Merge pull request #1058 from Tria-plc/dev

syncing
This commit is contained in:
Nathnael Wondisha
2026-08-01 10:39:41 +03:00
committed by GitHub
36 changed files with 1343 additions and 113 deletions

View File

@@ -0,0 +1,24 @@
import { MigrationInterface, QueryRunner } from "typeorm";
/**
* Pending→Active is the only company-level approval event; `updatedAt` can't
* stand in for it since any field edit bumps that too. Nullable — existing
* