||||
legacySourceTable: true,
|
||||
voidedAt: true,
|
||||
outstanding: true,
|
||||
type: { select: { nameEn: true, nameEs: true } },
|
||||
},
|
||||
});
|
||||
|
||||
const running = new Map<string, Prisma.Decimal>();
|
||||
const movements = rows.map((r) => {
|
||||
const voided = r.voidedAt != null;
|
||||
const prev = running.get(r.currency) ?? new Prisma.Decimal(0);
|
||||
const next = prev.plus(r.amount);
|
||||
// Neither a voided row nor an outstanding (unpaid) one moves the running
|
||||
// balance — both show tagged, with the balance unchanged from the previous
|
||||
// live movement. Outstanding rows start counting once resolved.
|
||||
const next = voided || r.outstanding ? prev : prev.plus(r.amount);
|
||||
running.set(r.currency, next);
|
||||
return {
|
||||
id: r.id,
|
||||
@@ -595,6 +705,8 @@ export class BillingService {
|
||||
message: r.message,
|
||||
source: r.legacySourceTable,
|
||||
type: r.type,
|
||||
voided,
|
||||
outstanding: r.outstanding,
|
||||
/** Balance in this row's currency after applying it. */
|
||||
balanceAfter: next.toFixed(2),
|
||||
};
|
||||
@@ -628,6 +740,9 @@ export class BillingService {
|
||||
>();
|
||||
|
||||
for (const r of rows) {
|
||||
// Voided rows never enter a total; outstanding rows don't either until
|
||||
// they're resolved (legacy SALDOS ULTIMO 0's `HAVING NOPAGO = 0`).
|
||||
if (r.voidedAt != null || r.outstanding) continue;
|
||||
const c =
|
||||
perCurrency.get(r.currency) ??
|
||||
{
|
||||
@@ -675,6 +790,7 @@ export class BillingService {
|
||||
{ name: string; currency: string; total: Prisma.Decimal; count: number }
|
||||
>();
|
||||
for (const r of rows) {
|
||||
if (r.voidedAt != null || r.outstanding) continue;
|
||||
if (!r.amount.lessThan(0)) continue;
|
||||
const name = r.type?.nameEs || r.type?.nameEn || "Sin clasificar";
|
||||
const key = `${name}|${r.currency}`;
|
||||
@@ -722,4 +838,255 @@ export class BillingService {
|
||||
movements,
|
||||
};
|
||||
}
|
||||
|
||||
// --- writes (append + void; never edit or delete a booked row) ------------
|
||||
|
||||
async createMovement(dto: CreateMovementDto) {
|
||||
const customer = await this.prisma.customer.findUnique({
|
||||
where: { id: dto.customerId },
|
||||
select: { id: true },
|
||||
});
|
||||
if (!customer) throw new NotFoundException(`Customer ${dto.customerId} not found`);
|
||||
const date = new Date(dto.transactionDate);
|
||||
if (isNaN(date.getTime())) throw new BadRequestException("Fecha inválida");
|
||||
|
||||
return this.prisma.transaction.create({
|
||||
data: {
|
||||
customerId: dto.customerId,
|
||||
domain: dto.domain,
|
||||
amount: dto.amount,
|
||||
transactionDate: date,
|
||||
currency: dto.currency,
|
||||
typeId: dto.typeId,
|
||||
period: dto.period,
|
||||
reference: dto.reference,
|
||||
checkNumber: dto.checkNumber,
|
||||
message: dto.message,
|
||||
outstanding: dto.outstanding ?? false,
|
||||
captureSource: "MANUAL",
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Batch capture by check — many customers' receipts against one physical
|
||||
* check. One `$transaction`, so a bad line rejects the whole batch rather
|
||||
* than leaving a half-captured check that reconciles against nothing.
|
||||
*
|
||||
* Returns the check-level total alongside the rows so the UI can show it
|
||||
* against the physical check amount, which is the entire point of the legacy
|
||||
* flow this replaces (`CAPTURA *` feeding `EDITA CHEQUE COUNT`).
|
||||
*
|
||||
* ── Integration seam for OCR auto-capture (RECEIPT_CAPTURE_SPEC §2) ────────
|
||||
* This method is the SINGLE write path for multi-row capture, and the OCR
|
||||
* pipeline is required to post through it rather than writing `Transaction`
|
||||
* rows itself — one validation path, one audit trail. Three guarantees exist
|
||||
* for that caller specifically, and must not be broken:
|
||||
*
|
||||
* 1. `items[i]` corresponds to `dto.lines[i]`. Prisma's array
|
||||
* `$transaction` preserves order, so the caller can zip the result back
|
||||
* onto its own records — which is how `StatementDocument.postedTransactionId`
|
||||
* gets set after a confirmed batch posts.
|
||||
* 2. `opts.refs[i]` stamps `captureRef` on row `i` (a `StatementDocument.id`).
|
||||
* Re-posting a ref that already has a live row is rejected, so a
|
||||
* double-clicked "confirm" or a retried job cannot double-charge a
|
||||
* customer. Voided rows don't block a re-post — a corrected statement
|
||||
* must be re-postable after its bad row is voided.
|
||||
* 3. `opts.source` records the capture path; it is NOT accepted over HTTP,
|
||||
* so a client cannot label its hand-keyed rows as machine-captured.
|
||||
*
|
||||
* Everything the OCR module adds on top (batches, per-document status, the
|
||||
* review queue) lives in its own module; nothing about it needs to change
|
||||
* this signature.
|
||||
*/
|
||||
async createBatch(dto: BatchCreateDto, opts: CaptureOptions = {}) {
|
||||
const date = new Date(dto.transactionDate);
|
||||
if (isNaN(date.getTime())) throw new BadRequestException("Fecha inválida");
|
||||
|
||||
// Validate every customer up front, in one query — a per-line lookup inside
|
||||
// the transaction would be N round-trips and would fail halfway through.
|
||||
const ids = [...new Set(dto.lines.map((l) => l.customerId))];
|
||||
const found = await this.prisma.customer.findMany({
|
||||
where: { id: { in: ids } },
|
||||
select: { id: true },
|
||||
});
|
||||
if (found.length !== ids.length) {
|
||||
const known = new Set(found.map((c) => c.id));
|
||||
const missing = ids.filter((id) => !known.has(id));
|
||||
throw new BadRequestException(
|
||||
`Cliente(s) no encontrado(s): ${missing.join(", ")}`,
|
||||
);
|
||||
}
|
||||
|
||||
// Duplicate-post guard (seam guarantee 2). Only live rows block: a voided
|
||||
// row means the earlier post was reversed, so the corrected statement must
|
||||
// be allowed through.
|
||||
const refs = (opts.refs ?? []).filter((r): r is string => !!r);
|
||||
if (refs.length) {
|
||||
const clash = await this.prisma.transaction.findMany({
|
||||
where: { captureRef: { in: refs }, voidedAt: null },
|
||||
select: { captureRef: true },
|
||||
});
|
||||
if (clash.length) {
|
||||
const dupes = [...new Set(clash.map((c) => c.captureRef))];
|
||||
throw new BadRequestException(
|
||||
`Ya existen movimientos para: ${dupes.join(", ")}`,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
const currency = dto.currency ?? "MXN";
|
||||
const source = opts.source ?? "BATCH";
|
||||
const created = await this.prisma.$transaction(
|
||||
dto.lines.map((line, i) =>
|
||||
this.prisma.transaction.create({
|
||||
data: {
|
||||
customerId: line.customerId,
|
||||
domain: dto.domain,
|
||||
amount: line.amount,
|
||||
transactionDate: date,
|
||||
currency,
|
||||
typeId: dto.typeId,
|
||||
checkNumber: dto.checkNumber,
|
||||
period: line.period,
|
||||
reference: line.reference,
|
||||
message: line.message,
|
||||
outstanding: line.outstanding ?? false,
|
||||
captureSource: source,
|
||||
captureRef: opts.refs?.[i],
|
||||
},
|
||||
}),
|
||||
),
|
||||
);
|
||||
|
||||
// Outstanding lines are captured but unfunded, so they don't belong in the
|
||||
// figure staff reconcile against the physical check.
|
||||
const total = created.reduce(
|
||||
(sum, t) => (t.outstanding ? sum : sum.plus(t.amount)),
|
||||
new Prisma.Decimal(0),
|
||||
);
|
||||
|
||||
return {
|
||||
/** Parallel to `dto.lines` — see seam guarantee 1. */
|
||||
items: created,
|
||||
checkNumber: dto.checkNumber,
|
||||
currency,
|
||||
source,
|
||||
count: created.length,
|
||||
outstandingCount: created.filter((t) => t.outstanding).length,
|
||||
total: total.toFixed(2),
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve an outstanding row: the check was finally cut. Takes the resolution
|
||||
* date and check number and clears the flag, so the amount starts counting
|
||||
* toward the balance. Legacy: "se actualiza registro con fecha del día y el
|
||||
* cheque a pagar y quitas outstanding".
|
||||
*/
|
||||
async resolveOutstanding(id: string, dto: ResolveOutstandingDto) {
|
||||
const tx = await this.prisma.transaction.findUnique({
|
||||
where: { id },
|
||||
select: { id: true, voidedAt: true, outstanding: true },
|
||||
});
|
||||
if (!tx) throw new NotFoundException(`Transaction ${id} not found`);
|
||||
if (tx.voidedAt) {
|
||||
throw new BadRequestException("El movimiento está anulado");
|
||||
}
|
||||
if (!tx.outstanding) {
|
||||
throw new BadRequestException("El movimiento no está pendiente de pago");
|
||||
}
|
||||
const date = new Date(dto.resolvedDate);
|
||||
if (isNaN(date.getTime())) throw new BadRequestException("Fecha inválida");
|
||||
|
||||
return this.prisma.transaction.update({
|
||||
where: { id },
|
||||
data: {
|
||||
outstanding: false,
|
||||
checkNumber: dto.checkNumber,
|
||||
transactionDate: date,
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Every live movement cut against one check, plus its total — the
|
||||
* reconciliation view replacing `EDITA CHEQUE ALF/COUNT/NUM` and
|
||||
* `REPORTE POR CHEQUE`. Voided rows are dropped entirely (they reconcile
|
||||
* against nothing); outstanding rows are listed but excluded from the total,
|
||||
* since the check didn't fund them.
|
||||
*/
|
||||
async byCheck(checkNumber: string) {
|
||||
const rows = await this.prisma.transaction.findMany({
|
||||
where: { checkNumber, voidedAt: null },
|
||||
orderBy: [{ transactionDate: "asc" }, { id: "asc" }],
|
||||
select: {
|
||||
id: true,
|
||||
transactionDate: true,
|
||||
domain: true,
|
||||
amount: true,
|
||||
currency: true,
|
||||
reference: true,
|
||||
period: true,
|
||||
message: true,
|
||||
outstanding: true,
|
||||
type: { select: { nameEn: true, nameEs: true } },
|
||||
customer: { select: { id: true, name: true, nameSource: true } },
|
||||
},
|
||||
});
|
||||
|
||||
// Per currency: a check is one currency in practice, but the ledger has
|
||||
// both and this module never sums across them.
|
||||
const totals = new Map<string, { currency: string; total: Prisma.Decimal; count: number }>();
|
||||
for (const r of rows) {
|
||||
if (r.outstanding) continue;
|
||||
const e =
|
||||
totals.get(r.currency) ??
|
||||
{ currency: r.currency, total: new Prisma.Decimal(0), count: 0 };
|
||||
e.total = e.total.plus(r.amount);
|
||||
e.count += 1;
|
||||
totals.set(r.currency, e);
|
||||
}
|
||||
|
||||
return {
|
||||
checkNumber,
|
||||
items: rows.map((r) => ({
|
||||
id: r.id,
|
||||
transactionDate: r.transactionDate,
|
||||
domain: r.domain,
|
||||
amount: r.amount,
|
||||
currency: r.currency,
|
||||
direction: r.amount.lessThan(0) ? "charge" : "credit",
|
||||
reference: r.reference,
|
||||
period: r.period,
|
||||
message: r.message,
|
||||
outstanding: r.outstanding,
|
||||
type: r.type,
|
||||
customerId: r.customer.id,
|
||||
customerName: r.customer.name,
|
||||
customerNameSource: r.customer.nameSource,
|
||||
})),
|
||||
count: rows.length,
|
||||
outstandingCount: rows.filter((r) => r.outstanding).length,
|
||||
totals: [...totals.values()].map((t) => ({
|
||||
currency: t.currency,
|
||||
total: t.total.toFixed(2),
|
||||
count: t.count,
|
||||
})),
|
||||
};
|
||||
}
|
||||
|
||||
/** Reverse a movement by marking it voided; it stops counting toward totals. */
|
||||
async voidMovement(id: string, userId: string) {
|
||||
const tx = await this.prisma.transaction.findUnique({
|
||||
where: { id },
|
||||
select: { id: true, voidedAt: true },
|
||||
});
|
||||
if (!tx) throw new NotFoundException(`Transaction ${id} not found`);
|
||||
if (tx.voidedAt) throw new BadRequestException("El movimiento ya está anulado");
|
||||
return this.prisma.transaction.update({
|
||||
where: { id },
|
||||
data: { voidedAt: new Date(), voidedById: userId },
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,85 @@
|
||||
import {
|
||||
ArrayMaxSize,
|
||||
ArrayMinSize,
|
||||
IsArray,
|
||||
IsBoolean,
|
||||
IsEnum,
|
||||
IsNumber,
|
||||
IsOptional,
|
||||
IsString,
|
||||
MinLength,
|
||||
ValidateNested,
|
||||
} from "class-validator";
|
||||
import { Type } from "class-transformer";
|
||||
import { Currency, TransactionDomain } from "@jorgecuadros/database";
|
||||
|
||||
/**
|
||||
* A new ledger movement. `amount` is signed: negative = cargo (charge),
|
||||
* positive = abono (credit) — the module's sign convention. Booked movements
|
||||
* are never edited; a mistake is corrected by voiding and re-capturing.
|
||||
*/
|
||||
export class CreateMovementDto {
|
||||
@IsString() @MinLength(1) customerId!: string;
|
||||
@IsEnum(TransactionDomain) domain!: TransactionDomain;
|
||||
@IsNumber() amount!: number;
|
||||
@IsString() @MinLength(1) transactionDate!: string;
|
||||
|
||||
@IsOptional() @IsEnum(Currency) currency?: Currency;
|
||||
@IsOptional() @IsString() typeId?: string;
|
||||
@IsOptional() @IsString() period?: string;
|
||||
@IsOptional() @IsString() reference?: string;
|
||||
@IsOptional() @IsString() checkNumber?: string;
|
||||
@IsOptional() @IsString() message?: string;
|
||||
/**
|
||||
* Legacy "NOPAGO": the bill was captured but not actually paid (no funds).
|
||||
* The row posts normally and stays visible, but is kept out of every balance
|
||||
* aggregate until resolved — see BillingService's NOT_OUTSTANDING.
|
||||
*/
|
||||
@IsOptional() @IsBoolean() outstanding?: boolean;
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolving an outstanding row: the check finally got cut, so the movement
|
||||
* takes the resolution date and check number and starts counting toward the
|
||||
* balance. Legacy behavior: "se actualiza registro con fecha del día y el
|
||||
* cheque a pagar y quitas outstanding".
|
||||
*/
|
||||
export class ResolveOutstandingDto {
|
||||
@IsString() @MinLength(1) checkNumber!: string;
|
||||
@IsString() @MinLength(1) resolvedDate!: string;
|
||||
}
|
||||
|
||||
/** One customer's line within a batch; check-level fields live on the parent. */
|
||||
export class BatchLineDto {
|
||||
@IsString() @MinLength(1) customerId!: string;
|
||||
@IsNumber() amount!: number;
|
||||
|
||||
@IsOptional() @IsString() reference?: string;
|
||||
@IsOptional() @IsString() period?: string;
|
||||
@IsOptional() @IsString() message?: string;
|
||||
@IsOptional() @IsBoolean() outstanding?: boolean;
|
||||
}
|
||||
|
||||
/**
|
||||
* Batch capture by check — the legacy "Editor" flow: key many customers'
|
||||
* receipts against one check, then reconcile the captured total against the
|
||||
* physical check. Deliberately NOT a persisted batch entity: `checkNumber` is
|
||||
* already a column, and grouping by it answers every legacy by-check query.
|
||||
*/
|
||||
export class BatchCreateDto {
|
||||
@IsEnum(TransactionDomain) domain!: TransactionDomain;
|
||||
@IsString() @MinLength(1) transactionDate!: string;
|
||||
@IsString() @MinLength(1) checkNumber!: string;
|
||||
|
||||
@IsOptional() @IsEnum(Currency) currency?: Currency;
|
||||
@IsOptional() @IsString() typeId?: string;
|
||||
|
||||
// Capped so one request can't open a transaction over an unbounded row set;
|
||||
// a physical check batch is tens of lines, not thousands.
|
||||
@IsArray()
|
||||
@ArrayMinSize(1)
|
||||
@ArrayMaxSize(500)
|
||||
@ValidateNested({ each: true })
|
||||
@Type(() => BatchLineDto)
|
||||
lines!: BatchLineDto[];
|
||||
}
|
||||
@@ -0,0 +1,34 @@
|
||||
import { Injectable } from "@nestjs/common";
|
||||
import { Prisma } from "@jorgecuadros/database";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
|
||||
/**
|
||||
* Thin writer over the existing ActivityLog model. Every mutating route calls
|
||||
* this so who-did-what is recorded — the structural replacement for the old
|
||||
* PHP app's scattered Logger calls. Best-effort: a logging failure must never
|
||||
* fail the underlying write, so callers `void audit.log(...)` without awaiting.
|
||||
*/
|
||||
@Injectable()
|
||||
export class AuditService {
|
||||
constructor(private readonly prisma: PrismaService) {}
|
||||
|
||||
async log(
|
||||
userId: string | null | undefined,
|
||||
event: string,
|
||||
message?: Record<string, unknown>,
|
||||
level = "info",
|
||||
): Promise<void> {
|
||||
try {
|
||||
await this.prisma.activityLog.create({
|
||||
data: {
|
||||
userId: userId ?? undefined,
|
||||
event,
|
||||
level,
|
||||
message: (message as Prisma.InputJsonValue) ?? undefined,
|
||||
},
|
||||
});
|
||||
} catch {
|
||||
/* never let audit logging break a real write */
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
// Small shared coercers for DTO fields that arrive as strings from JSON.
|
||||
// Distinguishing "field absent" (undefined -> leave unchanged) from
|
||||
// "field cleared" (null/"" -> set null) matters for PATCH semantics.
|
||||
|
||||
export function toDate(v?: string | null): Date | null | undefined {
|
||||
if (v === undefined) return undefined;
|
||||
if (v === "" || v === null) return null;
|
||||
const d = new Date(v);
|
||||
return isNaN(d.getTime()) ? undefined : d;
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
import { Global, Module } from "@nestjs/common";
|
||||
import { AuditService } from "./audit.service";
|
||||
|
||||
@Global()
|
||||
@Module({
|
||||
providers: [AuditService],
|
||||
exports: [AuditService],
|
||||
})
|
||||
export class CommonModule {}
|
||||
@@ -0,0 +1,42 @@
|
||||
import {
|
||||
IsBoolean,
|
||||
IsEmail,
|
||||
IsEnum,
|
||||
IsNumber,
|
||||
IsOptional,
|
||||
IsString,
|
||||
MinLength,
|
||||
} from "class-validator";
|
||||
import { Currency } from "@jorgecuadros/database";
|
||||
|
||||
/**
|
||||
* Editable customer fields. Internal/derived columns (nameSource, nameMissing,
|
||||
* legacy* provenance, archivedAt) are managed by the service, not the client.
|
||||
* `name` is the only required field; everything else is optional.
|
||||
*/
|
||||
export class CreateCustomerDto {
|
||||
@IsString()
|
||||
@MinLength(1)
|
||||
name!: string;
|
||||
|
||||
@IsOptional() @IsString() addressLine1?: string;
|
||||
@IsOptional() @IsString() addressLine2?: string;
|
||||
@IsOptional() @IsString() city?: string;
|
||||
@IsOptional() @IsString() state?: string;
|
||||
@IsOptional() @IsString() zipCode?: string;
|
||||
@IsOptional() @IsString() country?: string;
|
||||
@IsOptional() @IsString() phone?: string;
|
||||
@IsOptional() @IsString() mobile?: string;
|
||||
@IsOptional() @IsString() fax?: string;
|
||||
@IsOptional() @IsEmail() email?: string;
|
||||
@IsOptional() @IsString() notes?: string;
|
||||
@IsOptional() @IsString() identificationType?: string;
|
||||
@IsOptional() @IsString() identificationNumber?: string;
|
||||
/** ISO date string; coerced to Date by the service. */
|
||||
@IsOptional() @IsString() identificationExpiration?: string;
|
||||
@IsOptional() @IsString() customerSince?: string;
|
||||
@IsOptional() @IsBoolean() status?: boolean;
|
||||
@IsOptional() @IsNumber() minimumBalance?: number;
|
||||
@IsOptional() @IsNumber() feeAmount?: number;
|
||||
@IsOptional() @IsEnum(Currency) preferredCurrency?: Currency;
|
||||
}
|
||||
@@ -1,11 +1,35 @@
|
||||
import { Controller, Get, Param, Query, UseGuards } from "@nestjs/common";
|
||||
import {
|
||||
Body,
|
||||
Controller,
|
||||
Delete,
|
||||
Get,
|
||||
Param,
|
||||
Patch,
|
||||
Post,
|
||||
Query,
|
||||
Req,
|
||||
UseGuards,
|
||||
} from "@nestjs/common";
|
||||
import { Request } from "express";
|
||||
import { AuthenticatedGuard } from "../auth/authenticated.guard";
|
||||
import { AbilityGuard } from "../auth/ability.guard";
|
||||
import { RequireAbility } from "../auth/require-ability.decorator";
|
||||
import { AuditService } from "../common/audit.service";
|
||||
import { CustomersService } from "./customers.service";
|
||||
import { CreateCustomerDto } from "./create-customer.dto";
|
||||
import { UpdateCustomerDto } from "./update-customer.dto";
|
||||
|
||||
@UseGuards(AuthenticatedGuard)
|
||||
@UseGuards(AuthenticatedGuard, AbilityGuard)
|
||||
@Controller("customers")
|
||||
export class CustomersController {
|
||||
constructor(private readonly customers: CustomersService) {}
|
||||
constructor(
|
||||
private readonly customers: CustomersService,
|
||||
private readonly audit: AuditService,
|
||||
) {}
|
||||
|
||||
private actingId(req: Request): string {
|
||||
return (req.user as { id: string }).id;
|
||||
}
|
||||
|
||||
@Get("stats")
|
||||
stats() {
|
||||
@@ -18,14 +42,57 @@ export class CustomersController {
|
||||
@Query("page") page?: string,
|
||||
@Query("pageSize") pageSize?: string,
|
||||
@Query("line") line?: "utility" | "insurance" | "both",
|
||||
@Query("includeArchived") includeArchived?: string,
|
||||
) {
|
||||
const p = Math.max(1, Number(page) || 1);
|
||||
const ps = Math.min(100, Math.max(1, Number(pageSize) || 25));
|
||||
return this.customers.list({ query, page: p, pageSize: ps, line });
|
||||
return this.customers.list({
|
||||
query,
|
||||
page: p,
|
||||
pageSize: ps,
|
||||
line,
|
||||
includeArchived: includeArchived === "true",
|
||||
});
|
||||
}
|
||||
|
||||
@Get(":id")
|
||||
detail(@Param("id") id: string) {
|
||||
return this.customers.detail(id);
|
||||
}
|
||||
|
||||
@Post()
|
||||
@RequireAbility("customer:create")
|
||||
async create(@Body() dto: CreateCustomerDto, @Req() req: Request) {
|
||||
const c = await this.customers.create(dto);
|
||||
void this.audit.log(this.actingId(req), "customer.create", { customerId: c.id, name: c.name });
|
||||
return c;
|
||||
}
|
||||
|
||||
@Patch(":id")
|
||||
@RequireAbility("customer:update")
|
||||
async update(
|
||||
@Param("id") id: string,
|
||||
@Body() dto: UpdateCustomerDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const c = await this.customers.update(id, dto);
|
||||
void this.audit.log(this.actingId(req), "customer.update", { customerId: id });
|
||||
return c;
|
||||
}
|
||||
|
||||
@Delete(":id")
|
||||
@RequireAbility("customer:delete")
|
||||
async archive(@Param("id") id: string, @Req() req: Request) {
|
||||
const c = await this.customers.archive(id);
|
||||
void this.audit.log(this.actingId(req), "customer.archive", { customerId: id });
|
||||
return c;
|
||||
}
|
||||
|
||||
@Post(":id/restore")
|
||||
@RequireAbility("customer:delete")
|
||||
async restore(@Param("id") id: string, @Req() req: Request) {
|
||||
const c = await this.customers.restore(id);
|
||||
void this.audit.log(this.actingId(req), "customer.restore", { customerId: id });
|
||||
return c;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,12 +1,23 @@
|
||||
import { Injectable, NotFoundException } from "@nestjs/common";
|
||||
import { Prisma } from "@jorgecuadros/database";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
import { CreateCustomerDto } from "./create-customer.dto";
|
||||
import { UpdateCustomerDto } from "./update-customer.dto";
|
||||
|
||||
export interface ListParams {
|
||||
query?: string;
|
||||
page: number;
|
||||
pageSize: number;
|
||||
line?: "utility" | "insurance" | "both";
|
||||
includeArchived?: boolean;
|
||||
}
|
||||
|
||||
/** Parse an optional ISO date string to a Date (or null to clear it). */
|
||||
function toDate(v?: string): Date | null | undefined {
|
||||
if (v === undefined) return undefined;
|
||||
if (v === "" || v === null) return null;
|
||||
const d = new Date(v);
|
||||
return isNaN(d.getTime()) ? undefined : d;
|
||||
}
|
||||
|
||||
@Injectable()
|
||||
@@ -14,9 +25,11 @@ export class CustomersService {
|
||||
constructor(private readonly prisma: PrismaService) {}
|
||||
|
||||
/** Unified customer list with search + business-line filter, paginated. */
|
||||
async list({ query, page, pageSize, line }: ListParams) {
|
||||
async list({ query, page, pageSize, line, includeArchived }: ListParams) {
|
||||
const where: Prisma.CustomerWhereInput = {};
|
||||
|
||||
if (!includeArchived) where.archivedAt = null;
|
||||
|
||||
if (query && query.trim()) {
|
||||
const q = query.trim();
|
||||
where.OR = [
|
||||
@@ -54,6 +67,7 @@ export class CustomersService {
|
||||
phone: true,
|
||||
mobile: true,
|
||||
status: true,
|
||||
archivedAt: true,
|
||||
_count: { select: { properties: true, policies: true, transactions: true } },
|
||||
},
|
||||
}),
|
||||
@@ -69,6 +83,7 @@ export class CustomersService {
|
||||
phone: r.phone,
|
||||
mobile: r.mobile,
|
||||
status: r.status,
|
||||
archived: r.archivedAt != null,
|
||||
propertyCount: r._count.properties,
|
||||
policyCount: r._count.policies,
|
||||
transactionCount: r._count.transactions,
|
||||
@@ -117,7 +132,8 @@ export class CustomersService {
|
||||
// business lines" payoff), computed in the DB rather than in JS.
|
||||
const summary = await this.prisma.transaction.groupBy({
|
||||
by: ["domain", "currency"],
|
||||
where: { customerId: id },
|
||||
// Exclude voided rows so the per-domain balance matches the statement.
|
||||
where: { customerId: id, voidedAt: null },
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
});
|
||||
@@ -133,6 +149,58 @@ export class CustomersService {
|
||||
};
|
||||
}
|
||||
|
||||
// --- writes ---------------------------------------------------------------
|
||||
|
||||
private toData(dto: CreateCustomerDto | UpdateCustomerDto) {
|
||||
// Whitelisted by the DTO already; map the date strings to Date objects.
|
||||
const { identificationExpiration, customerSince, ...rest } = dto;
|
||||
return {
|
||||
...rest,
|
||||
...(identificationExpiration !== undefined && {
|
||||
identificationExpiration: toDate(identificationExpiration),
|
||||
}),
|
||||
...(customerSince !== undefined && { customerSince: toDate(customerSince) }),
|
||||
};
|
||||
}
|
||||
|
||||
async create(dto: CreateCustomerDto) {
|
||||
return this.prisma.customer.create({
|
||||
// App-created rows: nameMissing false (name is required), no legacy
|
||||
// provenance — those columns stay null, marking a native record.
|
||||
data: { ...this.toData(dto), name: dto.name, nameMissing: false },
|
||||
});
|
||||
}
|
||||
|
||||
async update(id: string, dto: UpdateCustomerDto) {
|
||||
await this.ensureExists(id);
|
||||
return this.prisma.customer.update({ where: { id }, data: this.toData(dto) });
|
||||
}
|
||||
|
||||
/** Soft-delete: hide from default lists, keep the row + provenance. */
|
||||
async archive(id: string) {
|
||||
await this.ensureExists(id);
|
||||
return this.prisma.customer.update({
|
||||
where: { id },
|
||||
data: { archivedAt: new Date() },
|
||||
});
|
||||
}
|
||||
|
||||
async restore(id: string) {
|
||||
await this.ensureExists(id);
|
||||
return this.prisma.customer.update({
|
||||
where: { id },
|
||||
data: { archivedAt: null },
|
||||
});
|
||||
}
|
||||
|
||||
private async ensureExists(id: string) {
|
||||
const found = await this.prisma.customer.findUnique({
|
||||
where: { id },
|
||||
select: { id: true },
|
||||
});
|
||||
if (!found) throw new NotFoundException(`Customer ${id} not found`);
|
||||
}
|
||||
|
||||
/** Top-line counts for a dashboard header. */
|
||||
async stats() {
|
||||
const [customers, withUtilities, withInsurance, policies, properties, transactions] =
|
||||
|
||||
@@ -0,0 +1,34 @@
|
||||
import {
|
||||
IsBoolean,
|
||||
IsEmail,
|
||||
IsEnum,
|
||||
IsNumber,
|
||||
IsOptional,
|
||||
IsString,
|
||||
MinLength,
|
||||
} from "class-validator";
|
||||
import { Currency } from "@jorgecuadros/database";
|
||||
|
||||
/** Same editable fields as create, all optional. */
|
||||
export class UpdateCustomerDto {
|
||||
@IsOptional() @IsString() @MinLength(1) name?: string;
|
||||
@IsOptional() @IsString() addressLine1?: string;
|
||||
@IsOptional() @IsString() addressLine2?: string;
|
||||
@IsOptional() @IsString() city?: string;
|
||||
@IsOptional() @IsString() state?: string;
|
||||
@IsOptional() @IsString() zipCode?: string;
|
||||
@IsOptional() @IsString() country?: string;
|
||||
@IsOptional() @IsString() phone?: string;
|
||||
@IsOptional() @IsString() mobile?: string;
|
||||
@IsOptional() @IsString() fax?: string;
|
||||
@IsOptional() @IsEmail() email?: string;
|
||||
@IsOptional() @IsString() notes?: string;
|
||||
@IsOptional() @IsString() identificationType?: string;
|
||||
@IsOptional() @IsString() identificationNumber?: string;
|
||||
@IsOptional() @IsString() identificationExpiration?: string;
|
||||
@IsOptional() @IsString() customerSince?: string;
|
||||
@IsOptional() @IsBoolean() status?: boolean;
|
||||
@IsOptional() @IsNumber() minimumBalance?: number;
|
||||
@IsOptional() @IsNumber() feeAmount?: number;
|
||||
@IsOptional() @IsEnum(Currency) preferredCurrency?: Currency;
|
||||
}
|
||||
+21
-1
@@ -25,6 +25,26 @@ async function bootstrap() {
|
||||
throw new Error("SESSION_SECRET must be set (see .env.example)");
|
||||
}
|
||||
|
||||
// Whether the session cookie carries the Secure flag. This CANNOT simply
|
||||
// follow NODE_ENV: express-session silently declines to send a Secure cookie
|
||||
// over a plain-HTTP connection, so a production image served over http://ial
|
||||
// issues no cookie at all. Login then returns 200 with a user, no session is
|
||||
// established, every later request 403s, and the UI loops back to /login —
|
||||
// which is exactly what happened on the first galactus deploy.
|
||||
//
|
||||
// Leave it ON wherever the app is reached over TLS. Turn it OFF only for a
|
||||
// deployment that is HTTP but reached over an already-encrypted transport
|
||||
// (the galactus install is Tailscale-only, so WireGuard encrypts the wire).
|
||||
// Behind a TLS-terminating proxy, set trust proxy instead of turning this off.
|
||||
// An EMPTY value counts as unset, not as "false". Compose interpolation turns
|
||||
// an absent `${SESSION_COOKIE_SECURE:-}` into the empty string, so testing
|
||||
// `!== undefined` here would silently drop the Secure flag on any deployment
|
||||
// that merely passes the variable through without setting it.
|
||||
const cookieSecureRaw = process.env.SESSION_COOKIE_SECURE;
|
||||
const cookieSecure = cookieSecureRaw
|
||||
? cookieSecureRaw === "true"
|
||||
: process.env.NODE_ENV === "production";
|
||||
|
||||
app.use(
|
||||
session({
|
||||
secret: sessionSecret,
|
||||
@@ -32,7 +52,7 @@ async function bootstrap() {
|
||||
saveUninitialized: false,
|
||||
cookie: {
|
||||
httpOnly: true,
|
||||
secure: process.env.NODE_ENV === "production",
|
||||
secure: cookieSecure,
|
||||
maxAge: 1000 * 60 * 60 * 8, // 8-hour session, matches a staff workday
|
||||
},
|
||||
})
|
||||
|
||||
@@ -0,0 +1,120 @@
|
||||
import {
|
||||
Body,
|
||||
Controller,
|
||||
Delete,
|
||||
Get,
|
||||
Param,
|
||||
Post,
|
||||
Req,
|
||||
Res,
|
||||
StreamableFile,
|
||||
UploadedFile,
|
||||
UseGuards,
|
||||
UseInterceptors,
|
||||
} from "@nestjs/common";
|
||||
import { FileInterceptor } from "@nestjs/platform-express";
|
||||
import { Request, Response } from "express";
|
||||
import { AuthenticatedGuard } from "../auth/authenticated.guard";
|
||||
import { AbilityGuard } from "../auth/ability.guard";
|
||||
import { RequireAbility } from "../auth/require-ability.decorator";
|
||||
import { AuditService } from "../common/audit.service";
|
||||
import { OpsService } from "./ops.service";
|
||||
import { StartJobDto } from "./start-job.dto";
|
||||
|
||||
/** Every route is ADMIN-only (ability "db:manage"). */
|
||||
@UseGuards(AuthenticatedGuard, AbilityGuard)
|
||||
@RequireAbility("db:manage")
|
||||
@Controller("ops")
|
||||
export class OpsController {
|
||||
constructor(
|
||||
private readonly ops: OpsService,
|
||||
private readonly audit: AuditService,
|
||||
) {}
|
||||
|
||||
private actingId(req: Request): string {
|
||||
return (req.user as { id: string }).id;
|
||||
}
|
||||
|
||||
/* ------------------------------------------------------------- ingest */
|
||||
|
||||
@Get("ingest")
|
||||
listIngest() {
|
||||
return this.ops.listIngest();
|
||||
}
|
||||
|
||||
@Post("ingest/:name")
|
||||
@UseInterceptors(
|
||||
FileInterceptor("file", { limits: { fileSize: 2 * 1024 * 1024 * 1024 } }),
|
||||
)
|
||||
async uploadIngest(
|
||||
@Param("name") name: string,
|
||||
@UploadedFile() file: { buffer: Buffer; size: number } | undefined,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
if (!file) throw new Error("No se recibió ningún archivo.");
|
||||
await this.ops.saveIngest(name, file.buffer);
|
||||
void this.audit.log(this.actingId(req), "ops.ingest.upload", {
|
||||
name,
|
||||
size: file.size,
|
||||
});
|
||||
return { ok: true };
|
||||
}
|
||||
|
||||
@Delete("ingest/:name")
|
||||
async deleteIngest(@Param("name") name: string, @Req() req: Request) {
|
||||
await this.ops.deleteIngest(name);
|
||||
void this.audit.log(this.actingId(req), "ops.ingest.delete", { name });
|
||||
return { ok: true };
|
||||
}
|
||||
|
||||
/* ------------------------------------------------------------ backups */
|
||||
|
||||
@Get("backups")
|
||||
listBackups() {
|
||||
return this.ops.listBackups();
|
||||
}
|
||||
|
||||
@Get("backups/:name/download")
|
||||
download(
|
||||
@Param("name") name: string,
|
||||
@Res({ passthrough: true }) res: Response,
|
||||
): StreamableFile {
|
||||
const { stream, name: safe } = this.ops.backupStream(name);
|
||||
res.set({
|
||||
"Content-Type": "application/gzip",
|
||||
"Content-Disposition": `attachment; filename="${safe}"`,
|
||||
});
|
||||
return new StreamableFile(stream);
|
||||
}
|
||||
|
||||
@Delete("backups/:name")
|
||||
async deleteBackup(@Param("name") name: string, @Req() req: Request) {
|
||||
await this.ops.deleteBackup(name);
|
||||
void this.audit.log(this.actingId(req), "ops.backup.delete", { name });
|
||||
return { ok: true };
|
||||
}
|
||||
|
||||
/* --------------------------------------------------------------- jobs */
|
||||
|
||||
@Get("jobs")
|
||||
listJobs() {
|
||||
return this.ops.listJobs();
|
||||
}
|
||||
|
||||
@Get("jobs/:id")
|
||||
getJob(@Param("id") id: string) {
|
||||
return this.ops.getJob(id);
|
||||
}
|
||||
|
||||
@Post("jobs")
|
||||
async startJob(@Body() dto: StartJobDto, @Req() req: Request) {
|
||||
const userId = this.actingId(req);
|
||||
const job = await this.ops.startJob(dto.kind, { file: dto.file }, userId);
|
||||
void this.audit.log(userId, "ops.job.start", {
|
||||
jobId: job.id,
|
||||
kind: dto.kind,
|
||||
file: dto.file,
|
||||
});
|
||||
return job;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
import { Module } from "@nestjs/common";
|
||||
import { OpsController } from "./ops.controller";
|
||||
import { OpsService } from "./ops.service";
|
||||
|
||||
@Module({
|
||||
controllers: [OpsController],
|
||||
providers: [OpsService],
|
||||
})
|
||||
export class OpsModule {}
|
||||
@@ -0,0 +1,446 @@
|
||||
import {
|
||||
BadRequestException,
|
||||
ConflictException,
|
||||
Injectable,
|
||||
Logger,
|
||||
NotFoundException,
|
||||
OnModuleInit,
|
||||
} from "@nestjs/common";
|
||||
import { spawn } from "node:child_process";
|
||||
import { createReadStream, promises as fs } from "node:fs";
|
||||
import * as path from "node:path";
|
||||
import { OpsJobKind } from "@jorgecuadros/database";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
|
||||
/**
|
||||
* Admin database operations. Everything long-running (mysqldump, mysql restore,
|
||||
* the Python migration) runs as a detached child process recorded as one OpsJob
|
||||
* row whose `log` is appended as the process talks; the web polls that row.
|
||||
*
|
||||
* Only ONE mutating job runs at a time (a RUNNING row blocks a new start) — a
|
||||
* restore or re-import racing a migration would corrupt the database.
|
||||
*/
|
||||
|
||||
/** The four legacy Access files. Uploads are allowlisted to exactly these
|
||||
* names so an ingest write can never land at an arbitrary path. */
|
||||
export const INGEST_FILES = [
|
||||
"UTILITIES.accdb",
|
||||
"SEGUROS 16.mdb",
|
||||
"SEGUROS 16_be.mdb",
|
||||
"SCOTHIA.mdb",
|
||||
] as const;
|
||||
export type IngestName = (typeof INGEST_FILES)[number];
|
||||
|
||||
/**
|
||||
* Prefix for every command containing a pipe. Without it the exit status of
|
||||
* `mysqldump | gzip` is gzip's, so a dump that failed immediately still looks
|
||||
* like a successful job. Both Alpine's busybox ash (the API image) and macOS
|
||||
* `sh` (dev) support it; POSIX does not require it, so `sh -c` is the contract.
|
||||
*/
|
||||
const PIPEFAIL = "set -o pipefail; ";
|
||||
|
||||
interface MysqlConn {
|
||||
host: string;
|
||||
port: string;
|
||||
user: string;
|
||||
password: string;
|
||||
database: string;
|
||||
}
|
||||
|
||||
@Injectable()
|
||||
export class OpsService implements OnModuleInit {
|
||||
private readonly logger = new Logger(OpsService.name);
|
||||
|
||||
// Resolve from this source file so it works regardless of process.cwd()
|
||||
// (the API runs from apps/api/, but the Python ETL lives at repo-root migration/).
|
||||
private readonly migrationDir =
|
||||
process.env.MIGRATION_DIR ??
|
||||
path.resolve(__dirname, "..", "..", "..", "..", "migration");
|
||||
private readonly ingestDir =
|
||||
process.env.INGEST_DIR ?? path.join(this.migrationDir, "ingest");
|
||||
private readonly backupDir =
|
||||
process.env.BACKUP_DIR ?? path.join(this.migrationDir, "backups");
|
||||
private readonly migrationEnv = process.env.MIGRATION_ENV ?? "dev";
|
||||
|
||||
constructor(private readonly prisma: PrismaService) {}
|
||||
|
||||
async onModuleInit(): Promise<void> {
|
||||
await fs.mkdir(this.ingestDir, { recursive: true });
|
||||
await fs.mkdir(this.backupDir, { recursive: true });
|
||||
}
|
||||
|
||||
/* -------------------------------------------------------------- ingest */
|
||||
|
||||
private assertIngestName(name: string): IngestName {
|
||||
if (!INGEST_FILES.includes(name as IngestName)) {
|
||||
throw new BadRequestException(
|
||||
`Archivo no permitido. Debe ser uno de: ${INGEST_FILES.join(", ")}`,
|
||||
);
|
||||
}
|
||||
return name as IngestName;
|
||||
}
|
||||
|
||||
async listIngest(): Promise<
|
||||
{ name: string; present: boolean; size: number | null; modifiedAt: string | null }[]
|
||||
> {
|
||||
return Promise.all(
|
||||
INGEST_FILES.map(async (name) => {
|
||||
try {
|
||||
const st = await fs.stat(path.join(this.ingestDir, name));
|
||||
return {
|
||||
name,
|
||||
present: true,
|
||||
size: st.size,
|
||||
modifiedAt: st.mtime.toISOString(),
|
||||
};
|
||||
} catch {
|
||||
return { name, present: false, size: null, modifiedAt: null };
|
||||
}
|
||||
}),
|
||||
);
|
||||
}
|
||||
|
||||
async saveIngest(name: string, data: Buffer): Promise<void> {
|
||||
const safe = this.assertIngestName(name);
|
||||
await fs.writeFile(path.join(this.ingestDir, safe), data);
|
||||
}
|
||||
|
||||
async deleteIngest(name: string): Promise<void> {
|
||||
const safe = this.assertIngestName(name);
|
||||
await fs.rm(path.join(this.ingestDir, safe), { force: true });
|
||||
}
|
||||
|
||||
/* ------------------------------------------------------------- backups */
|
||||
|
||||
private assertBackupName(name: string): string {
|
||||
// No path separators, must be a produced backup file.
|
||||
if (!/^[A-Za-z0-9._-]+\.sql\.gz$/.test(name)) {
|
||||
throw new BadRequestException("Nombre de respaldo inválido.");
|
||||
}
|
||||
return name;
|
||||
}
|
||||
|
||||
async listBackups(): Promise<
|
||||
{ name: string; size: number; createdAt: string }[]
|
||||
> {
|
||||
let names: string[];
|
||||
try {
|
||||
names = await fs.readdir(this.backupDir);
|
||||
} catch {
|
||||
return [];
|
||||
}
|
||||
const rows = await Promise.all(
|
||||
names
|
||||
.filter((n) => n.endsWith(".sql.gz"))
|
||||
.map(async (name) => {
|
||||
const st = await fs.stat(path.join(this.backupDir, name));
|
||||
return { name, size: st.size, createdAt: st.mtime.toISOString() };
|
||||
}),
|
||||
);
|
||||
return rows.sort((a, b) => b.createdAt.localeCompare(a.createdAt));
|
||||
}
|
||||
|
||||
backupStream(name: string) {
|
||||
const safe = this.assertBackupName(name);
|
||||
const full = path.join(this.backupDir, safe);
|
||||
return { stream: createReadStream(full), name: safe };
|
||||
}
|
||||
|
||||
async deleteBackup(name: string): Promise<void> {
|
||||
const safe = this.assertBackupName(name);
|
||||
await fs.rm(path.join(this.backupDir, safe), { force: true });
|
||||
}
|
||||
|
||||
/* ---------------------------------------------------------------- jobs */
|
||||
|
||||
listJobs(limit = 20) {
|
||||
return this.prisma.opsJob.findMany({
|
||||
orderBy: { startedAt: "desc" },
|
||||
take: limit,
|
||||
});
|
||||
}
|
||||
|
||||
async getJob(id: string) {
|
||||
const job = await this.prisma.opsJob.findUnique({ where: { id } });
|
||||
if (!job) throw new NotFoundException("Trabajo no encontrado.");
|
||||
return job;
|
||||
}
|
||||
|
||||
/**
|
||||
* Start a mutating op. Refuses if another job is already RUNNING. Returns the
|
||||
* new job row immediately; the process runs on in the background and appends
|
||||
* to `log` until it exits.
|
||||
*/
|
||||
async startJob(
|
||||
kind: OpsJobKind,
|
||||
params: Record<string, unknown>,
|
||||
userId: string | undefined,
|
||||
) {
|
||||
const running = await this.prisma.opsJob.count({ where: { status: "RUNNING" } });
|
||||
if (running > 0) {
|
||||
throw new ConflictException(
|
||||
"Ya hay una operación en curso. Espere a que termine.",
|
||||
);
|
||||
}
|
||||
|
||||
const conn = this.opsConn();
|
||||
const { cmd, resolvedParams } = await this.buildCommand(kind, params, conn);
|
||||
|
||||
const job = await this.prisma.opsJob.create({
|
||||
data: {
|
||||
kind,
|
||||
status: "RUNNING",
|
||||
log: "",
|
||||
params: resolvedParams as object,
|
||||
createdById: userId,
|
||||
},
|
||||
});
|
||||
|
||||
this.run(job.id, cmd, conn.password);
|
||||
return job;
|
||||
}
|
||||
|
||||
/* --------------------------------------------------------- internals */
|
||||
|
||||
private parseDbUrl(): MysqlConn {
|
||||
const raw = process.env.DATABASE_URL;
|
||||
if (!raw) throw new BadRequestException("DATABASE_URL no está configurada.");
|
||||
const u = new URL(raw);
|
||||
return {
|
||||
host: u.hostname,
|
||||
port: u.port || "3306",
|
||||
user: decodeURIComponent(u.username),
|
||||
password: decodeURIComponent(u.password),
|
||||
database: u.pathname.replace(/^\//, ""),
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* The credentials mysqldump/mysql run as — deliberately NOT the application
|
||||
* user. `--single-transaction` issues FLUSH TABLES, which needs the global
|
||||
* RELOAD privilege, and the app user is granted only `ALL ON jorgecuadros.*`
|
||||
* plus `USAGE ON *.*`; `--skip-lock-tables` does not avoid it. A restore of a
|
||||
* dump taken before --set-gtid-purged=OFF likewise needs SUPER to replay its
|
||||
* SET @@GLOBAL.GTID_PURGED. So an admin credential is supplied out of band
|
||||
* rather than elevating the runtime user for the sake of one admin screen —
|
||||
* the same choice deploy/scripts/pre-migrate-backup.mjs makes.
|
||||
*
|
||||
* Host, port and database always come from DATABASE_URL: the ops user is a
|
||||
* different login on the SAME server, never a way to point at another one.
|
||||
*
|
||||
* With the vars unset this falls back to the DATABASE_URL credentials, which
|
||||
* is what local development wants — a dev MySQL grants the app user far more.
|
||||
*/
|
||||
private opsConn(): MysqlConn {
|
||||
const conn = this.parseDbUrl();
|
||||
const user = process.env.OPS_DB_ADMIN_USER;
|
||||
const password = process.env.OPS_DB_ADMIN_PASSWORD;
|
||||
if (!user || !password) {
|
||||
this.logger.warn(
|
||||
"OPS_DB_ADMIN_USER/OPS_DB_ADMIN_PASSWORD no configuradas; " +
|
||||
`usando el usuario de la aplicación (${conn.user}) para mysqldump. ` +
|
||||
"En producción esto falla por falta del privilegio RELOAD.",
|
||||
);
|
||||
return conn;
|
||||
}
|
||||
return { ...conn, user, password };
|
||||
}
|
||||
|
||||
/** mysql/mysqldump connection flags. The password goes through MYSQL_PWD in
|
||||
* the child env, never on the command line (which would leak via `ps`). */
|
||||
private connFlags(c: MysqlConn): string {
|
||||
return `--host=${c.host} --port=${c.port} --user=${shq(c.user)}`;
|
||||
}
|
||||
|
||||
private timestamp(): string {
|
||||
return new Date().toISOString().replace(/[:.]/g, "-").replace("T", "_").slice(0, 19);
|
||||
}
|
||||
|
||||
/**
|
||||
* One hardened mysqldump, shared by BACKUP and by the safety backups SYNC and
|
||||
* REIMPORT take first. Kept byte-for-byte in spirit with the dump in
|
||||
* deploy/scripts/pre-migrate-backup.mjs — the two write into the same volume
|
||||
* and both are listed as restore points by this same screen.
|
||||
*
|
||||
* --set-gtid-purged=OFF: the production server is the replication SOURCE with
|
||||
* GTID on, so without it every dump embeds SET @@GLOBAL.GTID_PURGED and is
|
||||
* unrestorable onto the very server it came from.
|
||||
*
|
||||
* The table-count assertion is not belt-and-braces: `gzip -t` passes on the
|
||||
* ~372-byte output of a mysqldump that died on its first statement, so a
|
||||
* failed dump would otherwise be recorded as a successful backup. (`set -o
|
||||
* pipefail` is set by the caller for the same reason — without it the exit
|
||||
* status of the pipeline is gzip's, and gzip succeeded.)
|
||||
*
|
||||
* A failed attempt deletes its own output, so a truncated file never appears
|
||||
* in the restore list looking like an ordinary restore point.
|
||||
*/
|
||||
private dumpCommand(flags: string, db: string, out: string): string {
|
||||
return (
|
||||
`( mysqldump ${flags} --single-transaction --routines --triggers ` +
|
||||
`--no-tablespaces --set-gtid-purged=OFF ${db} | gzip -c > ${out} && ` +
|
||||
`gzip -t ${out} && ` +
|
||||
`TABLAS=$(gunzip -c ${out} | grep -c 'CREATE TABLE') && ` +
|
||||
`echo "tablas capturadas: $TABLAS" && ` +
|
||||
`[ "$TABLAS" -ge 1 ] ) || ` +
|
||||
`{ rm -f ${out}; echo 'respaldo incompleto eliminado'; exit 1; }`
|
||||
);
|
||||
}
|
||||
|
||||
private async buildCommand(
|
||||
kind: OpsJobKind,
|
||||
params: Record<string, unknown>,
|
||||
conn: MysqlConn,
|
||||
): Promise<{ cmd: string; resolvedParams: Record<string, unknown> }> {
|
||||
const flags = this.connFlags(conn);
|
||||
const db = shq(conn.database);
|
||||
|
||||
if (kind === "BACKUP") {
|
||||
const file = `backup-${this.migrationEnv}-${this.timestamp()}.sql.gz`;
|
||||
const out = shq(path.join(this.backupDir, file));
|
||||
return {
|
||||
cmd: `${PIPEFAIL}${this.dumpCommand(flags, db, out)}`,
|
||||
resolvedParams: { file },
|
||||
};
|
||||
}
|
||||
|
||||
if (kind === "RESTORE") {
|
||||
const name = this.assertBackupName(String(params.file ?? ""));
|
||||
const full = path.join(this.backupDir, name);
|
||||
await fs.access(full).catch(() => {
|
||||
throw new NotFoundException(`Respaldo no encontrado: ${name}`);
|
||||
});
|
||||
return {
|
||||
// pipefail matters here too: a corrupt archive makes gunzip fail while
|
||||
// mysql, fed a truncated stream, can still exit 0 — a restore that
|
||||
// reported success having replayed only part of the dump.
|
||||
cmd: `${PIPEFAIL}gunzip -c ${shq(full)} | mysql ${flags} ${db}`,
|
||||
resolvedParams: { file: name },
|
||||
};
|
||||
}
|
||||
|
||||
if (kind === "SYNC") {
|
||||
const file = `pre-sync-${this.migrationEnv}-${this.timestamp()}.sql.gz`;
|
||||
const out = shq(path.join(this.backupDir, file));
|
||||
const py = await this.pythonBin();
|
||||
const runAll = shq(path.join(this.migrationDir, "run_all.py"));
|
||||
const cmd =
|
||||
`${PIPEFAIL}echo '== Respaldo de seguridad previo ==' && ` +
|
||||
`${this.dumpCommand(flags, db, out)} && ` +
|
||||
`echo '== Sincronización aditiva desde carpeta de ingesta ==' && ` +
|
||||
`${shq(py)} ${runAll} --env ${shq(this.migrationEnv)} --sync`;
|
||||
return { cmd, resolvedParams: { safetyBackup: file } };
|
||||
}
|
||||
|
||||
if (kind === "REIMPORT") {
|
||||
// Safety backup first, then a full truncate+rebuild from the ingest files.
|
||||
const file = `pre-reimport-${this.migrationEnv}-${this.timestamp()}.sql.gz`;
|
||||
const out = shq(path.join(this.backupDir, file));
|
||||
const py = await this.pythonBin();
|
||||
const runAll = shq(path.join(this.migrationDir, "run_all.py"));
|
||||
const cmd =
|
||||
`${PIPEFAIL}echo '== Respaldo de seguridad previo ==' && ` +
|
||||
`${this.dumpCommand(flags, db, out)} && ` +
|
||||
`echo '== Reimportación desde carpeta de ingesta ==' && ` +
|
||||
`${shq(py)} ${runAll} --env ${shq(this.migrationEnv)} --stage`;
|
||||
return { cmd, resolvedParams: { safetyBackup: file } };
|
||||
}
|
||||
|
||||
throw new BadRequestException(`Operación no soportada: ${kind}`);
|
||||
}
|
||||
|
||||
/** Prefer the migration venv python if it exists (local dev), else system. */
|
||||
private async pythonBin(): Promise<string> {
|
||||
const venv = path.join(this.migrationDir, ".venv", "bin", "python");
|
||||
try {
|
||||
await fs.access(venv);
|
||||
return venv;
|
||||
} catch {
|
||||
return process.env.PYTHON_BIN ?? "python3";
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* `password` is the ops credential from opsConn(), exported as MYSQL_PWD so it
|
||||
* never reaches argv (which `ps` exposes to every process on the host).
|
||||
*
|
||||
* It does not leak into the Python ETL that SYNC and REIMPORT go on to run:
|
||||
* migration/dbenv.py connects with pymysql using the credentials inside
|
||||
* DATABASE_URL and never consults MYSQL_PWD. The ETL keeps running as the
|
||||
* application user, which is what it should be doing.
|
||||
*/
|
||||
private run(jobId: string, cmd: string, password: string): void {
|
||||
const child = spawn("sh", ["-c", cmd], {
|
||||
cwd: this.migrationDir,
|
||||
env: {
|
||||
...process.env,
|
||||
MYSQL_PWD: password,
|
||||
INGEST_DIR: this.ingestDir,
|
||||
BACKUP_DIR: this.backupDir,
|
||||
},
|
||||
});
|
||||
|
||||
let buffer = "";
|
||||
let pending = "";
|
||||
let flushing = false;
|
||||
let flushTimer: NodeJS.Timeout | null = null;
|
||||
|
||||
const flush = async () => {
|
||||
if (flushing || !pending) return;
|
||||
flushing = true;
|
||||
const chunk = pending;
|
||||
pending = "";
|
||||
try {
|
||||
await this.prisma.opsJob.update({
|
||||
where: { id: jobId },
|
||||
data: { log: { set: buffer } },
|
||||
});
|
||||
} catch (e) {
|
||||
this.logger.warn(`ops job ${jobId} log flush failed: ${String(e)}`);
|
||||
} finally {
|
||||
flushing = false;
|
||||
void chunk;
|
||||
}
|
||||
};
|
||||
|
||||
const onData = (d: Buffer) => {
|
||||
const text = d.toString();
|
||||
buffer += text;
|
||||
pending += text;
|
||||
if (!flushTimer) {
|
||||
flushTimer = setTimeout(() => {
|
||||
flushTimer = null;
|
||||
void flush();
|
||||
}, 1000);
|
||||
}
|
||||
};
|
||||
|
||||
child.stdout.on("data", onData);
|
||||
child.stderr.on("data", onData);
|
||||
|
||||
const finalize = async (status: "SUCCESS" | "FAILED", tail: string) => {
|
||||
if (flushTimer) clearTimeout(flushTimer);
|
||||
buffer += tail;
|
||||
await this.prisma.opsJob
|
||||
.update({
|
||||
where: { id: jobId },
|
||||
data: { status, log: { set: buffer }, finishedAt: new Date() },
|
||||
})
|
||||
.catch((e) => this.logger.error(`ops job ${jobId} finalize failed: ${String(e)}`));
|
||||
};
|
||||
|
||||
child.on("error", (err) => {
|
||||
void finalize("FAILED", `\n[proceso no pudo iniciar] ${err.message}\n`);
|
||||
});
|
||||
|
||||
child.on("close", (code) => {
|
||||
if (code === 0) void finalize("SUCCESS", `\n[completado con éxito]\n`);
|
||||
else void finalize("FAILED", `\n[terminó con código ${code}]\n`);
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
/** Single-quote a value for a POSIX shell command. */
|
||||
function shq(v: string): string {
|
||||
return `'${v.replace(/'/g, `'\\''`)}'`;
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
import { IsEnum, IsOptional, IsString } from "class-validator";
|
||||
import { OpsJobKind } from "@jorgecuadros/database";
|
||||
|
||||
export class StartJobDto {
|
||||
@IsEnum(OpsJobKind)
|
||||
kind!: OpsJobKind;
|
||||
|
||||
/** Target backup filename — required for RESTORE, ignored otherwise. */
|
||||
@IsOptional()
|
||||
@IsString()
|
||||
file?: string;
|
||||
}
|
||||
@@ -0,0 +1,78 @@
|
||||
import {
|
||||
IsBoolean,
|
||||
IsEmail,
|
||||
IsEnum,
|
||||
IsInt,
|
||||
IsNumber,
|
||||
IsOptional,
|
||||
IsString,
|
||||
} from "class-validator";
|
||||
import { Currency } from "@jorgecuadros/database";
|
||||
|
||||
// Each child DTO covers create; updates reuse the same shape with all fields
|
||||
// optional via the corresponding Update class. Route supplies the policyId.
|
||||
|
||||
export class InstallmentDto {
|
||||
@IsInt() sequence!: number;
|
||||
@IsOptional() @IsNumber() amount?: number;
|
||||
@IsOptional() @IsEnum(Currency) currency?: Currency;
|
||||
@IsOptional() @IsString() dueDate?: string;
|
||||
@IsOptional() @IsString() paidDate?: string;
|
||||
@IsOptional() @IsString() checkNumber?: string;
|
||||
@IsOptional() @IsBoolean() isCash?: boolean;
|
||||
}
|
||||
export class UpdateInstallmentDto {
|
||||
@IsOptional() @IsInt() sequence?: number;
|
||||
@IsOptional() @IsNumber() amount?: number;
|
||||
@IsOptional() @IsEnum(Currency) currency?: Currency;
|
||||
@IsOptional() @IsString() dueDate?: string;
|
||||
@IsOptional() @IsString() paidDate?: string;
|
||||
@IsOptional() @IsString() checkNumber?: string;
|
||||
@IsOptional() @IsBoolean() isCash?: boolean;
|
||||
}
|
||||
|
||||
export class VehicleDto {
|
||||
@IsOptional() @IsString() make?: string;
|
||||
@IsOptional() @IsString() model?: string;
|
||||
@IsOptional() @IsString() modelYear?: string;
|
||||
@IsOptional() @IsString() bodyType?: string;
|
||||
@IsOptional() @IsString() engineNumber?: string;
|
||||
@IsOptional() @IsString() licensePlate?: string;
|
||||
@IsOptional() @IsString() vinNumber?: string;
|
||||
@IsOptional() @IsString() stateCode?: string;
|
||||
@IsOptional() @IsString() notes?: string;
|
||||
}
|
||||
export class UpdateVehicleDto extends VehicleDto {}
|
||||
|
||||
export class DriverDto {
|
||||
@IsOptional() @IsString() fullName?: string;
|
||||
@IsOptional() @IsString() birthDate?: string;
|
||||
@IsOptional() @IsString() sex?: string;
|
||||
@IsOptional() @IsString() occupation?: string;
|
||||
@IsOptional() @IsString() licenseNumber?: string;
|
||||
@IsOptional() @IsString() licenseState?: string;
|
||||
}
|
||||
export class UpdateDriverDto extends DriverDto {}
|
||||
|
||||
export class BeneficiaryDto {
|
||||
@IsOptional() @IsString() name?: string;
|
||||
@IsOptional() @IsString() address?: string;
|
||||
@IsOptional() @IsString() phone?: string;
|
||||
@IsOptional() @IsEmail() email?: string;
|
||||
}
|
||||
export class UpdateBeneficiaryDto extends BeneficiaryDto {}
|
||||
|
||||
export class ClaimDto {
|
||||
@IsOptional() @IsString() claimType?: string;
|
||||
@IsOptional() @IsString() incidentDate?: string;
|
||||
@IsOptional() @IsString() reportedDate?: string;
|
||||
@IsOptional() @IsString() description?: string;
|
||||
@IsOptional() @IsString() adjusterId?: string;
|
||||
@IsOptional() @IsNumber() claimedAmount?: number;
|
||||
@IsOptional() @IsNumber() settledAmount?: number;
|
||||
@IsOptional() @IsString() settlementDate?: string;
|
||||
@IsOptional() @IsString() checkNumber?: string;
|
||||
@IsOptional() @IsBoolean() resolved?: boolean;
|
||||
@IsOptional() @IsString() resolutionNotes?: string;
|
||||
}
|
||||
export class UpdateClaimDto extends ClaimDto {}
|
||||
@@ -0,0 +1,26 @@
|
||||
import { IsOptional, IsString, MinLength } from "class-validator";
|
||||
|
||||
export class ProviderDto {
|
||||
@IsString() @MinLength(1) name!: string;
|
||||
}
|
||||
export class UpdateProviderDto {
|
||||
@IsOptional() @IsString() @MinLength(1) name?: string;
|
||||
}
|
||||
|
||||
export class PolicyTypeDto {
|
||||
@IsString() @MinLength(1) name!: string;
|
||||
@IsOptional() @IsString() shortDescription?: string;
|
||||
}
|
||||
export class UpdatePolicyTypeDto {
|
||||
@IsOptional() @IsString() @MinLength(1) name?: string;
|
||||
@IsOptional() @IsString() shortDescription?: string;
|
||||
}
|
||||
|
||||
export class AdjusterDto {
|
||||
@IsOptional() @IsString() company?: string;
|
||||
@IsOptional() @IsString() city?: string;
|
||||
@IsOptional() @IsString() name?: string;
|
||||
@IsOptional() @IsString() phone?: string;
|
||||
@IsOptional() @IsString() beeper?: string;
|
||||
}
|
||||
export class UpdateAdjusterDto extends AdjusterDto {}
|
||||
@@ -0,0 +1,146 @@
|
||||
import {
|
||||
Body,
|
||||
Controller,
|
||||
Delete,
|
||||
Get,
|
||||
Param,
|
||||
Patch,
|
||||
Post,
|
||||
Req,
|
||||
UseGuards,
|
||||
} from "@nestjs/common";
|
||||
import { Request } from "express";
|
||||
import { AuthenticatedGuard } from "../auth/authenticated.guard";
|
||||
import { AbilityGuard } from "../auth/ability.guard";
|
||||
import { RequireAbility } from "../auth/require-ability.decorator";
|
||||
import { AuditService } from "../common/audit.service";
|
||||
import { PoliciesService } from "./policies.service";
|
||||
import {
|
||||
AdjusterDto,
|
||||
PolicyTypeDto,
|
||||
ProviderDto,
|
||||
UpdateAdjusterDto,
|
||||
UpdatePolicyTypeDto,
|
||||
UpdateProviderDto,
|
||||
} from "./lookup.dto";
|
||||
|
||||
/**
|
||||
* Insurance reference data: providers, policy types, adjusters. Reading is open
|
||||
* to any authenticated user (the policy form needs the options); mutating needs
|
||||
* "lookup:manage" (MANAGER+).
|
||||
*/
|
||||
@UseGuards(AuthenticatedGuard, AbilityGuard)
|
||||
@Controller("lookups")
|
||||
export class LookupsController {
|
||||
constructor(
|
||||
private readonly policies: PoliciesService,
|
||||
private readonly audit: AuditService,
|
||||
) {}
|
||||
|
||||
private actingId(req: Request): string {
|
||||
return (req.user as { id: string }).id;
|
||||
}
|
||||
|
||||
@Get()
|
||||
list() {
|
||||
return this.policies.listLookups();
|
||||
}
|
||||
|
||||
@Post("providers")
|
||||
@RequireAbility("lookup:manage")
|
||||
async createProvider(@Body() dto: ProviderDto, @Req() req: Request) {
|
||||
const row = await this.policies.createProvider(dto);
|
||||
void this.audit.log(this.actingId(req), "lookup.provider.create", {
|
||||
providerId: row.id,
|
||||
name: row.name,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
@Patch("providers/:id")
|
||||
@RequireAbility("lookup:manage")
|
||||
async updateProvider(
|
||||
@Param("id") id: string,
|
||||
@Body() dto: UpdateProviderDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const row = await this.policies.updateProvider(id, dto);
|
||||
void this.audit.log(this.actingId(req), "lookup.provider.update", {
|
||||
providerId: id,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
@Delete("providers/:id")
|
||||
@RequireAbility("lookup:manage")
|
||||
async removeProvider(@Param("id") id: string, @Req() req: Request) {
|
||||
const row = await this.policies.removeProvider(id);
|
||||
void this.audit.log(this.actingId(req), "lookup.provider.delete", {
|
||||
providerId: id,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
|
||||
@Post("policy-types")
|
||||
@RequireAbility("lookup:manage")
|
||||
async createType(@Body() dto: PolicyTypeDto, @Req() req: Request) {
|
||||
const row = await this.policies.createPolicyType(dto);
|
||||
void this.audit.log(this.actingId(req), "lookup.policyType.create", {
|
||||
policyTypeId: row.id,
|
||||
name: row.name,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
@Patch("policy-types/:id")
|
||||
@RequireAbility("lookup:manage")
|
||||
async updateType(
|
||||
@Param("id") id: string,
|
||||
@Body() dto: UpdatePolicyTypeDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const row = await this.policies.updatePolicyType(id, dto);
|
||||
void this.audit.log(this.actingId(req), "lookup.policyType.update", {
|
||||
policyTypeId: id,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
@Delete("policy-types/:id")
|
||||
@RequireAbility("lookup:manage")
|
||||
async removeType(@Param("id") id: string, @Req() req: Request) {
|
||||
const row = await this.policies.removePolicyType(id);
|
||||
void this.audit.log(this.actingId(req), "lookup.policyType.delete", {
|
||||
policyTypeId: id,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
|
||||
@Post("adjusters")
|
||||
@RequireAbility("lookup:manage")
|
||||
async createAdjuster(@Body() dto: AdjusterDto, @Req() req: Request) {
|
||||
const row = await this.policies.createAdjuster(dto);
|
||||
void this.audit.log(this.actingId(req), "lookup.adjuster.create", {
|
||||
adjusterId: row.id,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
@Patch("adjusters/:id")
|
||||
@RequireAbility("lookup:manage")
|
||||
async updateAdjuster(
|
||||
@Param("id") id: string,
|
||||
@Body() dto: UpdateAdjusterDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const row = await this.policies.updateAdjuster(id, dto);
|
||||
void this.audit.log(this.actingId(req), "lookup.adjuster.update", {
|
||||
adjusterId: id,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
@Delete("adjusters/:id")
|
||||
@RequireAbility("lookup:manage")
|
||||
async removeAdjuster(@Param("id") id: string, @Req() req: Request) {
|
||||
const row = await this.policies.removeAdjuster(id);
|
||||
void this.audit.log(this.actingId(req), "lookup.adjuster.delete", {
|
||||
adjusterId: id,
|
||||
});
|
||||
return row;
|
||||
}
|
||||
}
|
||||
@@ -1,10 +1,43 @@
|
||||
import { Controller, Get, Param, Query, UseGuards } from "@nestjs/common";
|
||||
import {
|
||||
Body,
|
||||
Controller,
|
||||
Delete,
|
||||
Get,
|
||||
Param,
|
||||
Patch,
|
||||
Post,
|
||||
Query,
|
||||
Req,
|
||||
Res,
|
||||
StreamableFile,
|
||||
UploadedFile,
|
||||
UseGuards,
|
||||
UseInterceptors,
|
||||
} from "@nestjs/common";
|
||||
import { FileInterceptor } from "@nestjs/platform-express";
|
||||
import { Request, Response } from "express";
|
||||
import { downloadName, type UploadedFileLike } from "../storage/upload-file";
|
||||
import { AuthenticatedGuard } from "../auth/authenticated.guard";
|
||||
import { AbilityGuard } from "../auth/ability.guard";
|
||||
import { RequireAbility } from "../auth/require-ability.decorator";
|
||||
import { AuditService } from "../common/audit.service";
|
||||
import {
|
||||
PoliciesService,
|
||||
type PolicySort,
|
||||
type PolicyStatus,
|
||||
} from "./policies.service";
|
||||
import { CreatePolicyDto, UpdatePolicyDto } from "./policy.dto";
|
||||
import {
|
||||
BeneficiaryDto,
|
||||
ClaimDto,
|
||||
DriverDto,
|
||||
InstallmentDto,
|
||||
UpdateBeneficiaryDto,
|
||||
UpdateClaimDto,
|
||||
UpdateDriverDto,
|
||||
UpdateInstallmentDto,
|
||||
VehicleDto,
|
||||
} from "./children.dto";
|
||||
|
||||
const STATUSES: PolicyStatus[] = ["active", "expiring", "expired", "undated"];
|
||||
const SORTS: PolicySort[] = [
|
||||
@@ -15,15 +48,21 @@ const SORTS: PolicySort[] = [
|
||||
"premium_desc",
|
||||
];
|
||||
|
||||
/** Clamped expiry window; 30 days is the default renewal horizon. */
|
||||
function parseDays(days?: string): number {
|
||||
return Math.min(365, Math.max(1, Number(days) || 30));
|
||||
}
|
||||
|
||||
@UseGuards(AuthenticatedGuard)
|
||||
@UseGuards(AuthenticatedGuard, AbilityGuard)
|
||||
@Controller("policies")
|
||||
export class PoliciesController {
|
||||
constructor(private readonly policies: PoliciesService) {}
|
||||
constructor(
|
||||
private readonly policies: PoliciesService,
|
||||
private readonly audit: AuditService,
|
||||
) {}
|
||||
|
||||
private actingId(req: Request): string {
|
||||
return (req.user as { id: string }).id;
|
||||
}
|
||||
|
||||
@Get("stats")
|
||||
stats(@Query("days") days?: string) {
|
||||
@@ -45,6 +84,7 @@ export class PoliciesController {
|
||||
@Query("typeId") typeId?: string,
|
||||
@Query("providerId") providerId?: string,
|
||||
@Query("liquidated") liquidated?: string,
|
||||
@Query("includeArchived") includeArchived?: string,
|
||||
@Query("sort") sort?: string,
|
||||
) {
|
||||
return this.policies.list({
|
||||
@@ -59,6 +99,7 @@ export class PoliciesController {
|
||||
providerId: providerId || undefined,
|
||||
liquidated:
|
||||
liquidated === "true" ? true : liquidated === "false" ? false : undefined,
|
||||
includeArchived: includeArchived === "true",
|
||||
sort: SORTS.includes(sort as PolicySort)
|
||||
? (sort as PolicySort)
|
||||
: "expiry_desc",
|
||||
@@ -69,4 +110,176 @@ export class PoliciesController {
|
||||
detail(@Param("id") id: string, @Query("days") days?: string) {
|
||||
return this.policies.detail(id, parseDays(days));
|
||||
}
|
||||
|
||||
// --- header writes --------------------------------------------------------
|
||||
|
||||
@Post()
|
||||
@RequireAbility("policy:create")
|
||||
async create(@Body() dto: CreatePolicyDto, @Req() req: Request) {
|
||||
const p = await this.policies.create(dto);
|
||||
void this.audit.log(this.actingId(req), "policy.create", { policyId: p.id });
|
||||
return p;
|
||||
}
|
||||
|
||||
@Patch(":id")
|
||||
@RequireAbility("policy:update")
|
||||
async update(@Param("id") id: string, @Body() dto: UpdatePolicyDto, @Req() req: Request) {
|
||||
const p = await this.policies.update(id, dto);
|
||||
void this.audit.log(this.actingId(req), "policy.update", { policyId: id });
|
||||
return p;
|
||||
}
|
||||
|
||||
@Delete(":id")
|
||||
@RequireAbility("policy:delete")
|
||||
async archive(@Param("id") id: string, @Req() req: Request) {
|
||||
const p = await this.policies.archive(id);
|
||||
void this.audit.log(this.actingId(req), "policy.archive", { policyId: id });
|
||||
return p;
|
||||
}
|
||||
|
||||
@Post(":id/restore")
|
||||
@RequireAbility("policy:delete")
|
||||
async restore(@Param("id") id: string, @Req() req: Request) {
|
||||
const p = await this.policies.restore(id);
|
||||
void this.audit.log(this.actingId(req), "policy.restore", { policyId: id });
|
||||
return p;
|
||||
}
|
||||
|
||||
// --- children (all editing a policy => policy:update) ---------------------
|
||||
|
||||
@Post(":id/installments")
|
||||
@RequireAbility("policy:update")
|
||||
addInstallment(@Param("id") id: string, @Body() dto: InstallmentDto) {
|
||||
return this.policies.addInstallment(id, dto);
|
||||
}
|
||||
@Patch(":id/installments/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
updateInstallment(
|
||||
@Param("id") id: string,
|
||||
@Param("childId") childId: string,
|
||||
@Body() dto: UpdateInstallmentDto,
|
||||
) {
|
||||
return this.policies.updateInstallment(id, childId, dto);
|
||||
}
|
||||
@Delete(":id/installments/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
removeInstallment(@Param("id") id: string, @Param("childId") childId: string) {
|
||||
return this.policies.removeInstallment(id, childId);
|
||||
}
|
||||
|
||||
@Post(":id/vehicles")
|
||||
@RequireAbility("policy:update")
|
||||
addVehicle(@Param("id") id: string, @Body() dto: VehicleDto) {
|
||||
return this.policies.addVehicle(id, dto);
|
||||
}
|
||||
@Patch(":id/vehicles/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
updateVehicle(
|
||||
@Param("id") id: string,
|
||||
@Param("childId") childId: string,
|
||||
@Body() dto: VehicleDto,
|
||||
) {
|
||||
return this.policies.updateVehicle(id, childId, dto);
|
||||
}
|
||||
@Delete(":id/vehicles/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
removeVehicle(@Param("id") id: string, @Param("childId") childId: string) {
|
||||
return this.policies.removeVehicle(id, childId);
|
||||
}
|
||||
|
||||
@Post(":id/drivers")
|
||||
@RequireAbility("policy:update")
|
||||
addDriver(@Param("id") id: string, @Body() dto: DriverDto) {
|
||||
return this.policies.addDriver(id, dto);
|
||||
}
|
||||
@Patch(":id/drivers/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
updateDriver(
|
||||
@Param("id") id: string,
|
||||
@Param("childId") childId: string,
|
||||
@Body() dto: UpdateDriverDto,
|
||||
) {
|
||||
return this.policies.updateDriver(id, childId, dto);
|
||||
}
|
||||
@Delete(":id/drivers/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
removeDriver(@Param("id") id: string, @Param("childId") childId: string) {
|
||||
return this.policies.removeDriver(id, childId);
|
||||
}
|
||||
|
||||
@Post(":id/beneficiaries")
|
||||
@RequireAbility("policy:update")
|
||||
addBeneficiary(@Param("id") id: string, @Body() dto: BeneficiaryDto) {
|
||||
return this.policies.addBeneficiary(id, dto);
|
||||
}
|
||||
@Patch(":id/beneficiaries/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
updateBeneficiary(
|
||||
@Param("id") id: string,
|
||||
@Param("childId") childId: string,
|
||||
@Body() dto: UpdateBeneficiaryDto,
|
||||
) {
|
||||
return this.policies.updateBeneficiary(id, childId, dto);
|
||||
}
|
||||
@Delete(":id/beneficiaries/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
removeBeneficiary(@Param("id") id: string, @Param("childId") childId: string) {
|
||||
return this.policies.removeBeneficiary(id, childId);
|
||||
}
|
||||
|
||||
@Post(":id/claims")
|
||||
@RequireAbility("policy:update")
|
||||
addClaim(@Param("id") id: string, @Body() dto: ClaimDto) {
|
||||
return this.policies.addClaim(id, dto);
|
||||
}
|
||||
@Patch(":id/claims/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
updateClaim(
|
||||
@Param("id") id: string,
|
||||
@Param("childId") childId: string,
|
||||
@Body() dto: UpdateClaimDto,
|
||||
) {
|
||||
return this.policies.updateClaim(id, childId, dto);
|
||||
}
|
||||
@Delete(":id/claims/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
removeClaim(@Param("id") id: string, @Param("childId") childId: string) {
|
||||
return this.policies.removeClaim(id, childId);
|
||||
}
|
||||
|
||||
// --- documents ------------------------------------------------------------
|
||||
|
||||
@Post(":id/documents")
|
||||
@RequireAbility("policy:update")
|
||||
@UseInterceptors(
|
||||
FileInterceptor("file", { limits: { fileSize: 50 * 1024 * 1024 } }),
|
||||
)
|
||||
addDocument(
|
||||
@Param("id") id: string,
|
||||
@UploadedFile() file: UploadedFileLike | undefined,
|
||||
@Query("type") type: string | undefined,
|
||||
) {
|
||||
if (!file) throw new Error("No se recibió ningún archivo.");
|
||||
return this.policies.addDocument(id, file, type);
|
||||
}
|
||||
|
||||
@Get(":id/documents/:childId/download")
|
||||
async downloadDocument(
|
||||
@Param("id") id: string,
|
||||
@Param("childId") childId: string,
|
||||
@Res({ passthrough: true }) res: Response,
|
||||
): Promise<StreamableFile> {
|
||||
const { row, stream, contentType } = await this.policies.getDocument(id, childId);
|
||||
res.set({
|
||||
"Content-Type": contentType ?? "application/octet-stream",
|
||||
"Content-Disposition": `attachment; filename="${downloadName(row.storageKey, row.documentType)}"`,
|
||||
});
|
||||
return new StreamableFile(stream);
|
||||
}
|
||||
|
||||
@Delete(":id/documents/:childId")
|
||||
@RequireAbility("policy:update")
|
||||
removeDocument(@Param("id") id: string, @Param("childId") childId: string) {
|
||||
return this.policies.removeDocument(id, childId);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,9 +1,10 @@
|
||||
import { Module } from "@nestjs/common";
|
||||
import { PoliciesController } from "./policies.controller";
|
||||
import { LookupsController } from "./lookups.controller";
|
||||
import { PoliciesService } from "./policies.service";
|
||||
|
||||
@Module({
|
||||
controllers: [PoliciesController],
|
||||
controllers: [PoliciesController, LookupsController],
|
||||
providers: [PoliciesService],
|
||||
})
|
||||
export class PoliciesModule {}
|
||||
|
||||
@@ -1,6 +1,30 @@
|
||||
import { Injectable, NotFoundException } from "@nestjs/common";
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { Prisma } from "@jorgecuadros/database";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
import { StorageService } from "../storage/storage.service";
|
||||
import { extForUpload, type UploadedFileLike } from "../storage/upload-file";
|
||||
import { toDate } from "../common/coerce";
|
||||
import { CreatePolicyDto, UpdatePolicyDto } from "./policy.dto";
|
||||
import {
|
||||
BeneficiaryDto,
|
||||
ClaimDto,
|
||||
DriverDto,
|
||||
InstallmentDto,
|
||||
UpdateBeneficiaryDto,
|
||||
UpdateClaimDto,
|
||||
UpdateDriverDto,
|
||||
UpdateInstallmentDto,
|
||||
VehicleDto,
|
||||
} from "./children.dto";
|
||||
import {
|
||||
AdjusterDto,
|
||||
PolicyTypeDto,
|
||||
ProviderDto,
|
||||
UpdateAdjusterDto,
|
||||
UpdatePolicyTypeDto,
|
||||
UpdateProviderDto,
|
||||
} from "./lookup.dto";
|
||||
|
||||
/**
|
||||
* Vigencia buckets, derived from `policyTo` against today. `undated` is a real
|
||||
@@ -27,6 +51,7 @@ export interface ListParams {
|
||||
typeId?: string;
|
||||
providerId?: string;
|
||||
liquidated?: boolean;
|
||||
includeArchived?: boolean;
|
||||
sort: PolicySort;
|
||||
}
|
||||
|
||||
@@ -55,7 +80,10 @@ function daysUntil(policyTo: Date | null, from: Date): number | null {
|
||||
|
||||
@Injectable()
|
||||
export class PoliciesService {
|
||||
constructor(private readonly prisma: PrismaService) {}
|
||||
constructor(
|
||||
private readonly prisma: PrismaService,
|
||||
private readonly storage: StorageService,
|
||||
) {}
|
||||
|
||||
private statusWhere(
|
||||
status: PolicyStatus | undefined,
|
||||
@@ -97,11 +125,13 @@ export class PoliciesService {
|
||||
|
||||
/** Policy list with search, vigencia/type/provider filters, paginated. */
|
||||
async list(params: ListParams) {
|
||||
const { query, page, pageSize, status, days, typeId, providerId, liquidated, sort } =
|
||||
params;
|
||||
const { query, page, pageSize, status, days, typeId, providerId, liquidated,
|
||||
includeArchived, sort } = params;
|
||||
|
||||
const where: Prisma.PolicyWhereInput = { ...this.statusWhere(status, days) };
|
||||
|
||||
if (!includeArchived) where.archivedAt = null;
|
||||
|
||||
if (query && query.trim()) {
|
||||
const q = query.trim();
|
||||
where.OR = [
|
||||
@@ -134,6 +164,7 @@ export class PoliciesService {
|
||||
total: true,
|
||||
currency: true,
|
||||
liquidated: true,
|
||||
archivedAt: true,
|
||||
customer: { select: { id: true, name: true, city: true } },
|
||||
policyType: { select: { id: true, name: true } },
|
||||
insuranceProvider: { select: { id: true, name: true } },
|
||||
@@ -155,6 +186,7 @@ export class PoliciesService {
|
||||
total: r.total,
|
||||
currency: r.currency,
|
||||
liquidated: r.liquidated,
|
||||
archived: r.archivedAt != null,
|
||||
customerId: r.customer.id,
|
||||
customerName: r.customer.name,
|
||||
customerCity: r.customer.city,
|
||||
@@ -278,4 +310,270 @@ export class PoliciesService {
|
||||
daysToExpiry: daysUntil(policy.policyTo, from),
|
||||
};
|
||||
}
|
||||
|
||||
// --- policy header writes -------------------------------------------------
|
||||
|
||||
private headerData(dto: CreatePolicyDto | UpdatePolicyDto) {
|
||||
const { policyDate, policyFrom, policyTo, liquidationDate, ...rest } =
|
||||
dto as CreatePolicyDto;
|
||||
return {
|
||||
...rest,
|
||||
...(policyDate !== undefined && { policyDate: toDate(policyDate) }),
|
||||
...(policyFrom !== undefined && { policyFrom: toDate(policyFrom) }),
|
||||
...(policyTo !== undefined && { policyTo: toDate(policyTo) }),
|
||||
...(liquidationDate !== undefined && { liquidationDate: toDate(liquidationDate) }),
|
||||
};
|
||||
}
|
||||
|
||||
async create(dto: CreatePolicyDto) {
|
||||
// Validate the customer FK up front for a clean 404 instead of a raw
|
||||
// Prisma constraint error.
|
||||
const customer = await this.prisma.customer.findUnique({
|
||||
where: { id: dto.customerId },
|
||||
select: { id: true },
|
||||
});
|
||||
if (!customer) throw new NotFoundException(`Customer ${dto.customerId} not found`);
|
||||
|
||||
return this.prisma.policy.create({
|
||||
data: {
|
||||
...this.headerData(dto),
|
||||
policyNumber: dto.policyNumber,
|
||||
customerId: dto.customerId,
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
async update(id: string, dto: UpdatePolicyDto) {
|
||||
await this.ensurePolicy(id);
|
||||
return this.prisma.policy.update({ where: { id }, data: this.headerData(dto) });
|
||||
}
|
||||
|
||||
async archive(id: string) {
|
||||
await this.ensurePolicy(id);
|
||||
return this.prisma.policy.update({ where: { id }, data: { archivedAt: new Date() } });
|
||||
}
|
||||
|
||||
async restore(id: string) {
|
||||
await this.ensurePolicy(id);
|
||||
return this.prisma.policy.update({ where: { id }, data: { archivedAt: null } });
|
||||
}
|
||||
|
||||
private async ensurePolicy(id: string) {
|
||||
const found = await this.prisma.policy.findUnique({
|
||||
where: { id },
|
||||
select: { id: true },
|
||||
});
|
||||
if (!found) throw new NotFoundException(`Policy ${id} not found`);
|
||||
}
|
||||
|
||||
// --- child rows -----------------------------------------------------------
|
||||
// Each child is created under a policy and edited/removed by its own id,
|
||||
// scoped to that policy so one policy's id can't touch another's rows.
|
||||
|
||||
private async ensureChild(
|
||||
model: "policyPaymentInstallment" | "vehicle" | "insuredDriver" | "policyBeneficiary" | "claim",
|
||||
policyId: string,
|
||||
childId: string,
|
||||
) {
|
||||
await this.ensurePolicy(policyId);
|
||||
// @ts-expect-error dynamic delegate access is safe for these known models
|
||||
const row = await this.prisma[model].findFirst({
|
||||
where: { id: childId, policyId },
|
||||
select: { id: true },
|
||||
});
|
||||
if (!row) throw new NotFoundException(`Child ${childId} not found on policy ${policyId}`);
|
||||
}
|
||||
|
||||
async addInstallment(policyId: string, dto: InstallmentDto) {
|
||||
await this.ensurePolicy(policyId);
|
||||
return this.prisma.policyPaymentInstallment.create({
|
||||
data: {
|
||||
policyId,
|
||||
sequence: dto.sequence,
|
||||
amount: dto.amount,
|
||||
currency: dto.currency,
|
||||
dueDate: toDate(dto.dueDate) ?? undefined,
|
||||
paidDate: toDate(dto.paidDate) ?? undefined,
|
||||
checkNumber: dto.checkNumber,
|
||||
isCash: dto.isCash,
|
||||
},
|
||||
});
|
||||
}
|
||||
async updateInstallment(policyId: string, id: string, dto: UpdateInstallmentDto) {
|
||||
await this.ensureChild("policyPaymentInstallment", policyId, id);
|
||||
return this.prisma.policyPaymentInstallment.update({
|
||||
where: { id },
|
||||
data: {
|
||||
sequence: dto.sequence,
|
||||
amount: dto.amount,
|
||||
currency: dto.currency,
|
||||
...(dto.dueDate !== undefined && { dueDate: toDate(dto.dueDate) }),
|
||||
...(dto.paidDate !== undefined && { paidDate: toDate(dto.paidDate) }),
|
||||
checkNumber: dto.checkNumber,
|
||||
isCash: dto.isCash,
|
||||
},
|
||||
});
|
||||
}
|
||||
async removeInstallment(policyId: string, id: string) {
|
||||
await this.ensureChild("policyPaymentInstallment", policyId, id);
|
||||
return this.prisma.policyPaymentInstallment.delete({ where: { id } });
|
||||
}
|
||||
|
||||
async addVehicle(policyId: string, dto: VehicleDto) {
|
||||
await this.ensurePolicy(policyId);
|
||||
return this.prisma.vehicle.create({ data: { policyId, ...dto } });
|
||||
}
|
||||
async updateVehicle(policyId: string, id: string, dto: VehicleDto) {
|
||||
await this.ensureChild("vehicle", policyId, id);
|
||||
return this.prisma.vehicle.update({ where: { id }, data: { ...dto } });
|
||||
}
|
||||
async removeVehicle(policyId: string, id: string) {
|
||||
await this.ensureChild("vehicle", policyId, id);
|
||||
return this.prisma.vehicle.delete({ where: { id } });
|
||||
}
|
||||
|
||||
async addDriver(policyId: string, dto: DriverDto) {
|
||||
await this.ensurePolicy(policyId);
|
||||
return this.prisma.insuredDriver.create({
|
||||
data: { policyId, ...dto, birthDate: toDate(dto.birthDate) ?? undefined },
|
||||
});
|
||||
}
|
||||
async updateDriver(policyId: string, id: string, dto: UpdateDriverDto) {
|
||||
await this.ensureChild("insuredDriver", policyId, id);
|
||||
return this.prisma.insuredDriver.update({
|
||||
where: { id },
|
||||
data: { ...dto, ...(dto.birthDate !== undefined && { birthDate: toDate(dto.birthDate) }) },
|
||||
});
|
||||
}
|
||||
async removeDriver(policyId: string, id: string) {
|
||||
await this.ensureChild("insuredDriver", policyId, id);
|
||||
return this.prisma.insuredDriver.delete({ where: { id } });
|
||||
}
|
||||
|
||||
async addBeneficiary(policyId: string, dto: BeneficiaryDto) {
|
||||
await this.ensurePolicy(policyId);
|
||||
return this.prisma.policyBeneficiary.create({ data: { policyId, ...dto } });
|
||||
}
|
||||
async updateBeneficiary(policyId: string, id: string, dto: UpdateBeneficiaryDto) {
|
||||
await this.ensureChild("policyBeneficiary", policyId, id);
|
||||
return this.prisma.policyBeneficiary.update({ where: { id }, data: { ...dto } });
|
||||
}
|
||||
async removeBeneficiary(policyId: string, id: string) {
|
||||
await this.ensureChild("policyBeneficiary", policyId, id);
|
||||
return this.prisma.policyBeneficiary.delete({ where: { id } });
|
||||
}
|
||||
|
||||
async addClaim(policyId: string, dto: ClaimDto) {
|
||||
await this.ensurePolicy(policyId);
|
||||
return this.prisma.claim.create({ data: { policyId, ...this.claimData(dto) } });
|
||||
}
|
||||
async updateClaim(policyId: string, id: string, dto: UpdateClaimDto) {
|
||||
await this.ensureChild("claim", policyId, id);
|
||||
return this.prisma.claim.update({ where: { id }, data: this.claimData(dto) });
|
||||
}
|
||||
async removeClaim(policyId: string, id: string) {
|
||||
await this.ensureChild("claim", policyId, id);
|
||||
return this.prisma.claim.delete({ where: { id } });
|
||||
}
|
||||
private claimData(dto: ClaimDto) {
|
||||
const { incidentDate, reportedDate, settlementDate, ...rest } = dto;
|
||||
return {
|
||||
...rest,
|
||||
...(incidentDate !== undefined && { incidentDate: toDate(incidentDate) }),
|
||||
...(reportedDate !== undefined && { reportedDate: toDate(reportedDate) }),
|
||||
...(settlementDate !== undefined && { settlementDate: toDate(settlementDate) }),
|
||||
};
|
||||
}
|
||||
|
||||
// --- documents ------------------------------------------------------------
|
||||
// Blob in object storage under `policy/<policyId>/…`; row is the pointer.
|
||||
|
||||
async addDocument(
|
||||
policyId: string,
|
||||
file: UploadedFileLike,
|
||||
documentType?: string,
|
||||
) {
|
||||
await this.ensurePolicy(policyId);
|
||||
const key = `policy/${policyId}/${randomUUID()}${extForUpload(file)}`;
|
||||
await this.storage.put(key, file.buffer, file.mimetype);
|
||||
return this.prisma.policyDocument.create({
|
||||
data: {
|
||||
policyId,
|
||||
documentType: documentType?.trim() || "DOCUMENT",
|
||||
storageKey: key,
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
async getDocument(policyId: string, id: string) {
|
||||
const row = await this.prisma.policyDocument.findFirst({
|
||||
where: { id, policyId },
|
||||
});
|
||||
if (!row) throw new NotFoundException(`Document ${id} not found on policy ${policyId}`);
|
||||
const blob = await this.storage.getStream(row.storageKey);
|
||||
return { row, ...blob };
|
||||
}
|
||||
|
||||
async removeDocument(policyId: string, id: string) {
|
||||
await this.ensurePolicy(policyId);
|
||||
const row = await this.prisma.policyDocument.findFirst({
|
||||
where: { id, policyId },
|
||||
select: { id: true, storageKey: true },
|
||||
});
|
||||
if (!row) throw new NotFoundException(`Document ${id} not found on policy ${policyId}`);
|
||||
const deleted = await this.prisma.policyDocument.delete({ where: { id } });
|
||||
await this.storage.delete(row.storageKey);
|
||||
return deleted;
|
||||
}
|
||||
|
||||
// --- lookups (providers / policy types / adjusters) -----------------------
|
||||
|
||||
listLookups() {
|
||||
return this.prisma.$transaction([
|
||||
this.prisma.insuranceProvider.findMany({
|
||||
orderBy: { name: "asc" },
|
||||
select: { id: true, name: true, _count: { select: { policies: true } } },
|
||||
}),
|
||||
this.prisma.policyType.findMany({
|
||||
orderBy: { name: "asc" },
|
||||
select: {
|
||||
id: true,
|
||||
name: true,
|
||||
shortDescription: true,
|
||||
_count: { select: { policies: true } },
|
||||
},
|
||||
}),
|
||||
this.prisma.adjuster.findMany({ orderBy: { name: "asc" } }),
|
||||
]).then(([providers, types, adjusters]) => ({ providers, types, adjusters }));
|
||||
}
|
||||
|
||||
createProvider(dto: ProviderDto) {
|
||||
return this.prisma.insuranceProvider.create({ data: dto });
|
||||
}
|
||||
updateProvider(id: string, dto: UpdateProviderDto) {
|
||||
return this.prisma.insuranceProvider.update({ where: { id }, data: dto });
|
||||
}
|
||||
removeProvider(id: string) {
|
||||
return this.prisma.insuranceProvider.delete({ where: { id } });
|
||||
}
|
||||
|
||||
createPolicyType(dto: PolicyTypeDto) {
|
||||
return this.prisma.policyType.create({ data: dto });
|
||||
}
|
||||
updatePolicyType(id: string, dto: UpdatePolicyTypeDto) {
|
||||
return this.prisma.policyType.update({ where: { id }, data: dto });
|
||||
}
|
||||
removePolicyType(id: string) {
|
||||
return this.prisma.policyType.delete({ where: { id } });
|
||||
}
|
||||
|
||||
createAdjuster(dto: AdjusterDto) {
|
||||
return this.prisma.adjuster.create({ data: dto });
|
||||
}
|
||||
updateAdjuster(id: string, dto: UpdateAdjusterDto) {
|
||||
return this.prisma.adjuster.update({ where: { id }, data: dto });
|
||||
}
|
||||
removeAdjuster(id: string) {
|
||||
return this.prisma.adjuster.delete({ where: { id } });
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,62 @@
|
||||
import {
|
||||
IsBoolean,
|
||||
IsInt,
|
||||
IsNumber,
|
||||
IsOptional,
|
||||
IsString,
|
||||
MinLength,
|
||||
} from "class-validator";
|
||||
import { Currency } from "@jorgecuadros/database";
|
||||
import { IsEnum } from "class-validator";
|
||||
|
||||
/** Editable policy-header fields. coveragesJson (freeform legacy blob) is not
|
||||
* exposed for editing. Dates arrive as ISO strings and are coerced by the
|
||||
* service. `total` is legacy-dead data — the UI uses netPremium. */
|
||||
export class CreatePolicyDto {
|
||||
@IsString() @MinLength(1) policyNumber!: string;
|
||||
@IsString() @MinLength(1) customerId!: string;
|
||||
|
||||
@IsOptional() @IsString() policyTypeId?: string;
|
||||
@IsOptional() @IsString() insuranceProviderId?: string;
|
||||
@IsOptional() @IsString() agentName?: string;
|
||||
@IsOptional() @IsString() policyDate?: string;
|
||||
@IsOptional() @IsString() policyFrom?: string;
|
||||
@IsOptional() @IsString() policyTo?: string;
|
||||
@IsOptional() @IsInt() coveragePeriodDays?: number;
|
||||
@IsOptional() @IsNumber() netPremium?: number;
|
||||
@IsOptional() @IsNumber() policyFee?: number;
|
||||
@IsOptional() @IsNumber() brokerFee?: number;
|
||||
@IsOptional() @IsNumber() commission?: number;
|
||||
@IsOptional() @IsNumber() total?: number;
|
||||
@IsOptional() @IsEnum(Currency) currency?: Currency;
|
||||
@IsOptional() @IsString() observations?: string;
|
||||
@IsOptional() @IsString() notes?: string;
|
||||
@IsOptional() @IsBoolean() endorsement?: boolean;
|
||||
@IsOptional() @IsBoolean() liquidated?: boolean;
|
||||
@IsOptional() @IsString() liquidationNumber?: string;
|
||||
@IsOptional() @IsString() liquidationDate?: string;
|
||||
}
|
||||
|
||||
/** All header fields optional (customerId is not re-assignable on update). */
|
||||
export class UpdatePolicyDto {
|
||||
@IsOptional() @IsString() @MinLength(1) policyNumber?: string;
|
||||
@IsOptional() @IsString() policyTypeId?: string;
|
||||
@IsOptional() @IsString() insuranceProviderId?: string;
|
||||
@IsOptional() @IsString() agentName?: string;
|
||||
@IsOptional() @IsString() policyDate?: string;
|
||||
@IsOptional() @IsString() policyFrom?: string;
|
||||
@IsOptional() @IsString() policyTo?: string;
|
||||
@IsOptional() @IsInt() coveragePeriodDays?: number;
|
||||
@IsOptional() @IsNumber() netPremium?: number;
|
||||
@IsOptional() @IsNumber() policyFee?: number;
|
||||
@IsOptional() @IsNumber() brokerFee?: number;
|
||||
@IsOptional() @IsNumber() commission?: number;
|
||||
@IsOptional() @IsNumber() total?: number;
|
||||
@IsOptional() @IsEnum(Currency) currency?: Currency;
|
||||
@IsOptional() @IsString() observations?: string;
|
||||
@IsOptional() @IsString() notes?: string;
|
||||
@IsOptional() @IsBoolean() endorsement?: boolean;
|
||||
@IsOptional() @IsBoolean() liquidated?: boolean;
|
||||
@IsOptional() @IsString() liquidationNumber?: string;
|
||||
@IsOptional() @IsString() liquidationDate?: string;
|
||||
}
|
||||
@@ -1,11 +1,40 @@
|
||||
import { Controller, Get, Param, Query, UseGuards } from "@nestjs/common";
|
||||
import {
|
||||
Body,
|
||||
Controller,
|
||||
Delete,
|
||||
Get,
|
||||
Param,
|
||||
Patch,
|
||||
Post,
|
||||
Put,
|
||||
Query,
|
||||
Req,
|
||||
Res,
|
||||
StreamableFile,
|
||||
UploadedFile,
|
||||
UseGuards,
|
||||
UseInterceptors,
|
||||
} from "@nestjs/common";
|
||||
import { FileInterceptor } from "@nestjs/platform-express";
|
||||
import { ServiceKind } from "@jorgecuadros/database";
|
||||
import { Request, Response } from "express";
|
||||
import { downloadName, type UploadedFileLike } from "../storage/upload-file";
|
||||
import { AuthenticatedGuard } from "../auth/authenticated.guard";
|
||||
import { AbilityGuard } from "../auth/ability.guard";
|
||||
import { RequireAbility } from "../auth/require-ability.decorator";
|
||||
import { AuditService } from "../common/audit.service";
|
||||
import {
|
||||
PropertiesService,
|
||||
type PropertySort,
|
||||
type TrustFilter,
|
||||
} from "./properties.service";
|
||||
import {
|
||||
CreatePropertyDto,
|
||||
ServiceDto,
|
||||
TrustDto,
|
||||
UpdatePropertyDto,
|
||||
UpdateServiceDto,
|
||||
} from "./property.dto";
|
||||
|
||||
const KINDS: ServiceKind[] = [
|
||||
"WATER",
|
||||
@@ -35,15 +64,21 @@ const SORTS: PropertySort[] = [
|
||||
"trust_due_desc",
|
||||
];
|
||||
|
||||
/** Clamped trust-renewal window; 30 days matches the policies module. */
|
||||
function parseDays(days?: string): number {
|
||||
return Math.min(365, Math.max(1, Number(days) || 30));
|
||||
}
|
||||
|
||||
@UseGuards(AuthenticatedGuard)
|
||||
@UseGuards(AuthenticatedGuard, AbilityGuard)
|
||||
@Controller("properties")
|
||||
export class PropertiesController {
|
||||
constructor(private readonly properties: PropertiesService) {}
|
||||
constructor(
|
||||
private readonly properties: PropertiesService,
|
||||
private readonly audit: AuditService,
|
||||
) {}
|
||||
|
||||
private actingId(req: Request): string {
|
||||
return (req.user as { id: string }).id;
|
||||
}
|
||||
|
||||
@Get("stats")
|
||||
stats(@Query("days") days?: string) {
|
||||
@@ -67,6 +102,7 @@ export class PropertiesController {
|
||||
@Query("hasServices") hasServices?: string,
|
||||
@Query("customerId") customerId?: string,
|
||||
@Query("days") days?: string,
|
||||
@Query("includeArchived") includeArchived?: string,
|
||||
@Query("sort") sort?: string,
|
||||
) {
|
||||
return this.properties.list({
|
||||
@@ -85,6 +121,7 @@ export class PropertiesController {
|
||||
hasServices === "true" ? true : hasServices === "false" ? false : undefined,
|
||||
customerId: customerId || undefined,
|
||||
days: parseDays(days),
|
||||
includeArchived: includeArchived === "true",
|
||||
sort: SORTS.includes(sort as PropertySort)
|
||||
? (sort as PropertySort)
|
||||
: "customer",
|
||||
@@ -95,4 +132,109 @@ export class PropertiesController {
|
||||
detail(@Param("id") id: string, @Query("days") days?: string) {
|
||||
return this.properties.detail(id, parseDays(days));
|
||||
}
|
||||
|
||||
// --- header writes --------------------------------------------------------
|
||||
|
||||
@Post()
|
||||
@RequireAbility("property:create")
|
||||
async create(@Body() dto: CreatePropertyDto, @Req() req: Request) {
|
||||
const p = await this.properties.create(dto);
|
||||
void this.audit.log(this.actingId(req), "property.create", { propertyId: p.id });
|
||||
return p;
|
||||
}
|
||||
|
||||
@Patch(":id")
|
||||
@RequireAbility("property:update")
|
||||
async update(@Param("id") id: string, @Body() dto: UpdatePropertyDto, @Req() req: Request) {
|
||||
const p = await this.properties.update(id, dto);
|
||||
void this.audit.log(this.actingId(req), "property.update", { propertyId: id });
|
||||
return p;
|
||||
}
|
||||
|
||||
@Delete(":id")
|
||||
@RequireAbility("property:delete")
|
||||
async archive(@Param("id") id: string, @Req() req: Request) {
|
||||
const p = await this.properties.archive(id);
|
||||
void this.audit.log(this.actingId(req), "property.archive", { propertyId: id });
|
||||
return p;
|
||||
}
|
||||
|
||||
@Post(":id/restore")
|
||||
@RequireAbility("property:delete")
|
||||
async restore(@Param("id") id: string, @Req() req: Request) {
|
||||
const p = await this.properties.restore(id);
|
||||
void this.audit.log(this.actingId(req), "property.restore", { propertyId: id });
|
||||
return p;
|
||||
}
|
||||
|
||||
// --- services (property:update) -------------------------------------------
|
||||
|
||||
@Post(":id/services")
|
||||
@RequireAbility("property:update")
|
||||
addService(@Param("id") id: string, @Body() dto: ServiceDto) {
|
||||
return this.properties.addService(id, dto);
|
||||
}
|
||||
@Patch(":id/services/:childId")
|
||||
@RequireAbility("property:update")
|
||||
updateService(
|
||||
@Param("id") id: string,
|
||||
@Param("childId") childId: string,
|
||||
@Body() dto: UpdateServiceDto,
|
||||
) {
|
||||
return this.properties.updateService(id, childId, dto);
|
||||
}
|
||||
@Delete(":id/services/:childId")
|
||||
@RequireAbility("property:update")
|
||||
removeService(@Param("id") id: string, @Param("childId") childId: string) {
|
||||
return this.properties.removeService(id, childId);
|
||||
}
|
||||
|
||||
// --- trust account (1:1) --------------------------------------------------
|
||||
|
||||
@Put(":id/trust")
|
||||
@RequireAbility("property:update")
|
||||
upsertTrust(@Param("id") id: string, @Body() dto: TrustDto) {
|
||||
return this.properties.upsertTrust(id, dto);
|
||||
}
|
||||
@Delete(":id/trust")
|
||||
@RequireAbility("property:update")
|
||||
removeTrust(@Param("id") id: string) {
|
||||
return this.properties.removeTrust(id);
|
||||
}
|
||||
|
||||
// --- documents ------------------------------------------------------------
|
||||
|
||||
@Post(":id/documents")
|
||||
@RequireAbility("property:update")
|
||||
@UseInterceptors(
|
||||
FileInterceptor("file", { limits: { fileSize: 50 * 1024 * 1024 } }),
|
||||
)
|
||||
addDocument(
|
||||
@Param("id") id: string,
|
||||
@UploadedFile() file: UploadedFileLike | undefined,
|
||||
@Query("type") type: string | undefined,
|
||||
) {
|
||||
if (!file) throw new Error("No se recibió ningún archivo.");
|
||||
return this.properties.addDocument(id, file, type);
|
||||
}
|
||||
|
||||
@Get(":id/documents/:childId/download")
|
||||
async downloadDocument(
|
||||
@Param("id") id: string,
|
||||
@Param("childId") childId: string,
|
||||
@Res({ passthrough: true }) res: Response,
|
||||
): Promise<StreamableFile> {
|
||||
const { row, stream, contentType } = await this.properties.getDocument(id, childId);
|
||||
res.set({
|
||||
"Content-Type": contentType ?? "application/octet-stream",
|
||||
"Content-Disposition": `attachment; filename="${downloadName(row.storageKey, row.documentType)}"`,
|
||||
});
|
||||
return new StreamableFile(stream);
|
||||
}
|
||||
|
||||
@Delete(":id/documents/:childId")
|
||||
@RequireAbility("property:update")
|
||||
removeDocument(@Param("id") id: string, @Param("childId") childId: string) {
|
||||
return this.properties.removeDocument(id, childId);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,6 +1,17 @@
|
||||
import { Injectable, NotFoundException } from "@nestjs/common";
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { Prisma, ServiceKind } from "@jorgecuadros/database";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
import { StorageService } from "../storage/storage.service";
|
||||
import { extForUpload } from "../storage/upload-file";
|
||||
import { toDate } from "../common/coerce";
|
||||
import {
|
||||
CreatePropertyDto,
|
||||
ServiceDto,
|
||||
TrustDto,
|
||||
UpdatePropertyDto,
|
||||
UpdateServiceDto,
|
||||
} from "./property.dto";
|
||||
|
||||
/**
|
||||
* Trust (fideicomiso) renewal buckets, derived from `trustAccount.dueDate2`
|
||||
@@ -37,6 +48,7 @@ export interface ListParams {
|
||||
customerId?: string;
|
||||
/** Window in days for the `expiring` trust bucket. */
|
||||
days: number;
|
||||
includeArchived?: boolean;
|
||||
sort: PropertySort;
|
||||
}
|
||||
|
||||
@@ -74,7 +86,10 @@ function daysUntil(dueDate: Date | null | undefined, from: Date): number | null
|
||||
|
||||
@Injectable()
|
||||
export class PropertiesService {
|
||||
constructor(private readonly prisma: PrismaService) {}
|
||||
constructor(
|
||||
private readonly prisma: PrismaService,
|
||||
private readonly storage: StorageService,
|
||||
) {}
|
||||
|
||||
private trustWhere(
|
||||
trust: TrustFilter | undefined,
|
||||
@@ -134,11 +149,14 @@ export class PropertiesService {
|
||||
hasServices,
|
||||
customerId,
|
||||
days,
|
||||
includeArchived,
|
||||
sort,
|
||||
} = params;
|
||||
|
||||
const and: Prisma.PropertyWhereInput[] = [this.trustWhere(trust, days)];
|
||||
|
||||
if (!includeArchived) and.push({ archivedAt: null });
|
||||
|
||||
// Sorting by trust due date is only meaningful for properties that have a
|
||||
// trust; MySQL would otherwise float the ~966 trust-less rows (NULL first
|
||||
// on ASC) above every real due date. Scoping is explicit in the UI label.
|
||||
@@ -191,6 +209,7 @@ export class PropertiesService {
|
||||
phone2: true,
|
||||
phone3: true,
|
||||
zone: true,
|
||||
archivedAt: true,
|
||||
customer: {
|
||||
select: { id: true, name: true, city: true, state: true },
|
||||
},
|
||||
@@ -221,6 +240,7 @@ export class PropertiesService {
|
||||
addressLine1: r.addressLine1,
|
||||
addressLine2: r.addressLine2,
|
||||
zone: r.zone,
|
||||
archived: r.archivedAt != null,
|
||||
phones: [r.phone1, r.phone2, r.phone3].filter(Boolean) as string[],
|
||||
customerId: r.customer.id,
|
||||
customerName: r.customer.name,
|
||||
@@ -411,7 +431,7 @@ export class PropertiesService {
|
||||
});
|
||||
const ledger = await this.prisma.transaction.groupBy({
|
||||
by: ["currency"],
|
||||
where: { customerId: property.customerId, domain: "UTILITY" },
|
||||
where: { customerId: property.customerId, domain: "UTILITY", voidedAt: null },
|
||||
_sum: { amount: true },
|
||||
_count: { _all: true },
|
||||
});
|
||||
@@ -443,4 +463,131 @@ export class PropertiesService {
|
||||
})),
|
||||
};
|
||||
}
|
||||
|
||||
// --- property header writes -----------------------------------------------
|
||||
|
||||
async create(dto: CreatePropertyDto) {
|
||||
const customer = await this.prisma.customer.findUnique({
|
||||
where: { id: dto.customerId },
|
||||
select: { id: true },
|
||||
});
|
||||
if (!customer) throw new NotFoundException(`Customer ${dto.customerId} not found`);
|
||||
return this.prisma.property.create({ data: { ...dto } });
|
||||
}
|
||||
|
||||
async update(id: string, dto: UpdatePropertyDto) {
|
||||
await this.ensureProperty(id);
|
||||
return this.prisma.property.update({ where: { id }, data: { ...dto } });
|
||||
}
|
||||
|
||||
async archive(id: string) {
|
||||
await this.ensureProperty(id);
|
||||
return this.prisma.property.update({ where: { id }, data: { archivedAt: new Date() } });
|
||||
}
|
||||
async restore(id: string) {
|
||||
await this.ensureProperty(id);
|
||||
return this.prisma.property.update({ where: { id }, data: { archivedAt: null } });
|
||||
}
|
||||
|
||||
private async ensureProperty(id: string) {
|
||||
const found = await this.prisma.property.findUnique({
|
||||
where: { id },
|
||||
select: { id: true },
|
||||
});
|
||||
if (!found) throw new NotFoundException(`Property ${id} not found`);
|
||||
}
|
||||
|
||||
private async ensureService(propertyId: string, serviceId: string) {
|
||||
await this.ensureProperty(propertyId);
|
||||
const row = await this.prisma.propertyService.findFirst({
|
||||
where: { id: serviceId, propertyId },
|
||||
select: { id: true },
|
||||
});
|
||||
if (!row) throw new NotFoundException(`Service ${serviceId} not found on property ${propertyId}`);
|
||||
}
|
||||
|
||||
// --- services -------------------------------------------------------------
|
||||
|
||||
async addService(propertyId: string, dto: ServiceDto) {
|
||||
await this.ensureProperty(propertyId);
|
||||
return this.prisma.propertyService.create({ data: { propertyId, ...dto } });
|
||||
}
|
||||
async updateService(propertyId: string, id: string, dto: UpdateServiceDto) {
|
||||
await this.ensureService(propertyId, id);
|
||||
return this.prisma.propertyService.update({ where: { id }, data: { ...dto } });
|
||||
}
|
||||
async removeService(propertyId: string, id: string) {
|
||||
await this.ensureService(propertyId, id);
|
||||
return this.prisma.propertyService.delete({ where: { id } });
|
||||
}
|
||||
|
||||
// --- trust account (1:1 upsert) -------------------------------------------
|
||||
|
||||
async upsertTrust(propertyId: string, dto: TrustDto) {
|
||||
await this.ensureProperty(propertyId);
|
||||
const data = {
|
||||
bankName: dto.bankName,
|
||||
trustNumber: dto.trustNumber,
|
||||
bankFee: dto.bankFee,
|
||||
...(dto.dueDate1 !== undefined && { dueDate1: toDate(dto.dueDate1) }),
|
||||
...(dto.dueDate2 !== undefined && { dueDate2: toDate(dto.dueDate2) }),
|
||||
};
|
||||
return this.prisma.trustAccount.upsert({
|
||||
where: { propertyId },
|
||||
create: { propertyId, ...data },
|
||||
update: data,
|
||||
});
|
||||
}
|
||||
async removeTrust(propertyId: string) {
|
||||
await this.ensureProperty(propertyId);
|
||||
const existing = await this.prisma.trustAccount.findUnique({
|
||||
where: { propertyId },
|
||||
select: { id: true },
|
||||
});
|
||||
if (!existing) throw new NotFoundException(`No trust account on property ${propertyId}`);
|
||||
return this.prisma.trustAccount.delete({ where: { propertyId } });
|
||||
}
|
||||
|
||||
// --- documents ------------------------------------------------------------
|
||||
// The blob lives in object storage (MinIO); the row is just the pointer. Keys
|
||||
// stay under the `service/<propertyId>/…` prefix the migration established.
|
||||
|
||||
async addDocument(
|
||||
propertyId: string,
|
||||
file: { buffer: Buffer; originalname?: string; mimetype?: string },
|
||||
documentType?: string,
|
||||
) {
|
||||
await this.ensureProperty(propertyId);
|
||||
const ext = extForUpload(file);
|
||||
const key = `service/${propertyId}/${randomUUID()}${ext}`;
|
||||
await this.storage.put(key, file.buffer, file.mimetype);
|
||||
return this.prisma.serviceDocument.create({
|
||||
data: {
|
||||
propertyId,
|
||||
documentType: documentType?.trim() || "DOCUMENT",
|
||||
storageKey: key,
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
async getDocument(propertyId: string, id: string) {
|
||||
const row = await this.prisma.serviceDocument.findFirst({
|
||||
where: { id, propertyId },
|
||||
});
|
||||
if (!row) throw new NotFoundException(`Document ${id} not found on property ${propertyId}`);
|
||||
const blob = await this.storage.getStream(row.storageKey);
|
||||
return { row, ...blob };
|
||||
}
|
||||
|
||||
async removeDocument(propertyId: string, id: string) {
|
||||
await this.ensureProperty(propertyId);
|
||||
const row = await this.prisma.serviceDocument.findFirst({
|
||||
where: { id, propertyId },
|
||||
select: { id: true, storageKey: true },
|
||||
});
|
||||
if (!row) throw new NotFoundException(`Document ${id} not found on property ${propertyId}`);
|
||||
const deleted = await this.prisma.serviceDocument.delete({ where: { id } });
|
||||
await this.storage.delete(row.storageKey);
|
||||
return deleted;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
import {
|
||||
IsBoolean,
|
||||
IsEnum,
|
||||
IsNumber,
|
||||
IsOptional,
|
||||
IsString,
|
||||
MinLength,
|
||||
} from "class-validator";
|
||||
import { ServiceKind } from "@jorgecuadros/database";
|
||||
|
||||
export class CreatePropertyDto {
|
||||
@IsString() @MinLength(1) customerId!: string;
|
||||
@IsOptional() @IsString() policyId?: string;
|
||||
@IsOptional() @IsString() addressLine1?: string;
|
||||
@IsOptional() @IsString() addressLine2?: string;
|
||||
@IsOptional() @IsString() phone1?: string;
|
||||
@IsOptional() @IsString() phone2?: string;
|
||||
@IsOptional() @IsString() phone3?: string;
|
||||
@IsOptional() @IsString() zone?: string;
|
||||
}
|
||||
|
||||
export class UpdatePropertyDto {
|
||||
@IsOptional() @IsString() policyId?: string;
|
||||
@IsOptional() @IsString() addressLine1?: string;
|
||||
@IsOptional() @IsString() addressLine2?: string;
|
||||
@IsOptional() @IsString() phone1?: string;
|
||||
@IsOptional() @IsString() phone2?: string;
|
||||
@IsOptional() @IsString() phone3?: string;
|
||||
@IsOptional() @IsString() zone?: string;
|
||||
}
|
||||
|
||||
export class ServiceDto {
|
||||
@IsEnum(ServiceKind) kind!: ServiceKind;
|
||||
@IsOptional() @IsString() accountNumber?: string;
|
||||
@IsOptional() @IsString() meterNumber?: string;
|
||||
@IsOptional() @IsString() route?: string;
|
||||
@IsOptional() @IsString() dueDay?: string;
|
||||
@IsOptional() @IsBoolean() active?: boolean;
|
||||
@IsOptional() @IsString() notes?: string;
|
||||
}
|
||||
export class UpdateServiceDto {
|
||||
@IsOptional() @IsEnum(ServiceKind) kind?: ServiceKind;
|
||||
@IsOptional() @IsString() accountNumber?: string;
|
||||
@IsOptional() @IsString() meterNumber?: string;
|
||||
@IsOptional() @IsString() route?: string;
|
||||
@IsOptional() @IsString() dueDay?: string;
|
||||
@IsOptional() @IsBoolean() active?: boolean;
|
||||
@IsOptional() @IsString() notes?: string;
|
||||
}
|
||||
|
||||
/** Trust is 1:1 with a property — this both creates and updates it (upsert). */
|
||||
export class TrustDto {
|
||||
@IsOptional() @IsString() bankName?: string;
|
||||
@IsOptional() @IsString() trustNumber?: string;
|
||||
@IsOptional() @IsNumber() bankFee?: number;
|
||||
@IsOptional() @IsString() dueDate1?: string;
|
||||
@IsOptional() @IsString() dueDate2?: string;
|
||||
}
|
||||
@@ -0,0 +1,103 @@
|
||||
/**
|
||||
* Company info used on every report header (PDF + print). Read from
|
||||
* the environment so the office can edit it without a code change —
|
||||
* the .env.example file lists the keys; defaults below are placeholders
|
||||
* the office should override for production.
|
||||
*
|
||||
* Single source of truth: the API renders the header. The web header
|
||||
* (login + AppShell) still reads the static "Jorge Cuadros & Asociados"
|
||||
* strings for now — those are visual brand, the API's COMPANY_INFO
|
||||
* block is the legal/locator block on printed documents.
|
||||
*/
|
||||
|
||||
import * as fs from "node:fs";
|
||||
import * as path from "node:path";
|
||||
|
||||
export interface CompanyInfo {
|
||||
name: string;
|
||||
/** Street address — line 1. */
|
||||
addressLine1: string;
|
||||
/** Street address — line 2 (suite, floor, etc.). Optional. */
|
||||
addressLine2: string;
|
||||
/** "City, State, ZIP, Country" — single line. */
|
||||
cityState: string;
|
||||
phone: string;
|
||||
email: string;
|
||||
/** Mexican tax ID ("RFC"). Optional. */
|
||||
taxId: string;
|
||||
website: string;
|
||||
/** Absolute path to the logo PNG. Null when missing — renderers fall
|
||||
* back to a text mark. */
|
||||
logoPath: string | null;
|
||||
/** Logo buffer + intrinsic size, eagerly loaded so the PDF renderer
|
||||
* doesn't do a sync read on every report. Null when no logo. */
|
||||
logo: { buffer: Buffer; width: number; height: number } | null;
|
||||
}
|
||||
|
||||
function envOr(key: string, fallback: string): string {
|
||||
const v = process.env[key];
|
||||
return v && v.trim() ? v : fallback;
|
||||
}
|
||||
|
||||
function resolveLogoPath(): string | null {
|
||||
const explicit = process.env.COMPANY_LOGO_PATH;
|
||||
if (explicit) {
|
||||
return fs.existsSync(explicit) ? explicit : null;
|
||||
}
|
||||
// Default: look in apps/api/assets/company_logo.png (copied from
|
||||
// apps/web/public/images/company_logo.png — single canonical image
|
||||
// kept in lock-step; see .env.example for the override path).
|
||||
const candidates = [
|
||||
path.resolve(__dirname, "..", "..", "assets", "company_logo.png"),
|
||||
path.resolve(__dirname, "..", "..", "..", "web", "public", "images", "company_logo.png"),
|
||||
];
|
||||
for (const c of candidates) {
|
||||
if (fs.existsSync(c)) return c;
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
let cached: CompanyInfo | null = null;
|
||||
|
||||
export function getCompanyInfo(): CompanyInfo {
|
||||
if (cached) return cached;
|
||||
const logoPath = resolveLogoPath();
|
||||
let logo: CompanyInfo["logo"] = null;
|
||||
if (logoPath) {
|
||||
try {
|
||||
const buf = fs.readFileSync(logoPath);
|
||||
// Intrinsic PNG size: read IHDR (bytes 16-23 of the file).
|
||||
// Width = BE uint32 at offset 16, height = BE uint32 at offset 20.
|
||||
const w =
|
||||
logoPath.endsWith(".png") && buf.length >= 24
|
||||
? buf.readUInt32BE(16)
|
||||
: 0;
|
||||
const h =
|
||||
logoPath.endsWith(".png") && buf.length >= 24
|
||||
? buf.readUInt32BE(20)
|
||||
: 0;
|
||||
logo = { buffer: buf, width: w, height: h };
|
||||
} catch {
|
||||
logo = null;
|
||||
}
|
||||
}
|
||||
cached = {
|
||||
name: envOr("COMPANY_NAME", "Jorge Cuadros & Asociados"),
|
||||
addressLine1: envOr(
|
||||
"COMPANY_ADDRESS_LINE1",
|
||||
"Av. Revolución 1234, Int. 5",
|
||||
),
|
||||
addressLine2: envOr("COMPANY_ADDRESS_LINE2", ""),
|
||||
cityState: envOr(
|
||||
"COMPANY_CITY_STATE",
|
||||
"Tijuana, Baja California 22000, México",
|
||||
),
|
||||
phone: envOr("COMPANY_PHONE", "(664) 000-0000"),
|
||||
email: envOr("COMPANY_EMAIL", "contacto@jorgecuadros.local"),
|
||||
taxId: envOr("COMPANY_TAX_ID", ""),
|
||||
website: envOr("COMPANY_WEBSITE", "jorgecuadros.local"),
|
||||
logoPath,
|
||||
logo,
|
||||
};
|
||||
return cached;
|
||||
}
|
||||
@@ -0,0 +1,433 @@
|
||||
/**
|
||||
* Output renderers for the reports module.
|
||||
*
|
||||
* Every report's `run` returns `{ columns, rows, totals?, subtitle? }`.
|
||||
* CSV/XLSX/PDF all derive from the same shape so adding a report = one
|
||||
* registry entry, no per-format template.
|
||||
*
|
||||
* PDF uses pdfkit. The statement format (edo-cuenta-datos) uses a
|
||||
* different layout than the tabular one — handled inline.
|
||||
*/
|
||||
|
||||
// pdfkit exports its constructor via `module.exports = PDFDocument`, so a
|
||||
// namespace import gets the type, and `import = require()` gets the value.
|
||||
import PDFDocument = require("pdfkit");
|
||||
import * as ExcelJS from "exceljs";
|
||||
import type { ColumnDef, ReportResult } from "./reports.types";
|
||||
import { getCompanyInfo } from "./company";
|
||||
|
||||
type Doc = PDFKit.PDFDocument;
|
||||
|
||||
/* ----------------------------------------------------------------- CSV */
|
||||
|
||||
function csvCell(v: unknown): string {
|
||||
if (v === null || v === undefined) return "";
|
||||
const s = String(v);
|
||||
if (s.includes(",") || s.includes('"') || s.includes("\n") || s.includes("\r")) {
|
||||
return `"${s.replace(/"/g, '""')}"`;
|
||||
}
|
||||
return s;
|
||||
}
|
||||
|
||||
export function renderCsv(columns: ColumnDef[], result: ReportResult): string {
|
||||
const headers = columns.map((c) => csvCell(c.label)).join(",");
|
||||
const lines = result.rows.map((r) =>
|
||||
columns
|
||||
.map((c) => {
|
||||
const v = r[c.key];
|
||||
if (typeof v === "number") return v;
|
||||
return csvCell(v);
|
||||
})
|
||||
.join(","),
|
||||
);
|
||||
const totals: string[] = [];
|
||||
if (result.totals) {
|
||||
for (const [k, v] of Object.entries(result.totals)) {
|
||||
totals.push(csvCell(k), csvCell(v));
|
||||
}
|
||||
}
|
||||
return [headers, ...lines, ...(totals.length ? [totals.join(",")] : [])].join(
|
||||
"\n",
|
||||
);
|
||||
}
|
||||
|
||||
/* ----------------------------------------------------------------- XLSX */
|
||||
|
||||
export async function renderXlsx(
|
||||
columns: ColumnDef[],
|
||||
result: ReportResult,
|
||||
): Promise<Buffer> {
|
||||
const wb = new ExcelJS.Workbook();
|
||||
wb.creator = "Jorge Cuadros & Asociados";
|
||||
const ws = wb.addWorksheet("Reporte", {
|
||||
views: [{ state: "frozen", ySplit: 1 }],
|
||||
});
|
||||
ws.columns = columns.map((c) => ({
|
||||
header: c.label,
|
||||
key: c.key,
|
||||
width: Math.max(10, Math.min(40, (c.label.length + 2) * 1.2)),
|
||||
}));
|
||||
ws.getRow(1).font = { bold: true };
|
||||
ws.getRow(1).fill = {
|
||||
type: "pattern",
|
||||
pattern: "solid",
|
||||
fgColor: { argb: "FFE2EDE9" }, // brand-tint
|
||||
};
|
||||
for (const row of result.rows) {
|
||||
ws.addRow(row);
|
||||
}
|
||||
// Number formatting for money columns.
|
||||
for (const col of columns) {
|
||||
if (col.type === "money" || col.type === "number") {
|
||||
ws.getColumn(col.key).numFmt =
|
||||
col.type === "money" ? "#,##0.00" : "#,##0";
|
||||
ws.getColumn(col.key).alignment = { horizontal: "right" };
|
||||
}
|
||||
}
|
||||
if (result.totals) {
|
||||
const last = ws.addRow({});
|
||||
let i = 1;
|
||||
for (const [k, v] of Object.entries(result.totals)) {
|
||||
const cell = ws.getCell(last.number, i);
|
||||
cell.value = `${k}: ${v}`;
|
||||
cell.font = { bold: true };
|
||||
i++;
|
||||
}
|
||||
}
|
||||
const buf = await wb.xlsx.writeBuffer();
|
||||
return Buffer.from(buf);
|
||||
}
|
||||
|
||||
/* ----------------------------------------------------------------- PDF */
|
||||
|
||||
const BRAND = "#0c322d";
|
||||
const ACCENT = "#bf5a34";
|
||||
const MUTED = "#756c5c";
|
||||
const LINE = "#e4dccb";
|
||||
|
||||
function fmtMoney(v: unknown): string {
|
||||
if (v === null || v === undefined || v === "") return "";
|
||||
const n = Number(v);
|
||||
if (!Number.isFinite(n)) return String(v);
|
||||
return n.toLocaleString("es-MX", { minimumFractionDigits: 2, maximumFractionDigits: 2 });
|
||||
}
|
||||
|
||||
function pdfRow(
|
||||
doc: Doc,
|
||||
y: number,
|
||||
cols: Array<{ label: string; width: number; align?: "left" | "right" }>,
|
||||
values: Array<{ text: string; align?: "left" | "right" }>,
|
||||
x: number,
|
||||
): number {
|
||||
let cx = x;
|
||||
for (let i = 0; i < cols.length; i++) {
|
||||
const c = cols[i];
|
||||
const v = values[i] ?? { text: "" };
|
||||
const align = v.align ?? c.align ?? "left";
|
||||
const w = c.width;
|
||||
doc
|
||||
.font("Helvetica")
|
||||
.fontSize(9)
|
||||
.fillColor("#211d17")
|
||||
.text(v.text, cx, y, {
|
||||
width: w - 4,
|
||||
align,
|
||||
ellipsis: true,
|
||||
lineBreak: false,
|
||||
height: 16,
|
||||
});
|
||||
cx += w;
|
||||
}
|
||||
return y + 18;
|
||||
}
|
||||
|
||||
export function renderPdf(
|
||||
columns: ColumnDef[],
|
||||
result: ReportResult,
|
||||
title: string,
|
||||
): Promise<Buffer> {
|
||||
return new Promise((resolve, reject) => {
|
||||
const doc = new PDFDocument({
|
||||
size: "LETTER",
|
||||
layout: "landscape",
|
||||
margins: { top: 96, bottom: 56, left: 48, right: 48 },
|
||||
bufferPages: true,
|
||||
info: {
|
||||
Title: title,
|
||||
Author: "Jorge Cuadros & Asociados",
|
||||
Subject: "Reporte",
|
||||
Creator: "Jorge Cuadros Platform — Reports module",
|
||||
},
|
||||
});
|
||||
const chunks: Buffer[] = [];
|
||||
doc.on("data", (c: Buffer) => chunks.push(c));
|
||||
doc.on("end", () => resolve(Buffer.concat(chunks)));
|
||||
doc.on("error", reject);
|
||||
|
||||
const company = getCompanyInfo();
|
||||
const pageW = doc.page.width - 96;
|
||||
|
||||
/** The header is repeated on every page (via addPage + manual draw). */
|
||||
const drawHeader = () => {
|
||||
// Background bar (brand pine) for the masthead.
|
||||
doc.rect(0, 0, doc.page.width, 60).fill(BRAND);
|
||||
|
||||
// Logo, fitted to a 40px box, with 8px padding.
|
||||
let textX = 48;
|
||||
if (company.logo) {
|
||||
const targetH = 40;
|
||||
const scale = targetH / company.logo.height;
|
||||
const w = company.logo.width * scale;
|
||||
doc.image(company.logo.buffer, 48, 10, { height: targetH });
|
||||
textX = 48 + w + 14;
|
||||
}
|
||||
|
||||
// Company name (large) + "Reporte" tag below it.
|
||||
doc
|
||||
.fillColor("#f5f1e8")
|
||||
.font("Helvetica-Bold")
|
||||
.fontSize(15)
|
||||
.text(company.name, textX, 14, { width: pageW - (textX - 48), lineBreak: false });
|
||||
doc
|
||||
.font("Helvetica")
|
||||
.fontSize(8)
|
||||
.fillColor("#cde0db")
|
||||
.text("Reporte", textX, 36, { lineBreak: false });
|
||||
|
||||
// Right-aligned company locator (address + phone + email).
|
||||
const rightLines = [
|
||||
company.addressLine1,
|
||||
company.addressLine2,
|
||||
[company.cityState].filter(Boolean).join(" · "),
|
||||
[company.phone, company.email].filter(Boolean).join(" · "),
|
||||
company.taxId ? `RFC: ${company.taxId}` : "",
|
||||
].filter(Boolean);
|
||||
doc.font("Helvetica").fontSize(8).fillColor("#cde0db");
|
||||
let ry = 12;
|
||||
for (const line of rightLines) {
|
||||
doc.text(line, 48, ry, {
|
||||
width: pageW,
|
||||
align: "right",
|
||||
lineBreak: false,
|
||||
ellipsis: true,
|
||||
});
|
||||
ry += 10;
|
||||
}
|
||||
|
||||
// Thin accent line under the masthead.
|
||||
doc.rect(0, 60, doc.page.width, 2).fill(ACCENT);
|
||||
|
||||
// Title + subtitle + printed-at.
|
||||
doc
|
||||
.font("Helvetica-Bold")
|
||||
.fontSize(15)
|
||||
.fillColor(BRAND)
|
||||
.text(title, 48, 72, { lineBreak: false });
|
||||
let metaY = 92;
|
||||
if (result.subtitle) {
|
||||
doc
|
||||
.font("Helvetica")
|
||||
.fontSize(9)
|
||||
.fillColor(MUTED)
|
||||
.text(result.subtitle, 48, metaY, { lineBreak: false });
|
||||
metaY += 12;
|
||||
}
|
||||
const printedAt = new Date().toLocaleString("es-MX");
|
||||
doc
|
||||
.font("Helvetica")
|
||||
.fontSize(8)
|
||||
.fillColor(MUTED)
|
||||
.text(`Impreso: ${printedAt}`, 48, metaY, { lineBreak: false });
|
||||
};
|
||||
|
||||
drawHeader();
|
||||
|
||||
// Column widths: distribute page width minus margins, weighted.
|
||||
const totalW = columns.reduce((s, c) => s + (c.width ?? 12), 0);
|
||||
const cols = columns.map((c) => ({
|
||||
label: c.label,
|
||||
width: ((c.width ?? 12) / totalW) * pageW,
|
||||
align: c.align,
|
||||
}));
|
||||
|
||||
let y = 130;
|
||||
const drawTableHeader = () => {
|
||||
doc.rect(48, y, pageW, 18).fill("#faf6ee");
|
||||
y = pdfRow(
|
||||
doc,
|
||||
y + 4,
|
||||
cols,
|
||||
cols.map((c) => ({ text: c.label, align: c.align })),
|
||||
48,
|
||||
);
|
||||
doc
|
||||
.moveTo(48, y)
|
||||
.lineTo(48 + pageW, y)
|
||||
.strokeColor(LINE)
|
||||
.lineWidth(0.5)
|
||||
.stroke();
|
||||
};
|
||||
drawTableHeader();
|
||||
|
||||
// Body rows.
|
||||
for (const r of result.rows) {
|
||||
if (y > doc.page.height - 64) {
|
||||
doc.addPage({ layout: "landscape", margins: { top: 96, bottom: 56, left: 48, right: 48 } });
|
||||
drawHeader();
|
||||
y = 130;
|
||||
drawTableHeader();
|
||||
}
|
||||
const vals = columns.map((c) => {
|
||||
const v = r[c.key];
|
||||
const text = c.type === "money" ? fmtMoney(v) : v == null ? "" : String(v);
|
||||
return { text, align: c.align };
|
||||
});
|
||||
y = pdfRow(doc, y + 4, cols, vals, 48);
|
||||
doc
|
||||
.moveTo(48, y)
|
||||
.lineTo(48 + pageW, y)
|
||||
.strokeColor("#e4dccb")
|
||||
.lineWidth(0.4)
|
||||
.stroke();
|
||||
}
|
||||
|
||||
// Totals.
|
||||
if (result.totals) {
|
||||
y += 6;
|
||||
doc.rect(48, y, pageW, 18).fill(ACCENT);
|
||||
doc
|
||||
.font("Helvetica-Bold")
|
||||
.fontSize(9)
|
||||
.fillColor("#f5f1e8")
|
||||
.text(
|
||||
Object.entries(result.totals)
|
||||
.map(([k, v]) => `${k}: ${v}`)
|
||||
.join(" · "),
|
||||
52,
|
||||
y + 5,
|
||||
{ width: pageW - 8, align: "left" },
|
||||
);
|
||||
}
|
||||
|
||||
doc.end();
|
||||
});
|
||||
}
|
||||
|
||||
/* ----------------------------------------------------------------- print (HTML) */
|
||||
|
||||
/**
|
||||
* Print-stylesheet-friendly HTML. The web app's print stylesheet hides
|
||||
* nav, but otherwise this is a plain table the browser paginates itself.
|
||||
*
|
||||
* The header carries the company info (logo + name + locator) so printed
|
||||
* pages stand alone — staff can hand one to a customer and the office
|
||||
* identification is on every sheet, not buried in the cover page.
|
||||
*/
|
||||
export function renderPrintHtml(
|
||||
columns: ColumnDef[],
|
||||
result: ReportResult,
|
||||
title: string,
|
||||
): string {
|
||||
const company = getCompanyInfo();
|
||||
const head = (label: string, align?: "left" | "right") =>
|
||||
`<th style="text-align:${align ?? "left"};padding:6px 8px;border-bottom:2px solid #0c322d;background:#faf6ee;font-size:11px">${escapeHtml(label)}</th>`;
|
||||
const cell = (v: unknown, c: ColumnDef) => {
|
||||
const text = c.type === "money" ? fmtMoney(v) : v == null ? "" : String(v);
|
||||
const align = c.align ?? "left";
|
||||
return `<td style="text-align:${align};padding:4px 8px;border-bottom:1px solid #e4dccb;font-size:11px;${c.type === "money" ? "font-variant-numeric:tabular-nums" : ""}">${escapeHtml(text)}</td>`;
|
||||
};
|
||||
const rows = result.rows
|
||||
.map(
|
||||
(r) =>
|
||||
`<tr>${columns
|
||||
.map((c) => cell(r[c.key], c))
|
||||
.join("")}</tr>`,
|
||||
)
|
||||
.join("");
|
||||
const totals = result.totals
|
||||
? `<tr><td colspan="${columns.length}" style="padding:8px;background:#bf5a34;color:#f5f1e8;font-weight:600;font-size:11px">${Object.entries(
|
||||
result.totals,
|
||||
)
|
||||
.map(([k, v]) => `${escapeHtml(k)}: ${escapeHtml(String(v))}`)
|
||||
.join(" · ")}</td></tr>`
|
||||
: "";
|
||||
|
||||
// Logo embedded as base64 data URL — the print page is opened as a
|
||||
// new tab and printed standalone, so a relative path to the web app
|
||||
// wouldn't resolve when launched outside the web's origin.
|
||||
const logoDataUrl = company.logo
|
||||
? `data:image/png;base64,${company.logo.buffer.toString("base64")}`
|
||||
: null;
|
||||
|
||||
const locatorLines = [
|
||||
company.addressLine1,
|
||||
company.addressLine2,
|
||||
company.cityState,
|
||||
[company.phone, company.email].filter(Boolean).join(" · "),
|
||||
company.taxId ? `RFC: ${company.taxId}` : "",
|
||||
].filter(Boolean);
|
||||
|
||||
return `<!doctype html>
|
||||
<html lang="es"><head>
|
||||
<meta charset="utf-8" />
|
||||
<title>${escapeHtml(title)} — ${escapeHtml(company.name)}</title>
|
||||
<style>
|
||||
@page { size: letter landscape; margin: 0.5in; }
|
||||
body { font-family: -apple-system, "Helvetica Neue", Helvetica, Arial, sans-serif; color: #211d17; margin: 0; }
|
||||
.masthead { display: flex; align-items: flex-start; gap: 16px; padding: 12px 16px; background: #0c322d; color: #f5f1e8; border-radius: 6px 6px 0 0; }
|
||||
.masthead-logo { flex: 0 0 auto; }
|
||||
.masthead-logo img { display: block; height: 56px; width: auto; }
|
||||
.masthead-text { flex: 1; min-width: 0; }
|
||||
.masthead-name { font-family: Georgia, "Times New Roman", serif; font-size: 20px; font-weight: 600; line-height: 1.1; }
|
||||
.masthead-tag { font-size: 11px; color: #cde0db; margin-top: 2px; text-transform: uppercase; letter-spacing: 0.06em; }
|
||||
.masthead-locator { font-size: 10px; color: #cde0db; text-align: right; line-height: 1.35; white-space: nowrap; }
|
||||
.accent { height: 3px; background: #bf5a34; }
|
||||
.head { padding: 12px 4px 8px; }
|
||||
.head h1 { font-family: Georgia, "Times New Roman", serif; font-size: 18px; margin: 0; color: #0c322d; }
|
||||
.head p { font-size: 11px; color: #756c5c; margin: 2px 0 0; }
|
||||
table { width: 100%; border-collapse: collapse; }
|
||||
@media print {
|
||||
.noprint { display: none; }
|
||||
.masthead { border-radius: 0; }
|
||||
}
|
||||
.noprint { padding: 8px 0; }
|
||||
.noprint button { padding: 6px 12px; background: #0c322d; color: #f5f1e8; border: 0; border-radius: 4px; cursor: pointer; font-size: 12px; }
|
||||
.footer { margin-top: 16px; font-size: 9px; color: #756c5c; border-top: 1px solid #e4dccb; padding-top: 6px; display: flex; justify-content: space-between; }
|
||||
</style>
|
||||
</head><body>
|
||||
<div class="noprint"><button onclick="window.print()">Imprimir / Guardar PDF</button></div>
|
||||
<div class="masthead">
|
||||
${logoDataUrl ? `<div class="masthead-logo"><img src="${logoDataUrl}" alt="" /></div>` : ""}
|
||||
<div class="masthead-text">
|
||||
<div class="masthead-name">${escapeHtml(company.name)}</div>
|
||||
<div class="masthead-tag">Reporte</div>
|
||||
</div>
|
||||
<div class="masthead-locator">
|
||||
${locatorLines.map((l) => escapeHtml(l)).join("<br/>")}
|
||||
${company.website ? `<br/>${escapeHtml(company.website)}` : ""}
|
||||
</div>
|
||||
</div>
|
||||
<div class="accent"></div>
|
||||
<div class="head">
|
||||
<h1>${escapeHtml(title)}</h1>
|
||||
${result.subtitle ? `<p>${escapeHtml(result.subtitle)}</p>` : ""}
|
||||
<p>Impreso: ${new Date().toLocaleString("es-MX")}</p>
|
||||
</div>
|
||||
<table>
|
||||
<thead><tr>${columns.map((c) => head(c.label, c.align)).join("")}</tr></thead>
|
||||
<tbody>${rows}${totals}</tbody>
|
||||
</table>
|
||||
<div class="footer">
|
||||
<span>${escapeHtml(company.name)} · ${escapeHtml(company.phone)} · ${escapeHtml(company.email)}</span>
|
||||
<span>${escapeHtml(title)}</span>
|
||||
</div>
|
||||
</body></html>`;
|
||||
}
|
||||
|
||||
function escapeHtml(s: string): string {
|
||||
return s
|
||||
.replace(/&/g, "&")
|
||||
.replace(/</g, "<")
|
||||
.replace(/>/g, ">")
|
||||
.replace(/"/g, """);
|
||||
}
|
||||
@@ -0,0 +1,130 @@
|
||||
import {
|
||||
Body,
|
||||
Controller,
|
||||
Get,
|
||||
Header,
|
||||
Param,
|
||||
Post,
|
||||
Query,
|
||||
Res,
|
||||
UseGuards,
|
||||
} from "@nestjs/common";
|
||||
import type { Response } from "express";
|
||||
import { AuthenticatedGuard } from "../auth/authenticated.guard";
|
||||
import { ReportsService } from "./reports.service";
|
||||
import {
|
||||
renderCsv,
|
||||
renderPdf,
|
||||
renderPrintHtml,
|
||||
renderXlsx,
|
||||
} from "./outputs";
|
||||
import { findReport } from "./reports.registry";
|
||||
|
||||
/**
|
||||
* Reports routes. Every report is dispatched by slug; outputs are
|
||||
* differentiated by `?format=...` (default `json`). Reads only — gated
|
||||
* by AuthenticatedGuard alone, like every other read in the app.
|
||||
*/
|
||||
@UseGuards(AuthenticatedGuard)
|
||||
@Controller("reports")
|
||||
export class ReportsController {
|
||||
constructor(private readonly reports: ReportsService) {}
|
||||
|
||||
/** Catalog of all registered reports (the /reportes index). */
|
||||
@Get()
|
||||
catalog() {
|
||||
return { items: this.reports.catalog() };
|
||||
}
|
||||
|
||||
/** Run a report and return the JSON result (rows + totals + the def's columns). */
|
||||
@Get(":slug")
|
||||
async runJson(
|
||||
@Param("slug") slug: string,
|
||||
@Query() query: Record<string, string | undefined>,
|
||||
) {
|
||||
const def = findReport(slug);
|
||||
const result = await this.reports.run(slug, query);
|
||||
return { ...result, columns: def?.columns ?? [] };
|
||||
}
|
||||
|
||||
/** CSV download. */
|
||||
@Get(":slug/csv")
|
||||
@Header("Content-Type", "text/csv; charset=utf-8")
|
||||
async runCsv(
|
||||
@Param("slug") slug: string,
|
||||
@Query() query: Record<string, string | undefined>,
|
||||
@Res() res: Response,
|
||||
) {
|
||||
const def = findReport(slug);
|
||||
const result = await this.reports.run(slug, query);
|
||||
const filename = `${def?.title ?? slug}-${new Date().toISOString().slice(0, 10)}.csv`;
|
||||
res.setHeader(
|
||||
"Content-Disposition",
|
||||
`attachment; filename="${filename.replace(/[^\wÀ-ſ .-]/g, "_")}"`,
|
||||
);
|
||||
res.send(renderCsv(def?.columns ?? [], result));
|
||||
}
|
||||
|
||||
/** XLSX download. */
|
||||
@Get(":slug/xlsx")
|
||||
async runXlsx(
|
||||
@Param("slug") slug: string,
|
||||
@Query() query: Record<string, string | undefined>,
|
||||
@Res() res: Response,
|
||||
) {
|
||||
const def = findReport(slug);
|
||||
const result = await this.reports.run(slug, query);
|
||||
const filename = `${def?.title ?? slug}-${new Date().toISOString().slice(0, 10)}.xlsx`;
|
||||
const buf = await renderXlsx(def?.columns ?? [], result);
|
||||
res.setHeader(
|
||||
"Content-Type",
|
||||
"application/vnd.openxmlformats-officedocument.spreadsheetml.sheet",
|
||||
);
|
||||
res.setHeader(
|
||||
"Content-Disposition",
|
||||
`attachment; filename="${filename.replace(/[^\wÀ-ſ .-]/g, "_")}"`,
|
||||
);
|
||||
res.send(buf);
|
||||
}
|
||||
|
||||
/** PDF download. */
|
||||
@Get(":slug/pdf")
|
||||
async runPdf(
|
||||
@Param("slug") slug: string,
|
||||
@Query() query: Record<string, string | undefined>,
|
||||
@Res() res: Response,
|
||||
) {
|
||||
const def = findReport(slug);
|
||||
const result = await this.reports.run(slug, query);
|
||||
const buf = await renderPdf(def?.columns ?? [], result, def?.title ?? slug);
|
||||
const filename = `${def?.title ?? slug}-${new Date().toISOString().slice(0, 10)}.pdf`;
|
||||
res.setHeader("Content-Type", "application/pdf");
|
||||
res.setHeader(
|
||||
"Content-Disposition",
|
||||
`attachment; filename="${filename.replace(/[^\wÀ-ſ .-]/g, "_")}"`,
|
||||
);
|
||||
res.send(buf);
|
||||
}
|
||||
|
||||
/** Browser-printable HTML view (the user hits Print → Save as PDF). */
|
||||
@Get(":slug/print")
|
||||
@Header("Content-Type", "text/html; charset=utf-8")
|
||||
async runPrint(
|
||||
@Param("slug") slug: string,
|
||||
@Query() query: Record<string, string | undefined>,
|
||||
) {
|
||||
const def = findReport(slug);
|
||||
const result = await this.reports.run(slug, query);
|
||||
return renderPrintHtml(def?.columns ?? [], result, def?.title ?? slug);
|
||||
}
|
||||
|
||||
/** POST a customer-picker-driven report (statement). Mirrors GET to keep
|
||||
* the param contract simple: same body shape, same response. */
|
||||
@Post(":slug")
|
||||
async runPost(
|
||||
@Param("slug") slug: string,
|
||||
@Body() body: Record<string, string | undefined>,
|
||||
) {
|
||||
return this.reports.run(slug, body);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
import { Module } from "@nestjs/common";
|
||||
import { ReportsController } from "./reports.controller";
|
||||
import { ReportsService } from "./reports.service";
|
||||
|
||||
@Module({
|
||||
controllers: [ReportsController],
|
||||
providers: [ReportsService],
|
||||
})
|
||||
export class ReportsModule {}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,45 @@
|
||||
import { Injectable, NotFoundException } from "@nestjs/common";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
import { findReport, REPORTS } from "./reports.registry";
|
||||
import type { ReportDef } from "./reports.types";
|
||||
|
||||
/**
|
||||
* The reports service. Two responsibilities:
|
||||
* 1. Run a report by slug with the given params — just dispatch.
|
||||
* 2. Return the catalog for the /reportes index page.
|
||||
*
|
||||
* Output rendering (CSV/XLSX/PDF/HTML print) lives in `outputs.ts`; this
|
||||
* service is data only. The controller maps URLs to (slug, format) and
|
||||
* hands the result to outputs.
|
||||
*/
|
||||
@Injectable()
|
||||
export class ReportsService {
|
||||
constructor(private readonly prisma: PrismaService) {}
|
||||
|
||||
/** List every registered report, in display order. */
|
||||
catalog(): Array<{
|
||||
slug: string;
|
||||
title: string;
|
||||
description: string;
|
||||
domain: string;
|
||||
legacyName: string | null;
|
||||
format: string;
|
||||
params: ReportDef["params"];
|
||||
}> {
|
||||
return REPORTS.map((r) => ({
|
||||
slug: r.slug,
|
||||
title: r.title,
|
||||
description: r.description,
|
||||
domain: r.domain,
|
||||
legacyName: r.legacyName,
|
||||
format: r.format,
|
||||
params: r.params,
|
||||
}));
|
||||
}
|
||||
|
||||
async run(slug: string, params: Record<string, string | undefined>) {
|
||||
const def = findReport(slug);
|
||||
if (!def) throw new NotFoundException(`Reporte "${slug}" no encontrado`);
|
||||
return def.run(this.prisma, params);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,142 @@
|
||||
/**
|
||||
* The reports module — plan step 10.
|
||||
*
|
||||
* Each "report" is one entry in `reports.registry.ts`. The entry declares
|
||||
* its slug (URL id), title, what filters it accepts, what columns it
|
||||
* returns, and a `run` function that produces the data from Prisma. The
|
||||
* service dispatches on slug; the controller exposes JSON + CSV + XLSX +
|
||||
* PDF + HTML print; the catalog endpoint exposes the registry itself so
|
||||
* the `/reportes` page can render the same data.
|
||||
*
|
||||
* Output philosophy: a report returns a uniform shape — `columns` (typed
|
||||
* schema) + `rows` (any[] of values matching the column types) + `totals`
|
||||
* (record of column key → summary value). All three output formats
|
||||
* (CSV/XLSX/PDF/print) derive from this same shape so adding a new
|
||||
* report is one entry, never a per-format template.
|
||||
*/
|
||||
|
||||
import { Prisma } from "@jorgecuadros/database";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
|
||||
/** Top-level grouping for the catalog page; matches the existing nav. */
|
||||
export type ReportDomain =
|
||||
| "clientes"
|
||||
| "polizas"
|
||||
| "servicios"
|
||||
| "estado-cuenta"
|
||||
| "chequera";
|
||||
|
||||
/** How the runner should render rows: a grid, a per-customer statement, or
|
||||
* one printable letter per row (e.g. renewal notices — see `format:
|
||||
* "letter"` reports for the `__kind: "letter"` row shape they emit). */
|
||||
export type ReportFormat = "tabular" | "statement" | "letter";
|
||||
|
||||
/** Filter controls the report's UI should render. */
|
||||
export type ParamDef =
|
||||
| {
|
||||
key: string;
|
||||
label: string;
|
||||
kind: "text" | "number";
|
||||
placeholder?: string;
|
||||
defaultValue?: string;
|
||||
}
|
||||
| {
|
||||
key: string;
|
||||
label: string;
|
||||
kind: "date";
|
||||
/** Inclusive bound, true for `to`, false for `from`. */
|
||||
endOfDay?: boolean;
|
||||
defaultValue?: string;
|
||||
}
|
||||
| {
|
||||
key: string;
|
||||
label: string;
|
||||
kind: "select";
|
||||
options: { value: string; label: string }[];
|
||||
defaultValue?: string;
|
||||
}
|
||||
| {
|
||||
key: string;
|
||||
label: string;
|
||||
kind: "customer-picker";
|
||||
};
|
||||
|
||||
/** One column of the output table. */
|
||||
export interface ColumnDef {
|
||||
key: string;
|
||||
label: string;
|
||||
/** Render hint for the on-screen + print table. */
|
||||
type: "text" | "number" | "money" | "date";
|
||||
/** Right-align numbers/money; default false (left). */
|
||||
align?: "left" | "right";
|
||||
/** Used for column-width hints in the print/PDF layout. */
|
||||
width?: number;
|
||||
}
|
||||
|
||||
/** Shape every report's `run` resolves to. Columns come from the def. */
|
||||
export interface ReportResult {
|
||||
rows: Array<Record<string, unknown>>;
|
||||
totals?: Record<string, string | number>;
|
||||
/** Optional free-form subtitle for print/PDF (e.g. date range, scope). */
|
||||
subtitle?: string;
|
||||
}
|
||||
|
||||
/** A report's static declaration. */
|
||||
export interface ReportDef {
|
||||
slug: string;
|
||||
title: string;
|
||||
description: string;
|
||||
domain: ReportDomain;
|
||||
/** The original Access report name (per docs/LEGACY_DATABASES_OBJECTS.md)
|
||||
* for traceability. Null when this is a new report with no legacy equiv. */
|
||||
legacyName: string | null;
|
||||
format: ReportFormat;
|
||||
params: ParamDef[];
|
||||
columns: ColumnDef[];
|
||||
/**
|
||||
* Run the report. Receives the Prisma client and the validated params
|
||||
* record (keys are the `key` from ParamDef, values are the strings the
|
||||
* runner collected; numeric/date params arrive as strings — the report
|
||||
* parses them). Must apply the same NOT_VOIDED filter on transactions as
|
||||
* the billing module so totals match.
|
||||
*/
|
||||
run: (
|
||||
prisma: PrismaService,
|
||||
params: Record<string, string | undefined>,
|
||||
) => Promise<ReportResult>;
|
||||
}
|
||||
|
||||
/** A typed bag of helpers for the report functions. */
|
||||
export interface ReportCtx {
|
||||
prisma: PrismaService;
|
||||
params: Record<string, string | undefined>;
|
||||
}
|
||||
|
||||
/** Helper: a `YYYY-MM-DD` bound; unparseable is undefined. */
|
||||
export function parseDate(
|
||||
v: string | undefined,
|
||||
endOfDay = false,
|
||||
): Date | undefined {
|
||||
if (!v) return undefined;
|
||||
const d = new Date(endOfDay ? `${v}T23:59:59.999Z` : `${v}T00:00:00.000Z`);
|
||||
return Number.isNaN(d.getTime()) ? undefined : d;
|
||||
}
|
||||
|
||||
/** Helper: integer param with default. */
|
||||
export function intParam(
|
||||
p: Record<string, string | undefined>,
|
||||
key: string,
|
||||
def: number,
|
||||
min = 1,
|
||||
max = 1000,
|
||||
): number {
|
||||
const n = Number(p[key]);
|
||||
if (!Number.isFinite(n)) return def;
|
||||
return Math.min(max, Math.max(min, Math.round(n)));
|
||||
}
|
||||
|
||||
/** Helper: not-voided filter, shared with billing.service. */
|
||||
export const NOT_VOIDED: Prisma.TransactionWhereInput = { voidedAt: null };
|
||||
export const NOT_VOIDED_BANK: Prisma.BankTransactionWhereInput = {
|
||||
voidedAt: null,
|
||||
};
|
||||
@@ -0,0 +1,10 @@
|
||||
import { Global, Module } from "@nestjs/common";
|
||||
import { StorageService } from "./storage.service";
|
||||
|
||||
/** Global so any feature module can inject StorageService without re-importing. */
|
||||
@Global()
|
||||
@Module({
|
||||
providers: [StorageService],
|
||||
exports: [StorageService],
|
||||
})
|
||||
export class StorageModule {}
|
||||
@@ -0,0 +1,122 @@
|
||||
import {
|
||||
Injectable,
|
||||
Logger,
|
||||
OnModuleInit,
|
||||
ServiceUnavailableException,
|
||||
} from "@nestjs/common";
|
||||
import { ConfigService } from "@nestjs/config";
|
||||
import {
|
||||
CreateBucketCommand,
|
||||
DeleteObjectCommand,
|
||||
GetObjectCommand,
|
||||
HeadBucketCommand,
|
||||
PutObjectCommand,
|
||||
S3Client,
|
||||
} from "@aws-sdk/client-s3";
|
||||
import type { Readable } from "node:stream";
|
||||
|
||||
/**
|
||||
* S3 / MinIO object storage for document blobs. MySQL keeps only the pointer
|
||||
* (`storageKey`) + metadata; the bytes live here. Same bucket the migration's
|
||||
* `blob_extract.py` writes to, so keys stay under the `service/…` and
|
||||
* `policy/…` prefixes it established.
|
||||
*
|
||||
* Env (see deploy/.env.dev): S3_ENDPOINT, S3_BUCKET, and creds — S3_ACCESS_KEY
|
||||
* / S3_SECRET_KEY, falling back to MINIO_ROOT_USER / MINIO_ROOT_PASSWORD so a
|
||||
* single MinIO credential set drives both the migration and the API.
|
||||
*/
|
||||
@Injectable()
|
||||
export class StorageService implements OnModuleInit {
|
||||
private readonly logger = new Logger(StorageService.name);
|
||||
private readonly client: S3Client | null;
|
||||
readonly bucket: string;
|
||||
|
||||
constructor(config: ConfigService) {
|
||||
const endpoint = config.get<string>("S3_ENDPOINT");
|
||||
this.bucket = config.get<string>("S3_BUCKET") ?? "jorgecuadros-documents";
|
||||
const accessKeyId =
|
||||
config.get<string>("S3_ACCESS_KEY") ?? config.get<string>("MINIO_ROOT_USER");
|
||||
const secretAccessKey =
|
||||
config.get<string>("S3_SECRET_KEY") ?? config.get<string>("MINIO_ROOT_PASSWORD");
|
||||
|
||||
if (!endpoint || !accessKeyId || !secretAccessKey) {
|
||||
this.logger.warn(
|
||||
"Object storage not configured (missing S3_ENDPOINT / credentials); " +
|
||||
"document upload & download are disabled.",
|
||||
);
|
||||
this.client = null;
|
||||
return;
|
||||
}
|
||||
|
||||
this.client = new S3Client({
|
||||
endpoint,
|
||||
region: config.get<string>("S3_REGION") ?? "us-east-1",
|
||||
credentials: { accessKeyId, secretAccessKey },
|
||||
forcePathStyle: true, // MinIO needs path-style addressing
|
||||
});
|
||||
}
|
||||
|
||||
/** Best-effort bucket check on boot; never blocks API startup. */
|
||||
async onModuleInit() {
|
||||
if (!this.client) return;
|
||||
try {
|
||||
await this.client.send(new HeadBucketCommand({ Bucket: this.bucket }));
|
||||
} catch {
|
||||
try {
|
||||
await this.client.send(new CreateBucketCommand({ Bucket: this.bucket }));
|
||||
this.logger.log(`Created bucket "${this.bucket}".`);
|
||||
} catch (err) {
|
||||
this.logger.warn(
|
||||
`Could not verify/create bucket "${this.bucket}": ${(err as Error).message}`,
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
private require(): S3Client {
|
||||
if (!this.client) {
|
||||
throw new ServiceUnavailableException(
|
||||
"El almacenamiento de documentos no está configurado.",
|
||||
);
|
||||
}
|
||||
return this.client;
|
||||
}
|
||||
|
||||
async put(key: string, body: Buffer, contentType?: string): Promise<void> {
|
||||
await this.require().send(
|
||||
new PutObjectCommand({
|
||||
Bucket: this.bucket,
|
||||
Key: key,
|
||||
Body: body,
|
||||
ContentType: contentType,
|
||||
}),
|
||||
);
|
||||
}
|
||||
|
||||
async getStream(key: string): Promise<{
|
||||
stream: Readable;
|
||||
contentType?: string;
|
||||
contentLength?: number;
|
||||
}> {
|
||||
const out = await this.require().send(
|
||||
new GetObjectCommand({ Bucket: this.bucket, Key: key }),
|
||||
);
|
||||
return {
|
||||
stream: out.Body as Readable,
|
||||
contentType: out.ContentType,
|
||||
contentLength: out.ContentLength,
|
||||
};
|
||||
}
|
||||
|
||||
/** Best-effort blob delete; a missing object is not an error. */
|
||||
async delete(key: string): Promise<void> {
|
||||
if (!this.client) return;
|
||||
try {
|
||||
await this.client.send(
|
||||
new DeleteObjectCommand({ Bucket: this.bucket, Key: key }),
|
||||
);
|
||||
} catch (err) {
|
||||
this.logger.warn(`Failed to delete blob "${key}": ${(err as Error).message}`);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,32 @@
|
||||
import { extname } from "node:path";
|
||||
|
||||
/** Multer file shape we rely on (subset of Express.Multer.File). */
|
||||
export interface UploadedFileLike {
|
||||
buffer: Buffer;
|
||||
originalname?: string;
|
||||
mimetype?: string;
|
||||
size?: number;
|
||||
}
|
||||
|
||||
const MIME_EXT: Record<string, string> = {
|
||||
"application/pdf": ".pdf",
|
||||
"image/jpeg": ".jpg",
|
||||
"image/png": ".png",
|
||||
"image/gif": ".gif",
|
||||
"image/tiff": ".tif",
|
||||
"image/bmp": ".bmp",
|
||||
};
|
||||
|
||||
/** File extension for a stored blob, from the original name, else the mimetype. */
|
||||
export function extForUpload(file: UploadedFileLike): string {
|
||||
const fromName = file.originalname ? extname(file.originalname).toLowerCase() : "";
|
||||
if (fromName) return fromName;
|
||||
return (file.mimetype && MIME_EXT[file.mimetype]) || "";
|
||||
}
|
||||
|
||||
/** Download filename for a stored document, from its key + document type. */
|
||||
export function downloadName(storageKey: string, documentType: string): string {
|
||||
const ext = extname(storageKey) || "";
|
||||
const base = documentType.replace(/[^\w.-]+/g, "_") || "document";
|
||||
return base.toLowerCase().endsWith(ext.toLowerCase()) ? base : `${base}${ext}`;
|
||||
}
|
||||
@@ -0,0 +1,21 @@
|
||||
import { IsEmail, IsEnum, IsOptional, IsString, MinLength } from "class-validator";
|
||||
import { UserRole } from "@jorgecuadros/database";
|
||||
|
||||
export class CreateUserDto {
|
||||
@IsString()
|
||||
@MinLength(1)
|
||||
name!: string;
|
||||
|
||||
@IsEmail()
|
||||
email!: string;
|
||||
|
||||
@IsString()
|
||||
@MinLength(8)
|
||||
password!: string;
|
||||
|
||||
@IsEnum(UserRole)
|
||||
role!: UserRole;
|
||||
|
||||
@IsOptional()
|
||||
active?: boolean;
|
||||
}
|
||||
@@ -0,0 +1,7 @@
|
||||
import { IsString, MinLength } from "class-validator";
|
||||
|
||||
export class ResetPasswordDto {
|
||||
@IsString()
|
||||
@MinLength(8)
|
||||
password!: string;
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
import { IsBoolean, IsEmail, IsEnum, IsOptional, IsString, MinLength } from "class-validator";
|
||||
import { UserRole } from "@jorgecuadros/database";
|
||||
|
||||
/** Password changes go through the dedicated reset-password route, not here. */
|
||||
export class UpdateUserDto {
|
||||
@IsOptional()
|
||||
@IsString()
|
||||
@MinLength(1)
|
||||
name?: string;
|
||||
|
||||
@IsOptional()
|
||||
@IsEmail()
|
||||
email?: string;
|
||||
|
||||
@IsOptional()
|
||||
@IsEnum(UserRole)
|
||||
role?: UserRole;
|
||||
|
||||
@IsOptional()
|
||||
@IsBoolean()
|
||||
active?: boolean;
|
||||
}
|
||||
@@ -0,0 +1,82 @@
|
||||
import {
|
||||
Body,
|
||||
Controller,
|
||||
Delete,
|
||||
Get,
|
||||
HttpCode,
|
||||
Param,
|
||||
Patch,
|
||||
Post,
|
||||
Req,
|
||||
UseGuards,
|
||||
} from "@nestjs/common";
|
||||
import { Request } from "express";
|
||||
import { AuthenticatedGuard } from "../auth/authenticated.guard";
|
||||
import { AbilityGuard } from "../auth/ability.guard";
|
||||
import { RequireAbility } from "../auth/require-ability.decorator";
|
||||
import { AuditService } from "../common/audit.service";
|
||||
import { UsersService } from "./users.service";
|
||||
import { CreateUserDto } from "./create-user.dto";
|
||||
import { UpdateUserDto } from "./update-user.dto";
|
||||
import { ResetPasswordDto } from "./reset-password.dto";
|
||||
|
||||
/** Every route here is ADMIN-only (ability "user:manage"). */
|
||||
@UseGuards(AuthenticatedGuard, AbilityGuard)
|
||||
@RequireAbility("user:manage")
|
||||
@Controller("users")
|
||||
export class UsersController {
|
||||
constructor(
|
||||
private readonly users: UsersService,
|
||||
private readonly audit: AuditService,
|
||||
) {}
|
||||
|
||||
private actingId(req: Request): string {
|
||||
return (req.user as { id: string }).id;
|
||||
}
|
||||
|
||||
@Get()
|
||||
list() {
|
||||
return this.users.list();
|
||||
}
|
||||
|
||||
@Post()
|
||||
async create(@Body() dto: CreateUserDto, @Req() req: Request) {
|
||||
const user = await this.users.create(dto);
|
||||
void this.audit.log(this.actingId(req), "user.create", {
|
||||
userId: user.id,
|
||||
email: user.email,
|
||||
role: user.role,
|
||||
});
|
||||
return user;
|
||||
}
|
||||
|
||||
@Patch(":id")
|
||||
async update(
|
||||
@Param("id") id: string,
|
||||
@Body() dto: UpdateUserDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const user = await this.users.update(id, dto, this.actingId(req));
|
||||
void this.audit.log(this.actingId(req), "user.update", { userId: id, changes: dto });
|
||||
return user;
|
||||
}
|
||||
|
||||
@Post(":id/reset-password")
|
||||
async resetPassword(
|
||||
@Param("id") id: string,
|
||||
@Body() dto: ResetPasswordDto,
|
||||
@Req() req: Request,
|
||||
) {
|
||||
const user = await this.users.resetPassword(id, dto.password);
|
||||
void this.audit.log(this.actingId(req), "user.reset_password", { userId: id });
|
||||
return user;
|
||||
}
|
||||
|
||||
@Delete(":id")
|
||||
@HttpCode(204)
|
||||
async remove(@Param("id") id: string, @Req() req: Request) {
|
||||
const actingId = this.actingId(req);
|
||||
await this.users.remove(id, actingId);
|
||||
void this.audit.log(actingId, "user.delete", { userId: id });
|
||||
}
|
||||
}
|
||||
@@ -1,8 +1,10 @@
|
||||
import { Module } from "@nestjs/common";
|
||||
import { UsersService } from "./users.service";
|
||||
import { UsersController } from "./users.controller";
|
||||
|
||||
@Module({
|
||||
providers: [UsersService],
|
||||
controllers: [UsersController],
|
||||
exports: [UsersService],
|
||||
})
|
||||
export class UsersModule {}
|
||||
|
||||
@@ -1,11 +1,36 @@
|
||||
import { Injectable } from "@nestjs/common";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
import {
|
||||
BadRequestException,
|
||||
ConflictException,
|
||||
Injectable,
|
||||
NotFoundException,
|
||||
} from "@nestjs/common";
|
||||
import * as argon2 from "argon2";
|
||||
import { Prisma } from "@jorgecuadros/database";
|
||||
import type { User } from "@jorgecuadros/database";
|
||||
import { PrismaService } from "../prisma/prisma.service";
|
||||
import { CreateUserDto } from "./create-user.dto";
|
||||
import { UpdateUserDto } from "./update-user.dto";
|
||||
|
||||
/** Shape returned to the UI — never carries passwordHash. */
|
||||
const safeSelect = {
|
||||
id: true,
|
||||
name: true,
|
||||
email: true,
|
||||
role: true,
|
||||
active: true,
|
||||
uiScale: true,
|
||||
createdAt: true,
|
||||
updatedAt: true,
|
||||
} satisfies Prisma.UserSelect;
|
||||
|
||||
export type SafeUserRow = Prisma.UserGetPayload<{ select: typeof safeSelect }>;
|
||||
|
||||
@Injectable()
|
||||
export class UsersService {
|
||||
constructor(private readonly prisma: PrismaService) {}
|
||||
|
||||
// --- used by auth (need the hash / full row) -----------------------------
|
||||
|
||||
findByEmail(email: string): Promise<User | null> {
|
||||
return this.prisma.user.findUnique({ where: { email } });
|
||||
}
|
||||
@@ -13,4 +38,125 @@ export class UsersService {
|
||||
findById(id: string): Promise<User | null> {
|
||||
return this.prisma.user.findUnique({ where: { id } });
|
||||
}
|
||||
|
||||
// --- admin CRUD (safe rows only) -----------------------------------------
|
||||
|
||||
list(): Promise<SafeUserRow[]> {
|
||||
return this.prisma.user.findMany({
|
||||
orderBy: [{ active: "desc" }, { name: "asc" }],
|
||||
select: safeSelect,
|
||||
});
|
||||
}
|
||||
|
||||
async create(dto: CreateUserDto): Promise<SafeUserRow> {
|
||||
const passwordHash = await argon2.hash(dto.password);
|
||||
try {
|
||||
return await this.prisma.user.create({
|
||||
data: {
|
||||
name: dto.name,
|
||||
email: dto.email,
|
||||
passwordHash,
|
||||
role: dto.role,
|
||||
active: dto.active ?? true,
|
||||
},
|
||||
select: safeSelect,
|
||||
});
|
||||
} catch (e) {
|
||||
throw this.mapError(e);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* `actingUserId` is the admin making the change — used to stop an admin from
|
||||
* locking themselves out (deactivating or demoting their own account).
|
||||
*/
|
||||
async update(
|
||||
id: string,
|
||||
dto: UpdateUserDto,
|
||||
actingUserId: string,
|
||||
): Promise<SafeUserRow> {
|
||||
await this.ensureExists(id);
|
||||
|
||||
if (id === actingUserId) {
|
||||
if (dto.active === false) {
|
||||
throw new BadRequestException("No puede desactivar su propia cuenta");
|
||||
}
|
||||
if (dto.role && dto.role !== "ADMIN") {
|
||||
throw new BadRequestException("No puede quitarse su propio rol de administrador");
|
||||
}
|
||||
}
|
||||
|
||||
try {
|
||||
return await this.prisma.user.update({
|
||||
where: { id },
|
||||
data: {
|
||||
name: dto.name,
|
||||
email: dto.email,
|
||||
role: dto.role,
|
||||
active: dto.active,
|
||||
},
|
||||
select: safeSelect,
|
||||
});
|
||||
} catch (e) {
|
||||
throw this.mapError(e);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Self-service preference write — no ability check, because the only account
|
||||
* it can touch is the caller's own (the controller passes the session id).
|
||||
*/
|
||||
updatePreferences(id: string, uiScale: number): Promise<SafeUserRow> {
|
||||
return this.prisma.user.update({
|
||||
where: { id },
|
||||
data: { uiScale },
|
||||
select: safeSelect,
|
||||
});
|
||||
}
|
||||
|
||||
async resetPassword(id: string, password: string): Promise<SafeUserRow> {
|
||||
await this.ensureExists(id);
|
||||
const passwordHash = await argon2.hash(password);
|
||||
return this.prisma.user.update({
|
||||
where: { id },
|
||||
data: { passwordHash },
|
||||
select: safeSelect,
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Hard-delete a user. The schema's ActivityLog.userId FK would otherwise
|
||||
* block the row (default `Restrict`), so null it out in the same
|
||||
* transaction. Rows + the actor id captured in the `message` JSON stay
|
||||
* intact for the audit trail.
|
||||
*/
|
||||
async remove(id: string, actingUserId: string): Promise<void> {
|
||||
if (id === actingUserId) {
|
||||
throw new BadRequestException("No puede eliminar su propia cuenta");
|
||||
}
|
||||
await this.ensureExists(id);
|
||||
try {
|
||||
await this.prisma.$transaction([
|
||||
this.prisma.activityLog.updateMany({
|
||||
where: { userId: id },
|
||||
data: { userId: null },
|
||||
}),
|
||||
this.prisma.user.delete({ where: { id } }),
|
||||
]);
|
||||
} catch (e) {
|
||||
throw this.mapError(e);
|
||||
}
|
||||
}
|
||||
|
||||
private async ensureExists(id: string): Promise<void> {
|
||||
const found = await this.prisma.user.findUnique({ where: { id }, select: { id: true } });
|
||||
if (!found) throw new NotFoundException(`Usuario ${id} no encontrado`);
|
||||
}
|
||||
|
||||
private mapError(e: unknown): Error {
|
||||
if (e instanceof Prisma.PrismaClientKnownRequestError && e.code === "P2002") {
|
||||
return new ConflictException("Ya existe un usuario con ese correo");
|
||||
}
|
||||
return e as Error;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
{
|
||||
"name": "@jorgecuadros/web",
|
||||
"version": "0.1.0",
|
||||
"version": "1.0.1",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"dev": "next dev",
|
||||
"dev": "next dev -p 4500",
|
||||
"build": "next build",
|
||||
"start": "next start",
|
||||
"lint": "next lint"
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 110 KiB |
@@ -0,0 +1,525 @@
|
||||
"use client";
|
||||
|
||||
import Link from "next/link";
|
||||
import { useEffect, useState } from "react";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import {
|
||||
createBankAccount,
|
||||
createBankInstitution,
|
||||
listBankAccounts,
|
||||
listBankInstitutions,
|
||||
updateBankAccount,
|
||||
updateBankInstitution,
|
||||
} from "@/lib/api";
|
||||
import { domainLabel } from "@/lib/labels";
|
||||
import type {
|
||||
BankAccount,
|
||||
BankInstitution,
|
||||
Currency,
|
||||
TransactionDomain,
|
||||
} from "@/lib/types";
|
||||
|
||||
/**
|
||||
* Chequera accounts admin — docs/RECEIPT_CAPTURE_SPEC.md §3.
|
||||
*
|
||||
* Two levels: the bank (institution) and the accounts held at it. Opening an
|
||||
* account is rare and consequential — its currency is what every movement
|
||||
* booked into it is denominated in, and it can't be changed afterwards without
|
||||
* silently re-denominating history, so the edit form deliberately has no
|
||||
* currency field.
|
||||
*
|
||||
* Accounts are never deleted: `bank_transactions.bankAccountId` is a required
|
||||
* FK, so a used account can't be removed without destroying its register.
|
||||
* Closing one (`active: false`) hides it from new captures while leaving the
|
||||
* history readable, matching this app's never-hard-delete convention.
|
||||
*/
|
||||
const CURRENCIES: Currency[] = ["MXN", "USD"];
|
||||
const BUSINESS_LINES: TransactionDomain[] = ["UTILITY", "INSURANCE", "TRUST"];
|
||||
|
||||
export default function CuentasChequeraPage() {
|
||||
return (
|
||||
<AppShell>
|
||||
<Cuentas />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
function Cuentas() {
|
||||
const canEdit = useCan("bank:manage-accounts");
|
||||
const [banks, setBanks] = useState<BankInstitution[] | null>(null);
|
||||
const [accounts, setAccounts] = useState<BankAccount[] | null>(null);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
function reload() {
|
||||
Promise.all([listBankInstitutions(), listBankAccounts()])
|
||||
.then(([b, a]) => {
|
||||
setBanks(b);
|
||||
setAccounts(a);
|
||||
})
|
||||
.catch((e) => setError(e?.message ?? "No se pudieron cargar las cuentas."));
|
||||
}
|
||||
useEffect(reload, []);
|
||||
|
||||
if (!canEdit) {
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<h1 className="page-title">Cuentas de chequera</h1>
|
||||
</div>
|
||||
<div className="state-box state-error">
|
||||
No tiene permisos para administrar cuentas bancarias.
|
||||
</div>
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<p className="eyebrow">
|
||||
<Link href="/banco">Chequera</Link>
|
||||
</p>
|
||||
<h1 className="page-title">Cuentas de chequera</h1>
|
||||
<p className="section-note">
|
||||
Cada cuenta es una chequera física y se lleva por separado. La moneda
|
||||
se fija al darla de alta porque todos sus movimientos quedan
|
||||
registrados en ella; para cambiarla hay que abrir otra cuenta. Las
|
||||
cuentas no se eliminan: se cierran, y su historial sigue consultable.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
{error && <div className="state-box state-error">{error}</div>}
|
||||
|
||||
{!banks || !accounts ? (
|
||||
<div className="empty-inline">
|
||||
<span className="spinner" aria-label="Cargando" />
|
||||
</div>
|
||||
) : (
|
||||
<>
|
||||
<BanksSection banks={banks} onChanged={reload} />
|
||||
<AccountsSection
|
||||
banks={banks}
|
||||
accounts={accounts}
|
||||
onChanged={reload}
|
||||
/>
|
||||
</>
|
||||
)}
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
/* ------------------------------------------------------------------ banks */
|
||||
|
||||
function BanksSection({
|
||||
banks,
|
||||
onChanged,
|
||||
}: {
|
||||
banks: BankInstitution[];
|
||||
onChanged: () => void;
|
||||
}) {
|
||||
const [adding, setAdding] = useState(false);
|
||||
const [editingId, setEditingId] = useState<string | null>(null);
|
||||
const [name, setName] = useState("");
|
||||
const [country, setCountry] = useState("");
|
||||
const [busy, setBusy] = useState(false);
|
||||
|
||||
function startAdd() {
|
||||
setEditingId(null);
|
||||
setAdding(true);
|
||||
setName("");
|
||||
setCountry("");
|
||||
}
|
||||
function startEdit(b: BankInstitution) {
|
||||
setAdding(false);
|
||||
setEditingId(b.id);
|
||||
setName(b.name);
|
||||
setCountry(b.country ?? "");
|
||||
}
|
||||
function cancel() {
|
||||
setAdding(false);
|
||||
setEditingId(null);
|
||||
}
|
||||
|
||||
async function submit() {
|
||||
if (!name.trim()) {
|
||||
window.alert("El nombre del banco es obligatorio.");
|
||||
return;
|
||||
}
|
||||
setBusy(true);
|
||||
try {
|
||||
const payload = { name: name.trim(), country: country.trim() };
|
||||
if (editingId) await updateBankInstitution(editingId, payload);
|
||||
else await createBankInstitution(payload);
|
||||
cancel();
|
||||
onChanged();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo guardar el banco.");
|
||||
} finally {
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
const editor = (
|
||||
<div className="child-editor">
|
||||
<div className="form-grid">
|
||||
<label className="field">
|
||||
<span className="field-label">
|
||||
Banco <span aria-hidden>*</span>
|
||||
</span>
|
||||
<input
|
||||
className="input"
|
||||
value={name}
|
||||
onChange={(e) => setName(e.target.value)}
|
||||
placeholder="Ej. Scotiabank"
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">País</span>
|
||||
<input
|
||||
className="input"
|
||||
value={country}
|
||||
onChange={(e) => setCountry(e.target.value)}
|
||||
placeholder="MX / US"
|
||||
/>
|
||||
</label>
|
||||
</div>
|
||||
<div className="form-actions">
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-primary"
|
||||
onClick={submit}
|
||||
disabled={busy}
|
||||
>
|
||||
{busy ? "Guardando…" : editingId ? "Guardar" : "Agregar"}
|
||||
</button>
|
||||
<button type="button" className="btn btn-ghost" onClick={cancel}>
|
||||
Cancelar
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
|
||||
return (
|
||||
<div className="card" style={{ padding: 16, marginBottom: 14 }}>
|
||||
<div className="child-head">
|
||||
<h3 className="section-title" style={{ margin: 0 }}>
|
||||
Bancos
|
||||
<span className="section-count"> {banks.length}</span>
|
||||
</h3>
|
||||
{!adding && editingId === null && (
|
||||
<button type="button" className="btn btn-outline" onClick={startAdd}>
|
||||
+ Agregar
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
|
||||
{banks.length === 0 && !adding ? (
|
||||
<div className="empty-inline">Sin bancos registrados.</div>
|
||||
) : (
|
||||
<div className="tx-scroll">
|
||||
<table className="tx-table">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Banco</th>
|
||||
<th>País</th>
|
||||
<th className="num">Acciones</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{adding && (
|
||||
<tr>
|
||||
<td colSpan={3}>{editor}</td>
|
||||
</tr>
|
||||
)}
|
||||
{banks.map((b) =>
|
||||
editingId === b.id ? (
|
||||
<tr key={b.id}>
|
||||
<td colSpan={3}>{editor}</td>
|
||||
</tr>
|
||||
) : (
|
||||
<tr key={b.id}>
|
||||
<td>{b.name}</td>
|
||||
<td>{b.country || "—"}</td>
|
||||
<td>
|
||||
<div className="row-actions">
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
onClick={() => startEdit(b)}
|
||||
>
|
||||
Editar
|
||||
</button>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
),
|
||||
)}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
/* --------------------------------------------------------------- accounts */
|
||||
|
||||
function AccountsSection({
|
||||
banks,
|
||||
accounts,
|
||||
onChanged,
|
||||
}: {
|
||||
banks: BankInstitution[];
|
||||
accounts: BankAccount[];
|
||||
onChanged: () => void;
|
||||
}) {
|
||||
const [adding, setAdding] = useState(false);
|
||||
const [editingId, setEditingId] = useState<string | null>(null);
|
||||
const [bankId, setBankId] = useState("");
|
||||
const [label, setLabel] = useState("");
|
||||
const [currency, setCurrency] = useState<Currency>("MXN");
|
||||
const [businessLine, setBusinessLine] = useState<string>("");
|
||||
const [active, setActive] = useState(true);
|
||||
const [busy, setBusy] = useState(false);
|
||||
|
||||
function startAdd() {
|
||||
setEditingId(null);
|
||||
setAdding(true);
|
||||
setBankId(banks[0]?.id ?? "");
|
||||
setLabel("");
|
||||
setCurrency("MXN");
|
||||
setBusinessLine("");
|
||||
setActive(true);
|
||||
}
|
||||
function startEdit(a: BankAccount) {
|
||||
setAdding(false);
|
||||
setEditingId(a.id);
|
||||
setBankId(a.bankId);
|
||||
setLabel(a.label);
|
||||
setCurrency(a.currency);
|
||||
setBusinessLine(a.businessLine ?? "");
|
||||
setActive(a.active);
|
||||
}
|
||||
function cancel() {
|
||||
setAdding(false);
|
||||
setEditingId(null);
|
||||
}
|
||||
|
||||
async function submit() {
|
||||
if (!bankId) {
|
||||
window.alert("Selecciona el banco de la cuenta.");
|
||||
return;
|
||||
}
|
||||
if (!label.trim()) {
|
||||
window.alert("El nombre de la cuenta es obligatorio.");
|
||||
return;
|
||||
}
|
||||
setBusy(true);
|
||||
try {
|
||||
const line = businessLine
|
||||
? (businessLine as TransactionDomain)
|
||||
: undefined;
|
||||
if (editingId) {
|
||||
// No `currency`: see the file header.
|
||||
await updateBankAccount(editingId, {
|
||||
bankId,
|
||||
label: label.trim(),
|
||||
businessLine: line,
|
||||
active,
|
||||
});
|
||||
} else {
|
||||
await createBankAccount({
|
||||
bankId,
|
||||
label: label.trim(),
|
||||
currency,
|
||||
businessLine: line,
|
||||
active,
|
||||
});
|
||||
}
|
||||
cancel();
|
||||
onChanged();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo guardar la cuenta.");
|
||||
} finally {
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
const editor = (
|
||||
<div className="child-editor">
|
||||
<div className="form-grid">
|
||||
<label className="field">
|
||||
<span className="field-label">
|
||||
Banco <span aria-hidden>*</span>
|
||||
</span>
|
||||
<select
|
||||
className="select"
|
||||
value={bankId}
|
||||
onChange={(e) => setBankId(e.target.value)}
|
||||
>
|
||||
<option value="">—</option>
|
||||
{banks.map((b) => (
|
||||
<option key={b.id} value={b.id}>
|
||||
{b.name}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">
|
||||
Nombre de la cuenta <span aria-hidden>*</span>
|
||||
</span>
|
||||
<input
|
||||
className="input"
|
||||
value={label}
|
||||
onChange={(e) => setLabel(e.target.value)}
|
||||
placeholder="Ej. Seguros — Bank of America (USD)"
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">
|
||||
Moneda <span aria-hidden>*</span>
|
||||
</span>
|
||||
<select
|
||||
className="select"
|
||||
value={currency}
|
||||
disabled={editingId !== null}
|
||||
onChange={(e) => setCurrency(e.target.value as Currency)}
|
||||
>
|
||||
{CURRENCIES.map((c) => (
|
||||
<option key={c} value={c}>
|
||||
{c}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
{editingId !== null && (
|
||||
<span className="section-note">
|
||||
No se puede cambiar: los movimientos ya registrados están en esta
|
||||
moneda.
|
||||
</span>
|
||||
)}
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Línea de negocio</span>
|
||||
<select
|
||||
className="select"
|
||||
value={businessLine}
|
||||
onChange={(e) => setBusinessLine(e.target.value)}
|
||||
>
|
||||
<option value="">Sin asignar</option>
|
||||
{BUSINESS_LINES.map((d) => (
|
||||
<option key={d} value={d}>
|
||||
{domainLabel(d)}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
<span className="section-note">
|
||||
Referencia nada más: una chequera puede pagar de varias líneas.
|
||||
</span>
|
||||
</label>
|
||||
<label
|
||||
className="field"
|
||||
style={{ flexDirection: "row", alignItems: "center", gap: 8 }}
|
||||
>
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={active}
|
||||
onChange={(e) => setActive(e.target.checked)}
|
||||
/>
|
||||
<span className="field-label" style={{ margin: 0 }}>
|
||||
Cuenta abierta
|
||||
</span>
|
||||
</label>
|
||||
</div>
|
||||
<div className="form-actions">
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-primary"
|
||||
onClick={submit}
|
||||
disabled={busy}
|
||||
>
|
||||
{busy ? "Guardando…" : editingId ? "Guardar" : "Agregar"}
|
||||
</button>
|
||||
<button type="button" className="btn btn-ghost" onClick={cancel}>
|
||||
Cancelar
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
|
||||
return (
|
||||
<div className="card" style={{ padding: 16, marginBottom: 14 }}>
|
||||
<div className="child-head">
|
||||
<h3 className="section-title" style={{ margin: 0 }}>
|
||||
Cuentas
|
||||
<span className="section-count"> {accounts.length}</span>
|
||||
</h3>
|
||||
{!adding && editingId === null && banks.length > 0 && (
|
||||
<button type="button" className="btn btn-outline" onClick={startAdd}>
|
||||
+ Agregar
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
|
||||
{banks.length === 0 ? (
|
||||
<div className="empty-inline">
|
||||
Registra primero el banco donde está la cuenta.
|
||||
</div>
|
||||
) : accounts.length === 0 && !adding ? (
|
||||
<div className="empty-inline">Sin cuentas registradas.</div>
|
||||
) : (
|
||||
<div className="tx-scroll">
|
||||
<table className="tx-table">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Cuenta</th>
|
||||
<th>Banco</th>
|
||||
<th>Moneda</th>
|
||||
<th>Línea</th>
|
||||
<th>Estatus</th>
|
||||
<th className="num">Acciones</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{adding && (
|
||||
<tr>
|
||||
<td colSpan={6}>{editor}</td>
|
||||
</tr>
|
||||
)}
|
||||
{accounts.map((a) =>
|
||||
editingId === a.id ? (
|
||||
<tr key={a.id}>
|
||||
<td colSpan={6}>{editor}</td>
|
||||
</tr>
|
||||
) : (
|
||||
<tr key={a.id}>
|
||||
<td>{a.label}</td>
|
||||
<td>{a.bankName}</td>
|
||||
<td className="mono">{a.currency}</td>
|
||||
<td>{a.businessLine ? domainLabel(a.businessLine) : "—"}</td>
|
||||
<td>{a.active ? "Abierta" : "Cerrada"}</td>
|
||||
<td>
|
||||
<div className="row-actions">
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
onClick={() => startEdit(a)}
|
||||
>
|
||||
Editar
|
||||
</button>
|
||||
<Link href="/banco" className="btn btn-ghost">
|
||||
Ver movimientos
|
||||
</Link>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
),
|
||||
)}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
+522
-42
@@ -1,13 +1,19 @@
|
||||
"use client";
|
||||
|
||||
import Link from "next/link";
|
||||
import { useCallback, useEffect, useRef, useState } from "react";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { ContextReports } from "@/components/ContextReports";
|
||||
import {
|
||||
createBankMovement,
|
||||
getBankFacets,
|
||||
getBankStats,
|
||||
getBankSummary,
|
||||
listBankAccounts,
|
||||
listBankMovements,
|
||||
voidBankMovement,
|
||||
} from "@/lib/api";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import {
|
||||
bankDirectionLabel,
|
||||
bankSourceLabel,
|
||||
@@ -18,6 +24,7 @@ import {
|
||||
monthName,
|
||||
} from "@/lib/labels";
|
||||
import type {
|
||||
BankAccount,
|
||||
BankCleared,
|
||||
BankDirection,
|
||||
BankFacets,
|
||||
@@ -27,23 +34,29 @@ import type {
|
||||
BankStats,
|
||||
BankSummary,
|
||||
BankTotals,
|
||||
CreateBankMovementInput,
|
||||
Currency,
|
||||
} from "@/lib/types";
|
||||
|
||||
/**
|
||||
* Bank register (chequera) browser — plan step 7.
|
||||
* Bank register (chequera) browser — plan step 7, multi-account since the
|
||||
* step-11 multi-bank work.
|
||||
*
|
||||
* This is the office's OWN checking account, not customer money. It is a
|
||||
* This is the office's OWN checking accounts, not customer money. It is a
|
||||
* separate page from /estado-cuenta on purpose: nothing here belongs in a
|
||||
* customer's statement and the two sets of figures are never combined.
|
||||
*
|
||||
* Two views:
|
||||
* Two views, both scoped to the ONE account picked at the top:
|
||||
* - "Movimientos": the register itself — every deposit and payment, by date,
|
||||
* payee, cheque number or amount.
|
||||
* - "Resumen": ingresos vs egresos per year, and per month inside a year,
|
||||
* with the running net movement since the register opened in 2013.
|
||||
* with the running net movement since the register opened.
|
||||
*
|
||||
* Single currency (MXN) — the source has no currency column. See the module
|
||||
* header in `bank.service.ts` for why there is no category/ramo filter.
|
||||
* Every amount is read in the selected account's currency. There is no "all
|
||||
* accounts" option on purpose — Utilities banks in MXN and Seguros in USD, so
|
||||
* one combined figure would be a number that never existed, exactly what
|
||||
* /estado-cuenta's per-currency rule avoids. See the module header in
|
||||
* `bank.service.ts` for why there is no category/ramo filter.
|
||||
*/
|
||||
type View = "movimientos" | "resumen";
|
||||
|
||||
@@ -76,7 +89,18 @@ export default function BancoPage() {
|
||||
);
|
||||
}
|
||||
|
||||
/** Remembers the last chequera a person looked at, per browser. */
|
||||
const ACCOUNT_KEY = "banco.bankAccountId";
|
||||
|
||||
function BankBrowser() {
|
||||
const canCapture = useCan("bank:create");
|
||||
const canVoid = useCan("bank:void");
|
||||
const canManageAccounts = useCan("bank:manage-accounts");
|
||||
|
||||
const [accounts, setAccounts] = useState<BankAccount[] | null>(null);
|
||||
const [accountId, setAccountId] = useState<string | null>(null);
|
||||
const [accountsError, setAccountsError] = useState<string | null>(null);
|
||||
|
||||
const [stats, setStats] = useState<BankStats | null>(null);
|
||||
const [facets, setFacets] = useState<BankFacets | null>(null);
|
||||
const [view, setView] = useState<View>("movimientos");
|
||||
@@ -93,19 +117,70 @@ function BankBrowser() {
|
||||
const [summaryYear, setSummaryYear] = useState<number | null>(null);
|
||||
const [loading, setLoading] = useState(true);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [captureOpen, setCaptureOpen] = useState(false);
|
||||
|
||||
const debounceRef = useRef<ReturnType<typeof setTimeout>>();
|
||||
|
||||
const account = accounts?.find((a) => a.id === accountId) ?? null;
|
||||
const currency = account?.currency ?? "MXN";
|
||||
|
||||
// Accounts load first: nothing else on this page can be requested until one
|
||||
// is selected, because every read is scoped to exactly one chequera.
|
||||
useEffect(() => {
|
||||
getBankStats().then(setStats).catch(() => setStats(null));
|
||||
getBankFacets().then(setFacets).catch(() => setFacets(null));
|
||||
listBankAccounts()
|
||||
.then((rows) => {
|
||||
setAccounts(rows);
|
||||
const remembered =
|
||||
typeof window !== "undefined"
|
||||
? window.localStorage.getItem(ACCOUNT_KEY)
|
||||
: null;
|
||||
const pick =
|
||||
rows.find((a) => a.id === remembered) ??
|
||||
rows.find((a) => a.active) ??
|
||||
rows[0];
|
||||
setAccountId(pick?.id ?? null);
|
||||
if (rows.length === 0) setLoading(false);
|
||||
})
|
||||
.catch((e) => {
|
||||
setAccountsError(e?.message ?? "No se pudieron cargar las cuentas.");
|
||||
setLoading(false);
|
||||
});
|
||||
}, []);
|
||||
|
||||
function pickAccount(id: string) {
|
||||
setAccountId(id);
|
||||
if (typeof window !== "undefined")
|
||||
window.localStorage.setItem(ACCOUNT_KEY, id);
|
||||
// The previous account's figures must not linger while the new ones load.
|
||||
setStats(null);
|
||||
setFacets(null);
|
||||
setMovements(null);
|
||||
setSummary(null);
|
||||
setSummaryYear(null);
|
||||
}
|
||||
|
||||
const refreshStats = useCallback(() => {
|
||||
if (!accountId) return;
|
||||
getBankStats(accountId)
|
||||
.then(setStats)
|
||||
.catch(() => setStats(null));
|
||||
}, [accountId]);
|
||||
|
||||
useEffect(() => {
|
||||
if (!accountId) return;
|
||||
refreshStats();
|
||||
getBankFacets(accountId)
|
||||
.then(setFacets)
|
||||
.catch(() => setFacets(null));
|
||||
}, [accountId, refreshStats]);
|
||||
|
||||
const runSearch = useCallback(
|
||||
(p: number) => {
|
||||
if (!accountId) return;
|
||||
setLoading(true);
|
||||
setError(null);
|
||||
listBankMovements({
|
||||
bankAccountId: accountId,
|
||||
query: query || undefined,
|
||||
direction: direction || undefined,
|
||||
cleared: cleared || undefined,
|
||||
@@ -124,23 +199,23 @@ function BankBrowser() {
|
||||
setLoading(false);
|
||||
});
|
||||
},
|
||||
[query, direction, cleared, from, to, sort],
|
||||
[accountId, query, direction, cleared, from, to, sort],
|
||||
);
|
||||
|
||||
useEffect(() => {
|
||||
if (view !== "movimientos") return;
|
||||
if (view !== "movimientos" || !accountId) return;
|
||||
if (debounceRef.current) clearTimeout(debounceRef.current);
|
||||
debounceRef.current = setTimeout(() => runSearch(1), 280);
|
||||
return () => {
|
||||
if (debounceRef.current) clearTimeout(debounceRef.current);
|
||||
};
|
||||
}, [runSearch, view]);
|
||||
}, [runSearch, view, accountId]);
|
||||
|
||||
useEffect(() => {
|
||||
if (view !== "resumen") return;
|
||||
if (view !== "resumen" || !accountId) return;
|
||||
setLoading(true);
|
||||
setError(null);
|
||||
getBankSummary(summaryYear ?? undefined)
|
||||
getBankSummary(accountId, summaryYear ?? undefined)
|
||||
.then((res) => {
|
||||
setSummary(res);
|
||||
setLoading(false);
|
||||
@@ -149,7 +224,7 @@ function BankBrowser() {
|
||||
setError(e?.message ?? "No se pudo cargar el resumen.");
|
||||
setLoading(false);
|
||||
});
|
||||
}, [view, summaryYear]);
|
||||
}, [view, summaryYear, accountId]);
|
||||
|
||||
function goToPage(p: number) {
|
||||
runSearch(p);
|
||||
@@ -186,21 +261,79 @@ function BankBrowser() {
|
||||
setSort("date_desc");
|
||||
}
|
||||
|
||||
if (accountsError) {
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<h1 className="page-title">Chequera</h1>
|
||||
</div>
|
||||
<div className="state-error" role="alert">
|
||||
{accountsError}
|
||||
</div>
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
// No chequera on file: the register has nothing it could be scoped to.
|
||||
if (accounts && accounts.length === 0) {
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<p className="eyebrow">Cuentas propias de la oficina</p>
|
||||
<h1 className="page-title">Chequera</h1>
|
||||
</div>
|
||||
<div className="state-box">
|
||||
<div className="state-glyph" aria-hidden>
|
||||
⌗
|
||||
</div>
|
||||
<h3>Sin cuentas registradas</h3>
|
||||
<p>
|
||||
{canManageAccounts ? (
|
||||
<>
|
||||
Registra una cuenta bancaria en{" "}
|
||||
<Link href="/banco/cuentas">Cuentas de chequera</Link> para
|
||||
empezar a capturar movimientos.
|
||||
</>
|
||||
) : (
|
||||
"Pide a un administrador que registre una cuenta bancaria."
|
||||
)}
|
||||
</p>
|
||||
</div>
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head rise">
|
||||
<p className="eyebrow">Cuenta propia de la oficina</p>
|
||||
<h1 className="page-title">Chequera</h1>
|
||||
<AccountPicker
|
||||
accounts={accounts}
|
||||
accountId={accountId}
|
||||
onPick={pickAccount}
|
||||
canManageAccounts={canManageAccounts}
|
||||
/>
|
||||
<BankStatStrip
|
||||
stats={stats}
|
||||
currency={currency}
|
||||
direction={view === "movimientos" ? direction : ""}
|
||||
onPickDirection={pickDirection}
|
||||
/>
|
||||
<p className="section-note">
|
||||
Movimientos de la cuenta bancaria de la oficina, en pesos. No forma
|
||||
parte del estado de cuenta de los clientes y sus cifras no se suman
|
||||
con las de ellos.
|
||||
Movimientos de{" "}
|
||||
<strong>{account ? account.label : "la cuenta seleccionada"}</strong>,
|
||||
en {currency}. Cada cuenta se lee por separado: las cifras de dos
|
||||
chequeras nunca se suman, igual que los saldos por moneda del estado
|
||||
de cuenta. Tampoco forman parte del estado de cuenta de los clientes.
|
||||
</p>
|
||||
<div style={{ marginTop: 8 }}>
|
||||
<ContextReports
|
||||
entries={[
|
||||
{ slug: "reporte-de-efectivo", label: "Reporte de efectivo" },
|
||||
]}
|
||||
/>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="toolbar">
|
||||
@@ -237,8 +370,36 @@ function BankBrowser() {
|
||||
</button>
|
||||
))}
|
||||
</div>
|
||||
{view === "movimientos" && canCapture && account?.active && (
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-primary"
|
||||
onClick={() => setCaptureOpen((v) => !v)}
|
||||
>
|
||||
{captureOpen ? "Cerrar captura" : "Capturar movimiento"}
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
|
||||
{account && !account.active && (
|
||||
<div className="section-note">
|
||||
Esta cuenta está cerrada: su historial se consulta, pero no admite
|
||||
movimientos nuevos.
|
||||
</div>
|
||||
)}
|
||||
|
||||
{view === "movimientos" && captureOpen && account && (
|
||||
<BankCaptureForm
|
||||
account={account}
|
||||
onSaved={() => {
|
||||
setCaptureOpen(false);
|
||||
runSearch(movements?.page ?? 1);
|
||||
refreshStats();
|
||||
}}
|
||||
onCancel={() => setCaptureOpen(false)}
|
||||
/>
|
||||
)}
|
||||
|
||||
{view === "movimientos" && (
|
||||
<div className="filter-row">
|
||||
<label className="filter-field">
|
||||
@@ -354,7 +515,7 @@ function BankBrowser() {
|
||||
)}
|
||||
|
||||
{view === "movimientos" && movements && !loading && (
|
||||
<FilteredTotals totals={movements.totals} />
|
||||
<FilteredTotals totals={movements.totals} currency={currency} />
|
||||
)}
|
||||
|
||||
{error ? (
|
||||
@@ -367,6 +528,7 @@ function BankBrowser() {
|
||||
<SummaryView
|
||||
summary={summary}
|
||||
year={summaryYear}
|
||||
currency={currency}
|
||||
onPickYear={pickYear}
|
||||
/>
|
||||
) : movements && movements.total === 0 ? (
|
||||
@@ -383,11 +545,25 @@ function BankBrowser() {
|
||||
<th>Beneficiario / concepto</th>
|
||||
<th>Origen</th>
|
||||
<th className="num">Monto</th>
|
||||
{canVoid && (
|
||||
<th style={{ width: 1, whiteSpace: "nowrap" }}>
|
||||
Acciones
|
||||
</th>
|
||||
)}
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{movements?.items.map((m) => (
|
||||
<BankRow key={m.id} m={m} />
|
||||
<BankRow
|
||||
key={m.id}
|
||||
m={m}
|
||||
currency={currency}
|
||||
canVoid={canVoid}
|
||||
onVoided={() => {
|
||||
runSearch(movements?.page ?? 1);
|
||||
refreshStats();
|
||||
}}
|
||||
/>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -406,13 +582,66 @@ function BankBrowser() {
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* Which chequera the whole page is reading. There is no "todas las cuentas"
|
||||
* option and there must not be one — see the file header.
|
||||
*/
|
||||
function AccountPicker({
|
||||
accounts,
|
||||
accountId,
|
||||
onPick,
|
||||
canManageAccounts,
|
||||
}: {
|
||||
accounts: BankAccount[] | null;
|
||||
accountId: string | null;
|
||||
onPick: (id: string) => void;
|
||||
canManageAccounts: boolean;
|
||||
}) {
|
||||
if (!accounts) {
|
||||
return (
|
||||
<div className="skeleton" style={{ height: 34, width: 260, marginTop: 12 }} />
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<div
|
||||
className="filter-row"
|
||||
style={{ marginTop: 12, alignItems: "flex-end" }}
|
||||
>
|
||||
<label className="filter-field">
|
||||
<span className="filter-label">Cuenta</span>
|
||||
<select
|
||||
className="input select"
|
||||
value={accountId ?? ""}
|
||||
onChange={(e) => onPick(e.target.value)}
|
||||
aria-label="Cuenta de chequera"
|
||||
>
|
||||
{accounts.map((a) => (
|
||||
<option key={a.id} value={a.id}>
|
||||
{a.label} · {a.currency}
|
||||
{a.active ? "" : " (cerrada)"}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
</label>
|
||||
{canManageAccounts && (
|
||||
<Link href="/banco/cuentas" className="btn btn-ghost">
|
||||
Administrar cuentas
|
||||
</Link>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
/** Headline figures; the ingreso/egreso cells double as register shortcuts. */
|
||||
function BankStatStrip({
|
||||
stats,
|
||||
currency,
|
||||
direction,
|
||||
onPickDirection,
|
||||
}: {
|
||||
stats: BankStats | null;
|
||||
currency: Currency;
|
||||
direction: BankDirection | "";
|
||||
onPickDirection: (d: BankDirection) => void;
|
||||
}) {
|
||||
@@ -443,7 +672,7 @@ function BankStatStrip({
|
||||
aria-pressed={direction === "income"}
|
||||
>
|
||||
<div className="stat-value tx-amount pos">
|
||||
{formatMoney(stats.income, "MXN")}
|
||||
{formatMoney(stats.income, currency)}
|
||||
</div>
|
||||
<div className="stat-label">
|
||||
En ingresos · {formatNumber(stats.incomeCount)} movimientos
|
||||
@@ -458,14 +687,14 @@ function BankStatStrip({
|
||||
aria-pressed={direction === "expense"}
|
||||
>
|
||||
<div className="stat-value tx-amount neg">
|
||||
{formatMoney(stats.expense, "MXN")}
|
||||
{formatMoney(stats.expense, currency)}
|
||||
</div>
|
||||
<div className="stat-label">
|
||||
En egresos · {formatNumber(stats.expenseCount)} movimientos
|
||||
</div>
|
||||
</button>
|
||||
<div className="stat-cell">
|
||||
<div className="stat-value">{formatMoney(stats.net, "MXN")}</div>
|
||||
<div className="stat-value">{formatMoney(stats.net, currency)}</div>
|
||||
{/* Not the bank balance: the register carries no opening balance. */}
|
||||
<div className="stat-label">Movimiento neto acumulado</div>
|
||||
</div>
|
||||
@@ -494,27 +723,33 @@ function BankStatStrip({
|
||||
}
|
||||
|
||||
/** Totals for everything the current filter matched, not just the page. */
|
||||
function FilteredTotals({ totals }: { totals: BankTotals }) {
|
||||
function FilteredTotals({
|
||||
totals,
|
||||
currency,
|
||||
}: {
|
||||
totals: BankTotals;
|
||||
currency: Currency;
|
||||
}) {
|
||||
if (totals.incomeCount + totals.expenseCount + totals.voidCount === 0)
|
||||
return null;
|
||||
return (
|
||||
<div className="filtered-totals">
|
||||
<div className="filtered-total">
|
||||
<span className="filtered-total-cur">MXN</span>
|
||||
<span className="filtered-total-cur">{currency}</span>
|
||||
<span>
|
||||
<strong className="tx-amount pos">
|
||||
{formatMoney(totals.income, "MXN")}
|
||||
{formatMoney(totals.income, currency)}
|
||||
</strong>{" "}
|
||||
en ingresos · {formatNumber(totals.incomeCount)}
|
||||
</span>
|
||||
<span>
|
||||
<strong className="tx-amount neg">
|
||||
{formatMoney(totals.expense, "MXN")}
|
||||
{formatMoney(totals.expense, currency)}
|
||||
</strong>{" "}
|
||||
en egresos · {formatNumber(totals.expenseCount)}
|
||||
</span>
|
||||
<span className="filtered-total-net">
|
||||
Neto <strong>{formatMoney(totals.net, "MXN")}</strong>
|
||||
Neto <strong>{formatMoney(totals.net, currency)}</strong>
|
||||
</span>
|
||||
{totals.voidCount > 0 && (
|
||||
<span>{formatNumber(totals.voidCount)} cancelados</span>
|
||||
@@ -524,17 +759,46 @@ function FilteredTotals({ totals }: { totals: BankTotals }) {
|
||||
);
|
||||
}
|
||||
|
||||
function BankRow({ m }: { m: BankListItem }) {
|
||||
function BankRow({
|
||||
m,
|
||||
currency,
|
||||
canVoid,
|
||||
onVoided,
|
||||
}: {
|
||||
m: BankListItem;
|
||||
currency: Currency;
|
||||
canVoid: boolean;
|
||||
onVoided: () => void;
|
||||
}) {
|
||||
const [busy, setBusy] = useState(false);
|
||||
|
||||
async function doVoid() {
|
||||
if (
|
||||
!window.confirm(
|
||||
"¿Anular este movimiento? Quedará tachado y no contará en los totales.",
|
||||
)
|
||||
)
|
||||
return;
|
||||
setBusy(true);
|
||||
try {
|
||||
await voidBankMovement(m.id);
|
||||
onVoided();
|
||||
} catch (e) {
|
||||
window.alert(
|
||||
(e as Error)?.message ?? "No se pudo anular el movimiento.",
|
||||
);
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<tr>
|
||||
<tr style={m.voided ? { textDecoration: "line-through", opacity: 0.55 } : undefined}>
|
||||
<td className="mono" style={{ whiteSpace: "nowrap" }}>
|
||||
{formatDate(m.transactionDate)}
|
||||
</td>
|
||||
<td className="tx-ref">
|
||||
{m.reference || "—"}
|
||||
{!m.cleared && (
|
||||
<div className="tx-concept">Sin operar</div>
|
||||
)}
|
||||
{!m.cleared && <div className="tx-concept">Sin operar</div>}
|
||||
</td>
|
||||
<td>
|
||||
{m.concept || <span className="muted">Sin concepto</span>}
|
||||
@@ -543,10 +807,25 @@ function BankRow({ m }: { m: BankListItem }) {
|
||||
<td>{bankSourceLabel(m.source)}</td>
|
||||
<td className="num">
|
||||
<span className={`tx-amount ${bankTone(m.direction)}`}>
|
||||
{m.direction === "void" ? "—" : formatMoney(m.amount, "MXN")}
|
||||
{m.direction === "void" ? "—" : formatMoney(m.amount, currency)}
|
||||
</span>
|
||||
<div className="tx-cur">{bankDirectionLabel(m.direction)}</div>
|
||||
</td>
|
||||
{canVoid && (
|
||||
<td style={{ whiteSpace: "nowrap" }}>
|
||||
{!m.voided && (
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
style={{ padding: "4px 10px", fontSize: 12 }}
|
||||
onClick={doVoid}
|
||||
disabled={busy}
|
||||
>
|
||||
{busy ? "Anulando…" : "Anular"}
|
||||
</button>
|
||||
)}
|
||||
</td>
|
||||
)}
|
||||
</tr>
|
||||
);
|
||||
}
|
||||
@@ -558,10 +837,12 @@ function BankRow({ m }: { m: BankListItem }) {
|
||||
function SummaryView({
|
||||
summary,
|
||||
year,
|
||||
currency,
|
||||
onPickYear,
|
||||
}: {
|
||||
summary: BankSummary | null;
|
||||
year: number | null;
|
||||
currency: Currency;
|
||||
onPickYear: (y: number) => void;
|
||||
}) {
|
||||
if (!summary) return null;
|
||||
@@ -595,12 +876,12 @@ function SummaryView({
|
||||
<td className="num">{formatNumber(r.count)}</td>
|
||||
<td className="num">
|
||||
<span className="tx-amount pos">
|
||||
{formatMoney(r.income, "MXN")}
|
||||
{formatMoney(r.income, currency)}
|
||||
</span>
|
||||
</td>
|
||||
<td className="num">
|
||||
<span className="tx-amount neg">
|
||||
{formatMoney(r.expense, "MXN")}
|
||||
{formatMoney(r.expense, currency)}
|
||||
</span>
|
||||
</td>
|
||||
<td className="num">
|
||||
@@ -609,10 +890,10 @@ function SummaryView({
|
||||
Number(r.net) < 0 ? "neg" : "pos"
|
||||
}`}
|
||||
>
|
||||
{formatMoney(r.net, "MXN")}
|
||||
{formatMoney(r.net, currency)}
|
||||
</span>
|
||||
</td>
|
||||
<td className="num mono">{formatMoney(r.cumulative, "MXN")}</td>
|
||||
<td className="num mono">{formatMoney(r.cumulative, currency)}</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
@@ -632,7 +913,7 @@ function SummaryView({
|
||||
<span className="section-rule cuenta" />
|
||||
<h2 className="section-title">Meses de {year}</h2>
|
||||
<span className="section-count">
|
||||
abre en {formatMoney(summary.opening, "MXN")}
|
||||
abre en {formatMoney(summary.opening, currency)}
|
||||
</span>
|
||||
</div>
|
||||
<div className="card">
|
||||
@@ -655,12 +936,12 @@ function SummaryView({
|
||||
<td className="num">{formatNumber(r.count)}</td>
|
||||
<td className="num">
|
||||
<span className="tx-amount pos">
|
||||
{formatMoney(r.income, "MXN")}
|
||||
{formatMoney(r.income, currency)}
|
||||
</span>
|
||||
</td>
|
||||
<td className="num">
|
||||
<span className="tx-amount neg">
|
||||
{formatMoney(r.expense, "MXN")}
|
||||
{formatMoney(r.expense, currency)}
|
||||
</span>
|
||||
</td>
|
||||
<td className="num">
|
||||
@@ -669,11 +950,11 @@ function SummaryView({
|
||||
Number(r.net) < 0 ? "neg" : "pos"
|
||||
}`}
|
||||
>
|
||||
{formatMoney(r.net, "MXN")}
|
||||
{formatMoney(r.net, currency)}
|
||||
</span>
|
||||
</td>
|
||||
<td className="num mono">
|
||||
{formatMoney(r.cumulative, "MXN")}
|
||||
{formatMoney(r.cumulative, currency)}
|
||||
</td>
|
||||
</tr>
|
||||
))}
|
||||
@@ -687,6 +968,205 @@ function SummaryView({
|
||||
);
|
||||
}
|
||||
|
||||
/** Inline capture form for a single chequera movement. The amount is in the
|
||||
* selected account's currency; sign convention: positive = ingreso, negative
|
||||
* = egreso. Booked rows are never edited — fix mistakes with voidBankMovement
|
||||
* + a fresh capture. */
|
||||
function BankCaptureForm({
|
||||
account,
|
||||
onSaved,
|
||||
onCancel,
|
||||
}: {
|
||||
account: BankAccount;
|
||||
onSaved: () => void;
|
||||
onCancel: () => void;
|
||||
}) {
|
||||
const [direction, setDirection] = useState<BankDirection>("expense");
|
||||
const [amount, setAmount] = useState("");
|
||||
const [transactionDate, setTransactionDate] = useState(
|
||||
new Date().toISOString().slice(0, 10),
|
||||
);
|
||||
const [concept, setConcept] = useState("");
|
||||
const [reference, setReference] = useState("");
|
||||
const [transactionType, setTransactionType] = useState("");
|
||||
const [cleared, setCleared] = useState(true);
|
||||
const [transferred, setTransferred] = useState(false);
|
||||
const [notes, setNotes] = useState("");
|
||||
const [amountInWords, setAmountInWords] = useState("");
|
||||
const [saving, setSaving] = useState(false);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
function s(v: string): string | undefined {
|
||||
const t = v.trim();
|
||||
return t === "" ? undefined : t;
|
||||
}
|
||||
|
||||
async function submit(e: React.FormEvent) {
|
||||
e.preventDefault();
|
||||
const abs = Number(amount);
|
||||
if (!Number.isFinite(abs) || abs <= 0) {
|
||||
setError("El monto debe ser un número mayor a cero.");
|
||||
return;
|
||||
}
|
||||
const signed = direction === "income" ? Math.abs(abs) : -Math.abs(abs);
|
||||
const payload: CreateBankMovementInput = {
|
||||
bankAccountId: account.id,
|
||||
amount: signed,
|
||||
transactionDate,
|
||||
concept: s(concept),
|
||||
reference: s(reference),
|
||||
transactionType: s(transactionType),
|
||||
cleared,
|
||||
transferred,
|
||||
notes: s(notes),
|
||||
amountInWords: s(amountInWords),
|
||||
};
|
||||
setSaving(true);
|
||||
setError(null);
|
||||
try {
|
||||
await createBankMovement(payload);
|
||||
onSaved();
|
||||
} catch (e2) {
|
||||
setError((e2 as Error)?.message ?? "No se pudo guardar el movimiento.");
|
||||
setSaving(false);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<form onSubmit={submit}>
|
||||
{error && <div className="state-box state-error">{error}</div>}
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 4 }}>
|
||||
Capturar movimiento de chequera
|
||||
</h2>
|
||||
<p className="section-note" style={{ marginBottom: 14 }}>
|
||||
Se registra en <strong>{account.label}</strong>, en {account.currency}.
|
||||
</p>
|
||||
<div className="form-grid">
|
||||
<label className="field">
|
||||
<span className="field-label">
|
||||
Tipo <span aria-hidden>*</span>
|
||||
</span>
|
||||
<select
|
||||
className="select"
|
||||
value={direction}
|
||||
onChange={(e) => setDirection(e.target.value as BankDirection)}
|
||||
>
|
||||
<option value="income">Ingreso</option>
|
||||
<option value="expense">Egreso</option>
|
||||
</select>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">
|
||||
Fecha <span aria-hidden>*</span>
|
||||
</span>
|
||||
<input
|
||||
className="input"
|
||||
type="date"
|
||||
required
|
||||
value={transactionDate}
|
||||
onChange={(e) => setTransactionDate(e.target.value)}
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">
|
||||
Monto ({account.currency}) <span aria-hidden>*</span>
|
||||
</span>
|
||||
<input
|
||||
className="input"
|
||||
type="number"
|
||||
step="0.01"
|
||||
required
|
||||
min="0"
|
||||
value={amount}
|
||||
onChange={(e) => setAmount(e.target.value)}
|
||||
placeholder="0.00"
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Concepto</span>
|
||||
<input
|
||||
className="input"
|
||||
value={concept}
|
||||
onChange={(e) => setConcept(e.target.value)}
|
||||
placeholder="Beneficiario o motivo"
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Referencia / cheque</span>
|
||||
<input
|
||||
className="input"
|
||||
value={reference}
|
||||
onChange={(e) => setReference(e.target.value)}
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Tipo en origen</span>
|
||||
<input
|
||||
className="input"
|
||||
value={transactionType}
|
||||
onChange={(e) => setTransactionType(e.target.value)}
|
||||
placeholder="INGRESO / EGRESO"
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Monto en letras</span>
|
||||
<input
|
||||
className="input"
|
||||
value={amountInWords}
|
||||
onChange={(e) => setAmountInWords(e.target.value)}
|
||||
placeholder="Ej. CIENTO CINCUENTA MIL PESOS 00/100"
|
||||
/>
|
||||
</label>
|
||||
<label
|
||||
className="field"
|
||||
style={{ flexDirection: "row", alignItems: "center", gap: 8 }}
|
||||
>
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={cleared}
|
||||
onChange={(e) => setCleared(e.target.checked)}
|
||||
/>
|
||||
<span className="field-label" style={{ margin: 0 }}>
|
||||
Operado por el banco
|
||||
</span>
|
||||
</label>
|
||||
<label
|
||||
className="field"
|
||||
style={{ flexDirection: "row", alignItems: "center", gap: 8 }}
|
||||
>
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={transferred}
|
||||
onChange={(e) => setTransferred(e.target.checked)}
|
||||
/>
|
||||
<span className="field-label" style={{ margin: 0 }}>
|
||||
Transferencia
|
||||
</span>
|
||||
</label>
|
||||
</div>
|
||||
<label className="field" style={{ marginTop: 16 }}>
|
||||
<span className="field-label">Notas</span>
|
||||
<textarea
|
||||
className="input"
|
||||
rows={2}
|
||||
value={notes}
|
||||
onChange={(e) => setNotes(e.target.value)}
|
||||
/>
|
||||
</label>
|
||||
</div>
|
||||
<div className="form-actions">
|
||||
<button type="submit" className="btn btn-primary" disabled={saving}>
|
||||
{saving ? "Guardando…" : "Capturar movimiento"}
|
||||
</button>
|
||||
<button type="button" className="btn btn-outline" onClick={onCancel}>
|
||||
Cancelar
|
||||
</button>
|
||||
</div>
|
||||
</form>
|
||||
);
|
||||
}
|
||||
|
||||
function Pager({
|
||||
page,
|
||||
pageCount,
|
||||
|
||||
@@ -0,0 +1,102 @@
|
||||
"use client";
|
||||
|
||||
import { useEffect, useState } from "react";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { ChildCollection, type ChildConfig } from "@/components/ChildCollection";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import { createLookup, getLookups, removeLookup, updateLookup } from "@/lib/api";
|
||||
import type { LookupsResponse } from "@/lib/types";
|
||||
|
||||
const PROVIDER: ChildConfig = {
|
||||
apiKind: "providers",
|
||||
title: "Aseguradoras",
|
||||
fields: [{ key: "name", label: "Nombre" }],
|
||||
};
|
||||
const TYPE: ChildConfig = {
|
||||
apiKind: "policy-types",
|
||||
title: "Tipos de póliza",
|
||||
fields: [
|
||||
{ key: "name", label: "Nombre" },
|
||||
{ key: "shortDescription", label: "Descripción" },
|
||||
],
|
||||
};
|
||||
const ADJUSTER: ChildConfig = {
|
||||
apiKind: "adjusters",
|
||||
title: "Ajustadores",
|
||||
fields: [
|
||||
{ key: "company", label: "Empresa" },
|
||||
{ key: "name", label: "Nombre" },
|
||||
{ key: "city", label: "Ciudad" },
|
||||
{ key: "phone", label: "Teléfono" },
|
||||
{ key: "beeper", label: "Beeper" },
|
||||
],
|
||||
};
|
||||
|
||||
export default function CatalogosPage() {
|
||||
return (
|
||||
<AppShell>
|
||||
<Catalogos />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
function Catalogos() {
|
||||
const canEdit = useCan("lookup:manage");
|
||||
const [data, setData] = useState<LookupsResponse | null>(null);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
function reload() {
|
||||
getLookups().then(setData).catch((e) => setError(e?.message ?? "Error al cargar."));
|
||||
}
|
||||
useEffect(reload, []);
|
||||
|
||||
if (!canEdit) {
|
||||
return (
|
||||
<>
|
||||
<div className="page-head"><h1 className="page-title">Catálogos</h1></div>
|
||||
<div className="state-box state-error">
|
||||
No tiene permisos para administrar catálogos.
|
||||
</div>
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
const section = (config: ChildConfig, rows: Record<string, unknown>[]) => (
|
||||
<ChildCollection
|
||||
config={config}
|
||||
rows={rows}
|
||||
canEdit={canEdit}
|
||||
onAdd={async (p) => {
|
||||
await createLookup(config.apiKind, p);
|
||||
reload();
|
||||
}}
|
||||
onSave={async (id, p) => {
|
||||
await updateLookup(config.apiKind, id, p);
|
||||
reload();
|
||||
}}
|
||||
onRemove={async (id) => {
|
||||
await removeLookup(config.apiKind, id);
|
||||
reload();
|
||||
}}
|
||||
/>
|
||||
);
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<p className="eyebrow">Datos de referencia de seguros</p>
|
||||
<h1 className="page-title">Catálogos</h1>
|
||||
</div>
|
||||
{error && <div className="state-box state-error">{error}</div>}
|
||||
{!data ? (
|
||||
<div className="empty-inline"><span className="spinner" aria-label="Cargando" /></div>
|
||||
) : (
|
||||
<>
|
||||
{section(PROVIDER, data.providers as unknown as Record<string, unknown>[])}
|
||||
{section(TYPE, data.types as unknown as Record<string, unknown>[])}
|
||||
{section(ADJUSTER, data.adjusters as unknown as Record<string, unknown>[])}
|
||||
</>
|
||||
)}
|
||||
</>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,58 @@
|
||||
"use client";
|
||||
|
||||
import { useEffect, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { CustomerForm } from "@/components/CustomerForm";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import { getCustomer } from "@/lib/api";
|
||||
import type { CustomerDetail } from "@/lib/types";
|
||||
|
||||
export default function EditarClientePage({
|
||||
params,
|
||||
}: {
|
||||
params: { id: string };
|
||||
}) {
|
||||
return (
|
||||
<AppShell>
|
||||
<EditarCliente id={params.id} />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
function EditarCliente({ id }: { id: string }) {
|
||||
const allowed = useCan("customer:update");
|
||||
const [customer, setCustomer] = useState<CustomerDetail | null>(null);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
useEffect(() => {
|
||||
if (!allowed) return;
|
||||
getCustomer(id)
|
||||
.then(setCustomer)
|
||||
.catch((e) => setError(e?.message ?? "No se pudo cargar el cliente."));
|
||||
}, [id, allowed]);
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<Link href={`/clientes/${id}`} className="back-link">
|
||||
← Cliente
|
||||
</Link>
|
||||
<h1 className="page-title">Editar cliente</h1>
|
||||
</div>
|
||||
{!allowed ? (
|
||||
<div className="state-box state-error">
|
||||
No tiene permisos para editar clientes.
|
||||
</div>
|
||||
) : error ? (
|
||||
<div className="state-box state-error">{error}</div>
|
||||
) : !customer ? (
|
||||
<div className="empty-inline">
|
||||
<span className="spinner" aria-label="Cargando" />
|
||||
</div>
|
||||
) : (
|
||||
<CustomerForm customer={customer} />
|
||||
)}
|
||||
</>
|
||||
);
|
||||
}
|
||||
@@ -3,7 +3,15 @@
|
||||
import { useEffect, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { getCustomer } from "@/lib/api";
|
||||
import { ContextReports } from "@/components/ContextReports";
|
||||
import {
|
||||
archiveCustomer,
|
||||
getCustomer,
|
||||
policyDocumentDownloadUrl,
|
||||
propertyDocumentDownloadUrl,
|
||||
restoreCustomer,
|
||||
} from "@/lib/api";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import {
|
||||
domainLabel,
|
||||
formatDate,
|
||||
@@ -86,12 +94,35 @@ function Detail({ id }: { id: string }) {
|
||||
|
||||
return (
|
||||
<div className="rise">
|
||||
<BackLink />
|
||||
<div className="detail-actionbar">
|
||||
<BackLink />
|
||||
<ContextReports
|
||||
entries={[
|
||||
{
|
||||
slug: "edo-cuenta-datos",
|
||||
label: "Estado de cuenta (reporte)",
|
||||
params: { customerId: data.id },
|
||||
},
|
||||
]}
|
||||
/>
|
||||
<CustomerActions
|
||||
customer={data}
|
||||
onChange={() => getCustomer(id).then(setData).catch(() => {})}
|
||||
/>
|
||||
</div>
|
||||
<Hero data={data} hasUtilities={hasUtilities} hasInsurance={hasInsurance} />
|
||||
|
||||
<DatosSection data={data} />
|
||||
<PropiedadesSection properties={data.properties} />
|
||||
<PolizasSection policies={data.policies} />
|
||||
<PropiedadesSection
|
||||
properties={data.properties}
|
||||
customerId={data.id}
|
||||
customerName={data.name}
|
||||
/>
|
||||
<PolizasSection
|
||||
policies={data.policies}
|
||||
customerId={data.id}
|
||||
customerName={data.name}
|
||||
/>
|
||||
<EstadoCuentaSection
|
||||
customerId={data.id}
|
||||
summary={data.transactionSummary}
|
||||
@@ -110,6 +141,58 @@ function BackLink() {
|
||||
);
|
||||
}
|
||||
|
||||
/** Edit / archive controls, each gated by the matching ability. */
|
||||
function CustomerActions({
|
||||
customer,
|
||||
onChange,
|
||||
}: {
|
||||
customer: CustomerDetail;
|
||||
onChange: () => void;
|
||||
}) {
|
||||
const canEdit = useCan("customer:update");
|
||||
const canDelete = useCan("customer:delete");
|
||||
const [busy, setBusy] = useState(false);
|
||||
const archived = customer.archivedAt != null;
|
||||
|
||||
async function toggleArchive() {
|
||||
const verb = archived ? "restaurar" : "archivar";
|
||||
if (!window.confirm(`¿Seguro que desea ${verb} este cliente?`)) return;
|
||||
setBusy(true);
|
||||
try {
|
||||
if (archived) await restoreCustomer(customer.id);
|
||||
else await archiveCustomer(customer.id);
|
||||
onChange();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo completar la acción.");
|
||||
} finally {
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
if (!canEdit && !canDelete) return null;
|
||||
|
||||
return (
|
||||
<div className="row-actions">
|
||||
{archived && <span className="badge badge-negative">Archivado</span>}
|
||||
{canEdit && (
|
||||
<Link href={`/clientes/${customer.id}/editar`} className="btn btn-outline">
|
||||
Editar
|
||||
</Link>
|
||||
)}
|
||||
{canDelete && (
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
onClick={toggleArchive}
|
||||
disabled={busy}
|
||||
>
|
||||
{archived ? "Restaurar" : "Archivar"}
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
/* ------------------------------------------------------------------ Hero */
|
||||
function Hero({
|
||||
data,
|
||||
@@ -274,14 +357,33 @@ function KV({
|
||||
}
|
||||
|
||||
/* ----------------------------------------------- Propiedades y servicios */
|
||||
function PropiedadesSection({ properties }: { properties: Property[] }) {
|
||||
function PropiedadesSection({
|
||||
properties,
|
||||
customerId,
|
||||
customerName,
|
||||
}: {
|
||||
properties: Property[];
|
||||
customerId: string;
|
||||
customerName: string;
|
||||
}) {
|
||||
const canCreate = useCan("property:create");
|
||||
return (
|
||||
<section className="section">
|
||||
<SectionHead
|
||||
rule="servicios"
|
||||
title="Propiedades y servicios"
|
||||
count={properties.length}
|
||||
/>
|
||||
<div className="detail-actionbar">
|
||||
<SectionHead
|
||||
rule="servicios"
|
||||
title="Propiedades y servicios"
|
||||
count={properties.length}
|
||||
/>
|
||||
{canCreate && (
|
||||
<Link
|
||||
href={`/servicios/nuevo?customerId=${customerId}&customerName=${encodeURIComponent(customerName)}`}
|
||||
className="btn btn-outline"
|
||||
>
|
||||
+ Nueva propiedad
|
||||
</Link>
|
||||
)}
|
||||
</div>
|
||||
<div className="card">
|
||||
{properties.length === 0 ? (
|
||||
<div className="empty-inline">
|
||||
@@ -393,14 +495,33 @@ function PropertyCard({ p }: { p: Property }) {
|
||||
}
|
||||
|
||||
/* ------------------------------------------------------ Pólizas de seguro */
|
||||
function PolizasSection({ policies }: { policies: Policy[] }) {
|
||||
function PolizasSection({
|
||||
policies,
|
||||
customerId,
|
||||
customerName,
|
||||
}: {
|
||||
policies: Policy[];
|
||||
customerId: string;
|
||||
customerName: string;
|
||||
}) {
|
||||
const canCreate = useCan("policy:create");
|
||||
return (
|
||||
<section className="section">
|
||||
<SectionHead
|
||||
rule="seguros"
|
||||
title="Pólizas de seguro"
|
||||
count={policies.length}
|
||||
/>
|
||||
<div className="detail-actionbar">
|
||||
<SectionHead
|
||||
rule="seguros"
|
||||
title="Pólizas de seguro"
|
||||
count={policies.length}
|
||||
/>
|
||||
{canCreate && (
|
||||
<Link
|
||||
href={`/polizas/nuevo?customerId=${customerId}&customerName=${encodeURIComponent(customerName)}`}
|
||||
className="btn btn-outline"
|
||||
>
|
||||
+ Nueva póliza
|
||||
</Link>
|
||||
)}
|
||||
</div>
|
||||
<div className="card">
|
||||
{policies.length === 0 ? (
|
||||
<div className="empty-inline">
|
||||
@@ -660,9 +781,10 @@ function TxRow({ t }: { t: Transaction }) {
|
||||
const tipo =
|
||||
t.type?.nameEs || t.type?.nameEn || "—";
|
||||
const concept = t.message || t.period || "—";
|
||||
const voided = !!t.voidedAt;
|
||||
|
||||
return (
|
||||
<tr>
|
||||
<tr style={voided ? { textDecoration: "line-through", opacity: 0.55 } : undefined}>
|
||||
<td className="mono" style={{ whiteSpace: "nowrap" }}>
|
||||
{formatDate(t.transactionDate)}
|
||||
</td>
|
||||
@@ -672,7 +794,14 @@ function TxRow({ t }: { t: Transaction }) {
|
||||
</td>
|
||||
<td>{tipo}</td>
|
||||
<td className="tx-ref">{t.reference || "—"}</td>
|
||||
<td className="tx-concept">{concept}</td>
|
||||
<td className="tx-concept">
|
||||
{concept}
|
||||
{voided && (
|
||||
<span className="tx-cur" style={{ marginLeft: 6, textDecoration: "none" }}>
|
||||
(anulado)
|
||||
</span>
|
||||
)}
|
||||
</td>
|
||||
<td className="num">
|
||||
<span className={`tx-amount ${sign}`}>
|
||||
{formatMoney(t.amount, t.currency)}
|
||||
@@ -685,15 +814,15 @@ function TxRow({ t }: { t: Transaction }) {
|
||||
|
||||
/* ----------------------------------------------------------- Documentos */
|
||||
function DocumentosSection({ data }: { data: CustomerDetail }) {
|
||||
type Doc = { type: string; key: string | null; scope: string };
|
||||
type Doc = { type: string; scope: string; href: string | null };
|
||||
const docs: Doc[] = [];
|
||||
data.properties.forEach((p) => {
|
||||
const label = [p.addressLine1].filter(Boolean).join("") || "Propiedad";
|
||||
p.documents.forEach((d) =>
|
||||
docs.push({
|
||||
type: d.documentType || "Documento",
|
||||
key: d.storageKey,
|
||||
scope: label,
|
||||
href: d.id ? propertyDocumentDownloadUrl(p.id, d.id) : null,
|
||||
}),
|
||||
);
|
||||
});
|
||||
@@ -701,8 +830,8 @@ function DocumentosSection({ data }: { data: CustomerDetail }) {
|
||||
p.documents.forEach((d) =>
|
||||
docs.push({
|
||||
type: d.documentType || "Documento",
|
||||
key: d.storageKey,
|
||||
scope: `Póliza ${p.policyNumber ?? ""}`.trim(),
|
||||
href: d.id ? policyDocumentDownloadUrl(p.id, d.id) : null,
|
||||
}),
|
||||
);
|
||||
});
|
||||
@@ -716,28 +845,24 @@ function DocumentosSection({ data }: { data: CustomerDetail }) {
|
||||
No hay documentos registrados para este cliente.
|
||||
</div>
|
||||
) : (
|
||||
<>
|
||||
<div className="doc-list">
|
||||
{docs.map((d, i) => (
|
||||
<div className="doc-item" key={i}>
|
||||
<span className="doc-icon" aria-hidden>
|
||||
▤
|
||||
</span>
|
||||
<div style={{ minWidth: 0 }}>
|
||||
<div className="doc-type">{d.type}</div>
|
||||
<div className="doc-key">{d.scope}</div>
|
||||
</div>
|
||||
<div className="doc-list">
|
||||
{docs.map((d, i) => (
|
||||
<div className="doc-item" key={i}>
|
||||
<span className="doc-icon" aria-hidden>
|
||||
▤
|
||||
</span>
|
||||
<div style={{ minWidth: 0, flex: 1 }}>
|
||||
<div className="doc-type">{d.type}</div>
|
||||
<div className="doc-key">{d.scope}</div>
|
||||
</div>
|
||||
))}
|
||||
</div>
|
||||
<div
|
||||
className="section-note"
|
||||
style={{ padding: "0 22px 18px" }}
|
||||
>
|
||||
Los archivos se almacenan en el object storage
|
||||
(storageKey); no se descargan desde esta vista.
|
||||
</div>
|
||||
</>
|
||||
{d.href && (
|
||||
<a className="btn btn-ghost" href={d.href}>
|
||||
Descargar
|
||||
</a>
|
||||
)}
|
||||
</div>
|
||||
))}
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
</section>
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
"use client";
|
||||
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { CustomerForm } from "@/components/CustomerForm";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
|
||||
export default function NuevoClientePage() {
|
||||
return (
|
||||
<AppShell>
|
||||
<NuevoCliente />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
function NuevoCliente() {
|
||||
const allowed = useCan("customer:create");
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<Link href="/clientes" className="back-link">
|
||||
← Clientes
|
||||
</Link>
|
||||
<h1 className="page-title">Nuevo cliente</h1>
|
||||
</div>
|
||||
{allowed ? (
|
||||
<CustomerForm />
|
||||
) : (
|
||||
<div className="state-box state-error">
|
||||
No tiene permisos para crear clientes.
|
||||
</div>
|
||||
)}
|
||||
</>
|
||||
);
|
||||
}
|
||||
@@ -3,7 +3,9 @@
|
||||
import { useCallback, useEffect, useRef, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { ContextReports } from "@/components/ContextReports";
|
||||
import { getStats, listCustomers } from "@/lib/api";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import { formatNumber, SIN_NOMBRE } from "@/lib/labels";
|
||||
import type {
|
||||
BusinessLine,
|
||||
@@ -39,6 +41,8 @@ function ClientesBrowser() {
|
||||
const [loading, setLoading] = useState(true);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
const canCreate = useCan("customer:create");
|
||||
|
||||
const debounceRef = useRef<ReturnType<typeof setTimeout>>();
|
||||
|
||||
useEffect(() => {
|
||||
@@ -93,7 +97,21 @@ function ClientesBrowser() {
|
||||
<>
|
||||
<div className="page-head rise">
|
||||
<p className="eyebrow">Directorio unificado</p>
|
||||
<h1 className="page-title">Clientes</h1>
|
||||
<div style={{ display: "flex", alignItems: "center", gap: 16 }}>
|
||||
<h1 className="page-title" style={{ margin: 0 }}>Clientes</h1>
|
||||
<span style={{ flex: 1 }} />
|
||||
<ContextReports
|
||||
entries={[
|
||||
{ slug: "listado-en-rojo", label: "En rojo" },
|
||||
{ slug: "pagos-no-efectuados", label: "Sin pagos (agua)" },
|
||||
]}
|
||||
/>
|
||||
{canCreate && (
|
||||
<Link href="/clientes/nuevo" className="btn btn-primary">
|
||||
+ Nuevo cliente
|
||||
</Link>
|
||||
)}
|
||||
</div>
|
||||
<StatStrip stats={stats} />
|
||||
</div>
|
||||
|
||||
|
||||
@@ -3,7 +3,13 @@
|
||||
import { useEffect, useMemo, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { getStatement } from "@/lib/api";
|
||||
import { MovementForm } from "@/components/MovementForm";
|
||||
import {
|
||||
getBillingFacets,
|
||||
getStatement,
|
||||
voidMovement,
|
||||
} from "@/lib/api";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import {
|
||||
balancePhrase,
|
||||
balanceTone,
|
||||
@@ -17,6 +23,7 @@ import {
|
||||
txTypeLabel,
|
||||
} from "@/lib/labels";
|
||||
import type {
|
||||
BillingFacets,
|
||||
LedgerCurrency,
|
||||
Statement,
|
||||
StatementMovement,
|
||||
@@ -48,14 +55,18 @@ export default function EstadoCuentaDetailPage({
|
||||
}
|
||||
|
||||
function StatementView({ id }: { id: string }) {
|
||||
const canCapture = useCan("ledger:create");
|
||||
const canVoid = useCan("ledger:void");
|
||||
const [data, setData] = useState<Statement | null>(null);
|
||||
const [facets, setFacets] = useState<BillingFacets | null>(null);
|
||||
const [loading, setLoading] = useState(true);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [captureOpen, setCaptureOpen] = useState(false);
|
||||
|
||||
const [currency, setCurrency] = useState<LedgerCurrency | null>(null);
|
||||
const [domain, setDomain] = useState<TransactionDomain | "">("");
|
||||
|
||||
useEffect(() => {
|
||||
function reload() {
|
||||
let alive = true;
|
||||
setLoading(true);
|
||||
setError(null);
|
||||
@@ -63,9 +74,10 @@ function StatementView({ id }: { id: string }) {
|
||||
.then((d) => {
|
||||
if (!alive) return;
|
||||
setData(d);
|
||||
// Default to the currency the customer actually moves the most in.
|
||||
// Default to the currency the customer actually moves the most in;
|
||||
// preserve a previously-chosen currency across reloads.
|
||||
const busiest = [...d.summary].sort((a, b) => b.count - a.count)[0];
|
||||
setCurrency(busiest?.currency ?? "MXN");
|
||||
setCurrency((prev) => prev ?? busiest?.currency ?? "MXN");
|
||||
setLoading(false);
|
||||
})
|
||||
.catch((e) => {
|
||||
@@ -80,6 +92,13 @@ function StatementView({ id }: { id: string }) {
|
||||
return () => {
|
||||
alive = false;
|
||||
};
|
||||
}
|
||||
|
||||
useEffect(() => {
|
||||
const cleanup = reload();
|
||||
getBillingFacets().then(setFacets).catch(() => setFacets(null));
|
||||
return cleanup;
|
||||
// eslint-disable-next-line react-hooks/exhaustive-deps
|
||||
}, [id]);
|
||||
|
||||
const movements = useMemo(() => {
|
||||
@@ -178,8 +197,35 @@ function StatementView({ id }: { id: string }) {
|
||||
title="Movimientos"
|
||||
count={movements.length}
|
||||
countSuffix={movements.length === 1 ? "movimiento" : "movimientos"}
|
||||
right={
|
||||
canCapture ? (
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-primary"
|
||||
onClick={() => setCaptureOpen((v) => !v)}
|
||||
>
|
||||
{captureOpen ? "Cerrar captura" : "Capturar movimiento"}
|
||||
</button>
|
||||
) : undefined
|
||||
}
|
||||
/>
|
||||
|
||||
{captureOpen && (
|
||||
<MovementForm
|
||||
concepts={facets?.types ?? []}
|
||||
defaultCurrency={currency ?? "MXN"}
|
||||
defaultCustomer={{
|
||||
id: data.customer.id,
|
||||
name: data.customer.name,
|
||||
}}
|
||||
onSaved={() => {
|
||||
setCaptureOpen(false);
|
||||
reload();
|
||||
}}
|
||||
onCancel={() => setCaptureOpen(false)}
|
||||
/>
|
||||
)}
|
||||
|
||||
<div className="filter-row">
|
||||
<label className="filter-field">
|
||||
<span className="filter-label">Moneda</span>
|
||||
@@ -228,11 +274,21 @@ function StatementView({ id }: { id: string }) {
|
||||
<th>Referencia</th>
|
||||
<th className="num">Cargo / Abono</th>
|
||||
<th className="num">Saldo</th>
|
||||
{canVoid && (
|
||||
<th style={{ width: 1, whiteSpace: "nowrap" }}>
|
||||
Acciones
|
||||
</th>
|
||||
)}
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{movements.map((m) => (
|
||||
<StatementRow key={m.id} m={m} />
|
||||
<StatementRow
|
||||
key={m.id}
|
||||
m={m}
|
||||
canVoid={canVoid}
|
||||
onVoided={reload}
|
||||
/>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -425,10 +481,39 @@ function ConceptosSection({
|
||||
);
|
||||
}
|
||||
|
||||
function StatementRow({ m }: { m: StatementMovement }) {
|
||||
function StatementRow({
|
||||
m,
|
||||
canVoid,
|
||||
onVoided,
|
||||
}: {
|
||||
m: StatementMovement;
|
||||
canVoid: boolean;
|
||||
onVoided: () => void;
|
||||
}) {
|
||||
const concept = m.message || m.period || null;
|
||||
const [busy, setBusy] = useState(false);
|
||||
|
||||
async function doVoid() {
|
||||
if (
|
||||
!window.confirm(
|
||||
"¿Anular este movimiento? Quedará tachado y no contará en los totales.",
|
||||
)
|
||||
)
|
||||
return;
|
||||
setBusy(true);
|
||||
try {
|
||||
await voidMovement(m.id);
|
||||
onVoided();
|
||||
} catch (e) {
|
||||
window.alert(
|
||||
(e as Error)?.message ?? "No se pudo anular el movimiento.",
|
||||
);
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<tr>
|
||||
<tr style={m.voided ? { textDecoration: "line-through", opacity: 0.55 } : undefined}>
|
||||
<td className="mono" style={{ whiteSpace: "nowrap" }}>
|
||||
{formatDate(m.transactionDate)}
|
||||
</td>
|
||||
@@ -455,6 +540,21 @@ function StatementRow({ m }: { m: StatementMovement }) {
|
||||
{formatMoney(m.balanceAfter, m.currency)}
|
||||
</span>
|
||||
</td>
|
||||
{canVoid && (
|
||||
<td style={{ whiteSpace: "nowrap" }}>
|
||||
{!m.voided && (
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
style={{ padding: "4px 10px", fontSize: 12 }}
|
||||
onClick={doVoid}
|
||||
disabled={busy}
|
||||
>
|
||||
{busy ? "Anulando…" : "Anular"}
|
||||
</button>
|
||||
)}
|
||||
</td>
|
||||
)}
|
||||
</tr>
|
||||
);
|
||||
}
|
||||
@@ -464,14 +564,23 @@ function SectionHead({
|
||||
title,
|
||||
count,
|
||||
countSuffix,
|
||||
right,
|
||||
}: {
|
||||
rule: string;
|
||||
title: string;
|
||||
count?: number;
|
||||
countSuffix?: string;
|
||||
right?: React.ReactNode;
|
||||
}) {
|
||||
return (
|
||||
<div className="section-head">
|
||||
<div
|
||||
className="section-head"
|
||||
style={
|
||||
right
|
||||
? { display: "flex", alignItems: "center", gap: 12, flexWrap: "wrap" }
|
||||
: undefined
|
||||
}
|
||||
>
|
||||
<span className={`section-rule ${rule}`} aria-hidden />
|
||||
<h2 className="section-title">{title}</h2>
|
||||
{count != null && (
|
||||
@@ -479,6 +588,9 @@ function SectionHead({
|
||||
{formatNumber(count)} {countSuffix ?? ""}
|
||||
</span>
|
||||
)}
|
||||
{right && (
|
||||
<div style={{ marginLeft: "auto" }}>{right}</div>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
@@ -0,0 +1,557 @@
|
||||
"use client";
|
||||
|
||||
import { useEffect, useMemo, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { CustomerPicker } from "@/components/CustomerPicker";
|
||||
import { createMovementBatch, getBillingFacets, getByCheck } from "@/lib/api";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import { formatMoney, formatNumber, txTypeLabel } from "@/lib/labels";
|
||||
import type {
|
||||
BatchCreateInput,
|
||||
BillingFacets,
|
||||
ByCheckResponse,
|
||||
Currency,
|
||||
LedgerCurrency,
|
||||
TransactionDomain,
|
||||
} from "@/lib/types";
|
||||
|
||||
/**
|
||||
* Batch capture by check — the "Editor" screen from the legacy system
|
||||
* (docs/RECEIPT_CAPTURE_SPEC.md §1.2).
|
||||
*
|
||||
* Staff key many customers' receipts against ONE physical check before cutting
|
||||
* it, then check that the captured total matches the check's amount. That
|
||||
* reconciliation is the whole point, so the running total is the most prominent
|
||||
* thing on the page and an optional "importe del cheque" field turns it into a
|
||||
* live difference.
|
||||
*
|
||||
* No batch entity is persisted: `checkNumber` is a plain column, and grouping
|
||||
* by it answers every by-check question (see the "Reporte por cheque" report).
|
||||
*/
|
||||
|
||||
const DOMAINS: { key: TransactionDomain; label: string }[] = [
|
||||
{ key: "UTILITY", label: "Servicios" },
|
||||
{ key: "INSURANCE", label: "Seguros" },
|
||||
{ key: "TRUST", label: "Fideicomiso" },
|
||||
];
|
||||
|
||||
interface Line {
|
||||
/** Local row key — lines have no server identity until the batch posts. */
|
||||
key: number;
|
||||
customerId: string;
|
||||
customerName: string;
|
||||
amount: string;
|
||||
reference: string;
|
||||
period: string;
|
||||
outstanding: boolean;
|
||||
}
|
||||
|
||||
function blankLine(key: number): Line {
|
||||
return {
|
||||
key,
|
||||
customerId: "",
|
||||
customerName: "",
|
||||
amount: "",
|
||||
reference: "",
|
||||
period: "",
|
||||
outstanding: false,
|
||||
};
|
||||
}
|
||||
|
||||
export default function BatchCapturePage() {
|
||||
return (
|
||||
<AppShell>
|
||||
<BatchCapture />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
function BatchCapture() {
|
||||
const canCapture = useCan("ledger:create");
|
||||
const [facets, setFacets] = useState<BillingFacets | null>(null);
|
||||
|
||||
// Check-level fields — shared by every line.
|
||||
const [domain, setDomain] = useState<TransactionDomain>("UTILITY");
|
||||
const [currency, setCurrency] = useState<LedgerCurrency>("MXN");
|
||||
const [typeId, setTypeId] = useState("");
|
||||
const [checkNumber, setCheckNumber] = useState("");
|
||||
const [transactionDate, setTransactionDate] = useState(
|
||||
new Date().toISOString().slice(0, 10),
|
||||
);
|
||||
/** The physical check's amount, for reconciliation only — never submitted. */
|
||||
const [checkAmount, setCheckAmount] = useState("");
|
||||
|
||||
const [lines, setLines] = useState<Line[]>([blankLine(1), blankLine(2), blankLine(3)]);
|
||||
const [nextKey, setNextKey] = useState(4);
|
||||
|
||||
const [saving, setSaving] = useState(false);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [posted, setPosted] = useState<ByCheckResponse | null>(null);
|
||||
|
||||
useEffect(() => {
|
||||
getBillingFacets().then(setFacets).catch(() => setFacets(null));
|
||||
}, []);
|
||||
|
||||
const filled = lines.filter(
|
||||
(l) => l.customerId && l.amount.trim() !== "" && Number.isFinite(Number(l.amount)),
|
||||
);
|
||||
|
||||
// Charges are captured as positive numbers and signed on submit, matching
|
||||
// MovementForm — staff type what's on the bill, not a negative.
|
||||
const total = useMemo(
|
||||
() =>
|
||||
filled
|
||||
.filter((l) => !l.outstanding)
|
||||
.reduce((sum, l) => sum + Math.abs(Number(l.amount)), 0),
|
||||
[filled],
|
||||
);
|
||||
const outstandingTotal = useMemo(
|
||||
() =>
|
||||
filled
|
||||
.filter((l) => l.outstanding)
|
||||
.reduce((sum, l) => sum + Math.abs(Number(l.amount)), 0),
|
||||
[filled],
|
||||
);
|
||||
|
||||
const checkAmt = Number(checkAmount);
|
||||
const hasCheckAmt = checkAmount.trim() !== "" && Number.isFinite(checkAmt);
|
||||
const diff = hasCheckAmt ? checkAmt - total : 0;
|
||||
const reconciled = hasCheckAmt && Math.abs(diff) < 0.005;
|
||||
|
||||
function update(key: number, patch: Partial<Line>) {
|
||||
setLines((ls) => ls.map((l) => (l.key === key ? { ...l, ...patch } : l)));
|
||||
}
|
||||
|
||||
function addLine() {
|
||||
setLines((ls) => [...ls, blankLine(nextKey)]);
|
||||
setNextKey((k) => k + 1);
|
||||
}
|
||||
|
||||
function removeLine(key: number) {
|
||||
setLines((ls) => (ls.length === 1 ? ls : ls.filter((l) => l.key !== key)));
|
||||
}
|
||||
|
||||
async function submit(e: React.FormEvent) {
|
||||
e.preventDefault();
|
||||
if (!checkNumber.trim()) {
|
||||
setError("Indica el número de cheque.");
|
||||
return;
|
||||
}
|
||||
if (filled.length === 0) {
|
||||
setError("Captura al menos una línea con cliente y monto.");
|
||||
return;
|
||||
}
|
||||
const dupes = filled
|
||||
.map((l) => l.customerId)
|
||||
.filter((id, i, arr) => arr.indexOf(id) !== i);
|
||||
if (dupes.length) {
|
||||
const names = filled
|
||||
.filter((l) => dupes.includes(l.customerId))
|
||||
.map((l) => l.customerName);
|
||||
if (
|
||||
!window.confirm(
|
||||
`Hay más de una línea para el mismo cliente (${[...new Set(names)].join(
|
||||
", ",
|
||||
)}). ¿Continuar?`,
|
||||
)
|
||||
)
|
||||
return;
|
||||
}
|
||||
|
||||
const payload: BatchCreateInput = {
|
||||
domain,
|
||||
transactionDate,
|
||||
checkNumber: checkNumber.trim(),
|
||||
currency: currency as Currency,
|
||||
typeId: typeId || undefined,
|
||||
lines: filled.map((l) => ({
|
||||
customerId: l.customerId,
|
||||
// Every line of a check batch is a charge the office paid out.
|
||||
amount: -Math.abs(Number(l.amount)),
|
||||
reference: l.reference.trim() || undefined,
|
||||
period: l.period.trim() || undefined,
|
||||
outstanding: l.outstanding || undefined,
|
||||
})),
|
||||
};
|
||||
|
||||
setSaving(true);
|
||||
setError(null);
|
||||
try {
|
||||
await createMovementBatch(payload);
|
||||
// Re-read through the by-check view so the confirmation shows what's
|
||||
// actually stored (including anything captured against this check
|
||||
// earlier), not just what this request sent.
|
||||
setPosted(await getByCheck(payload.checkNumber));
|
||||
} catch (e2) {
|
||||
setError((e2 as Error)?.message ?? "No se pudo guardar el lote.");
|
||||
} finally {
|
||||
setSaving(false);
|
||||
}
|
||||
}
|
||||
|
||||
function reset() {
|
||||
setPosted(null);
|
||||
setLines([blankLine(nextKey), blankLine(nextKey + 1), blankLine(nextKey + 2)]);
|
||||
setNextKey((k) => k + 3);
|
||||
setCheckNumber("");
|
||||
setCheckAmount("");
|
||||
}
|
||||
|
||||
if (!canCapture) {
|
||||
return (
|
||||
<div className="state-box state-error">
|
||||
No tienes permiso para capturar movimientos.
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
if (posted) {
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<div>
|
||||
<h1 className="page-title">Lote capturado</h1>
|
||||
<p className="eyebrow">
|
||||
Cheque {posted.checkNumber} · {formatNumber(posted.count)}{" "}
|
||||
{posted.count === 1 ? "movimiento" : "movimientos"}
|
||||
</p>
|
||||
</div>
|
||||
<div style={{ display: "flex", gap: 10 }}>
|
||||
<button type="button" className="btn btn-primary" onClick={reset}>
|
||||
Capturar otro cheque
|
||||
</button>
|
||||
<Link href="/estado-cuenta" className="btn btn-outline">
|
||||
Volver a estado de cuenta
|
||||
</Link>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="filtered-totals" style={{ marginBottom: 16 }}>
|
||||
{posted.totals.map((t) => (
|
||||
<div className="filtered-total" key={t.currency}>
|
||||
<span className="filtered-total-cur">{t.currency}</span>
|
||||
<span className="filtered-total-net">
|
||||
Total del cheque <strong>{formatMoney(t.total, t.currency)}</strong>
|
||||
</span>
|
||||
<span>{formatNumber(t.count)} movimientos</span>
|
||||
</div>
|
||||
))}
|
||||
{posted.outstandingCount > 0 && (
|
||||
<div className="filtered-total">
|
||||
<span>
|
||||
{formatNumber(posted.outstandingCount)} sin fondos (no suman al
|
||||
total)
|
||||
</span>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
|
||||
<div className="tx-scroll">
|
||||
<table className="tx-table">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Cliente</th>
|
||||
<th>Referencia</th>
|
||||
<th>Periodo</th>
|
||||
<th>Estado</th>
|
||||
<th className="num">Monto</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{posted.items.map((i) => (
|
||||
<tr key={i.id}>
|
||||
<td>
|
||||
<Link
|
||||
href={`/estado-cuenta/${i.customerId}`}
|
||||
className="inline-link"
|
||||
>
|
||||
{i.customerName}
|
||||
</Link>
|
||||
</td>
|
||||
<td>{i.reference || "—"}</td>
|
||||
<td>{i.period || "—"}</td>
|
||||
<td>{i.outstanding ? "Sin fondos" : "Pagado"}</td>
|
||||
<td className="num">
|
||||
<span className="tx-amount neg">
|
||||
{formatMoney(i.amount, i.currency)}
|
||||
</span>
|
||||
</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
|
||||
<p className="muted" style={{ marginTop: 14 }}>
|
||||
Para imprimir la conciliación, usa el reporte{" "}
|
||||
<Link
|
||||
href={`/reportes/cheque-count?checkNumber=${encodeURIComponent(
|
||||
posted.checkNumber,
|
||||
)}`}
|
||||
className="inline-link"
|
||||
>
|
||||
Reporte por cheque
|
||||
</Link>
|
||||
.
|
||||
</p>
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<div>
|
||||
<h1 className="page-title">Captura por cheque</h1>
|
||||
<p className="eyebrow">
|
||||
Captura los recibos de varios clientes contra un mismo cheque y
|
||||
concilia el total antes de guardar.
|
||||
</p>
|
||||
</div>
|
||||
<Link href="/estado-cuenta" className="btn btn-outline">
|
||||
Cancelar
|
||||
</Link>
|
||||
</div>
|
||||
|
||||
{error && <div className="state-box state-error">{error}</div>}
|
||||
|
||||
<form onSubmit={submit}>
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 14 }}>
|
||||
Datos del cheque
|
||||
</h2>
|
||||
<div className="form-grid">
|
||||
<label className="field">
|
||||
<span className="field-label">Número de cheque *</span>
|
||||
<input
|
||||
className="input"
|
||||
value={checkNumber}
|
||||
onChange={(e) => setCheckNumber(e.target.value)}
|
||||
required
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Fecha *</span>
|
||||
<input
|
||||
className="input"
|
||||
type="date"
|
||||
required
|
||||
value={transactionDate}
|
||||
onChange={(e) => setTransactionDate(e.target.value)}
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Línea de negocio *</span>
|
||||
<select
|
||||
className="select"
|
||||
value={domain}
|
||||
onChange={(e) => setDomain(e.target.value as TransactionDomain)}
|
||||
>
|
||||
{DOMAINS.map((d) => (
|
||||
<option key={d.key} value={d.key}>
|
||||
{d.label}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Moneda *</span>
|
||||
<select
|
||||
className="select"
|
||||
value={currency}
|
||||
onChange={(e) => setCurrency(e.target.value as LedgerCurrency)}
|
||||
>
|
||||
<option value="MXN">Pesos (MXN)</option>
|
||||
<option value="USD">Dólares (USD)</option>
|
||||
</select>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Concepto</span>
|
||||
<select
|
||||
className="select"
|
||||
value={typeId}
|
||||
onChange={(e) => setTypeId(e.target.value)}
|
||||
>
|
||||
<option value="">(sin concepto)</option>
|
||||
{facets?.types.map((t) => (
|
||||
<option key={t.id} value={t.id}>
|
||||
{txTypeLabel({ nameEn: t.name })}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Importe del cheque</span>
|
||||
<input
|
||||
className="input"
|
||||
type="number"
|
||||
step="0.01"
|
||||
min="0"
|
||||
value={checkAmount}
|
||||
onChange={(e) => setCheckAmount(e.target.value)}
|
||||
placeholder="Para conciliar"
|
||||
/>
|
||||
</label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<div
|
||||
style={{
|
||||
display: "flex",
|
||||
justifyContent: "space-between",
|
||||
alignItems: "center",
|
||||
marginBottom: 14,
|
||||
}}
|
||||
>
|
||||
<h2 className="section-title" style={{ margin: 0 }}>
|
||||
Recibos ({formatNumber(filled.length)})
|
||||
</h2>
|
||||
<button type="button" className="btn btn-outline" onClick={addLine}>
|
||||
Agregar línea
|
||||
</button>
|
||||
</div>
|
||||
|
||||
<div className="tx-scroll">
|
||||
<table className="tx-table">
|
||||
<thead>
|
||||
<tr>
|
||||
<th style={{ minWidth: 240 }}>Cliente *</th>
|
||||
<th style={{ minWidth: 120 }}>Referencia</th>
|
||||
<th style={{ minWidth: 100 }}>Periodo</th>
|
||||
<th style={{ minWidth: 110 }} className="num">
|
||||
Monto *
|
||||
</th>
|
||||
<th style={{ whiteSpace: "nowrap" }}>Sin fondos</th>
|
||||
<th style={{ width: 1 }} />
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{lines.map((l) => (
|
||||
<tr key={l.key}>
|
||||
<td>
|
||||
<CustomerPicker
|
||||
value={l.customerId}
|
||||
valueName={l.customerId ? l.customerName : undefined}
|
||||
onPick={(id, name) =>
|
||||
update(l.key, { customerId: id, customerName: name })
|
||||
}
|
||||
/>
|
||||
</td>
|
||||
<td>
|
||||
<input
|
||||
className="input"
|
||||
value={l.reference}
|
||||
onChange={(e) =>
|
||||
update(l.key, { reference: e.target.value })
|
||||
}
|
||||
/>
|
||||
</td>
|
||||
<td>
|
||||
<input
|
||||
className="input"
|
||||
value={l.period}
|
||||
onChange={(e) => update(l.key, { period: e.target.value })}
|
||||
placeholder="2026-07"
|
||||
/>
|
||||
</td>
|
||||
<td>
|
||||
<input
|
||||
className="input num"
|
||||
type="number"
|
||||
step="0.01"
|
||||
min="0"
|
||||
value={l.amount}
|
||||
onChange={(e) => update(l.key, { amount: e.target.value })}
|
||||
placeholder="0.00"
|
||||
/>
|
||||
</td>
|
||||
<td style={{ textAlign: "center" }}>
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={l.outstanding}
|
||||
onChange={(e) =>
|
||||
update(l.key, { outstanding: e.target.checked })
|
||||
}
|
||||
aria-label="Sin fondos"
|
||||
/>
|
||||
</td>
|
||||
<td>
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
style={{ padding: "4px 10px", fontSize: 12 }}
|
||||
onClick={() => removeLine(l.key)}
|
||||
disabled={lines.length === 1}
|
||||
>
|
||||
Quitar
|
||||
</button>
|
||||
</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 14 }}>
|
||||
Conciliación
|
||||
</h2>
|
||||
<div className="filtered-totals">
|
||||
<div className="filtered-total">
|
||||
<span className="filtered-total-cur">{currency}</span>
|
||||
<span className="filtered-total-net">
|
||||
Capturado <strong>{formatMoney(String(-total), currency)}</strong>
|
||||
</span>
|
||||
<span>{formatNumber(filled.filter((l) => !l.outstanding).length)} recibos</span>
|
||||
</div>
|
||||
{outstandingTotal > 0 && (
|
||||
<div className="filtered-total">
|
||||
<span>
|
||||
Sin fondos{" "}
|
||||
<strong>{formatMoney(String(-outstandingTotal), currency)}</strong>{" "}
|
||||
(no suma al cheque)
|
||||
</span>
|
||||
</div>
|
||||
)}
|
||||
{hasCheckAmt && (
|
||||
<div className="filtered-total">
|
||||
<span className="filtered-total-net">
|
||||
{reconciled ? (
|
||||
<strong className="tx-amount pos">Cuadra con el cheque</strong>
|
||||
) : (
|
||||
<>
|
||||
Diferencia{" "}
|
||||
<strong className="tx-amount neg">
|
||||
{formatMoney(String(diff), currency)}
|
||||
</strong>
|
||||
</>
|
||||
)}
|
||||
</span>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="form-actions">
|
||||
<button
|
||||
type="submit"
|
||||
className="btn btn-primary"
|
||||
disabled={saving || filled.length === 0}
|
||||
>
|
||||
{saving
|
||||
? "Guardando…"
|
||||
: `Capturar ${formatNumber(filled.length)} ${
|
||||
filled.length === 1 ? "recibo" : "recibos"
|
||||
}`}
|
||||
</button>
|
||||
<Link href="/estado-cuenta" className="btn btn-outline">
|
||||
Cancelar
|
||||
</Link>
|
||||
</div>
|
||||
</form>
|
||||
</>
|
||||
);
|
||||
}
|
||||
@@ -3,12 +3,17 @@
|
||||
import { useCallback, useEffect, useRef, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { ContextReports } from "@/components/ContextReports";
|
||||
import { MovementForm } from "@/components/MovementForm";
|
||||
import {
|
||||
getBillingFacets,
|
||||
getBillingStats,
|
||||
listBalances,
|
||||
listMovements,
|
||||
resolveOutstanding,
|
||||
voidMovement,
|
||||
} from "@/lib/api";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import {
|
||||
balancePhrase,
|
||||
balanceTone,
|
||||
@@ -95,6 +100,8 @@ export default function EstadoCuentaPage() {
|
||||
}
|
||||
|
||||
function BillingBrowser() {
|
||||
const canCapture = useCan("ledger:create");
|
||||
const canVoid = useCan("ledger:void");
|
||||
const [stats, setStats] = useState<BillingStats | null>(null);
|
||||
const [facets, setFacets] = useState<BillingFacets | null>(null);
|
||||
const [view, setView] = useState<View>("saldos");
|
||||
@@ -111,6 +118,8 @@ function BillingBrowser() {
|
||||
const [direction, setDirection] = useState<LedgerDirection | "">("");
|
||||
const [typeId, setTypeId] = useState("");
|
||||
const [source, setSource] = useState("");
|
||||
// "" = no filter, "true" = only NOPAGO rows, "false" = only settled ones.
|
||||
const [outstanding, setOutstanding] = useState<"" | "true" | "false">("");
|
||||
const [from, setFrom] = useState("");
|
||||
const [to, setTo] = useState("");
|
||||
const [movementSort, setMovementSort] = useState<MovementSort>("date_desc");
|
||||
@@ -119,6 +128,8 @@ function BillingBrowser() {
|
||||
const [movements, setMovements] = useState<MovementListResponse | null>(null);
|
||||
const [loading, setLoading] = useState(true);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [captureOpen, setCaptureOpen] = useState(false);
|
||||
const [resolving, setResolving] = useState<MovementListItem | null>(null);
|
||||
|
||||
const debounceRef = useRef<ReturnType<typeof setTimeout>>();
|
||||
|
||||
@@ -158,6 +169,7 @@ function BillingBrowser() {
|
||||
direction: direction || undefined,
|
||||
typeId: typeId || undefined,
|
||||
source: source || undefined,
|
||||
outstanding: outstanding === "" ? undefined : outstanding === "true",
|
||||
from: from || undefined,
|
||||
to: to || undefined,
|
||||
sort: movementSort,
|
||||
@@ -181,6 +193,7 @@ function BillingBrowser() {
|
||||
direction,
|
||||
typeId,
|
||||
source,
|
||||
outstanding,
|
||||
from,
|
||||
to,
|
||||
movementSort,
|
||||
@@ -250,6 +263,15 @@ function BillingBrowser() {
|
||||
<LedgerTotalsStrip stats={stats} />
|
||||
</div>
|
||||
|
||||
<div style={{ marginTop: 12 }}>
|
||||
<ContextReports
|
||||
entries={[
|
||||
{ slug: "listado-en-rojo", label: "En rojo" },
|
||||
{ slug: "reporte-de-efectivo", label: "Reporte de efectivo" },
|
||||
]}
|
||||
/>
|
||||
</div>
|
||||
|
||||
<div className="toolbar">
|
||||
<div className="search-box">
|
||||
<span className="search-icon" aria-hidden>
|
||||
@@ -287,8 +309,57 @@ function BillingBrowser() {
|
||||
</button>
|
||||
))}
|
||||
</div>
|
||||
{view === "movimientos" && canCapture && (
|
||||
<div style={{ display: "flex", gap: 10 }}>
|
||||
<Link href="/estado-cuenta/lote" className="btn btn-outline">
|
||||
Captura por cheque
|
||||
</Link>
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-primary"
|
||||
onClick={() => setCaptureOpen((v) => !v)}
|
||||
>
|
||||
{captureOpen ? "Cerrar captura" : "Capturar movimiento"}
|
||||
</button>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
|
||||
{view === "movimientos" && resolving && (
|
||||
<ResolveDialog
|
||||
movement={resolving}
|
||||
onCancel={() => setResolving(null)}
|
||||
onDone={() => {
|
||||
setResolving(null);
|
||||
runSearch(movements?.page ?? 1);
|
||||
getBillingStats()
|
||||
.then(setStats)
|
||||
.catch(() => setStats(null));
|
||||
}}
|
||||
/>
|
||||
)}
|
||||
|
||||
{view === "movimientos" && captureOpen && (
|
||||
<section className="section">
|
||||
<div className="section-head">
|
||||
<span className="section-rule cuenta" aria-hidden />
|
||||
<h2 className="section-title">Capturar movimiento</h2>
|
||||
</div>
|
||||
<MovementForm
|
||||
concepts={facets?.types ?? []}
|
||||
defaultCurrency={currency}
|
||||
onSaved={() => {
|
||||
setCaptureOpen(false);
|
||||
runSearch(movements?.page ?? 1);
|
||||
getBillingStats()
|
||||
.then(setStats)
|
||||
.catch(() => setStats(null));
|
||||
}}
|
||||
onCancel={() => setCaptureOpen(false)}
|
||||
/>
|
||||
</section>
|
||||
)}
|
||||
|
||||
<div className="filter-row">
|
||||
<label className="filter-field">
|
||||
<span className="filter-label">Moneda</span>
|
||||
@@ -401,6 +472,21 @@ function BillingBrowser() {
|
||||
</select>
|
||||
</label>
|
||||
|
||||
<label className="filter-field">
|
||||
<span className="filter-label">Estado de pago</span>
|
||||
<select
|
||||
className="input select"
|
||||
value={outstanding}
|
||||
onChange={(e) =>
|
||||
setOutstanding(e.target.value as "" | "true" | "false")
|
||||
}
|
||||
>
|
||||
<option value="">Todos</option>
|
||||
<option value="true">Sin fondos (pendientes)</option>
|
||||
<option value="false">Pagados</option>
|
||||
</select>
|
||||
</label>
|
||||
|
||||
<label className="filter-field">
|
||||
<span className="filter-label">Desde</span>
|
||||
<input
|
||||
@@ -506,11 +592,26 @@ function BillingBrowser() {
|
||||
<th>Concepto</th>
|
||||
<th>Referencia</th>
|
||||
<th className="num">Monto</th>
|
||||
{(canVoid || canCapture) && (
|
||||
<th style={{ width: 1, whiteSpace: "nowrap" }}>Acciones</th>
|
||||
)}
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{movements?.items.map((m) => (
|
||||
<MovementRow key={m.id} m={m} />
|
||||
<MovementRow
|
||||
key={m.id}
|
||||
m={m}
|
||||
canVoid={canVoid}
|
||||
canCapture={canCapture}
|
||||
onResolve={setResolving}
|
||||
onVoided={() => {
|
||||
runSearch(movements?.page ?? 1);
|
||||
getBillingStats()
|
||||
.then(setStats)
|
||||
.catch(() => setStats(null));
|
||||
}}
|
||||
/>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
@@ -739,9 +840,36 @@ function BalanceRow({
|
||||
);
|
||||
}
|
||||
|
||||
function MovementRow({ m }: { m: MovementListItem }) {
|
||||
function MovementRow({
|
||||
m,
|
||||
canVoid,
|
||||
canCapture,
|
||||
onVoided,
|
||||
onResolve,
|
||||
}: {
|
||||
m: MovementListItem;
|
||||
canVoid: boolean;
|
||||
canCapture: boolean;
|
||||
onVoided: () => void;
|
||||
onResolve: (m: MovementListItem) => void;
|
||||
}) {
|
||||
const [busy, setBusy] = useState(false);
|
||||
|
||||
async function doVoid() {
|
||||
if (!window.confirm("¿Anular este movimiento? Quedará tachado y no contará en los totales."))
|
||||
return;
|
||||
setBusy(true);
|
||||
try {
|
||||
await voidMovement(m.id);
|
||||
onVoided();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo anular el movimiento.");
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<tr>
|
||||
<tr style={m.voided ? { textDecoration: "line-through", opacity: 0.55 } : undefined}>
|
||||
<td className="mono" style={{ whiteSpace: "nowrap" }}>
|
||||
{formatDate(m.transactionDate)}
|
||||
</td>
|
||||
@@ -774,12 +902,136 @@ function MovementRow({ m }: { m: MovementListItem }) {
|
||||
</span>
|
||||
<div className="tx-cur">
|
||||
{m.currency} · {directionLabel(m.direction)}
|
||||
{m.outstanding && !m.voided && (
|
||||
<>
|
||||
{" · "}
|
||||
<span className="tx-outstanding">sin fondos</span>
|
||||
</>
|
||||
)}
|
||||
</div>
|
||||
</td>
|
||||
{(canVoid || canCapture) && (
|
||||
<td style={{ whiteSpace: "nowrap" }}>
|
||||
{/* Resolver only makes sense on a live outstanding row, and it's a
|
||||
capture action (completing one), not a void. */}
|
||||
{!m.voided && m.outstanding && canCapture && (
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
style={{ padding: "4px 10px", fontSize: 12 }}
|
||||
onClick={() => onResolve(m)}
|
||||
>
|
||||
Resolver
|
||||
</button>
|
||||
)}
|
||||
{!m.voided && canVoid && (
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
style={{ padding: "4px 10px", fontSize: 12 }}
|
||||
onClick={doVoid}
|
||||
disabled={busy}
|
||||
>
|
||||
{busy ? "Anulando…" : "Anular"}
|
||||
</button>
|
||||
)}
|
||||
</td>
|
||||
)}
|
||||
</tr>
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve an outstanding row: the check finally got cut. Takes the check number
|
||||
* and the date it was paid, which also becomes the movement's date — the legacy
|
||||
* behavior, since the ledger date is when money actually moved.
|
||||
*/
|
||||
function ResolveDialog({
|
||||
movement,
|
||||
onDone,
|
||||
onCancel,
|
||||
}: {
|
||||
movement: MovementListItem;
|
||||
onDone: () => void;
|
||||
onCancel: () => void;
|
||||
}) {
|
||||
const [checkNumber, setCheckNumber] = useState("");
|
||||
const [resolvedDate, setResolvedDate] = useState(
|
||||
new Date().toISOString().slice(0, 10),
|
||||
);
|
||||
const [busy, setBusy] = useState(false);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
async function submit(e: React.FormEvent) {
|
||||
e.preventDefault();
|
||||
if (!checkNumber.trim()) {
|
||||
setError("Indica el número de cheque.");
|
||||
return;
|
||||
}
|
||||
setBusy(true);
|
||||
setError(null);
|
||||
try {
|
||||
await resolveOutstanding(movement.id, {
|
||||
checkNumber: checkNumber.trim(),
|
||||
resolvedDate,
|
||||
});
|
||||
onDone();
|
||||
} catch (e2) {
|
||||
setError((e2 as Error)?.message ?? "No se pudo resolver el movimiento.");
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 6 }}>
|
||||
Resolver movimiento sin fondos
|
||||
</h2>
|
||||
<p className="muted" style={{ marginBottom: 14 }}>
|
||||
{movement.customerName} · {formatMoney(movement.amount, movement.currency)}{" "}
|
||||
{movement.currency}
|
||||
{movement.reference ? ` · ${movement.reference}` : ""}
|
||||
</p>
|
||||
{error && <div className="state-box state-error">{error}</div>}
|
||||
<form onSubmit={submit}>
|
||||
<div className="form-grid">
|
||||
<label className="field">
|
||||
<span className="field-label">Número de cheque *</span>
|
||||
<input
|
||||
className="input"
|
||||
value={checkNumber}
|
||||
onChange={(e) => setCheckNumber(e.target.value)}
|
||||
autoFocus
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Fecha de pago *</span>
|
||||
<input
|
||||
className="input"
|
||||
type="date"
|
||||
required
|
||||
value={resolvedDate}
|
||||
onChange={(e) => setResolvedDate(e.target.value)}
|
||||
/>
|
||||
</label>
|
||||
</div>
|
||||
<p className="muted" style={{ fontSize: 13, marginTop: 10 }}>
|
||||
El movimiento tomará esta fecha y empezará a contar en el saldo del
|
||||
cliente.
|
||||
</p>
|
||||
<div className="form-actions">
|
||||
<button type="submit" className="btn btn-primary" disabled={busy}>
|
||||
{busy ? "Resolviendo…" : "Resolver"}
|
||||
</button>
|
||||
<button type="button" className="btn btn-outline" onClick={onCancel}>
|
||||
Cancelar
|
||||
</button>
|
||||
</div>
|
||||
</form>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
function Pager({
|
||||
page,
|
||||
pageCount,
|
||||
|
||||
+1283
-271
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,501 @@
|
||||
"use client";
|
||||
|
||||
import { useEffect, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import {
|
||||
EXPIRY_WINDOW_DAYS,
|
||||
getBankStats,
|
||||
getBillingStats,
|
||||
getPolicyStats,
|
||||
getPropertyStats,
|
||||
getStats,
|
||||
listBankAccounts,
|
||||
} from "@/lib/api";
|
||||
import { useAuth } from "@/lib/abilities";
|
||||
import {
|
||||
balancePhrase,
|
||||
formatDate,
|
||||
formatMoney,
|
||||
formatNumber,
|
||||
policyStatusLabel,
|
||||
trustStatusLabel,
|
||||
} from "@/lib/labels";
|
||||
import type {
|
||||
BankAccount,
|
||||
BankStats,
|
||||
BillingStats,
|
||||
CustomerStats,
|
||||
PolicyStats,
|
||||
PropertyStats,
|
||||
} from "@/lib/types";
|
||||
|
||||
export default function InicioPage() {
|
||||
return (
|
||||
<AppShell>
|
||||
<HomeDashboard />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
interface DashboardData {
|
||||
customers: CustomerStats | null;
|
||||
policies: PolicyStats | null;
|
||||
properties: PropertyStats | null;
|
||||
billing: BillingStats | null;
|
||||
/** Figures for ONE chequera — see `bankAccount` for which. */
|
||||
bank: BankStats | null;
|
||||
/**
|
||||
* The chequera the card above is reading. The office keeps more than one, in
|
||||
* different currencies, so this card shows the default account rather than a
|
||||
* cross-account total, which would be a figure that never existed.
|
||||
*/
|
||||
bankAccount: BankAccount | null;
|
||||
bankAccountCount: number;
|
||||
}
|
||||
|
||||
/** Same default as /banco, so the two screens agree on which chequera opens. */
|
||||
function defaultAccount(accounts: BankAccount[]): BankAccount | null {
|
||||
const remembered =
|
||||
typeof window !== "undefined"
|
||||
? window.localStorage.getItem("banco.bankAccountId")
|
||||
: null;
|
||||
return (
|
||||
accounts.find((a) => a.id === remembered) ??
|
||||
accounts.find((a) => a.active) ??
|
||||
accounts[0] ??
|
||||
null
|
||||
);
|
||||
}
|
||||
|
||||
function HomeDashboard() {
|
||||
const user = useAuth();
|
||||
const [data, setData] = useState<DashboardData>({
|
||||
customers: null,
|
||||
policies: null,
|
||||
properties: null,
|
||||
billing: null,
|
||||
bank: null,
|
||||
bankAccount: null,
|
||||
bankAccountCount: 0,
|
||||
});
|
||||
const [loading, setLoading] = useState(true);
|
||||
|
||||
useEffect(() => {
|
||||
let alive = true;
|
||||
// The chequera figures need an account id, so that read is a two-step:
|
||||
// list the accounts, then ask the default one for its stats.
|
||||
const bank = listBankAccounts().then(async (accounts) => {
|
||||
const account = defaultAccount(accounts);
|
||||
if (!account) return { account: null, stats: null, count: 0 };
|
||||
return {
|
||||
account,
|
||||
stats: await getBankStats(account.id),
|
||||
count: accounts.length,
|
||||
};
|
||||
});
|
||||
|
||||
Promise.allSettled([
|
||||
getStats(),
|
||||
getPolicyStats(),
|
||||
getPropertyStats(),
|
||||
getBillingStats(),
|
||||
bank,
|
||||
]).then((results) => {
|
||||
if (!alive) return;
|
||||
const bankResult = results[4].status === "fulfilled" ? results[4].value : null;
|
||||
setData({
|
||||
customers: results[0].status === "fulfilled" ? results[0].value : null,
|
||||
policies: results[1].status === "fulfilled" ? results[1].value : null,
|
||||
properties: results[2].status === "fulfilled" ? results[2].value : null,
|
||||
billing: results[3].status === "fulfilled" ? results[3].value : null,
|
||||
bank: bankResult?.stats ?? null,
|
||||
bankAccount: bankResult?.account ?? null,
|
||||
bankAccountCount: bankResult?.count ?? 0,
|
||||
});
|
||||
setLoading(false);
|
||||
});
|
||||
return () => {
|
||||
alive = false;
|
||||
};
|
||||
}, []);
|
||||
|
||||
const greeting = greetingFor(user?.name);
|
||||
const lastBillingMovement = data.billing?.lastMovement ?? null;
|
||||
const lastBankMovement = data.bank?.lastMovement ?? null;
|
||||
|
||||
return (
|
||||
<div className="home rise">
|
||||
<div className="page-head">
|
||||
<p className="eyebrow">Resumen general</p>
|
||||
<h1 className="page-title">{greeting}</h1>
|
||||
<p className="muted" style={{ marginTop: 6, maxWidth: 640 }}>
|
||||
Vista rápida del estado de la cartera de clientes, las pólizas
|
||||
activas, los fideicomisos y los movimientos recientes.
|
||||
</p>
|
||||
<LastSeenLine
|
||||
billing={lastBillingMovement}
|
||||
bank={lastBankMovement}
|
||||
loading={loading}
|
||||
/>
|
||||
</div>
|
||||
|
||||
<section aria-label="Indicadores principales" className="home-section">
|
||||
<KpiCard
|
||||
href="/clientes"
|
||||
label="Clientes"
|
||||
loading={loading}
|
||||
primary={data.customers ? formatNumber(data.customers.customers) : "—"}
|
||||
sub={
|
||||
data.customers
|
||||
? [
|
||||
`${formatNumber(data.customers.withUtilities)} con servicios`,
|
||||
`${formatNumber(data.customers.withInsurance)} con seguros`,
|
||||
`${formatNumber(data.customers.bothLines)} en ambos ramos`,
|
||||
]
|
||||
: []
|
||||
}
|
||||
/>
|
||||
<KpiCard
|
||||
href="/servicios"
|
||||
label="Propiedades"
|
||||
loading={loading}
|
||||
primary={data.properties ? formatNumber(data.properties.properties) : "—"}
|
||||
sub={
|
||||
data.properties
|
||||
? [
|
||||
`${formatNumber(data.properties.services)} servicios`,
|
||||
`${formatNumber(data.properties.trusts)} fideicomisos`,
|
||||
`${formatNumber(data.properties.trustExpiring)} por vencer`,
|
||||
]
|
||||
: []
|
||||
}
|
||||
/>
|
||||
<KpiCard
|
||||
href="/polizas"
|
||||
label="Pólizas"
|
||||
loading={loading}
|
||||
primary={data.policies ? formatNumber(data.policies.total) : "—"}
|
||||
sub={
|
||||
data.policies
|
||||
? [
|
||||
`${formatNumber(data.policies.active)} vigentes`,
|
||||
`${formatNumber(data.policies.expiring)} por vencer (${EXPIRY_WINDOW_DAYS} d)`,
|
||||
`${formatNumber(data.policies.expired + data.policies.undated)} vencidas o sin fecha`,
|
||||
]
|
||||
: []
|
||||
}
|
||||
/>
|
||||
<KpiCard
|
||||
href="/estado-cuenta"
|
||||
label="Movimientos"
|
||||
loading={loading}
|
||||
primary={data.billing ? formatNumber(data.billing.movements) : "—"}
|
||||
sub={
|
||||
data.billing
|
||||
? [
|
||||
`${formatNumber(data.billing.ledgerCustomers)} clientes con cargo`,
|
||||
`${formatNumber(data.billing.crossLineCustomers)} con ambos ramos`,
|
||||
lastBillingMovement
|
||||
? `Último: ${formatDate(lastBillingMovement)}`
|
||||
: "Sin movimientos",
|
||||
]
|
||||
: []
|
||||
}
|
||||
/>
|
||||
</section>
|
||||
|
||||
<section aria-label="Atención" className="home-section">
|
||||
<div className="section-head">
|
||||
<h2 className="section-title">Atención</h2>
|
||||
<span className="section-sub">
|
||||
Lo que conviene revisar antes de cerrar el día
|
||||
</span>
|
||||
</div>
|
||||
|
||||
<div className="attention-grid">
|
||||
<AttentionCard
|
||||
href="/polizas?status=expiring"
|
||||
tone="warn"
|
||||
loading={loading}
|
||||
title="Pólizas por vencer"
|
||||
primary={
|
||||
data.policies ? formatNumber(data.policies.expiring) : "—"
|
||||
}
|
||||
sub={
|
||||
data.policies
|
||||
? `En los próximos ${EXPIRY_WINDOW_DAYS} días — ventana: ${policyStatusLabel("expiring")}`
|
||||
: undefined
|
||||
}
|
||||
meta={
|
||||
data.policies
|
||||
? `${formatNumber(data.policies.active)} vigentes · ${formatNumber(data.policies.expired)} vencidas`
|
||||
: undefined
|
||||
}
|
||||
/>
|
||||
<AttentionCard
|
||||
href="/servicios?trust=expiring"
|
||||
tone="warn"
|
||||
loading={loading}
|
||||
title="Fideicomisos por vencer"
|
||||
primary={
|
||||
data.properties ? formatNumber(data.properties.trustExpiring) : "—"
|
||||
}
|
||||
sub={
|
||||
data.properties
|
||||
? `Renueva en los próximos ${EXPIRY_WINDOW_DAYS} días (${trustStatusLabel("expiring")})`
|
||||
: undefined
|
||||
}
|
||||
meta={
|
||||
data.properties
|
||||
? `${formatNumber(data.properties.trusts)} fideicomisos en cartera`
|
||||
: undefined
|
||||
}
|
||||
/>
|
||||
<AttentionCard
|
||||
href="/polizas?status=undated"
|
||||
tone="muted"
|
||||
loading={loading}
|
||||
title="Pólizas sin vigencia"
|
||||
primary={data.policies ? formatNumber(data.policies.undated) : "—"}
|
||||
sub={
|
||||
data.policies
|
||||
? "Sin fecha de fin registrada — revisar y completar"
|
||||
: undefined
|
||||
}
|
||||
meta={
|
||||
data.policies
|
||||
? `${formatNumber(data.policies.liquidated)} liquidadas`
|
||||
: undefined
|
||||
}
|
||||
/>
|
||||
<AttentionCard
|
||||
href="/estado-cuenta"
|
||||
tone="info"
|
||||
loading={loading}
|
||||
title="Clientes con adeudo"
|
||||
primary={
|
||||
data.billing ? (
|
||||
<CurrencyTotals
|
||||
totals={data.billing.byCurrency}
|
||||
field="owing"
|
||||
/>
|
||||
) : (
|
||||
"—"
|
||||
)
|
||||
}
|
||||
sub={
|
||||
data.billing
|
||||
? `En ${formatNumber(data.billing.ledgerCustomers)} expedientes con cargo`
|
||||
: undefined
|
||||
}
|
||||
meta={
|
||||
data.billing
|
||||
? `${formatNumber(data.billing.crossLineCustomers)} clientes con cargo en ambos ramos`
|
||||
: undefined
|
||||
}
|
||||
/>
|
||||
<AttentionCard
|
||||
href="/banco"
|
||||
tone="info"
|
||||
loading={loading}
|
||||
title="Chequera del despacho"
|
||||
primary={
|
||||
data.bank && data.bankAccount ? (
|
||||
<span className={data.bank.net.startsWith("-") ? "money-neg" : "money-pos"}>
|
||||
{formatMoney(data.bank.net, data.bankAccount.currency)}
|
||||
</span>
|
||||
) : (
|
||||
"—"
|
||||
)
|
||||
}
|
||||
// Names the account, because this is one chequera's figure and the
|
||||
// office has more than one — they are never added together.
|
||||
sub={
|
||||
data.bank && data.bankAccount
|
||||
? `${data.bankAccount.label} · ${balancePhrase(data.bank.net)}`
|
||||
: undefined
|
||||
}
|
||||
meta={
|
||||
data.bank
|
||||
? `${formatNumber(data.bank.movements)} movimientos · ${formatNumber(data.bank.pending)} pendientes` +
|
||||
(data.bankAccountCount > 1
|
||||
? ` · ${formatNumber(data.bankAccountCount)} cuentas en total`
|
||||
: "")
|
||||
: undefined
|
||||
}
|
||||
/>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<section aria-label="Accesos rápidos" className="home-section">
|
||||
<div className="section-head">
|
||||
<h2 className="section-title">Accesos rápidos</h2>
|
||||
<span className="section-sub">
|
||||
Ir directo a cada módulo
|
||||
</span>
|
||||
</div>
|
||||
<div className="quick-grid">
|
||||
<QuickLink href="/clientes" label="Clientes" sub="Directorio unificado" />
|
||||
<QuickLink href="/servicios" label="Propiedades" sub="Servicios y fideicomisos" />
|
||||
<QuickLink href="/polizas" label="Pólizas" sub="Vigencias y liquidaciones" />
|
||||
<QuickLink href="/estado-cuenta" label="Estado de cuenta" sub="Cargos y abonos" />
|
||||
<QuickLink href="/banco" label="Chequera" sub="Ingresos y egresos" />
|
||||
</div>
|
||||
</section>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
function greetingFor(name?: string): string {
|
||||
const hour = new Date().getHours();
|
||||
const partOfDay =
|
||||
hour < 12 ? "Buenos días" : hour < 19 ? "Buenas tardes" : "Buenas noches";
|
||||
const display = (name ?? "").trim().split(/\s+/)[0];
|
||||
return display ? `${partOfDay}, ${display}` : partOfDay;
|
||||
}
|
||||
|
||||
function LastSeenLine({
|
||||
billing,
|
||||
bank,
|
||||
loading,
|
||||
}: {
|
||||
billing: string | null;
|
||||
bank: string | null;
|
||||
loading: boolean;
|
||||
}) {
|
||||
if (loading) {
|
||||
return (
|
||||
<p className="muted home-last-seen" aria-hidden="true">
|
||||
<span className="skeleton" style={{ display: "inline-block", width: 220, height: 12 }} />
|
||||
</p>
|
||||
);
|
||||
}
|
||||
if (!billing && !bank) return null;
|
||||
return (
|
||||
<p className="muted home-last-seen">
|
||||
{billing && <>Último movimiento de cartera: <strong>{formatDate(billing)}</strong></>}
|
||||
{billing && bank && <span aria-hidden="true"> · </span>}
|
||||
{bank && <>Último movimiento de chequera: <strong>{formatDate(bank)}</strong></>}
|
||||
</p>
|
||||
);
|
||||
}
|
||||
|
||||
function KpiCard({
|
||||
href,
|
||||
label,
|
||||
primary,
|
||||
sub,
|
||||
loading,
|
||||
}: {
|
||||
href: string;
|
||||
label: string;
|
||||
primary: React.ReactNode;
|
||||
sub: string[];
|
||||
loading: boolean;
|
||||
}) {
|
||||
return (
|
||||
<Link href={href} className="kpi-card card">
|
||||
<div className="kpi-label">{label}</div>
|
||||
<div className="kpi-primary">
|
||||
{loading ? (
|
||||
<span
|
||||
className="skeleton"
|
||||
style={{ display: "inline-block", width: 90, height: 30 }}
|
||||
/>
|
||||
) : (
|
||||
primary
|
||||
)}
|
||||
</div>
|
||||
<ul className="kpi-sub">
|
||||
{loading
|
||||
? Array.from({ length: 3 }).map((_, i) => (
|
||||
<li key={i} className="skeleton" style={{ height: 10 }} />
|
||||
))
|
||||
: sub.map((line) => <li key={line}>{line}</li>)}
|
||||
</ul>
|
||||
<span className="kpi-cta" aria-hidden="true">
|
||||
Ver módulo →
|
||||
</span>
|
||||
</Link>
|
||||
);
|
||||
}
|
||||
|
||||
function AttentionCard({
|
||||
href,
|
||||
tone,
|
||||
title,
|
||||
primary,
|
||||
sub,
|
||||
meta,
|
||||
loading,
|
||||
}: {
|
||||
href: string;
|
||||
tone: "warn" | "info" | "muted";
|
||||
title: string;
|
||||
primary: React.ReactNode;
|
||||
sub?: string;
|
||||
meta?: string;
|
||||
loading: boolean;
|
||||
}) {
|
||||
return (
|
||||
<Link href={href} className={`attention-card tone-${tone} card`}>
|
||||
<div className="attention-head">
|
||||
<span className="attention-title">{title}</span>
|
||||
<span className="attention-arrow" aria-hidden="true">→</span>
|
||||
</div>
|
||||
<div className="attention-primary">
|
||||
{loading ? (
|
||||
<span
|
||||
className="skeleton"
|
||||
style={{ display: "inline-block", width: 70, height: 28 }}
|
||||
/>
|
||||
) : (
|
||||
primary
|
||||
)}
|
||||
</div>
|
||||
{sub && !loading && <div className="attention-sub">{sub}</div>}
|
||||
{meta && !loading && <div className="attention-meta">{meta}</div>}
|
||||
</Link>
|
||||
);
|
||||
}
|
||||
|
||||
function QuickLink({
|
||||
href,
|
||||
label,
|
||||
sub,
|
||||
}: {
|
||||
href: string;
|
||||
label: string;
|
||||
sub: string;
|
||||
}) {
|
||||
return (
|
||||
<Link href={href} className="quick-link card">
|
||||
<span className="quick-label">{label}</span>
|
||||
<span className="quick-sub">{sub}</span>
|
||||
<span className="quick-arrow" aria-hidden="true">→</span>
|
||||
</Link>
|
||||
);
|
||||
}
|
||||
|
||||
function CurrencyTotals({
|
||||
totals,
|
||||
field,
|
||||
}: {
|
||||
totals: BillingStats["byCurrency"];
|
||||
field: "owing" | "inCredit";
|
||||
}) {
|
||||
if (!totals || totals.length === 0) return <>—</>;
|
||||
return (
|
||||
<span className="home-currency-totals">
|
||||
{totals.map((c) => (
|
||||
<span key={c.currency} className="home-currency-totals-row">
|
||||
<span className="badge badge-count">{c.currency}</span>
|
||||
<span className="home-currency-totals-num">
|
||||
{formatNumber(c[field])}
|
||||
</span>
|
||||
</span>
|
||||
))}
|
||||
</span>
|
||||
);
|
||||
}
|
||||
@@ -1,5 +1,6 @@
|
||||
import type { ReactNode } from "react";
|
||||
import "./globals.css";
|
||||
import { readBuildInfoFromEnv } from "@/lib/build-info";
|
||||
|
||||
export const metadata = {
|
||||
title: "Jorge Cuadros & Asociados — Plataforma",
|
||||
@@ -7,10 +8,45 @@ export const metadata = {
|
||||
"Plataforma interna unificada de clientes, servicios y seguros.",
|
||||
};
|
||||
|
||||
// The browser talks to the API cross-origin, so it needs the API URL at
|
||||
// runtime. NEXT_PUBLIC_* would bake it at build time (one URL per image); we
|
||||
// want the URL to come from the deploy .env instead. So read it here on the
|
||||
// server per request and inject it as window.__API_ORIGIN__ (see lib/api.ts).
|
||||
// force-dynamic guarantees process.env is read at request time, never baked
|
||||
// into a static prerender.
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
export default function RootLayout({ children }: { children: ReactNode }) {
|
||||
const apiOrigin =
|
||||
process.env.API_ORIGIN ??
|
||||
process.env.NEXT_PUBLIC_API_ORIGIN ??
|
||||
"http://localhost:3001";
|
||||
// Same reason as the API origin: read on the server per request so the built
|
||||
// image is not pinned to one build identity in its client bundle.
|
||||
const build = readBuildInfoFromEnv();
|
||||
|
||||
return (
|
||||
<html lang="es">
|
||||
<head>
|
||||
{/* Must run before the app bundle so lib/api.ts sees it at import. */}
|
||||
<script
|
||||
dangerouslySetInnerHTML={{
|
||||
__html:
|
||||
`window.__API_ORIGIN__=${JSON.stringify(apiOrigin)};` +
|
||||
`window.__APP_BUILD__=${JSON.stringify(build)};`,
|
||||
}}
|
||||
/>
|
||||
{/* Text-size preference, applied before first paint so the page never
|
||||
flashes at the default size. Mirrors lib/ui-scale.ts — keep the key
|
||||
and the clamp in sync with it. */}
|
||||
<script
|
||||
dangerouslySetInnerHTML={{
|
||||
__html:
|
||||
`try{var s=parseFloat(localStorage.getItem("jc.ui-scale"));` +
|
||||
`if(isFinite(s))document.documentElement.style.setProperty(` +
|
||||
`"--ui-scale",String(Math.min(1.5,Math.max(0.9,s))));}catch(e){}`,
|
||||
}}
|
||||
/>
|
||||
{/* Google Fonts via <link> so an offline build still runs with the
|
||||
system fallback stacks defined in globals.css. */}
|
||||
<link rel="preconnect" href="https://fonts.googleapis.com" />
|
||||
|
||||
@@ -16,7 +16,7 @@ export default function LoginPage() {
|
||||
useEffect(() => {
|
||||
let alive = true;
|
||||
me()
|
||||
.then(() => router.replace("/clientes"))
|
||||
.then(() => router.replace("/inicio"))
|
||||
.catch(() => {
|
||||
if (alive) setBootChecking(false);
|
||||
});
|
||||
@@ -31,7 +31,7 @@ export default function LoginPage() {
|
||||
setSubmitting(true);
|
||||
try {
|
||||
await login(email.trim(), password);
|
||||
router.replace("/clientes");
|
||||
router.replace("/inicio");
|
||||
} catch (err) {
|
||||
if (err instanceof ApiError && err.status === 401) {
|
||||
setError("Correo o contraseña incorrectos");
|
||||
@@ -65,9 +65,11 @@ export default function LoginPage() {
|
||||
<aside className="login-aside" aria-hidden="false">
|
||||
<div className="login-aside-top">
|
||||
<div className="login-brand">
|
||||
<span className="brand-mark" aria-hidden>
|
||||
JC
|
||||
</span>
|
||||
<img
|
||||
src="/images/company_logo.png"
|
||||
alt=""
|
||||
className="brand-mark"
|
||||
/>
|
||||
<div className="brand-text">
|
||||
<span className="brand-name" style={{ color: "#f6f3ec" }}>
|
||||
Jorge Cuadros
|
||||
|
||||
@@ -0,0 +1,529 @@
|
||||
"use client";
|
||||
|
||||
import { useCallback, useEffect, useRef, useState } from "react";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import {
|
||||
OPS_KIND_LABELS,
|
||||
OPS_STATUS_LABELS,
|
||||
formatBytes,
|
||||
formatDateTime,
|
||||
} from "@/lib/labels";
|
||||
import {
|
||||
backupDownloadUrl,
|
||||
deleteBackup,
|
||||
deleteIngest,
|
||||
getOpsJob,
|
||||
listBackups,
|
||||
listIngest,
|
||||
listOpsJobs,
|
||||
startOpsJob,
|
||||
uploadIngest,
|
||||
} from "@/lib/api";
|
||||
import type {
|
||||
BackupFile,
|
||||
IngestFile,
|
||||
OpsJob,
|
||||
OpsJobKind,
|
||||
} from "@/lib/types";
|
||||
|
||||
const INGEST_MAX_BYTES = 2 * 1024 * 1024 * 1024;
|
||||
|
||||
export default function OperacionesPage() {
|
||||
return (
|
||||
<AppShell>
|
||||
<Operaciones />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
type ConfirmState =
|
||||
| { kind: "REIMPORT" }
|
||||
| { kind: "SYNC" }
|
||||
| { kind: "RESTORE"; file: string }
|
||||
| null;
|
||||
|
||||
function Operaciones() {
|
||||
const allowed = useCan("db:manage");
|
||||
|
||||
const [ingest, setIngest] = useState<IngestFile[] | null>(null);
|
||||
const [backups, setBackups] = useState<BackupFile[] | null>(null);
|
||||
const [jobs, setJobs] = useState<OpsJob[] | null>(null);
|
||||
const [activeJob, setActiveJob] = useState<OpsJob | null>(null);
|
||||
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [notice, setNotice] = useState<string | null>(null);
|
||||
const [confirm, setConfirm] = useState<ConfirmState>(null);
|
||||
const [confirmText, setConfirmText] = useState("");
|
||||
const [uploading, setUploading] = useState<string | null>(null);
|
||||
const [starting, setStarting] = useState(false);
|
||||
|
||||
const fileInputs = useRef<Record<string, HTMLInputElement | null>>({});
|
||||
|
||||
const refreshLists = useCallback(() => {
|
||||
listIngest().then(setIngest).catch(() => setIngest([]));
|
||||
listBackups().then(setBackups).catch(() => setBackups([]));
|
||||
listOpsJobs()
|
||||
.then((rows) => {
|
||||
setJobs(rows);
|
||||
const running = rows.find((j) => j.status === "RUNNING");
|
||||
if (running) setActiveJob(running);
|
||||
})
|
||||
.catch(() => setJobs([]));
|
||||
}, []);
|
||||
|
||||
useEffect(() => {
|
||||
if (allowed) refreshLists();
|
||||
}, [allowed, refreshLists]);
|
||||
|
||||
// Poll the active job while it runs; refresh everything when it finishes.
|
||||
useEffect(() => {
|
||||
if (!activeJob || activeJob.status !== "RUNNING") return;
|
||||
const id = activeJob.id;
|
||||
const timer = setInterval(() => {
|
||||
getOpsJob(id)
|
||||
.then((job) => {
|
||||
setActiveJob(job);
|
||||
if (job.status !== "RUNNING") {
|
||||
clearInterval(timer);
|
||||
refreshLists();
|
||||
setNotice(
|
||||
job.status === "SUCCESS"
|
||||
? `${OPS_KIND_LABELS[job.kind]} completada.`
|
||||
: `${OPS_KIND_LABELS[job.kind]} terminó con error. Revise el registro.`,
|
||||
);
|
||||
}
|
||||
})
|
||||
.catch(() => {
|
||||
/* transient — keep polling */
|
||||
});
|
||||
}, 1500);
|
||||
return () => clearInterval(timer);
|
||||
}, [activeJob, refreshLists]);
|
||||
|
||||
if (!allowed) {
|
||||
return (
|
||||
<div className="page-head">
|
||||
<h1 className="page-title">Operaciones</h1>
|
||||
<div className="state-box state-error">
|
||||
No tiene permisos para administrar la base de datos.
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
const jobRunning = activeJob?.status === "RUNNING";
|
||||
|
||||
async function handleUpload(name: string, file: File | undefined) {
|
||||
if (!file) return;
|
||||
setError(null);
|
||||
setNotice(null);
|
||||
setUploading(name);
|
||||
try {
|
||||
await uploadIngest(name, file);
|
||||
setNotice(`${name} cargado.`);
|
||||
refreshLists();
|
||||
} catch (e) {
|
||||
setError((e as Error)?.message ?? "No se pudo cargar el archivo.");
|
||||
} finally {
|
||||
setUploading(null);
|
||||
const input = fileInputs.current[name];
|
||||
if (input) input.value = "";
|
||||
}
|
||||
}
|
||||
|
||||
async function handleDeleteIngest(name: string) {
|
||||
setError(null);
|
||||
try {
|
||||
await deleteIngest(name);
|
||||
refreshLists();
|
||||
} catch (e) {
|
||||
setError((e as Error)?.message ?? "No se pudo eliminar.");
|
||||
}
|
||||
}
|
||||
|
||||
async function handleDeleteBackup(name: string) {
|
||||
setError(null);
|
||||
try {
|
||||
await deleteBackup(name);
|
||||
refreshLists();
|
||||
} catch (e) {
|
||||
setError((e as Error)?.message ?? "No se pudo eliminar el respaldo.");
|
||||
}
|
||||
}
|
||||
|
||||
async function start(kind: OpsJobKind, file?: string) {
|
||||
setError(null);
|
||||
setNotice(null);
|
||||
setStarting(true);
|
||||
try {
|
||||
const job = await startOpsJob(kind, file);
|
||||
setActiveJob(job);
|
||||
setJobs((prev) => (prev ? [job, ...prev] : [job]));
|
||||
} catch (e) {
|
||||
setError((e as Error)?.message ?? "No se pudo iniciar la operación.");
|
||||
} finally {
|
||||
setStarting(false);
|
||||
}
|
||||
}
|
||||
|
||||
function askConfirm(state: ConfirmState) {
|
||||
setConfirm(state);
|
||||
setConfirmText("");
|
||||
setError(null);
|
||||
setNotice(null);
|
||||
}
|
||||
|
||||
async function runConfirmed() {
|
||||
if (!confirm) return;
|
||||
const c = confirm;
|
||||
setConfirm(null);
|
||||
if (c.kind === "REIMPORT") await start("REIMPORT");
|
||||
else if (c.kind === "SYNC") await start("SYNC");
|
||||
else await start("RESTORE", c.file);
|
||||
}
|
||||
|
||||
const ingestReady = (ingest ?? []).every((f) => f.present);
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<h1 className="page-title">Operaciones de base de datos</h1>
|
||||
</div>
|
||||
|
||||
{error && <div className="state-box state-error">{error}</div>}
|
||||
{notice && <div className="state-box">{notice}</div>}
|
||||
|
||||
{/* Active / running job with live log */}
|
||||
{activeJob && (
|
||||
<div className="card" style={{ padding: 20, marginBottom: 20 }}>
|
||||
<div className="row-actions" style={{ justifyContent: "space-between" }}>
|
||||
<h2 className="section-title" style={{ margin: 0 }}>
|
||||
{OPS_KIND_LABELS[activeJob.kind]}{" "}
|
||||
<span
|
||||
className={`badge ${
|
||||
activeJob.status === "SUCCESS"
|
||||
? "badge-positive"
|
||||
: activeJob.status === "FAILED"
|
||||
? "badge-negative"
|
||||
: "badge-neutral"
|
||||
}`}
|
||||
>
|
||||
{jobRunning && <span className="spinner" aria-hidden style={{ marginRight: 6 }} />}
|
||||
{OPS_STATUS_LABELS[activeJob.status]}
|
||||
</span>
|
||||
</h2>
|
||||
{!jobRunning && (
|
||||
<button className="btn btn-ghost" type="button" onClick={() => setActiveJob(null)}>
|
||||
Ocultar
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
<pre className="ops-log">{activeJob.log || "Iniciando…"}</pre>
|
||||
</div>
|
||||
)}
|
||||
|
||||
{/* Ingest folder */}
|
||||
<div className="card" style={{ padding: 20, marginBottom: 20 }}>
|
||||
<h2 className="section-title">Carpeta de ingesta</h2>
|
||||
<p className="inline-form-note">
|
||||
Los cuatro archivos originales de Access. La reimportación y la
|
||||
sincronización leen de aquí. Tamaño máximo por archivo: {formatBytes(INGEST_MAX_BYTES)}.
|
||||
</p>
|
||||
<div className="tx-scroll">
|
||||
<table className="tx-table">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Archivo</th>
|
||||
<th>Estado</th>
|
||||
<th className="num">Tamaño</th>
|
||||
<th>Modificado</th>
|
||||
<th className="num">Acciones</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{(ingest ?? []).map((f) => (
|
||||
<tr key={f.name}>
|
||||
<td className="mono">{f.name}</td>
|
||||
<td>
|
||||
<span className={`badge ${f.present ? "badge-positive" : "badge-negative"}`}>
|
||||
{f.present ? "Presente" : "Falta"}
|
||||
</span>
|
||||
</td>
|
||||
<td className="num">{formatBytes(f.size)}</td>
|
||||
<td>{formatDateTime(f.modifiedAt)}</td>
|
||||
<td>
|
||||
<div className="row-actions">
|
||||
<input
|
||||
ref={(el) => {
|
||||
fileInputs.current[f.name] = el;
|
||||
}}
|
||||
type="file"
|
||||
style={{ display: "none" }}
|
||||
onChange={(e) => handleUpload(f.name, e.target.files?.[0])}
|
||||
/>
|
||||
<button
|
||||
className="btn btn-outline"
|
||||
type="button"
|
||||
disabled={uploading === f.name}
|
||||
onClick={() => fileInputs.current[f.name]?.click()}
|
||||
>
|
||||
{uploading === f.name ? "Cargando…" : f.present ? "Reemplazar" : "Cargar"}
|
||||
</button>
|
||||
{f.present && (
|
||||
<button
|
||||
className="btn btn-ghost"
|
||||
type="button"
|
||||
onClick={() => handleDeleteIngest(f.name)}
|
||||
>
|
||||
Eliminar
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
{/* Operations */}
|
||||
<div className="card" style={{ padding: 20, marginBottom: 20 }}>
|
||||
<h2 className="section-title">Operaciones</h2>
|
||||
<div className="form-grid">
|
||||
<OpTile
|
||||
title="Respaldo"
|
||||
desc="Genera un volcado comprimido de la base de datos actual."
|
||||
action="Crear respaldo"
|
||||
tone="primary"
|
||||
disabled={jobRunning || starting}
|
||||
onClick={() => start("BACKUP")}
|
||||
/>
|
||||
<OpTile
|
||||
title="Reimportar (purga)"
|
||||
desc="Respalda, borra TODO y reconstruye desde los archivos de ingesta. Se pierden los datos capturados manualmente."
|
||||
action="Reimportar"
|
||||
tone="danger"
|
||||
disabled={jobRunning || starting || !ingestReady}
|
||||
onClick={() => askConfirm({ kind: "REIMPORT" })}
|
||||
/>
|
||||
<OpTile
|
||||
title="Sincronizar"
|
||||
desc="Respalda, luego importa lo nuevo del legado. Borra del sistema los registros del legado que ya no aparecen en los archivos de ingesta. Se conservan los datos capturados a mano."
|
||||
action="Sincronizar"
|
||||
tone="primary"
|
||||
disabled={jobRunning || starting || !ingestReady}
|
||||
onClick={() => askConfirm({ kind: "SYNC" })}
|
||||
/>
|
||||
</div>
|
||||
{!ingestReady && (
|
||||
<p className="inline-form-note" style={{ marginTop: 12 }}>
|
||||
La reimportación requiere que los cuatro archivos estén presentes.
|
||||
</p>
|
||||
)}
|
||||
</div>
|
||||
|
||||
{/* Backups */}
|
||||
<div className="card" style={{ padding: 20, marginBottom: 20 }}>
|
||||
<h2 className="section-title">Respaldos</h2>
|
||||
<p className="inline-form-note">
|
||||
Restaurar sobreescribe la base de datos completa con el respaldo elegido.
|
||||
</p>
|
||||
<div className="tx-scroll">
|
||||
<table className="tx-table">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Archivo</th>
|
||||
<th className="num">Tamaño</th>
|
||||
<th>Creado</th>
|
||||
<th className="num">Acciones</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{backups === null ? (
|
||||
<tr>
|
||||
<td colSpan={4}>
|
||||
<span className="spinner" aria-label="Cargando" />
|
||||
</td>
|
||||
</tr>
|
||||
) : backups.length === 0 ? (
|
||||
<tr>
|
||||
<td colSpan={4} className="muted">
|
||||
Sin respaldos.
|
||||
</td>
|
||||
</tr>
|
||||
) : (
|
||||
backups.map((b) => (
|
||||
<tr key={b.name}>
|
||||
<td className="mono">{b.name}</td>
|
||||
<td className="num">{formatBytes(b.size)}</td>
|
||||
<td>{formatDateTime(b.createdAt)}</td>
|
||||
<td>
|
||||
<div className="row-actions">
|
||||
<a className="btn btn-outline" href={backupDownloadUrl(b.name)}>
|
||||
Descargar
|
||||
</a>
|
||||
<button
|
||||
className="btn btn-outline"
|
||||
type="button"
|
||||
disabled={jobRunning || starting}
|
||||
onClick={() => askConfirm({ kind: "RESTORE", file: b.name })}
|
||||
>
|
||||
Restaurar
|
||||
</button>
|
||||
<button
|
||||
className="btn btn-ghost"
|
||||
type="button"
|
||||
onClick={() => handleDeleteBackup(b.name)}
|
||||
>
|
||||
Eliminar
|
||||
</button>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
))
|
||||
)}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
{/* Recent jobs */}
|
||||
<div className="card" style={{ padding: 20 }}>
|
||||
<h2 className="section-title">Historial</h2>
|
||||
<div className="tx-scroll">
|
||||
<table className="tx-table">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Operación</th>
|
||||
<th>Estado</th>
|
||||
<th>Inicio</th>
|
||||
<th>Fin</th>
|
||||
<th className="num"></th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{(jobs ?? []).map((j) => (
|
||||
<tr key={j.id}>
|
||||
<td>{OPS_KIND_LABELS[j.kind]}</td>
|
||||
<td>
|
||||
<span
|
||||
className={`badge ${
|
||||
j.status === "SUCCESS"
|
||||
? "badge-positive"
|
||||
: j.status === "FAILED"
|
||||
? "badge-negative"
|
||||
: "badge-neutral"
|
||||
}`}
|
||||
>
|
||||
{OPS_STATUS_LABELS[j.status]}
|
||||
</span>
|
||||
</td>
|
||||
<td>{formatDateTime(j.startedAt)}</td>
|
||||
<td>{formatDateTime(j.finishedAt)}</td>
|
||||
<td className="num">
|
||||
<button
|
||||
className="btn btn-ghost"
|
||||
type="button"
|
||||
onClick={() => setActiveJob(j)}
|
||||
>
|
||||
Ver registro
|
||||
</button>
|
||||
</td>
|
||||
</tr>
|
||||
))}
|
||||
{jobs && jobs.length === 0 && (
|
||||
<tr>
|
||||
<td colSpan={5} className="muted">
|
||||
Sin operaciones registradas.
|
||||
</td>
|
||||
</tr>
|
||||
)}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
{/* Destructive-op confirm */}
|
||||
{confirm && (
|
||||
<div className="modal-backdrop" role="dialog" aria-modal="true">
|
||||
<div className="card" style={{ padding: 24, maxWidth: 480 }}>
|
||||
<h2 className="section-title" style={{ marginTop: 0 }}>
|
||||
{confirm.kind === "REIMPORT"
|
||||
? "Confirmar reimportación"
|
||||
: confirm.kind === "SYNC"
|
||||
? "Confirmar sincronización"
|
||||
: "Confirmar restauración"}
|
||||
</h2>
|
||||
<p className="inline-form-note">
|
||||
{confirm.kind === "REIMPORT"
|
||||
? "Esto BORRA todos los datos actuales (incluidos los capturados a mano) y reconstruye desde los archivos de ingesta. Se creará un respaldo previo automático."
|
||||
: confirm.kind === "SYNC"
|
||||
? "Se creará un respaldo previo automático. Luego se importarán al sistema los registros nuevos del legado y se eliminarán los del legado que ya no aparezcan en los archivos de ingesta. Los datos capturados a mano NO se borran."
|
||||
: `Esto sobreescribe la base de datos completa con “${confirm.file}”. Se recomienda crear un respaldo antes.`}
|
||||
</p>
|
||||
<label className="field">
|
||||
<span className="field-label">Escriba CONFIRMAR para continuar</span>
|
||||
<input
|
||||
className="input"
|
||||
value={confirmText}
|
||||
onChange={(e) => setConfirmText(e.target.value)}
|
||||
autoFocus
|
||||
/>
|
||||
</label>
|
||||
<div className="form-actions">
|
||||
<button
|
||||
className={confirm.kind === "SYNC" ? "btn btn-primary" : "btn btn-danger"}
|
||||
type="button"
|
||||
disabled={confirmText !== "CONFIRMAR" || starting}
|
||||
onClick={runConfirmed}
|
||||
>
|
||||
{confirm.kind === "REIMPORT"
|
||||
? "Reimportar"
|
||||
: confirm.kind === "SYNC"
|
||||
? "Sincronizar"
|
||||
: "Restaurar"}
|
||||
</button>
|
||||
<button className="btn btn-outline" type="button" onClick={() => setConfirm(null)}>
|
||||
Cancelar
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
)}
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
function OpTile({
|
||||
title,
|
||||
desc,
|
||||
action,
|
||||
tone,
|
||||
disabled,
|
||||
onClick,
|
||||
}: {
|
||||
title: string;
|
||||
desc: string;
|
||||
action: string;
|
||||
tone: "primary" | "danger" | "muted";
|
||||
disabled: boolean;
|
||||
onClick: () => void;
|
||||
}) {
|
||||
const btnClass =
|
||||
tone === "danger" ? "btn btn-danger" : tone === "muted" ? "btn btn-outline" : "btn btn-primary";
|
||||
return (
|
||||
<div className="card" style={{ padding: 16 }}>
|
||||
<h3 className="section-title" style={{ fontSize: 15, margin: "0 0 4px" }}>
|
||||
{title}
|
||||
</h3>
|
||||
<p className="inline-form-note" style={{ minHeight: 48 }}>
|
||||
{desc}
|
||||
</p>
|
||||
<button className={btnClass} type="button" disabled={disabled} onClick={onClick}>
|
||||
{action}
|
||||
</button>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -1,5 +1,5 @@
|
||||
import { redirect } from "next/navigation";
|
||||
|
||||
export default function HomePage() {
|
||||
redirect("/clientes");
|
||||
redirect("/inicio");
|
||||
}
|
||||
|
||||
@@ -0,0 +1,54 @@
|
||||
"use client";
|
||||
|
||||
import { useEffect, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { PolicyForm } from "@/components/PolicyForm";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import { getPolicy } from "@/lib/api";
|
||||
import type { PolicyDetail } from "@/lib/types";
|
||||
|
||||
export default function EditarPolizaPage({
|
||||
params,
|
||||
}: {
|
||||
params: { id: string };
|
||||
}) {
|
||||
return (
|
||||
<AppShell>
|
||||
<EditarPoliza id={params.id} />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
function EditarPoliza({ id }: { id: string }) {
|
||||
const allowed = useCan("policy:update");
|
||||
const [policy, setPolicy] = useState<PolicyDetail | null>(null);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
useEffect(() => {
|
||||
if (!allowed) return;
|
||||
getPolicy(id)
|
||||
.then(setPolicy)
|
||||
.catch((e) => setError(e?.message ?? "No se pudo cargar la póliza."));
|
||||
}, [id, allowed]);
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<Link href={`/polizas/${id}`} className="back-link">← Póliza</Link>
|
||||
<h1 className="page-title">Editar póliza</h1>
|
||||
</div>
|
||||
{!allowed ? (
|
||||
<div className="state-box state-error">
|
||||
No tiene permisos para editar pólizas.
|
||||
</div>
|
||||
) : error ? (
|
||||
<div className="state-box state-error">{error}</div>
|
||||
) : !policy ? (
|
||||
<div className="empty-inline"><span className="spinner" aria-label="Cargando" /></div>
|
||||
) : (
|
||||
<PolicyForm policy={policy} />
|
||||
)}
|
||||
</>
|
||||
);
|
||||
}
|
||||
@@ -3,7 +3,21 @@
|
||||
import { useEffect, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { getPolicy } from "@/lib/api";
|
||||
import { ContextReports } from "@/components/ContextReports";
|
||||
import {
|
||||
addPolicyChild,
|
||||
archivePolicy,
|
||||
getLookups,
|
||||
getPolicy,
|
||||
policyDocumentDownloadUrl,
|
||||
removePolicyChild,
|
||||
removePolicyDocument,
|
||||
restorePolicy,
|
||||
updatePolicyChild,
|
||||
uploadPolicyDocument,
|
||||
} from "@/lib/api";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import { ChildCollection, type ChildConfig } from "@/components/ChildCollection";
|
||||
import {
|
||||
expiryPhrase,
|
||||
formatDate,
|
||||
@@ -12,7 +26,7 @@ import {
|
||||
premiumHeadline,
|
||||
SIN_NOMBRE,
|
||||
} from "@/lib/labels";
|
||||
import type { Installment, PolicyDetail } from "@/lib/types";
|
||||
import type { AdjusterRow, Installment, PolicyDetail } from "@/lib/types";
|
||||
|
||||
export default function PolizaDetailPage({
|
||||
params,
|
||||
@@ -73,9 +87,23 @@ function Detail({ id }: { id: string }) {
|
||||
|
||||
if (!data) return null;
|
||||
|
||||
const reload = () => getPolicy(id).then(setData).catch(() => {});
|
||||
|
||||
return (
|
||||
<div className="rise">
|
||||
<BackLink />
|
||||
<div className="detail-actionbar">
|
||||
<BackLink />
|
||||
<ContextReports
|
||||
entries={[
|
||||
{
|
||||
slug: "edo-cuenta-datos",
|
||||
label: "Estado de cuenta del cliente",
|
||||
params: { customerId: data.customer.id },
|
||||
},
|
||||
]}
|
||||
/>
|
||||
<PolicyActions data={data} onChange={reload} />
|
||||
</div>
|
||||
<Hero data={data} />
|
||||
<ClienteSection data={data} />
|
||||
<CondicionesSection data={data} />
|
||||
@@ -86,11 +114,164 @@ function Detail({ id }: { id: string }) {
|
||||
)}
|
||||
{data.claims.length > 0 && <SiniestrosSection data={data} />}
|
||||
<CoberturasSection data={data} />
|
||||
<DocumentosSection data={data} />
|
||||
<DocumentosSection data={data} onChange={reload} />
|
||||
<ChildrenEditor data={data} onChange={reload} />
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
/** Edit / archive controls for the policy header. */
|
||||
function PolicyActions({
|
||||
data,
|
||||
onChange,
|
||||
}: {
|
||||
data: PolicyDetail;
|
||||
onChange: () => void;
|
||||
}) {
|
||||
const canEdit = useCan("policy:update");
|
||||
const canDelete = useCan("policy:delete");
|
||||
const [busy, setBusy] = useState(false);
|
||||
const archived = data.archivedAt != null;
|
||||
|
||||
async function toggle() {
|
||||
const verb = archived ? "restaurar" : "archivar";
|
||||
if (!window.confirm(`¿Seguro que desea ${verb} esta póliza?`)) return;
|
||||
setBusy(true);
|
||||
try {
|
||||
if (archived) await restorePolicy(data.id);
|
||||
else await archivePolicy(data.id);
|
||||
onChange();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo completar la acción.");
|
||||
} finally {
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
if (!canEdit && !canDelete) return null;
|
||||
return (
|
||||
<div className="row-actions">
|
||||
{archived && <span className="badge badge-negative">Archivada</span>}
|
||||
{canEdit && (
|
||||
<Link href={`/polizas/${data.id}/editar`} className="btn btn-outline">
|
||||
Editar
|
||||
</Link>
|
||||
)}
|
||||
{canDelete && (
|
||||
<button type="button" className="btn btn-ghost" onClick={toggle} disabled={busy}>
|
||||
{archived ? "Restaurar" : "Archivar"}
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
/** Editable child collections — only shown to users who can edit the policy. */
|
||||
function ChildrenEditor({
|
||||
data,
|
||||
onChange,
|
||||
}: {
|
||||
data: PolicyDetail;
|
||||
onChange: () => void;
|
||||
}) {
|
||||
const canEdit = useCan("policy:update");
|
||||
const [adjusters, setAdjusters] = useState<AdjusterRow[]>([]);
|
||||
|
||||
useEffect(() => {
|
||||
if (canEdit) getLookups().then((l) => setAdjusters(l.adjusters)).catch(() => {});
|
||||
}, [canEdit]);
|
||||
|
||||
if (!canEdit) return null;
|
||||
|
||||
const INSTALLMENTS: ChildConfig = {
|
||||
apiKind: "installments",
|
||||
title: "Pagos",
|
||||
fields: [
|
||||
{ key: "sequence", label: "Sec.", type: "number" },
|
||||
{ key: "amount", label: "Monto", type: "number" },
|
||||
{ key: "currency", label: "Moneda", type: "select",
|
||||
options: [{ value: "MXN", label: "MXN" }, { value: "USD", label: "USD" }] },
|
||||
{ key: "dueDate", label: "Vence", type: "date" },
|
||||
{ key: "paidDate", label: "Pagado", type: "date" },
|
||||
{ key: "checkNumber", label: "Cheque" },
|
||||
{ key: "isCash", label: "Efectivo", type: "checkbox" },
|
||||
],
|
||||
};
|
||||
const VEHICLES: ChildConfig = {
|
||||
apiKind: "vehicles",
|
||||
title: "Vehículos",
|
||||
fields: [
|
||||
{ key: "make", label: "Marca" },
|
||||
{ key: "model", label: "Modelo" },
|
||||
{ key: "modelYear", label: "Año" },
|
||||
{ key: "licensePlate", label: "Placa" },
|
||||
{ key: "vinNumber", label: "VIN" },
|
||||
{ key: "stateCode", label: "Estado" },
|
||||
],
|
||||
};
|
||||
const DRIVERS: ChildConfig = {
|
||||
apiKind: "drivers",
|
||||
title: "Conductores",
|
||||
fields: [
|
||||
{ key: "fullName", label: "Nombre" },
|
||||
{ key: "birthDate", label: "Nacimiento", type: "date" },
|
||||
{ key: "sex", label: "Sexo" },
|
||||
{ key: "occupation", label: "Ocupación" },
|
||||
{ key: "licenseNumber", label: "Licencia" },
|
||||
{ key: "licenseState", label: "Estado" },
|
||||
],
|
||||
};
|
||||
const BENEFICIARIES: ChildConfig = {
|
||||
apiKind: "beneficiaries",
|
||||
title: "Beneficiarios",
|
||||
fields: [
|
||||
{ key: "name", label: "Nombre" },
|
||||
{ key: "phone", label: "Teléfono" },
|
||||
{ key: "email", label: "Correo" },
|
||||
{ key: "address", label: "Dirección" },
|
||||
],
|
||||
};
|
||||
const CLAIMS: ChildConfig = {
|
||||
apiKind: "claims",
|
||||
title: "Siniestros",
|
||||
fields: [
|
||||
{ key: "claimType", label: "Tipo" },
|
||||
{ key: "incidentDate", label: "Fecha", type: "date" },
|
||||
{ key: "description", label: "Descripción" },
|
||||
{ key: "adjusterId", label: "Ajustador", type: "select",
|
||||
options: adjusters.map((a) => ({ value: a.id, label: a.name ?? a.company ?? a.id })) },
|
||||
{ key: "claimedAmount", label: "Reclamado", type: "number" },
|
||||
{ key: "settledAmount", label: "Pagado", type: "number" },
|
||||
{ key: "resolved", label: "Resuelto", type: "checkbox" },
|
||||
],
|
||||
};
|
||||
|
||||
const bind = (cfg: ChildConfig, rows: Record<string, unknown>[]) => (
|
||||
<ChildCollection
|
||||
config={cfg}
|
||||
rows={rows}
|
||||
canEdit={canEdit}
|
||||
onAdd={async (p) => { await addPolicyChild(data.id, cfg.apiKind, p); onChange(); }}
|
||||
onSave={async (cid, p) => { await updatePolicyChild(data.id, cfg.apiKind, cid, p); onChange(); }}
|
||||
onRemove={async (cid) => { await removePolicyChild(data.id, cfg.apiKind, cid); onChange(); }}
|
||||
/>
|
||||
);
|
||||
|
||||
return (
|
||||
<section className="section">
|
||||
<div className="section-head">
|
||||
<span className="section-rule cuenta" aria-hidden />
|
||||
<h2 className="section-title">Administrar detalles</h2>
|
||||
</div>
|
||||
{bind(INSTALLMENTS, data.installments as unknown as Record<string, unknown>[])}
|
||||
{bind(VEHICLES, data.vehicles as unknown as Record<string, unknown>[])}
|
||||
{bind(DRIVERS, data.insuredDrivers as unknown as Record<string, unknown>[])}
|
||||
{bind(BENEFICIARIES, data.beneficiaries as unknown as Record<string, unknown>[])}
|
||||
{bind(CLAIMS, data.claims as unknown as Record<string, unknown>[])}
|
||||
</section>
|
||||
);
|
||||
}
|
||||
|
||||
function BackLink() {
|
||||
return (
|
||||
<Link href="/polizas" className="back-link">
|
||||
@@ -496,7 +677,35 @@ function CoberturasSection({ data }: { data: PolicyDetail }) {
|
||||
}
|
||||
|
||||
/* -------------------------------------------------------- Documentos */
|
||||
function DocumentosSection({ data }: { data: PolicyDetail }) {
|
||||
function DocumentosSection({
|
||||
data,
|
||||
onChange,
|
||||
}: {
|
||||
data: PolicyDetail;
|
||||
onChange: () => void;
|
||||
}) {
|
||||
const canEdit = useCan("policy:update");
|
||||
const [file, setFile] = useState<File | null>(null);
|
||||
const [type, setType] = useState("");
|
||||
const [busy, setBusy] = useState(false);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
async function upload() {
|
||||
if (!file) return;
|
||||
setBusy(true);
|
||||
setError(null);
|
||||
try {
|
||||
await uploadPolicyDocument(data.id, file, type.trim() || undefined);
|
||||
setFile(null);
|
||||
setType("");
|
||||
onChange();
|
||||
} catch (e) {
|
||||
setError((e as Error)?.message ?? "No se pudo subir el archivo.");
|
||||
} finally {
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<section className="section">
|
||||
<SectionHead rule="docs" title="Documentos" count={data.documents.length} />
|
||||
@@ -506,25 +715,74 @@ function DocumentosSection({ data }: { data: PolicyDetail }) {
|
||||
No hay documentos registrados para esta póliza.
|
||||
</div>
|
||||
) : (
|
||||
<>
|
||||
<div className="doc-list">
|
||||
{data.documents.map((d, i) => (
|
||||
<div className="doc-item" key={d.id ?? i}>
|
||||
<span className="doc-icon" aria-hidden>
|
||||
▤
|
||||
</span>
|
||||
<div style={{ minWidth: 0 }}>
|
||||
<div className="doc-type">{d.documentType || "Documento"}</div>
|
||||
<div className="doc-key">{d.storageKey || "—"}</div>
|
||||
</div>
|
||||
<div className="doc-list">
|
||||
{data.documents.map((d, i) => (
|
||||
<div className="doc-item" key={d.id ?? i}>
|
||||
<span className="doc-icon" aria-hidden>
|
||||
▤
|
||||
</span>
|
||||
<div style={{ minWidth: 0, flex: 1 }}>
|
||||
<div className="doc-type">{d.documentType || "Documento"}</div>
|
||||
<div className="doc-key">{d.storageKey || "—"}</div>
|
||||
</div>
|
||||
))}
|
||||
{d.id && (
|
||||
<a
|
||||
className="btn btn-ghost"
|
||||
href={policyDocumentDownloadUrl(data.id, d.id)}
|
||||
>
|
||||
Descargar
|
||||
</a>
|
||||
)}
|
||||
{canEdit && d.id && (
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
onClick={async () => {
|
||||
if (!window.confirm("¿Eliminar este documento?")) return;
|
||||
try {
|
||||
await removePolicyDocument(data.id, d.id!);
|
||||
onChange();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo eliminar.");
|
||||
}
|
||||
}}
|
||||
>
|
||||
Eliminar
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
))}
|
||||
</div>
|
||||
)}
|
||||
{canEdit && (
|
||||
<div style={{ padding: "0 22px 18px" }}>
|
||||
{error && (
|
||||
<div className="state-box state-error" style={{ marginBottom: 12 }}>
|
||||
{error}
|
||||
</div>
|
||||
)}
|
||||
<div className="inline-form">
|
||||
<input
|
||||
className="input"
|
||||
placeholder="Tipo (ej. CARATULA)"
|
||||
value={type}
|
||||
onChange={(e) => setType(e.target.value)}
|
||||
/>
|
||||
<input
|
||||
type="file"
|
||||
className="input"
|
||||
onChange={(e) => setFile(e.target.files?.[0] ?? null)}
|
||||
/>
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-primary"
|
||||
disabled={!file || busy}
|
||||
onClick={upload}
|
||||
>
|
||||
{busy ? "Subiendo…" : "Subir"}
|
||||
</button>
|
||||
</div>
|
||||
<div className="section-note" style={{ padding: "0 22px 18px" }}>
|
||||
Los archivos se almacenan en el object storage (storageKey); no se
|
||||
descargan desde esta vista.
|
||||
</div>
|
||||
</>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
</section>
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
"use client";
|
||||
|
||||
import { Suspense } from "react";
|
||||
import Link from "next/link";
|
||||
import { useSearchParams } from "next/navigation";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { PolicyForm } from "@/components/PolicyForm";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
|
||||
export default function NuevaPolizaPage() {
|
||||
return (
|
||||
<AppShell>
|
||||
<Suspense fallback={null}>
|
||||
<NuevaPoliza />
|
||||
</Suspense>
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
function NuevaPoliza() {
|
||||
const allowed = useCan("policy:create");
|
||||
const params = useSearchParams();
|
||||
const customerId = params.get("customerId") ?? undefined;
|
||||
const customerName = params.get("customerName") ?? undefined;
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<Link href="/polizas" className="back-link">← Pólizas</Link>
|
||||
<h1 className="page-title">Nueva póliza</h1>
|
||||
</div>
|
||||
{allowed ? (
|
||||
<PolicyForm fixedCustomerId={customerId} fixedCustomerName={customerName} />
|
||||
) : (
|
||||
<div className="state-box state-error">
|
||||
No tiene permisos para crear pólizas.
|
||||
</div>
|
||||
)}
|
||||
</>
|
||||
);
|
||||
}
|
||||
@@ -3,6 +3,8 @@
|
||||
import { useCallback, useEffect, useRef, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { ContextReports } from "@/components/ContextReports";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import {
|
||||
EXPIRY_WINDOW_DAYS,
|
||||
getPolicyFacets,
|
||||
@@ -54,6 +56,7 @@ export default function PolizasPage() {
|
||||
}
|
||||
|
||||
function PolizasBrowser() {
|
||||
const canCreate = useCan("policy:create");
|
||||
const [stats, setStats] = useState<PolicyStats | null>(null);
|
||||
const [facets, setFacets] = useState<PolicyFacets | null>(null);
|
||||
|
||||
@@ -122,7 +125,20 @@ function PolizasBrowser() {
|
||||
<>
|
||||
<div className="page-head rise">
|
||||
<p className="eyebrow">Cartera de seguros</p>
|
||||
<h1 className="page-title">Pólizas</h1>
|
||||
<div style={{ display: "flex", alignItems: "center", gap: 16 }}>
|
||||
<h1 className="page-title" style={{ margin: 0 }}>Pólizas</h1>
|
||||
<span style={{ flex: 1 }} />
|
||||
<ContextReports
|
||||
entries={[
|
||||
{ slug: "vigente", label: "Por vencer (Lic.)", params: { typeName: "LICENCIAS" } },
|
||||
{ slug: "vigente", label: "Por vencer (Mult.)", params: { typeName: "MULT" } },
|
||||
{ slug: "vigente", label: "Por vencer (Incen.)", params: { typeName: "INCEN" } },
|
||||
]}
|
||||
/>
|
||||
{canCreate && (
|
||||
<Link href="/polizas/nuevo" className="btn btn-primary">+ Nueva póliza</Link>
|
||||
)}
|
||||
</div>
|
||||
<StatStrip
|
||||
stats={stats}
|
||||
status={status}
|
||||
|
||||
@@ -0,0 +1,110 @@
|
||||
"use client";
|
||||
|
||||
import Link from "next/link";
|
||||
import { useEffect, useState } from "react";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { ReportRunner } from "@/components/ReportRunner";
|
||||
import { getReportCatalog } from "@/lib/api";
|
||||
import type { ReportDef } from "@/lib/types";
|
||||
|
||||
/**
|
||||
* /reportes/[slug] — one report's runner page. The whole page is
|
||||
* data-driven from the catalog; if a slug isn't in the registry the
|
||||
* page shows a "not found" inline message.
|
||||
*/
|
||||
export default function ReporteRunnerPage({
|
||||
params,
|
||||
searchParams,
|
||||
}: {
|
||||
params: { slug: string };
|
||||
searchParams?: Record<string, string | string[] | undefined>;
|
||||
}) {
|
||||
return (
|
||||
<AppShell>
|
||||
<Runner slug={params.slug} searchParams={searchParams} />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
function Runner({
|
||||
slug,
|
||||
searchParams,
|
||||
}: {
|
||||
slug: string;
|
||||
searchParams?: Record<string, string | string[] | undefined>;
|
||||
}) {
|
||||
const [def, setDef] = useState<ReportDef | null>(null);
|
||||
const [missing, setMissing] = useState(false);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
useEffect(() => {
|
||||
getReportCatalog()
|
||||
.then((c) => {
|
||||
const found = c.items.find((r) => r.slug === slug);
|
||||
if (found) setDef(found);
|
||||
else setMissing(true);
|
||||
})
|
||||
.catch((e) => setError(e?.message ?? "No se pudo cargar el reporte."));
|
||||
}, [slug]);
|
||||
|
||||
if (error) {
|
||||
return (
|
||||
<>
|
||||
<BackLink />
|
||||
<div className="report-error">{error}</div>
|
||||
</>
|
||||
);
|
||||
}
|
||||
if (missing) {
|
||||
return (
|
||||
<>
|
||||
<BackLink />
|
||||
<div className="empty-inline">Reporte "{slug}" no encontrado.</div>
|
||||
</>
|
||||
);
|
||||
}
|
||||
if (!def) {
|
||||
return (
|
||||
<>
|
||||
<BackLink />
|
||||
<div className="empty-inline">Cargando reporte…</div>
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
const initialParams: Record<string, string> = {};
|
||||
if (searchParams) {
|
||||
const allowed = new Set(def.params.map((p) => p.key));
|
||||
for (const [k, v] of Object.entries(searchParams)) {
|
||||
if (!allowed.has(k)) continue;
|
||||
const s = Array.isArray(v) ? v[0] : v;
|
||||
if (s) initialParams[k] = s;
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head rise">
|
||||
<p className="eyebrow">Reportes</p>
|
||||
<h1 className="page-title">{def.title}</h1>
|
||||
<p className="muted" style={{ marginTop: 6, maxWidth: 720 }}>
|
||||
{def.description}
|
||||
</p>
|
||||
{def.legacyName && (
|
||||
<p className="muted small" style={{ marginTop: 4 }}>
|
||||
Equivalente en Access: <code>{def.legacyName}</code>
|
||||
</p>
|
||||
)}
|
||||
</div>
|
||||
<ReportRunner def={def} initialParams={initialParams} />
|
||||
</>
|
||||
);
|
||||
}
|
||||
|
||||
function BackLink() {
|
||||
return (
|
||||
<Link href="/reportes" className="back-link">
|
||||
← Reportes
|
||||
</Link>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,100 @@
|
||||
"use client";
|
||||
|
||||
import Link from "next/link";
|
||||
import { useEffect, useState } from "react";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { getReportCatalog } from "@/lib/api";
|
||||
import type { ReportCatalog, ReportDef, ReportDomain } from "@/lib/types";
|
||||
|
||||
/**
|
||||
* The /reportes catalog. Index of every registered report, grouped by
|
||||
* domain (matches the main nav). Discovery layer for the 280+ reports
|
||||
* the system will eventually surface; for now we ship 6 in v1.
|
||||
*/
|
||||
export default function ReportesPage() {
|
||||
return (
|
||||
<AppShell>
|
||||
<ReportesCatalog />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
const DOMAIN_LABEL: Record<ReportDomain, string> = {
|
||||
clientes: "Clientes",
|
||||
polizas: "Pólizas",
|
||||
servicios: "Servicios",
|
||||
"estado-cuenta": "Estado de cuenta",
|
||||
chequera: "Chequera",
|
||||
};
|
||||
|
||||
const DOMAIN_ORDER: ReportDomain[] = [
|
||||
"clientes",
|
||||
"estado-cuenta",
|
||||
"polizas",
|
||||
"servicios",
|
||||
"chequera",
|
||||
];
|
||||
|
||||
function ReportesCatalog() {
|
||||
const [catalog, setCatalog] = useState<ReportCatalog | null>(null);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
useEffect(() => {
|
||||
getReportCatalog()
|
||||
.then(setCatalog)
|
||||
.catch((e) => setError(e?.message ?? "No se pudo cargar el catálogo."));
|
||||
}, []);
|
||||
|
||||
const grouped = new Map<ReportDomain, ReportDef[]>();
|
||||
if (catalog) {
|
||||
for (const r of catalog.items) {
|
||||
const list = grouped.get(r.domain) ?? [];
|
||||
list.push(r);
|
||||
grouped.set(r.domain, list);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head rise">
|
||||
<p className="eyebrow">Reportes</p>
|
||||
<h1 className="page-title">Catálogo de reportes</h1>
|
||||
<p className="muted" style={{ marginTop: 6, maxWidth: 640 }}>
|
||||
{catalog
|
||||
? `${catalog.items.length} reportes disponibles. Cada uno corre como consulta sobre el esquema actual — los filtros y totales se recalculan en vivo.`
|
||||
: "Cargando…"}
|
||||
</p>
|
||||
</div>
|
||||
|
||||
{error && <div className="report-error">{error}</div>}
|
||||
|
||||
<div className="report-catalog">
|
||||
{DOMAIN_ORDER.filter((d) => grouped.has(d)).map((d) => (
|
||||
<section key={d} className="report-catalog-group">
|
||||
<h2 className="report-catalog-title">{DOMAIN_LABEL[d]}</h2>
|
||||
<ul className="report-catalog-list">
|
||||
{(grouped.get(d) ?? []).map((r) => (
|
||||
<li key={r.slug} className="report-catalog-item">
|
||||
<Link href={`/reportes/${r.slug}`} className="report-catalog-link">
|
||||
<div className="report-catalog-item-title">{r.title}</div>
|
||||
<div className="report-catalog-item-desc">{r.description}</div>
|
||||
<div className="report-catalog-item-meta">
|
||||
{r.legacyName && (
|
||||
<span className="report-catalog-tag">
|
||||
Legacy: {r.legacyName}
|
||||
</span>
|
||||
)}
|
||||
<span className="report-catalog-tag muted">
|
||||
{r.format === "statement" ? "Estado de cuenta" : "Tabular"}
|
||||
</span>
|
||||
</div>
|
||||
</Link>
|
||||
</li>
|
||||
))}
|
||||
</ul>
|
||||
</section>
|
||||
))}
|
||||
</div>
|
||||
</>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,54 @@
|
||||
"use client";
|
||||
|
||||
import { useEffect, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { PropertyForm } from "@/components/PropertyForm";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import { getProperty } from "@/lib/api";
|
||||
import type { PropertyDetail } from "@/lib/types";
|
||||
|
||||
export default function EditarPropiedadPage({
|
||||
params,
|
||||
}: {
|
||||
params: { id: string };
|
||||
}) {
|
||||
return (
|
||||
<AppShell>
|
||||
<EditarPropiedad id={params.id} />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
function EditarPropiedad({ id }: { id: string }) {
|
||||
const allowed = useCan("property:update");
|
||||
const [property, setProperty] = useState<PropertyDetail | null>(null);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
useEffect(() => {
|
||||
if (!allowed) return;
|
||||
getProperty(id)
|
||||
.then(setProperty)
|
||||
.catch((e) => setError(e?.message ?? "No se pudo cargar la propiedad."));
|
||||
}, [id, allowed]);
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<Link href={`/servicios/${id}`} className="back-link">← Propiedad</Link>
|
||||
<h1 className="page-title">Editar propiedad</h1>
|
||||
</div>
|
||||
{!allowed ? (
|
||||
<div className="state-box state-error">
|
||||
No tiene permisos para editar propiedades.
|
||||
</div>
|
||||
) : error ? (
|
||||
<div className="state-box state-error">{error}</div>
|
||||
) : !property ? (
|
||||
<div className="empty-inline"><span className="spinner" aria-label="Cargando" /></div>
|
||||
) : (
|
||||
<PropertyForm property={property} />
|
||||
)}
|
||||
</>
|
||||
);
|
||||
}
|
||||
@@ -3,19 +3,34 @@
|
||||
import { useEffect, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { getProperty } from "@/lib/api";
|
||||
import {
|
||||
addService,
|
||||
archiveProperty,
|
||||
getProperty,
|
||||
propertyDocumentDownloadUrl,
|
||||
removePropertyDocument,
|
||||
removeService,
|
||||
removeTrust,
|
||||
restoreProperty,
|
||||
updateService,
|
||||
uploadPropertyDocument,
|
||||
upsertTrust,
|
||||
} from "@/lib/api";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import { ChildCollection, type ChildConfig } from "@/components/ChildCollection";
|
||||
import {
|
||||
expiryPhrase,
|
||||
formatDate,
|
||||
formatMoney,
|
||||
formatNumber,
|
||||
SERVICE_KIND_LABELS,
|
||||
serviceKindGlyph,
|
||||
serviceKindLabel,
|
||||
serviceNoteLabel,
|
||||
SIN_NOMBRE,
|
||||
trustStatusLabel,
|
||||
} from "@/lib/labels";
|
||||
import type { PropertyDetail, Service, Transaction } from "@/lib/types";
|
||||
import type { PropertyDetail, Service, Transaction, TrustInput } from "@/lib/types";
|
||||
|
||||
export default function PropiedadDetailPage({
|
||||
params,
|
||||
@@ -76,9 +91,14 @@ function Detail({ id }: { id: string }) {
|
||||
|
||||
if (!data) return null;
|
||||
|
||||
const reload = () => getProperty(id).then(setData).catch(() => {});
|
||||
|
||||
return (
|
||||
<div className="rise">
|
||||
<BackLink />
|
||||
<div className="detail-actionbar">
|
||||
<BackLink />
|
||||
<PropertyActions data={data} onChange={reload} />
|
||||
</div>
|
||||
<Hero data={data} />
|
||||
<ClienteSection data={data} />
|
||||
<ServiciosSection data={data} />
|
||||
@@ -86,10 +106,306 @@ function Detail({ id }: { id: string }) {
|
||||
{data.policy && <PolizaSection data={data} />}
|
||||
<MovimientosSection data={data} />
|
||||
<DocumentosSection data={data} />
|
||||
<PropertyEditor data={data} onChange={reload} />
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
/** Edit / archive controls for the property header. */
|
||||
function PropertyActions({
|
||||
data,
|
||||
onChange,
|
||||
}: {
|
||||
data: PropertyDetail;
|
||||
onChange: () => void;
|
||||
}) {
|
||||
const canEdit = useCan("property:update");
|
||||
const canDelete = useCan("property:delete");
|
||||
const [busy, setBusy] = useState(false);
|
||||
const archived = data.archivedAt != null;
|
||||
|
||||
async function toggle() {
|
||||
const verb = archived ? "restaurar" : "archivar";
|
||||
if (!window.confirm(`¿Seguro que desea ${verb} esta propiedad?`)) return;
|
||||
setBusy(true);
|
||||
try {
|
||||
if (archived) await restoreProperty(data.id);
|
||||
else await archiveProperty(data.id);
|
||||
onChange();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo completar la acción.");
|
||||
} finally {
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
if (!canEdit && !canDelete) return null;
|
||||
return (
|
||||
<div className="row-actions">
|
||||
{archived && <span className="badge badge-negative">Archivada</span>}
|
||||
{canEdit && (
|
||||
<Link href={`/servicios/${data.id}/editar`} className="btn btn-outline">
|
||||
Editar
|
||||
</Link>
|
||||
)}
|
||||
{canDelete && (
|
||||
<button type="button" className="btn btn-ghost" onClick={toggle} disabled={busy}>
|
||||
{archived ? "Restaurar" : "Archivar"}
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
/** Editable services + trust + documents — only for users who can edit. */
|
||||
function PropertyEditor({
|
||||
data,
|
||||
onChange,
|
||||
}: {
|
||||
data: PropertyDetail;
|
||||
onChange: () => void;
|
||||
}) {
|
||||
const canEdit = useCan("property:update");
|
||||
if (!canEdit) return null;
|
||||
|
||||
const SERVICES: ChildConfig = {
|
||||
apiKind: "services",
|
||||
title: "Servicios",
|
||||
fields: [
|
||||
{
|
||||
key: "kind",
|
||||
label: "Tipo",
|
||||
type: "select",
|
||||
options: Object.entries(SERVICE_KIND_LABELS).map(([value, label]) => ({
|
||||
value,
|
||||
label,
|
||||
})),
|
||||
},
|
||||
{ key: "accountNumber", label: "Cuenta" },
|
||||
{ key: "meterNumber", label: "Medidor" },
|
||||
{ key: "route", label: "Ruta" },
|
||||
{ key: "dueDay", label: "Día pago" },
|
||||
{ key: "notes", label: "Notas" },
|
||||
{ key: "active", label: "Activo", type: "checkbox" },
|
||||
],
|
||||
};
|
||||
|
||||
return (
|
||||
<section className="section">
|
||||
<div className="section-head">
|
||||
<span className="section-rule cuenta" aria-hidden />
|
||||
<h2 className="section-title">Administrar propiedad</h2>
|
||||
</div>
|
||||
|
||||
<ChildCollection
|
||||
config={SERVICES}
|
||||
rows={data.services as unknown as Record<string, unknown>[]}
|
||||
canEdit={canEdit}
|
||||
onAdd={async (p) => { await addService(data.id, p as never); onChange(); }}
|
||||
onSave={async (sid, p) => { await updateService(data.id, sid, p as never); onChange(); }}
|
||||
onRemove={async (sid) => { await removeService(data.id, sid); onChange(); }}
|
||||
/>
|
||||
|
||||
<TrustEditor data={data} onChange={onChange} />
|
||||
|
||||
<DocumentsEditor data={data} onChange={onChange} />
|
||||
</section>
|
||||
);
|
||||
}
|
||||
|
||||
/** Upload / download / delete document blobs stored in object storage (MinIO). */
|
||||
function DocumentsEditor({
|
||||
data,
|
||||
onChange,
|
||||
}: {
|
||||
data: PropertyDetail;
|
||||
onChange: () => void;
|
||||
}) {
|
||||
const [file, setFile] = useState<File | null>(null);
|
||||
const [type, setType] = useState("");
|
||||
const [busy, setBusy] = useState(false);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
async function upload() {
|
||||
if (!file) return;
|
||||
setBusy(true);
|
||||
setError(null);
|
||||
try {
|
||||
await uploadPropertyDocument(data.id, file, type.trim() || undefined);
|
||||
setFile(null);
|
||||
setType("");
|
||||
onChange();
|
||||
} catch (e) {
|
||||
setError((e as Error)?.message ?? "No se pudo subir el archivo.");
|
||||
} finally {
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="card" style={{ padding: 16 }}>
|
||||
<h3 className="section-title" style={{ marginTop: 0 }}>Documentos</h3>
|
||||
{data.documents.length > 0 && (
|
||||
<div className="tx-scroll">
|
||||
<table className="tx-table">
|
||||
<thead>
|
||||
<tr><th>Tipo</th><th>Clave</th><th className="num">Acción</th></tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{data.documents.map((d) => (
|
||||
<tr key={d.id ?? d.storageKey}>
|
||||
<td>{d.documentType ?? "—"}</td>
|
||||
<td className="mono">{d.storageKey ?? "—"}</td>
|
||||
<td>
|
||||
<div className="row-actions">
|
||||
{d.id && (
|
||||
<a
|
||||
className="btn btn-ghost"
|
||||
href={propertyDocumentDownloadUrl(data.id, d.id)}
|
||||
>
|
||||
Descargar
|
||||
</a>
|
||||
)}
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
onClick={async () => {
|
||||
if (!d.id) return;
|
||||
if (!window.confirm("¿Eliminar este documento?")) return;
|
||||
try {
|
||||
await removePropertyDocument(data.id, d.id);
|
||||
onChange();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo eliminar.");
|
||||
}
|
||||
}}
|
||||
>
|
||||
Eliminar
|
||||
</button>
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
)}
|
||||
{error && <div className="state-box state-error" style={{ marginTop: 12 }}>{error}</div>}
|
||||
<div className="inline-form" style={{ marginTop: 12 }}>
|
||||
<input
|
||||
className="input"
|
||||
placeholder="Tipo (ej. RECIBO)"
|
||||
value={type}
|
||||
onChange={(e) => setType(e.target.value)}
|
||||
/>
|
||||
<input
|
||||
type="file"
|
||||
className="input"
|
||||
onChange={(e) => setFile(e.target.files?.[0] ?? null)}
|
||||
/>
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-primary"
|
||||
disabled={!file || busy}
|
||||
onClick={upload}
|
||||
>
|
||||
{busy ? "Subiendo…" : "Subir"}
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
/** Trust is 1:1 — a small inline form that upserts or clears it. */
|
||||
function TrustEditor({
|
||||
data,
|
||||
onChange,
|
||||
}: {
|
||||
data: PropertyDetail;
|
||||
onChange: () => void;
|
||||
}) {
|
||||
const t = data.trustAccount;
|
||||
const [bankName, setBankName] = useState(t?.bankName ?? "");
|
||||
const [trustNumber, setTrustNumber] = useState(t?.trustNumber ?? "");
|
||||
const [bankFee, setBankFee] = useState(t?.bankFee != null ? String(t.bankFee) : "");
|
||||
const [dueDate1, setDueDate1] = useState(toDateInput(t?.dueDate1));
|
||||
const [dueDate2, setDueDate2] = useState(toDateInput(t?.dueDate2));
|
||||
const [busy, setBusy] = useState(false);
|
||||
|
||||
async function save() {
|
||||
setBusy(true);
|
||||
const input: TrustInput = {
|
||||
bankName: bankName.trim() || undefined,
|
||||
trustNumber: trustNumber.trim() || undefined,
|
||||
bankFee: bankFee.trim() === "" ? undefined : Number(bankFee),
|
||||
dueDate1: dueDate1 || undefined,
|
||||
dueDate2: dueDate2 || undefined,
|
||||
};
|
||||
try {
|
||||
await upsertTrust(data.id, input);
|
||||
onChange();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo guardar el fideicomiso.");
|
||||
} finally {
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
async function clear() {
|
||||
if (!window.confirm("¿Eliminar el fideicomiso de esta propiedad?")) return;
|
||||
try {
|
||||
await removeTrust(data.id);
|
||||
onChange();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo eliminar.");
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="card" style={{ padding: 16, marginBottom: 14 }}>
|
||||
<h3 className="section-title" style={{ marginTop: 0 }}>Fideicomiso</h3>
|
||||
<div className="form-grid">
|
||||
<label className="field">
|
||||
<span className="field-label">Banco</span>
|
||||
<input className="input" value={bankName} onChange={(e) => setBankName(e.target.value)} />
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">No. fideicomiso</span>
|
||||
<input className="input" value={trustNumber} onChange={(e) => setTrustNumber(e.target.value)} />
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Cuota banco</span>
|
||||
<input className="input" type="number" step="0.01" value={bankFee} onChange={(e) => setBankFee(e.target.value)} />
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Vence 1</span>
|
||||
<input className="input" type="date" value={dueDate1} onChange={(e) => setDueDate1(e.target.value)} />
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Vence 2 (próxima)</span>
|
||||
<input className="input" type="date" value={dueDate2} onChange={(e) => setDueDate2(e.target.value)} />
|
||||
</label>
|
||||
</div>
|
||||
<div className="form-actions">
|
||||
<button type="button" className="btn btn-primary" onClick={save} disabled={busy}>
|
||||
{busy ? "Guardando…" : t ? "Guardar fideicomiso" : "Crear fideicomiso"}
|
||||
</button>
|
||||
{t && (
|
||||
<button type="button" className="btn btn-ghost" onClick={clear}>
|
||||
Eliminar
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
function toDateInput(v: string | null | undefined): string {
|
||||
if (!v) return "";
|
||||
const d = new Date(v);
|
||||
return isNaN(d.getTime()) ? "" : d.toISOString().slice(0, 10);
|
||||
}
|
||||
|
||||
function BackLink() {
|
||||
return (
|
||||
<Link href="/servicios" className="back-link">
|
||||
@@ -490,17 +806,21 @@ function DocumentosSection({ data }: { data: PropertyDetail }) {
|
||||
<span className="doc-icon" aria-hidden>
|
||||
▤
|
||||
</span>
|
||||
<div style={{ minWidth: 0 }}>
|
||||
<div style={{ minWidth: 0, flex: 1 }}>
|
||||
<div className="doc-type">{d.documentType || "Documento"}</div>
|
||||
<div className="doc-key">{d.storageKey || "—"}</div>
|
||||
</div>
|
||||
{d.id && (
|
||||
<a
|
||||
className="btn btn-ghost"
|
||||
href={propertyDocumentDownloadUrl(data.id, d.id)}
|
||||
>
|
||||
Descargar
|
||||
</a>
|
||||
)}
|
||||
</div>
|
||||
))}
|
||||
</div>
|
||||
<div className="section-note" style={{ padding: "0 22px 18px" }}>
|
||||
Los archivos se almacenan en el object storage (storageKey); no se
|
||||
descargan desde esta vista.
|
||||
</div>
|
||||
</>
|
||||
)}
|
||||
</div>
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
"use client";
|
||||
|
||||
import { Suspense } from "react";
|
||||
import Link from "next/link";
|
||||
import { useSearchParams } from "next/navigation";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { PropertyForm } from "@/components/PropertyForm";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
|
||||
export default function NuevaPropiedadPage() {
|
||||
return (
|
||||
<AppShell>
|
||||
<Suspense fallback={null}>
|
||||
<NuevaPropiedad />
|
||||
</Suspense>
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
function NuevaPropiedad() {
|
||||
const allowed = useCan("property:create");
|
||||
const params = useSearchParams();
|
||||
const customerId = params.get("customerId") ?? undefined;
|
||||
const customerName = params.get("customerName") ?? undefined;
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<Link href="/servicios" className="back-link">← Propiedades</Link>
|
||||
<h1 className="page-title">Nueva propiedad</h1>
|
||||
</div>
|
||||
{allowed ? (
|
||||
<PropertyForm fixedCustomerId={customerId} fixedCustomerName={customerName} />
|
||||
) : (
|
||||
<div className="state-box state-error">
|
||||
No tiene permisos para crear propiedades.
|
||||
</div>
|
||||
)}
|
||||
</>
|
||||
);
|
||||
}
|
||||
@@ -3,6 +3,8 @@
|
||||
import { useCallback, useEffect, useRef, useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { ContextReports } from "@/components/ContextReports";
|
||||
import { useCan } from "@/lib/abilities";
|
||||
import {
|
||||
EXPIRY_WINDOW_DAYS,
|
||||
getPropertyFacets,
|
||||
@@ -81,6 +83,7 @@ export default function ServiciosPage() {
|
||||
}
|
||||
|
||||
function ServiciosBrowser() {
|
||||
const canCreate = useCan("property:create");
|
||||
const [stats, setStats] = useState<PropertyStats | null>(null);
|
||||
const [facets, setFacets] = useState<PropertyFacets | null>(null);
|
||||
|
||||
@@ -164,7 +167,20 @@ function ServiciosBrowser() {
|
||||
<>
|
||||
<div className="page-head rise">
|
||||
<p className="eyebrow">Administración de servicios</p>
|
||||
<h1 className="page-title">Propiedades</h1>
|
||||
<div style={{ display: "flex", alignItems: "center", gap: 16 }}>
|
||||
<h1 className="page-title" style={{ margin: 0 }}>Propiedades</h1>
|
||||
<span style={{ flex: 1 }} />
|
||||
<ContextReports
|
||||
entries={[
|
||||
{ slug: "faltantes", label: "Faltantes agua", params: { serviceKind: "WATER" } },
|
||||
{ slug: "faltantes", label: "Faltantes luz", params: { serviceKind: "ELECTRICITY" } },
|
||||
{ slug: "faltantes", label: "Faltantes tel.", params: { serviceKind: "PHONE" } },
|
||||
]}
|
||||
/>
|
||||
{canCreate && (
|
||||
<Link href="/servicios/nuevo" className="btn btn-primary">+ Nueva propiedad</Link>
|
||||
)}
|
||||
</div>
|
||||
<StatStrip stats={stats} focus={focus} onPickFocus={pickFocus} />
|
||||
<ServiceMixStrip
|
||||
stats={stats}
|
||||
|
||||
@@ -0,0 +1,357 @@
|
||||
"use client";
|
||||
|
||||
import { useEffect, useState } from "react";
|
||||
import { AppShell } from "@/components/AppShell";
|
||||
import { useAuth, useCan } from "@/lib/abilities";
|
||||
import { ROLE_LABEL, ROLES_DESC } from "@/lib/labels";
|
||||
import {
|
||||
createUser,
|
||||
deleteUser,
|
||||
listUsers,
|
||||
resetUserPassword,
|
||||
updateUser,
|
||||
} from "@/lib/api";
|
||||
import type { Role, UserRow } from "@/lib/types";
|
||||
|
||||
export default function UsuariosPage() {
|
||||
return (
|
||||
<AppShell>
|
||||
<UsuariosAdmin />
|
||||
</AppShell>
|
||||
);
|
||||
}
|
||||
|
||||
type FormState = {
|
||||
name: string;
|
||||
email: string;
|
||||
password: string;
|
||||
role: Role;
|
||||
active: boolean;
|
||||
};
|
||||
|
||||
const EMPTY_FORM: FormState = {
|
||||
name: "",
|
||||
email: "",
|
||||
password: "",
|
||||
role: "STAFF",
|
||||
active: true,
|
||||
};
|
||||
|
||||
function UsuariosAdmin() {
|
||||
const me = useAuth();
|
||||
const allowed = useCan("user:manage");
|
||||
|
||||
const [users, setUsers] = useState<UserRow[] | null>(null);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [notice, setNotice] = useState<string | null>(null);
|
||||
|
||||
// null = create mode; a user id = editing that row.
|
||||
const [editingId, setEditingId] = useState<string | null>(null);
|
||||
const [form, setForm] = useState<FormState>(EMPTY_FORM);
|
||||
const [saving, setSaving] = useState(false);
|
||||
|
||||
// Inline "reset password" target + value.
|
||||
const [pwTarget, setPwTarget] = useState<string | null>(null);
|
||||
const [pwValue, setPwValue] = useState("");
|
||||
|
||||
function refresh() {
|
||||
listUsers()
|
||||
.then(setUsers)
|
||||
.catch((e) => setError(e?.message ?? "No se pudieron cargar los usuarios."));
|
||||
}
|
||||
|
||||
useEffect(() => {
|
||||
if (allowed) refresh();
|
||||
}, [allowed]);
|
||||
|
||||
if (!allowed) {
|
||||
return (
|
||||
<div className="page-head">
|
||||
<h1 className="page-title">Usuarios</h1>
|
||||
<div className="state-box state-error">
|
||||
No tiene permisos para administrar usuarios.
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
function startCreate() {
|
||||
setEditingId(null);
|
||||
setForm(EMPTY_FORM);
|
||||
setNotice(null);
|
||||
setError(null);
|
||||
}
|
||||
|
||||
function startEdit(u: UserRow) {
|
||||
setEditingId(u.id);
|
||||
setForm({ name: u.name, email: u.email, password: "", role: u.role, active: u.active });
|
||||
setNotice(null);
|
||||
setError(null);
|
||||
}
|
||||
|
||||
async function submit(e: React.FormEvent) {
|
||||
e.preventDefault();
|
||||
setSaving(true);
|
||||
setError(null);
|
||||
setNotice(null);
|
||||
try {
|
||||
if (editingId) {
|
||||
await updateUser(editingId, {
|
||||
name: form.name,
|
||||
email: form.email,
|
||||
role: form.role,
|
||||
active: form.active,
|
||||
});
|
||||
setNotice("Usuario actualizado.");
|
||||
} else {
|
||||
await createUser({
|
||||
name: form.name,
|
||||
email: form.email,
|
||||
password: form.password,
|
||||
role: form.role,
|
||||
active: form.active,
|
||||
});
|
||||
setNotice("Usuario creado.");
|
||||
}
|
||||
startCreate();
|
||||
refresh();
|
||||
} catch (e2) {
|
||||
setError((e2 as Error)?.message ?? "No se pudo guardar el usuario.");
|
||||
} finally {
|
||||
setSaving(false);
|
||||
}
|
||||
}
|
||||
|
||||
async function submitPassword(id: string) {
|
||||
setError(null);
|
||||
try {
|
||||
await resetUserPassword(id, pwValue);
|
||||
setPwTarget(null);
|
||||
setPwValue("");
|
||||
setNotice("Contraseña restablecida.");
|
||||
} catch (e) {
|
||||
setError((e as Error)?.message ?? "No se pudo restablecer la contraseña.");
|
||||
}
|
||||
}
|
||||
|
||||
async function submitDelete(u: UserRow) {
|
||||
if (!window.confirm(`¿Eliminar al usuario "${u.name}"? Esta acción no se puede deshacer.`)) {
|
||||
return;
|
||||
}
|
||||
setError(null);
|
||||
setNotice(null);
|
||||
try {
|
||||
await deleteUser(u.id);
|
||||
if (editingId === u.id) startCreate();
|
||||
setNotice("Usuario eliminado.");
|
||||
refresh();
|
||||
} catch (e) {
|
||||
setError((e as Error)?.message ?? "No se pudo eliminar el usuario.");
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
<h1 className="page-title">Usuarios</h1>
|
||||
</div>
|
||||
|
||||
{error && <div className="state-box state-error">{error}</div>}
|
||||
{notice && <div className="state-box">{notice}</div>}
|
||||
|
||||
{/* Create / edit form */}
|
||||
<div className="card" style={{ padding: 20, marginBottom: 20 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 4 }}>
|
||||
{editingId ? "Editar usuario" : "Nuevo usuario"}
|
||||
</h2>
|
||||
<p className="inline-form-note">
|
||||
El rol define el acceso: Solo lectura no puede escribir; Personal y
|
||||
superior sí. Administrador gestiona usuarios.
|
||||
</p>
|
||||
<form onSubmit={submit}>
|
||||
<div className="form-grid">
|
||||
<label className="field">
|
||||
<span className="field-label">Nombre</span>
|
||||
<input
|
||||
className="input"
|
||||
required
|
||||
value={form.name}
|
||||
onChange={(e) => setForm({ ...form, name: e.target.value })}
|
||||
/>
|
||||
</label>
|
||||
<label className="field">
|
||||
<span className="field-label">Correo</span>
|
||||
<input
|
||||
className="input"
|
||||
type="email"
|
||||
required
|
||||
value={form.email}
|
||||
onChange={(e) => setForm({ ...form, email: e.target.value })}
|
||||
/>
|
||||
</label>
|
||||
{!editingId && (
|
||||
<label className="field">
|
||||
<span className="field-label">Contraseña (mín. 8)</span>
|
||||
<input
|
||||
className="input"
|
||||
type="password"
|
||||
required
|
||||
minLength={8}
|
||||
value={form.password}
|
||||
onChange={(e) => setForm({ ...form, password: e.target.value })}
|
||||
/>
|
||||
</label>
|
||||
)}
|
||||
<label className="field">
|
||||
<span className="field-label">Rol</span>
|
||||
<select
|
||||
className="select"
|
||||
value={form.role}
|
||||
onChange={(e) => setForm({ ...form, role: e.target.value as Role })}
|
||||
>
|
||||
{ROLES_DESC.map((r) => (
|
||||
<option key={r} value={r}>
|
||||
{ROLE_LABEL[r]}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
</label>
|
||||
<label className="field" style={{ justifyContent: "flex-end" }}>
|
||||
<span className="field-label">Activo</span>
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={form.active}
|
||||
disabled={editingId === me?.id}
|
||||
onChange={(e) => setForm({ ...form, active: e.target.checked })}
|
||||
/>
|
||||
</label>
|
||||
</div>
|
||||
<div className="form-actions">
|
||||
<button type="submit" className="btn btn-primary" disabled={saving}>
|
||||
{saving ? "Guardando…" : editingId ? "Guardar cambios" : "Crear usuario"}
|
||||
</button>
|
||||
{editingId && (
|
||||
<button type="button" className="btn btn-outline" onClick={startCreate}>
|
||||
Cancelar
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
</form>
|
||||
</div>
|
||||
|
||||
{/* List */}
|
||||
<div className="card">
|
||||
{users === null ? (
|
||||
<div className="empty-inline">
|
||||
<span className="spinner" aria-label="Cargando" />
|
||||
</div>
|
||||
) : users.length === 0 ? (
|
||||
<div className="empty-inline">Sin usuarios.</div>
|
||||
) : (
|
||||
<div className="tx-scroll">
|
||||
<table className="tx-table">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Nombre</th>
|
||||
<th>Correo</th>
|
||||
<th>Rol</th>
|
||||
<th>Estado</th>
|
||||
<th className="num">Acciones</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{users.map((u) => (
|
||||
<tr key={u.id}>
|
||||
<td>
|
||||
{u.name}
|
||||
{u.id === me?.id && (
|
||||
<span className="muted"> (usted)</span>
|
||||
)}
|
||||
</td>
|
||||
<td className="mono">{u.email}</td>
|
||||
<td>
|
||||
<span className="badge badge-neutral">{ROLE_LABEL[u.role]}</span>
|
||||
</td>
|
||||
<td>
|
||||
<span
|
||||
className={`badge ${u.active ? "badge-positive" : "badge-negative"}`}
|
||||
>
|
||||
{u.active ? "Activo" : "Inactivo"}
|
||||
</span>
|
||||
</td>
|
||||
<td>
|
||||
{pwTarget === u.id ? (
|
||||
<div className="row-actions">
|
||||
<input
|
||||
className="input"
|
||||
type="password"
|
||||
placeholder="Nueva contraseña"
|
||||
minLength={8}
|
||||
value={pwValue}
|
||||
onChange={(e) => setPwValue(e.target.value)}
|
||||
style={{ maxWidth: 180 }}
|
||||
/>
|
||||
<button
|
||||
className="btn btn-primary"
|
||||
type="button"
|
||||
disabled={pwValue.length < 8}
|
||||
onClick={() => submitPassword(u.id)}
|
||||
>
|
||||
Guardar
|
||||
</button>
|
||||
<button
|
||||
className="btn btn-ghost"
|
||||
type="button"
|
||||
onClick={() => {
|
||||
setPwTarget(null);
|
||||
setPwValue("");
|
||||
}}
|
||||
>
|
||||
Cancelar
|
||||
</button>
|
||||
</div>
|
||||
) : (
|
||||
<div className="row-actions">
|
||||
<button
|
||||
className="btn btn-outline"
|
||||
type="button"
|
||||
onClick={() => startEdit(u)}
|
||||
>
|
||||
Editar
|
||||
</button>
|
||||
<button
|
||||
className="btn btn-ghost"
|
||||
type="button"
|
||||
onClick={() => {
|
||||
setPwTarget(u.id);
|
||||
setPwValue("");
|
||||
}}
|
||||
>
|
||||
Contraseña
|
||||
</button>
|
||||
<button
|
||||
className="btn btn-ghost btn-danger"
|
||||
type="button"
|
||||
disabled={u.id === me?.id}
|
||||
title={
|
||||
u.id === me?.id
|
||||
? "No puede eliminar su propia cuenta"
|
||||
: "Eliminar usuario"
|
||||
}
|
||||
onClick={() => submitDelete(u)}
|
||||
>
|
||||
Eliminar
|
||||
</button>
|
||||
</div>
|
||||
)}
|
||||
</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
</>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
import { NextResponse } from "next/server";
|
||||
import { readBuildInfoFromEnv } from "@/lib/build-info";
|
||||
|
||||
// Read per request, never prerendered — the whole point is to report what THIS
|
||||
// running container is, and a baked answer would defeat that.
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
/**
|
||||
* The web tier's counterpart to the API's GET /version.
|
||||
*
|
||||
* Without this, the only way to see what the web container is running was to
|
||||
* scrape window.__APP_BUILD__ out of the HTML. The deploy workflow compares the
|
||||
* two tiers' gitSha to catch a half-applied release, so it needs a stable,
|
||||
* parseable answer from both sides.
|
||||
*/
|
||||
export function GET() {
|
||||
return NextResponse.json({ service: "web", ...readBuildInfoFromEnv() });
|
||||
}
|
||||
@@ -1,39 +1,268 @@
|
||||
"use client";
|
||||
|
||||
import { useEffect, useState, type ReactNode } from "react";
|
||||
import { useEffect, useRef, useState, type ReactNode } from "react";
|
||||
import { usePathname, useRouter } from "next/navigation";
|
||||
import Link from "next/link";
|
||||
import { logout, me } from "@/lib/api";
|
||||
import type { AuthUser } from "@/lib/types";
|
||||
import { getApiVersion, logout, me, updateUiScale, type ServiceVersion } from "@/lib/api";
|
||||
import { webBuildInfo } from "@/lib/build-info";
|
||||
import { AuthContext, can } from "@/lib/abilities";
|
||||
import { ROLE_LABEL } from "@/lib/labels";
|
||||
import {
|
||||
DEFAULT_UI_SCALE,
|
||||
applyUiScale,
|
||||
normalizeUiScale,
|
||||
readUiScale,
|
||||
saveUiScale,
|
||||
} from "@/lib/ui-scale";
|
||||
import { FontScaleControl } from "./FontScaleControl";
|
||||
import type { AuthUser, Ability } from "@/lib/types";
|
||||
|
||||
/**
|
||||
* Authenticated shell: gates on /auth/me, redirects to /login when the
|
||||
* session is missing, renders the brand header + logout, and wraps page
|
||||
* content. Used by every authenticated page.
|
||||
* content. Provides the AuthContext so any page can read the user's
|
||||
* abilities. Used by every authenticated page.
|
||||
*/
|
||||
const NAV = [
|
||||
{ href: "/clientes", label: "Clientes" },
|
||||
{ href: "/servicios", label: "Propiedades" },
|
||||
{ href: "/polizas", label: "Pólizas" },
|
||||
{ href: "/estado-cuenta", label: "Estado de cuenta" },
|
||||
{ href: "/banco", label: "Chequera" },
|
||||
|
||||
type NavLink = { href: string; label: string; ability?: Ability; exact?: boolean };
|
||||
type NavEntry =
|
||||
| ({ kind: "link" } & NavLink)
|
||||
| { kind: "group"; label: string; items: NavLink[] };
|
||||
|
||||
/**
|
||||
* Top nav. Daily screens stay one click away; the movement screens and the
|
||||
* admin screens are grouped behind menus so the bar doesn't saturate as the
|
||||
* app grows. A group disappears entirely when the user can't see any of its
|
||||
* items (gating here is cosmetic — the API enforces every write).
|
||||
*/
|
||||
const NAV: NavEntry[] = [
|
||||
{ kind: "link", href: "/inicio", label: "Inicio", exact: true },
|
||||
{ kind: "link", href: "/clientes", label: "Clientes" },
|
||||
{ kind: "link", href: "/polizas", label: "Pólizas" },
|
||||
{ kind: "link", href: "/servicios", label: "Propiedades" },
|
||||
{
|
||||
kind: "group",
|
||||
label: "Cobranza",
|
||||
items: [
|
||||
// Daily data-entry screen (the legacy "Editor"). Hidden from VIEWER, who
|
||||
// can't capture anyway — the page itself also refuses.
|
||||
{ href: "/estado-cuenta/lote", label: "Captura", ability: "ledger:create" },
|
||||
{ href: "/estado-cuenta", label: "Estado de cuenta" },
|
||||
{ href: "/banco", label: "Chequera" },
|
||||
],
|
||||
},
|
||||
{ kind: "link", href: "/reportes", label: "Reportes" },
|
||||
{
|
||||
kind: "group",
|
||||
label: "Admin",
|
||||
items: [
|
||||
{ href: "/catalogos", label: "Catálogos", ability: "lookup:manage" },
|
||||
{
|
||||
href: "/banco/cuentas",
|
||||
label: "Cuentas de chequera",
|
||||
ability: "bank:manage-accounts",
|
||||
},
|
||||
{ href: "/usuarios", label: "Usuarios", ability: "user:manage" },
|
||||
{ href: "/operaciones", label: "Operaciones", ability: "db:manage" },
|
||||
],
|
||||
},
|
||||
];
|
||||
|
||||
/** Every nav destination, flattened out of the groups. */
|
||||
const NAV_LINKS: NavLink[] = NAV.flatMap((entry) =>
|
||||
entry.kind === "link" ? [entry] : entry.items,
|
||||
);
|
||||
|
||||
/** The nav the given user may see, with empty groups dropped. */
|
||||
function visibleNav(user: AuthUser | null): NavEntry[] {
|
||||
const allowed = (item: NavLink) => !item.ability || can(user, item.ability);
|
||||
const out: NavEntry[] = [];
|
||||
for (const entry of NAV) {
|
||||
if (entry.kind === "link") {
|
||||
if (allowed(entry)) out.push(entry);
|
||||
continue;
|
||||
}
|
||||
const items = entry.items.filter(allowed);
|
||||
if (items.length > 0) out.push({ ...entry, items });
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
/**
|
||||
* Which nav entry is highlighted for a path. Longest matching href wins, so a
|
||||
* nested route (`/estado-cuenta/lote`) highlights its own entry instead of also
|
||||
* lighting up its parent (`/estado-cuenta`) — while `/estado-cuenta/<id>`, which
|
||||
* has no entry of its own, still correctly highlights the parent.
|
||||
*/
|
||||
function activeHref(pathname: string | null): string | null {
|
||||
if (!pathname) return null;
|
||||
let best: string | null = null;
|
||||
for (const item of NAV_LINKS) {
|
||||
const match = item.exact
|
||||
? pathname === item.href
|
||||
: pathname === item.href || pathname.startsWith(`${item.href}/`);
|
||||
if (match && (best === null || item.href.length > best.length)) {
|
||||
best = item.href;
|
||||
}
|
||||
}
|
||||
return best;
|
||||
}
|
||||
|
||||
/**
|
||||
* One collapsible group in the desktop bar. Opens on click, closes on outside
|
||||
* click, Escape, or navigation. The trigger stays highlighted while any of its
|
||||
* children is the current page.
|
||||
*/
|
||||
function NavMenu({
|
||||
label,
|
||||
items,
|
||||
current,
|
||||
pathname,
|
||||
}: {
|
||||
label: string;
|
||||
items: NavLink[];
|
||||
current: string | null;
|
||||
pathname: string | null;
|
||||
}) {
|
||||
const [open, setOpen] = useState(false);
|
||||
const ref = useRef<HTMLDivElement>(null);
|
||||
const holdsCurrent = items.some((item) => item.href === current);
|
||||
|
||||
useEffect(() => {
|
||||
setOpen(false);
|
||||
}, [pathname]);
|
||||
|
||||
useEffect(() => {
|
||||
if (!open) return;
|
||||
function onPointerDown(event: MouseEvent) {
|
||||
if (ref.current && !ref.current.contains(event.target as Node)) {
|
||||
setOpen(false);
|
||||
}
|
||||
}
|
||||
function onKeyDown(event: KeyboardEvent) {
|
||||
if (event.key === "Escape") setOpen(false);
|
||||
}
|
||||
document.addEventListener("mousedown", onPointerDown);
|
||||
document.addEventListener("keydown", onKeyDown);
|
||||
return () => {
|
||||
document.removeEventListener("mousedown", onPointerDown);
|
||||
document.removeEventListener("keydown", onKeyDown);
|
||||
};
|
||||
}, [open]);
|
||||
|
||||
return (
|
||||
<div className="appbar-menu" ref={ref}>
|
||||
<button
|
||||
type="button"
|
||||
className={`appbar-link appbar-menu-trigger${holdsCurrent ? " active" : ""}`}
|
||||
aria-expanded={open}
|
||||
aria-haspopup="true"
|
||||
onClick={() => setOpen((v) => !v)}
|
||||
>
|
||||
{label}
|
||||
<span className="appbar-caret" aria-hidden="true" />
|
||||
</button>
|
||||
{open && (
|
||||
<div className="appbar-dropdown" role="menu">
|
||||
{items.map((item) => (
|
||||
<Link
|
||||
key={item.href}
|
||||
href={item.href}
|
||||
role="menuitem"
|
||||
className={`appbar-dropdown-link${current === item.href ? " active" : ""}`}
|
||||
aria-current={current === item.href ? "page" : undefined}
|
||||
onClick={() => setOpen(false)}
|
||||
>
|
||||
{item.label}
|
||||
</Link>
|
||||
))}
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* What is deployed, from both halves. build.yml builds api + web in one matrix
|
||||
* run, so their versions cannot drift at build time — but they can at DEPLOY
|
||||
* time, if a stack is applied with only one image's tag moved. Showing both and
|
||||
* flagging a mismatch is the cheap check that catches a half-applied release.
|
||||
*/
|
||||
function BuildFooter() {
|
||||
const web = webBuildInfo();
|
||||
const [api, setApi] = useState<ServiceVersion | null>(null);
|
||||
|
||||
useEffect(() => {
|
||||
let alive = true;
|
||||
getApiVersion()
|
||||
.then((v) => {
|
||||
if (alive) setApi(v);
|
||||
})
|
||||
.catch(() => {
|
||||
// The shell already redirects to /login when the API is unreachable;
|
||||
// a missing version line is not worth a second error surface.
|
||||
});
|
||||
return () => {
|
||||
alive = false;
|
||||
};
|
||||
}, []);
|
||||
|
||||
// Compare the COMMIT, not the version string. On a branch build both tiers
|
||||
// report APP_VERSION "master", so comparing versions cannot see drift — which
|
||||
// is exactly how a stale web image once sat next to a current API with this
|
||||
// footer showing nothing wrong. The sha is the only field that actually
|
||||
// differs between two builds of the same branch.
|
||||
const mismatch = api !== null && api.gitSha !== web.gitSha;
|
||||
|
||||
return (
|
||||
<footer className="shell-footer">
|
||||
<span>Jorge Cuadros & Asociados</span>
|
||||
{/* The FULL 40-char commit, not an abbreviation: this line exists to be
|
||||
pasted into `git show` or compared against a registry tag, and a
|
||||
7-char prefix makes both a manual step. It is what GIT_SHA already
|
||||
carries — build.yml bakes in `github.sha` whole. */}
|
||||
<span
|
||||
className="shell-footer-build"
|
||||
title={`web ${web.version} (${web.gitSha}) — ${web.buildDate}`}
|
||||
>
|
||||
v{web.version} · {web.gitSha}
|
||||
{mismatch && api ? ` · API ${api.gitSha}` : ""}
|
||||
</span>
|
||||
{mismatch && (
|
||||
<span className="shell-footer-warn" role="status">
|
||||
versiones desincronizadas
|
||||
</span>
|
||||
)}
|
||||
</footer>
|
||||
);
|
||||
}
|
||||
|
||||
export function AppShell({ children }: { children: ReactNode }) {
|
||||
const router = useRouter();
|
||||
const pathname = usePathname();
|
||||
const [user, setUser] = useState<AuthUser | null>(null);
|
||||
const [checking, setChecking] = useState(true);
|
||||
const [loggingOut, setLoggingOut] = useState(false);
|
||||
const [drawerOpen, setDrawerOpen] = useState(false);
|
||||
const [uiScale, setUiScale] = useState(DEFAULT_UI_SCALE);
|
||||
const current = activeHref(pathname);
|
||||
const nav = visibleNav(user);
|
||||
|
||||
useEffect(() => {
|
||||
let alive = true;
|
||||
me()
|
||||
.then((u) => {
|
||||
if (alive) {
|
||||
setUser(u);
|
||||
setChecking(false);
|
||||
}
|
||||
if (!alive) return;
|
||||
setUser(u);
|
||||
setChecking(false);
|
||||
// The account wins over the localStorage copy the pre-hydration script
|
||||
// painted with: that copy is this browser's, while the account follows
|
||||
// the person between machines. Re-save so the next cold paint here is
|
||||
// already correct.
|
||||
const accountScale = normalizeUiScale(u.uiScale ?? DEFAULT_UI_SCALE);
|
||||
setUiScale(accountScale);
|
||||
applyUiScale(accountScale);
|
||||
saveUiScale(accountScale);
|
||||
})
|
||||
.catch(() => {
|
||||
router.replace("/login");
|
||||
@@ -43,6 +272,39 @@ export function AppShell({ children }: { children: ReactNode }) {
|
||||
};
|
||||
}, [router]);
|
||||
|
||||
// Before /auth/me answers, show whatever the pre-hydration script applied so
|
||||
// the control isn't briefly out of step with the page.
|
||||
useEffect(() => {
|
||||
setUiScale(readUiScale());
|
||||
}, []);
|
||||
|
||||
function changeUiScale(next: number) {
|
||||
setUiScale(next);
|
||||
applyUiScale(next);
|
||||
saveUiScale(next);
|
||||
setUser((prev) => (prev ? { ...prev, uiScale: next } : prev));
|
||||
// Fire and forget: the change is already applied and cached locally, so a
|
||||
// failed write only means it won't follow the user to another machine.
|
||||
updateUiScale(next).catch(() => {
|
||||
/* ignore */
|
||||
});
|
||||
}
|
||||
|
||||
// Navigating away closes the mobile drawer — the route change is the only
|
||||
// "done" signal we get from a <Link>.
|
||||
useEffect(() => {
|
||||
setDrawerOpen(false);
|
||||
}, [pathname]);
|
||||
|
||||
useEffect(() => {
|
||||
if (!drawerOpen) return;
|
||||
function onKeyDown(event: KeyboardEvent) {
|
||||
if (event.key === "Escape") setDrawerOpen(false);
|
||||
}
|
||||
document.addEventListener("keydown", onKeyDown);
|
||||
return () => document.removeEventListener("keydown", onKeyDown);
|
||||
}, [drawerOpen]);
|
||||
|
||||
async function handleLogout() {
|
||||
setLoggingOut(true);
|
||||
try {
|
||||
@@ -69,37 +331,50 @@ export function AppShell({ children }: { children: ReactNode }) {
|
||||
}
|
||||
|
||||
return (
|
||||
<>
|
||||
<AuthContext.Provider value={user}>
|
||||
<header className="appbar">
|
||||
<div className="appbar-inner">
|
||||
<Link href="/clientes" className="brand">
|
||||
<span className="brand-mark" aria-hidden>
|
||||
JC
|
||||
</span>
|
||||
<Link href="/inicio" className="brand">
|
||||
<img
|
||||
src="/images/company_logo.png"
|
||||
alt=""
|
||||
className="brand-mark"
|
||||
/>
|
||||
<span className="brand-text">
|
||||
<span className="brand-name">Jorge Cuadros</span>
|
||||
<span className="brand-sub">& Asociados</span>
|
||||
</span>
|
||||
</Link>
|
||||
<nav className="appbar-nav" aria-label="Principal">
|
||||
{NAV.map((item) => {
|
||||
const active = pathname?.startsWith(item.href) ?? false;
|
||||
return (
|
||||
{nav.map((entry) =>
|
||||
entry.kind === "link" ? (
|
||||
<Link
|
||||
key={item.href}
|
||||
href={item.href}
|
||||
className={`appbar-link${active ? " active" : ""}`}
|
||||
aria-current={active ? "page" : undefined}
|
||||
key={entry.href}
|
||||
href={entry.href}
|
||||
className={`appbar-link${current === entry.href ? " active" : ""}`}
|
||||
aria-current={current === entry.href ? "page" : undefined}
|
||||
>
|
||||
{item.label}
|
||||
{entry.label}
|
||||
</Link>
|
||||
);
|
||||
})}
|
||||
) : (
|
||||
<NavMenu
|
||||
key={entry.label}
|
||||
label={entry.label}
|
||||
items={entry.items}
|
||||
current={current}
|
||||
pathname={pathname}
|
||||
/>
|
||||
),
|
||||
)}
|
||||
</nav>
|
||||
<span className="appbar-spacer" />
|
||||
<div className="appbar-user">
|
||||
<FontScaleControl value={uiScale} onChange={changeUiScale} />
|
||||
{user && (
|
||||
<span className="appbar-user-name">{user.name}</span>
|
||||
<span className="appbar-user-name">
|
||||
{user.name}
|
||||
<span className="appbar-user-role">{ROLE_LABEL[user.role]}</span>
|
||||
</span>
|
||||
)}
|
||||
<button
|
||||
type="button"
|
||||
@@ -110,9 +385,59 @@ export function AppShell({ children }: { children: ReactNode }) {
|
||||
{loggingOut ? "Saliendo…" : "Cerrar sesión"}
|
||||
</button>
|
||||
</div>
|
||||
<button
|
||||
type="button"
|
||||
className="appbar-burger"
|
||||
aria-label={drawerOpen ? "Cerrar menú" : "Abrir menú"}
|
||||
aria-expanded={drawerOpen}
|
||||
onClick={() => setDrawerOpen((v) => !v)}
|
||||
>
|
||||
<span className={`burger-icon${drawerOpen ? " open" : ""}`} aria-hidden="true" />
|
||||
</button>
|
||||
</div>
|
||||
{drawerOpen && (
|
||||
<nav className="appbar-drawer" aria-label="Principal (móvil)">
|
||||
{nav.map((entry) =>
|
||||
entry.kind === "link" ? (
|
||||
<Link
|
||||
key={entry.href}
|
||||
href={entry.href}
|
||||
className={`appbar-drawer-link${current === entry.href ? " active" : ""}`}
|
||||
aria-current={current === entry.href ? "page" : undefined}
|
||||
>
|
||||
{entry.label}
|
||||
</Link>
|
||||
) : (
|
||||
<div key={entry.label} className="appbar-drawer-group">
|
||||
<span className="appbar-drawer-heading">{entry.label}</span>
|
||||
{entry.items.map((item) => (
|
||||
<Link
|
||||
key={item.href}
|
||||
href={item.href}
|
||||
className={`appbar-drawer-link${current === item.href ? " active" : ""}`}
|
||||
aria-current={current === item.href ? "page" : undefined}
|
||||
>
|
||||
{item.label}
|
||||
</Link>
|
||||
))}
|
||||
</div>
|
||||
),
|
||||
)}
|
||||
<FontScaleControl
|
||||
value={uiScale}
|
||||
onChange={changeUiScale}
|
||||
variant="inline"
|
||||
/>
|
||||
{user && (
|
||||
<div className="appbar-drawer-user">
|
||||
{user.name} · {ROLE_LABEL[user.role]}
|
||||
</div>
|
||||
)}
|
||||
</nav>
|
||||
)}
|
||||
</header>
|
||||
<main className="shell-main">{children}</main>
|
||||
</>
|
||||
<BuildFooter />
|
||||
</AuthContext.Provider>
|
||||
);
|
||||
}
|
||||
|
||||
@@ -0,0 +1,259 @@
|
||||
"use client";
|
||||
|
||||
import { useState } from "react";
|
||||
|
||||
/** A single editable field in a child row. */
|
||||
export type FieldDef = {
|
||||
key: string;
|
||||
label: string;
|
||||
type?: "text" | "number" | "date" | "checkbox" | "select";
|
||||
options?: { value: string; label: string }[];
|
||||
width?: number;
|
||||
};
|
||||
|
||||
export type ChildConfig = {
|
||||
/** URL segment: installments | vehicles | drivers | beneficiaries | claims */
|
||||
apiKind: string;
|
||||
title: string;
|
||||
fields: FieldDef[];
|
||||
};
|
||||
|
||||
type RowValues = Record<string, string | boolean>;
|
||||
|
||||
function toDateInput(v: unknown): string {
|
||||
if (!v || typeof v !== "string") return "";
|
||||
const d = new Date(v);
|
||||
return isNaN(d.getTime()) ? "" : d.toISOString().slice(0, 10);
|
||||
}
|
||||
|
||||
/** Build editable values for a field from an existing row (or blank). */
|
||||
function rowToValues(fields: FieldDef[], row?: Record<string, unknown>): RowValues {
|
||||
const v: RowValues = {};
|
||||
for (const f of fields) {
|
||||
const raw = row?.[f.key];
|
||||
if (f.type === "checkbox") v[f.key] = !!raw;
|
||||
else if (f.type === "date") v[f.key] = toDateInput(raw);
|
||||
else v[f.key] = raw == null ? "" : String(raw);
|
||||
}
|
||||
return v;
|
||||
}
|
||||
|
||||
/** Coerce editable values into an API payload (numbers/blanks handled). */
|
||||
function valuesToPayload(fields: FieldDef[], v: RowValues): Record<string, unknown> {
|
||||
const out: Record<string, unknown> = {};
|
||||
for (const f of fields) {
|
||||
const val = v[f.key];
|
||||
if (f.type === "checkbox") out[f.key] = !!val;
|
||||
else if (f.type === "number") {
|
||||
const s = String(val).trim();
|
||||
out[f.key] = s === "" ? undefined : Number(s);
|
||||
} else {
|
||||
const s = String(val).trim();
|
||||
out[f.key] = s === "" ? undefined : s;
|
||||
}
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
/**
|
||||
* Generic add/edit/remove editor for a policy's child collection. The parent
|
||||
* owns the API calls (so it can reload the policy afterward); this component is
|
||||
* pure UI over `rows` plus add/save/remove callbacks.
|
||||
*/
|
||||
export function ChildCollection({
|
||||
config,
|
||||
rows,
|
||||
canEdit,
|
||||
onAdd,
|
||||
onSave,
|
||||
onRemove,
|
||||
}: {
|
||||
config: ChildConfig;
|
||||
rows: Record<string, unknown>[];
|
||||
canEdit: boolean;
|
||||
onAdd: (payload: Record<string, unknown>) => Promise<void>;
|
||||
onSave: (id: string, payload: Record<string, unknown>) => Promise<void>;
|
||||
onRemove: (id: string) => Promise<void>;
|
||||
}) {
|
||||
const [editingId, setEditingId] = useState<string | null>(null);
|
||||
const [adding, setAdding] = useState(false);
|
||||
const [values, setValues] = useState<RowValues>({});
|
||||
const [busy, setBusy] = useState(false);
|
||||
|
||||
function startAdd() {
|
||||
setEditingId(null);
|
||||
setAdding(true);
|
||||
setValues(rowToValues(config.fields));
|
||||
}
|
||||
function startEdit(row: Record<string, unknown>) {
|
||||
setAdding(false);
|
||||
setEditingId(String(row.id));
|
||||
setValues(rowToValues(config.fields, row));
|
||||
}
|
||||
function cancel() {
|
||||
setAdding(false);
|
||||
setEditingId(null);
|
||||
}
|
||||
|
||||
async function submit() {
|
||||
setBusy(true);
|
||||
try {
|
||||
const payload = valuesToPayload(config.fields, values);
|
||||
if (editingId) await onSave(editingId, payload);
|
||||
else await onAdd(payload);
|
||||
cancel();
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo guardar.");
|
||||
} finally {
|
||||
setBusy(false);
|
||||
}
|
||||
}
|
||||
|
||||
async function remove(id: string) {
|
||||
if (!window.confirm("¿Eliminar este registro?")) return;
|
||||
try {
|
||||
await onRemove(id);
|
||||
} catch (e) {
|
||||
window.alert((e as Error)?.message ?? "No se pudo eliminar.");
|
||||
}
|
||||
}
|
||||
|
||||
const colCount = config.fields.length + (canEdit ? 1 : 0);
|
||||
|
||||
function editorRow() {
|
||||
return (
|
||||
<tr>
|
||||
<td colSpan={colCount}>{editor()}</td>
|
||||
</tr>
|
||||
);
|
||||
}
|
||||
|
||||
function editor() {
|
||||
return (
|
||||
<div className="child-editor">
|
||||
<div className="form-grid">
|
||||
{config.fields.map((f) => (
|
||||
<label className="field" key={f.key}>
|
||||
<span className="field-label">{f.label}</span>
|
||||
{f.type === "checkbox" ? (
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={!!values[f.key]}
|
||||
onChange={(e) => setValues({ ...values, [f.key]: e.target.checked })}
|
||||
/>
|
||||
) : f.type === "select" ? (
|
||||
<select
|
||||
className="select"
|
||||
value={String(values[f.key] ?? "")}
|
||||
onChange={(e) => setValues({ ...values, [f.key]: e.target.value })}
|
||||
>
|
||||
<option value="">—</option>
|
||||
{f.options?.map((o) => (
|
||||
<option key={o.value} value={o.value}>
|
||||
{o.label}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
) : (
|
||||
<input
|
||||
className="input"
|
||||
type={f.type === "number" ? "number" : f.type === "date" ? "date" : "text"}
|
||||
step={f.type === "number" ? "0.01" : undefined}
|
||||
value={String(values[f.key] ?? "")}
|
||||
onChange={(e) => setValues({ ...values, [f.key]: e.target.value })}
|
||||
/>
|
||||
)}
|
||||
</label>
|
||||
))}
|
||||
</div>
|
||||
<div className="form-actions">
|
||||
<button type="button" className="btn btn-primary" onClick={submit} disabled={busy}>
|
||||
{busy ? "Guardando…" : editingId ? "Guardar" : "Agregar"}
|
||||
</button>
|
||||
<button type="button" className="btn btn-ghost" onClick={cancel}>
|
||||
Cancelar
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="card" style={{ padding: 16, marginBottom: 14 }}>
|
||||
<div className="child-head">
|
||||
<h3 className="section-title" style={{ margin: 0 }}>
|
||||
{config.title}
|
||||
<span className="section-count"> {rows.length}</span>
|
||||
</h3>
|
||||
{canEdit && !adding && editingId === null && (
|
||||
<button type="button" className="btn btn-outline" onClick={startAdd}>
|
||||
+ Agregar
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
|
||||
{rows.length === 0 && !adding ? (
|
||||
<div className="empty-inline">Sin registros.</div>
|
||||
) : (
|
||||
<div className="tx-scroll">
|
||||
<table className="tx-table">
|
||||
<thead>
|
||||
<tr>
|
||||
{config.fields.map((f) => (
|
||||
<th key={f.key}>{f.label}</th>
|
||||
))}
|
||||
{canEdit && <th className="num">Acciones</th>}
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{adding && editorRow()}
|
||||
{rows.map((row) =>
|
||||
editingId === String(row.id) ? (
|
||||
<tr key={String(row.id)}>
|
||||
<td colSpan={colCount}>{editor()}</td>
|
||||
</tr>
|
||||
) : (
|
||||
<tr key={String(row.id)}>
|
||||
{config.fields.map((f) => (
|
||||
<td key={f.key}>{cellText(f, row[f.key])}</td>
|
||||
))}
|
||||
{canEdit && (
|
||||
<td>
|
||||
<div className="row-actions">
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
onClick={() => startEdit(row)}
|
||||
>
|
||||
Editar
|
||||
</button>
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
onClick={() => remove(String(row.id))}
|
||||
>
|
||||
Eliminar
|
||||
</button>
|
||||
</div>
|
||||
</td>
|
||||
)}
|
||||
</tr>
|
||||
),
|
||||
)}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
function cellText(f: FieldDef, raw: unknown): string {
|
||||
if (f.type === "checkbox") return raw ? "Sí" : "No";
|
||||
if (f.type === "date") return toDateInput(raw) || "—";
|
||||
if (f.type === "select") {
|
||||
const opt = f.options?.find((o) => o.value === String(raw));
|
||||
return opt ? opt.label : "—";
|
||||
}
|
||||
return raw == null || raw === "" ? "—" : String(raw);
|
||||
}
|
||||
@@ -0,0 +1,57 @@
|
||||
"use client";
|
||||
|
||||
import Link from "next/link";
|
||||
|
||||
/**
|
||||
* The context-report shortcut. One row of pill buttons that link to
|
||||
* pre-filtered /reportes/[slug] pages. Used in the page header of
|
||||
* domain pages (clientes, polizas, servicios, estado-cuenta, banco).
|
||||
*
|
||||
* `entries` accepts both static links (slug + label) and pre-filtered
|
||||
* links (slug + params object). Pre-filtered ones build the query
|
||||
* string automatically; the runner pre-fills the form.
|
||||
*/
|
||||
export interface ReportLink {
|
||||
slug: string;
|
||||
label: string;
|
||||
/** Optional pre-fill for the report's filter form. */
|
||||
params?: Record<string, string>;
|
||||
/** When true, opens the report in a new tab (for "see the catalog"
|
||||
* style entries where the user is going to look around). */
|
||||
external?: boolean;
|
||||
}
|
||||
|
||||
export function ContextReports({
|
||||
label = "Reportes",
|
||||
entries,
|
||||
}: {
|
||||
label?: string;
|
||||
entries: ReportLink[];
|
||||
}) {
|
||||
if (entries.length === 0) return null;
|
||||
return (
|
||||
<div className="context-reports" aria-label={label}>
|
||||
<span className="context-reports-label">{label}</span>
|
||||
{entries.map((e) => {
|
||||
const qs = e.params
|
||||
? "?" +
|
||||
new URLSearchParams(
|
||||
Object.entries(e.params).filter(([, v]) => v != null && v !== ""),
|
||||
).toString()
|
||||
: "";
|
||||
const href = `/reportes/${e.slug}${qs}`;
|
||||
return (
|
||||
<Link
|
||||
key={`${e.slug}-${JSON.stringify(e.params ?? {})}`}
|
||||
href={href}
|
||||
className="context-report-link"
|
||||
target={e.external ? "_blank" : undefined}
|
||||
rel={e.external ? "noopener" : undefined}
|
||||
>
|
||||
{e.label}
|
||||
</Link>
|
||||
);
|
||||
})}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,265 @@
|
||||
"use client";
|
||||
|
||||
import { useState } from "react";
|
||||
import { useRouter } from "next/navigation";
|
||||
import type { CustomerDetail, CustomerInput, Currency } from "@/lib/types";
|
||||
import { createCustomer, updateCustomer } from "@/lib/api";
|
||||
|
||||
/** ISO date (yyyy-mm-dd) for a date input, from an API date string. */
|
||||
function toDateInput(v: string | null | undefined): string {
|
||||
if (!v) return "";
|
||||
const d = new Date(v);
|
||||
return isNaN(d.getTime()) ? "" : d.toISOString().slice(0, 10);
|
||||
}
|
||||
|
||||
function numOrUndef(v: string | number | null | undefined): number | undefined {
|
||||
if (v === null || v === undefined || v === "") return undefined;
|
||||
const n = Number(v);
|
||||
return isNaN(n) ? undefined : n;
|
||||
}
|
||||
|
||||
type Values = {
|
||||
name: string;
|
||||
addressLine1: string;
|
||||
addressLine2: string;
|
||||
city: string;
|
||||
state: string;
|
||||
zipCode: string;
|
||||
country: string;
|
||||
phone: string;
|
||||
mobile: string;
|
||||
fax: string;
|
||||
email: string;
|
||||
identificationType: string;
|
||||
identificationNumber: string;
|
||||
identificationExpiration: string;
|
||||
customerSince: string;
|
||||
preferredCurrency: Currency;
|
||||
minimumBalance: string;
|
||||
feeAmount: string;
|
||||
status: boolean;
|
||||
notes: string;
|
||||
};
|
||||
|
||||
function initial(c?: CustomerDetail): Values {
|
||||
return {
|
||||
name: c?.name ?? "",
|
||||
addressLine1: c?.addressLine1 ?? "",
|
||||
addressLine2: c?.addressLine2 ?? "",
|
||||
city: c?.city ?? "",
|
||||
state: c?.state ?? "",
|
||||
zipCode: c?.zipCode ?? "",
|
||||
country: c?.country ?? "",
|
||||
phone: c?.phone ?? "",
|
||||
mobile: c?.mobile ?? "",
|
||||
fax: c?.fax ?? "",
|
||||
email: c?.email ?? "",
|
||||
identificationType: c?.identificationType ?? "",
|
||||
identificationNumber: c?.identificationNumber ?? "",
|
||||
identificationExpiration: toDateInput(c?.identificationExpiration),
|
||||
customerSince: toDateInput(c?.customerSince),
|
||||
preferredCurrency: (c?.preferredCurrency as Currency) ?? "USD",
|
||||
minimumBalance: c?.minimumBalance != null ? String(c.minimumBalance) : "",
|
||||
feeAmount: c?.feeAmount != null ? String(c.feeAmount) : "",
|
||||
status: c?.status ?? true,
|
||||
notes: c?.notes ?? "",
|
||||
};
|
||||
}
|
||||
|
||||
/** Empty string -> undefined so we don't send blanks as real values. */
|
||||
function s(v: string): string | undefined {
|
||||
const t = v.trim();
|
||||
return t === "" ? undefined : t;
|
||||
}
|
||||
|
||||
/**
|
||||
* Shared create/edit form. When `customer` is given it edits (PATCH), otherwise
|
||||
* it creates (POST). Redirects to the customer's detail page on success.
|
||||
*/
|
||||
export function CustomerForm({ customer }: { customer?: CustomerDetail }) {
|
||||
const router = useRouter();
|
||||
const editing = !!customer;
|
||||
const [v, setV] = useState<Values>(() => initial(customer));
|
||||
const [saving, setSaving] = useState(false);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
function set<K extends keyof Values>(key: K, val: Values[K]) {
|
||||
setV((prev) => ({ ...prev, [key]: val }));
|
||||
}
|
||||
|
||||
async function submit(e: React.FormEvent) {
|
||||
e.preventDefault();
|
||||
setSaving(true);
|
||||
setError(null);
|
||||
const payload: CustomerInput = {
|
||||
name: v.name.trim(),
|
||||
addressLine1: s(v.addressLine1),
|
||||
addressLine2: s(v.addressLine2),
|
||||
city: s(v.city),
|
||||
state: s(v.state),
|
||||
zipCode: s(v.zipCode),
|
||||
country: s(v.country),
|
||||
phone: s(v.phone),
|
||||
mobile: s(v.mobile),
|
||||
fax: s(v.fax),
|
||||
email: s(v.email),
|
||||
identificationType: s(v.identificationType),
|
||||
identificationNumber: s(v.identificationNumber),
|
||||
identificationExpiration: s(v.identificationExpiration),
|
||||
customerSince: s(v.customerSince),
|
||||
preferredCurrency: v.preferredCurrency,
|
||||
minimumBalance: numOrUndef(v.minimumBalance),
|
||||
feeAmount: numOrUndef(v.feeAmount),
|
||||
status: v.status,
|
||||
notes: s(v.notes),
|
||||
};
|
||||
try {
|
||||
const saved = editing
|
||||
? await updateCustomer(customer!.id, payload)
|
||||
: await createCustomer(payload);
|
||||
router.push(`/clientes/${saved.id}`);
|
||||
} catch (e2) {
|
||||
setError((e2 as Error)?.message ?? "No se pudo guardar el cliente.");
|
||||
setSaving(false);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<form onSubmit={submit}>
|
||||
{error && <div className="state-box state-error">{error}</div>}
|
||||
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 14 }}>Identidad</h2>
|
||||
<div className="form-grid">
|
||||
<Field label="Nombre" required>
|
||||
<input className="input" required value={v.name}
|
||||
onChange={(e) => set("name", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Correo">
|
||||
<input className="input" type="email" value={v.email}
|
||||
onChange={(e) => set("email", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Teléfono">
|
||||
<input className="input" value={v.phone}
|
||||
onChange={(e) => set("phone", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Celular">
|
||||
<input className="input" value={v.mobile}
|
||||
onChange={(e) => set("mobile", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Fax">
|
||||
<input className="input" value={v.fax}
|
||||
onChange={(e) => set("fax", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Cliente desde">
|
||||
<input className="input" type="date" value={v.customerSince}
|
||||
onChange={(e) => set("customerSince", e.target.value)} />
|
||||
</Field>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 14 }}>Domicilio</h2>
|
||||
<div className="form-grid">
|
||||
<Field label="Dirección 1">
|
||||
<input className="input" value={v.addressLine1}
|
||||
onChange={(e) => set("addressLine1", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Dirección 2">
|
||||
<input className="input" value={v.addressLine2}
|
||||
onChange={(e) => set("addressLine2", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Ciudad">
|
||||
<input className="input" value={v.city}
|
||||
onChange={(e) => set("city", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Estado">
|
||||
<input className="input" value={v.state}
|
||||
onChange={(e) => set("state", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Código postal">
|
||||
<input className="input" value={v.zipCode}
|
||||
onChange={(e) => set("zipCode", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="País">
|
||||
<input className="input" value={v.country}
|
||||
onChange={(e) => set("country", e.target.value)} />
|
||||
</Field>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 14 }}>
|
||||
Identificación y cuenta
|
||||
</h2>
|
||||
<div className="form-grid">
|
||||
<Field label="Tipo de identificación">
|
||||
<input className="input" value={v.identificationType}
|
||||
onChange={(e) => set("identificationType", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Número de identificación">
|
||||
<input className="input" value={v.identificationNumber}
|
||||
onChange={(e) => set("identificationNumber", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Vence identificación">
|
||||
<input className="input" type="date" value={v.identificationExpiration}
|
||||
onChange={(e) => set("identificationExpiration", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Moneda preferida">
|
||||
<select className="select" value={v.preferredCurrency}
|
||||
onChange={(e) => set("preferredCurrency", e.target.value as Currency)}>
|
||||
<option value="USD">USD</option>
|
||||
<option value="MXN">MXN</option>
|
||||
</select>
|
||||
</Field>
|
||||
<Field label="Saldo mínimo">
|
||||
<input className="input" type="number" step="0.01" value={v.minimumBalance}
|
||||
onChange={(e) => set("minimumBalance", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Cuota">
|
||||
<input className="input" type="number" step="0.01" value={v.feeAmount}
|
||||
onChange={(e) => set("feeAmount", e.target.value)} />
|
||||
</Field>
|
||||
<Field label="Activo">
|
||||
<input type="checkbox" checked={v.status}
|
||||
onChange={(e) => set("status", e.target.checked)} />
|
||||
</Field>
|
||||
</div>
|
||||
<label className="field" style={{ marginTop: 16 }}>
|
||||
<span className="field-label">Notas</span>
|
||||
<textarea className="input" rows={3} value={v.notes}
|
||||
onChange={(e) => set("notes", e.target.value)} />
|
||||
</label>
|
||||
</div>
|
||||
|
||||
<div className="form-actions">
|
||||
<button type="submit" className="btn btn-primary" disabled={saving}>
|
||||
{saving ? "Guardando…" : editing ? "Guardar cambios" : "Crear cliente"}
|
||||
</button>
|
||||
<button type="button" className="btn btn-outline" onClick={() => router.back()}>
|
||||
Cancelar
|
||||
</button>
|
||||
</div>
|
||||
</form>
|
||||
);
|
||||
}
|
||||
|
||||
function Field({
|
||||
label,
|
||||
required,
|
||||
children,
|
||||
}: {
|
||||
label: string;
|
||||
required?: boolean;
|
||||
children: React.ReactNode;
|
||||
}) {
|
||||
return (
|
||||
<label className="field">
|
||||
<span className="field-label">
|
||||
{label}
|
||||
{required && <span aria-hidden> *</span>}
|
||||
</span>
|
||||
{children}
|
||||
</label>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,90 @@
|
||||
"use client";
|
||||
|
||||
import { useEffect, useRef, useState } from "react";
|
||||
import { listCustomers } from "@/lib/api";
|
||||
import type { CustomerListItem } from "@/lib/types";
|
||||
|
||||
/**
|
||||
* Debounced customer search + select. Reports the chosen customer's id and name
|
||||
* upward. Used when creating a policy that isn't started from a customer page.
|
||||
*/
|
||||
export function CustomerPicker({
|
||||
value,
|
||||
valueName,
|
||||
onPick,
|
||||
}: {
|
||||
value: string;
|
||||
valueName?: string;
|
||||
onPick: (id: string, name: string) => void;
|
||||
}) {
|
||||
const [query, setQuery] = useState("");
|
||||
const [results, setResults] = useState<CustomerListItem[]>([]);
|
||||
const [open, setOpen] = useState(false);
|
||||
const debounce = useRef<ReturnType<typeof setTimeout>>();
|
||||
|
||||
useEffect(() => {
|
||||
if (debounce.current) clearTimeout(debounce.current);
|
||||
if (query.trim().length < 2) {
|
||||
setResults([]);
|
||||
return;
|
||||
}
|
||||
debounce.current = setTimeout(() => {
|
||||
listCustomers({ query, pageSize: 8 })
|
||||
.then((r) => {
|
||||
setResults(r.items);
|
||||
setOpen(true);
|
||||
})
|
||||
.catch(() => setResults([]));
|
||||
}, 260);
|
||||
return () => {
|
||||
if (debounce.current) clearTimeout(debounce.current);
|
||||
};
|
||||
}, [query]);
|
||||
|
||||
return (
|
||||
<div className="picker">
|
||||
{value ? (
|
||||
<div className="picker-selected">
|
||||
<span>{valueName ?? "Cliente seleccionado"}</span>
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
onClick={() => onPick("", "")}
|
||||
>
|
||||
Cambiar
|
||||
</button>
|
||||
</div>
|
||||
) : (
|
||||
<>
|
||||
<input
|
||||
className="input"
|
||||
placeholder="Buscar cliente por nombre…"
|
||||
value={query}
|
||||
onChange={(e) => setQuery(e.target.value)}
|
||||
onFocus={() => results.length && setOpen(true)}
|
||||
/>
|
||||
{open && results.length > 0 && (
|
||||
<ul className="picker-list">
|
||||
{results.map((c) => (
|
||||
<li key={c.id}>
|
||||
<button
|
||||
type="button"
|
||||
className="picker-item"
|
||||
onClick={() => {
|
||||
onPick(c.id, c.name);
|
||||
setOpen(false);
|
||||
setQuery("");
|
||||
}}
|
||||
>
|
||||
{c.name}
|
||||
{c.city && <span className="muted"> · {c.city}</span>}
|
||||
</button>
|
||||
</li>
|
||||
))}
|
||||
</ul>
|
||||
)}
|
||||
</>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,114 @@
|
||||
"use client";
|
||||
|
||||
import { useEffect, useRef, useState } from "react";
|
||||
import { UI_SCALES } from "@/lib/ui-scale";
|
||||
|
||||
/**
|
||||
* Text-size picker. Controlled: AppShell owns the value and handles applying
|
||||
* and persisting it, because the same setting is edited from two places (the
|
||||
* appbar popover and the mobile drawer) and reconciled against the account on
|
||||
* load.
|
||||
*
|
||||
* `variant="menu"` is the compact appbar popover; `variant="inline"` is the
|
||||
* flat row used inside the mobile drawer, where a popover inside a popover
|
||||
* would be awkward.
|
||||
*/
|
||||
export function FontScaleControl({
|
||||
value,
|
||||
onChange,
|
||||
variant = "menu",
|
||||
}: {
|
||||
value: number;
|
||||
onChange: (scale: number) => void;
|
||||
variant?: "menu" | "inline";
|
||||
}) {
|
||||
const [open, setOpen] = useState(false);
|
||||
const ref = useRef<HTMLDivElement>(null);
|
||||
|
||||
useEffect(() => {
|
||||
if (!open) return;
|
||||
function onPointerDown(event: MouseEvent) {
|
||||
if (ref.current && !ref.current.contains(event.target as Node)) {
|
||||
setOpen(false);
|
||||
}
|
||||
}
|
||||
function onKeyDown(event: KeyboardEvent) {
|
||||
if (event.key === "Escape") setOpen(false);
|
||||
}
|
||||
document.addEventListener("mousedown", onPointerDown);
|
||||
document.addEventListener("keydown", onKeyDown);
|
||||
return () => {
|
||||
document.removeEventListener("mousedown", onPointerDown);
|
||||
document.removeEventListener("keydown", onKeyDown);
|
||||
};
|
||||
}, [open]);
|
||||
|
||||
function choose(next: number) {
|
||||
onChange(next);
|
||||
setOpen(false);
|
||||
}
|
||||
|
||||
const options = UI_SCALES.map((option) => ({
|
||||
...option,
|
||||
selected: Math.abs(value - option.value) < 0.001,
|
||||
}));
|
||||
|
||||
if (variant === "inline") {
|
||||
return (
|
||||
<div className="scale-inline" role="radiogroup" aria-label="Tamaño de texto">
|
||||
<span className="appbar-drawer-heading">Tamaño de texto</span>
|
||||
<div className="scale-inline-options">
|
||||
{options.map((option) => (
|
||||
<button
|
||||
key={option.value}
|
||||
type="button"
|
||||
role="radio"
|
||||
aria-checked={option.selected}
|
||||
className={`scale-chip${option.selected ? " active" : ""}`}
|
||||
style={{ fontSize: `${option.value}em` }}
|
||||
onClick={() => choose(option.value)}
|
||||
>
|
||||
{option.short}
|
||||
<span className="sr-only"> {option.label}</span>
|
||||
</button>
|
||||
))}
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<div className="appbar-menu" ref={ref}>
|
||||
<button
|
||||
type="button"
|
||||
className="appbar-scale-trigger"
|
||||
aria-expanded={open}
|
||||
aria-haspopup="true"
|
||||
aria-label="Tamaño de texto"
|
||||
title="Tamaño de texto"
|
||||
onClick={() => setOpen((v) => !v)}
|
||||
>
|
||||
<span aria-hidden="true">
|
||||
A<span className="appbar-scale-big">A</span>
|
||||
</span>
|
||||
</button>
|
||||
{open && (
|
||||
<div className="appbar-dropdown appbar-dropdown-right" role="menu">
|
||||
{options.map((option) => (
|
||||
<button
|
||||
key={option.value}
|
||||
type="button"
|
||||
role="menuitemradio"
|
||||
aria-checked={option.selected}
|
||||
className={`appbar-dropdown-link scale-option${option.selected ? " active" : ""}`}
|
||||
onClick={() => choose(option.value)}
|
||||
>
|
||||
<span style={{ fontSize: `${option.value}em` }}>{option.short}</span>
|
||||
<span className="scale-option-label">{option.label}</span>
|
||||
</button>
|
||||
))}
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,291 @@
|
||||
"use client";
|
||||
|
||||
import { useState } from "react";
|
||||
import { CustomerPicker } from "@/components/CustomerPicker";
|
||||
import { createMovement } from "@/lib/api";
|
||||
import type {
|
||||
CreateMovementInput,
|
||||
Currency,
|
||||
Facet,
|
||||
LedgerCurrency,
|
||||
TransactionDomain,
|
||||
} from "@/lib/types";
|
||||
|
||||
const DOMAINS: { key: TransactionDomain; label: string }[] = [
|
||||
{ key: "UTILITY", label: "Servicios" },
|
||||
{ key: "INSURANCE", label: "Seguros" },
|
||||
{ key: "TRUST", label: "Fideicomiso" },
|
||||
];
|
||||
|
||||
type Direction = "charge" | "credit";
|
||||
|
||||
function today(): string {
|
||||
return new Date().toISOString().slice(0, 10);
|
||||
}
|
||||
|
||||
function s(v: string): string | undefined {
|
||||
const t = v.trim();
|
||||
return t === "" ? undefined : t;
|
||||
}
|
||||
|
||||
/** Capture form for one ledger movement. `defaultCustomer` pre-fills the picker
|
||||
* when opening from a customer's statement. `concepts` is the list of
|
||||
* transaction-type facets from the billing module. */
|
||||
export function MovementForm({
|
||||
concepts,
|
||||
defaultCurrency,
|
||||
defaultCustomer,
|
||||
defaultDomain,
|
||||
onSaved,
|
||||
onCancel,
|
||||
}: {
|
||||
concepts: Facet[];
|
||||
defaultCurrency?: LedgerCurrency;
|
||||
defaultCustomer?: { id: string; name: string };
|
||||
defaultDomain?: TransactionDomain;
|
||||
onSaved: () => void;
|
||||
onCancel: () => void;
|
||||
}) {
|
||||
const [customerId, setCustomerId] = useState(defaultCustomer?.id ?? "");
|
||||
const [customerName, setCustomerName] = useState(defaultCustomer?.name ?? "");
|
||||
const [domain, setDomain] = useState<TransactionDomain>(
|
||||
defaultDomain ?? "UTILITY",
|
||||
);
|
||||
const [direction, setDirection] = useState<Direction>("charge");
|
||||
const [amount, setAmount] = useState("");
|
||||
const [transactionDate, setTransactionDate] = useState(today());
|
||||
const [currency, setCurrency] = useState<LedgerCurrency>(
|
||||
defaultCurrency ?? "MXN",
|
||||
);
|
||||
const [typeId, setTypeId] = useState("");
|
||||
const [period, setPeriod] = useState("");
|
||||
const [reference, setReference] = useState("");
|
||||
const [checkNumber, setCheckNumber] = useState("");
|
||||
const [message, setMessage] = useState("");
|
||||
const [outstanding, setOutstanding] = useState(false);
|
||||
const [saving, setSaving] = useState(false);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
|
||||
// "Sin fondos" is a per-service *charge* concept: the office recorded a
|
||||
// utility bill it couldn't cover. It never applies to a credit (a payment
|
||||
// that arrived is, by definition, funded) or to the insurance/trust lines.
|
||||
const canBeOutstanding = domain === "UTILITY" && direction === "charge";
|
||||
|
||||
async function submit(e: React.FormEvent) {
|
||||
e.preventDefault();
|
||||
if (!customerId) {
|
||||
setError("Selecciona un cliente.");
|
||||
return;
|
||||
}
|
||||
const abs = Number(amount);
|
||||
if (!Number.isFinite(abs) || abs === 0) {
|
||||
setError("El monto debe ser un número distinto de cero.");
|
||||
return;
|
||||
}
|
||||
const signed = direction === "charge" ? -Math.abs(abs) : Math.abs(abs);
|
||||
const payload: CreateMovementInput = {
|
||||
customerId,
|
||||
domain,
|
||||
amount: signed,
|
||||
transactionDate,
|
||||
currency: currency as Currency,
|
||||
typeId: s(typeId),
|
||||
period: s(period),
|
||||
reference: s(reference),
|
||||
checkNumber: s(checkNumber),
|
||||
message: s(message),
|
||||
// Guarded by canBeOutstanding so a stale checkbox can't ride along after
|
||||
// the user switches the row to a credit or another business line.
|
||||
outstanding: canBeOutstanding && outstanding ? true : undefined,
|
||||
};
|
||||
setSaving(true);
|
||||
setError(null);
|
||||
try {
|
||||
await createMovement(payload);
|
||||
onSaved();
|
||||
} catch (e2) {
|
||||
setError((e2 as Error)?.message ?? "No se pudo guardar el movimiento.");
|
||||
setSaving(false);
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<form onSubmit={submit}>
|
||||
{error && <div className="state-box state-error">{error}</div>}
|
||||
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 14 }}>Cliente</h2>
|
||||
<CustomerPicker
|
||||
value={customerId}
|
||||
valueName={customerId ? customerName : undefined}
|
||||
onPick={(id, name) => {
|
||||
setCustomerId(id);
|
||||
setCustomerName(name);
|
||||
}}
|
||||
/>
|
||||
</div>
|
||||
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 14 }}>Movimiento</h2>
|
||||
<div className="form-grid">
|
||||
<Field label="Línea de negocio" required>
|
||||
<select
|
||||
className="select"
|
||||
value={domain}
|
||||
onChange={(e) => setDomain(e.target.value as TransactionDomain)}
|
||||
>
|
||||
{DOMAINS.map((d) => (
|
||||
<option key={d.key} value={d.key}>
|
||||
{d.label}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
</Field>
|
||||
<Field label="Fecha" required>
|
||||
<input
|
||||
className="input"
|
||||
type="date"
|
||||
required
|
||||
value={transactionDate}
|
||||
onChange={(e) => setTransactionDate(e.target.value)}
|
||||
/>
|
||||
</Field>
|
||||
<Field label="Tipo" required>
|
||||
<select
|
||||
className="select"
|
||||
value={direction}
|
||||
onChange={(e) => setDirection(e.target.value as Direction)}
|
||||
>
|
||||
<option value="charge">Cargo</option>
|
||||
<option value="credit">Abono</option>
|
||||
</select>
|
||||
</Field>
|
||||
<Field label="Monto" required>
|
||||
<input
|
||||
className="input"
|
||||
type="number"
|
||||
step="0.01"
|
||||
required
|
||||
min="0"
|
||||
value={amount}
|
||||
onChange={(e) => setAmount(e.target.value)}
|
||||
placeholder="0.00"
|
||||
/>
|
||||
</Field>
|
||||
<Field label="Moneda" required>
|
||||
<select
|
||||
className="select"
|
||||
value={currency}
|
||||
onChange={(e) => setCurrency(e.target.value as LedgerCurrency)}
|
||||
>
|
||||
<option value="MXN">Pesos (MXN)</option>
|
||||
<option value="USD">Dólares (USD)</option>
|
||||
</select>
|
||||
</Field>
|
||||
<Field label="Concepto">
|
||||
<select
|
||||
className="select"
|
||||
value={typeId}
|
||||
onChange={(e) => setTypeId(e.target.value)}
|
||||
>
|
||||
<option value="">(sin concepto)</option>
|
||||
{concepts.map((t) => (
|
||||
<option key={t.id} value={t.id}>
|
||||
{t.name}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
</Field>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="card" style={{ padding: 20, marginBottom: 16 }}>
|
||||
<h2 className="section-title" style={{ marginBottom: 14 }}>Detalles</h2>
|
||||
<div className="form-grid">
|
||||
<Field label="Periodo">
|
||||
<input
|
||||
className="input"
|
||||
value={period}
|
||||
onChange={(e) => setPeriod(e.target.value)}
|
||||
placeholder="Ej. 2025-01"
|
||||
/>
|
||||
</Field>
|
||||
<Field label="Referencia">
|
||||
<input
|
||||
className="input"
|
||||
value={reference}
|
||||
onChange={(e) => setReference(e.target.value)}
|
||||
/>
|
||||
</Field>
|
||||
<Field label="Número de cheque">
|
||||
<input
|
||||
className="input"
|
||||
value={checkNumber}
|
||||
onChange={(e) => setCheckNumber(e.target.value)}
|
||||
/>
|
||||
</Field>
|
||||
</div>
|
||||
<label className="field" style={{ marginTop: 16 }}>
|
||||
<span className="field-label">Mensaje</span>
|
||||
<textarea
|
||||
className="input"
|
||||
rows={2}
|
||||
value={message}
|
||||
onChange={(e) => setMessage(e.target.value)}
|
||||
/>
|
||||
</label>
|
||||
|
||||
{canBeOutstanding && (
|
||||
<label
|
||||
className="field"
|
||||
style={{ marginTop: 16, flexDirection: "row", alignItems: "center", gap: 10 }}
|
||||
>
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={outstanding}
|
||||
onChange={(e) => setOutstanding(e.target.checked)}
|
||||
/>
|
||||
<span>
|
||||
<span className="field-label" style={{ display: "block" }}>
|
||||
Sin fondos (pendiente de pago)
|
||||
</span>
|
||||
<span className="muted" style={{ fontSize: 13 }}>
|
||||
El cargo se registra pero no afecta el saldo del cliente hasta
|
||||
que se resuelva con un cheque.
|
||||
</span>
|
||||
</span>
|
||||
</label>
|
||||
)}
|
||||
</div>
|
||||
|
||||
<div className="form-actions">
|
||||
<button type="submit" className="btn btn-primary" disabled={saving}>
|
||||
{saving ? "Guardando…" : "Capturar movimiento"}
|
||||
</button>
|
||||
<button type="button" className="btn btn-outline" onClick={onCancel}>
|
||||
Cancelar
|
||||
</button>
|
||||
</div>
|
||||
</form>
|
||||
);
|
||||
}
|
||||
|
||||
function Field({
|
||||
label,
|
||||
required,
|
||||
children,
|
||||
}: {
|
||||
label: string;
|
||||
required?: boolean;
|
||||
children: React.ReactNode;
|
||||
}) {
|
||||
return (
|
||||
<label className="field">
|
||||
<span className="field-label">
|
||||
{label}
|
||||
{required && <span aria-hidden> *</span>}
|
||||
</span>
|
||||
{children}
|
||||
</label>
|
||||
);
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user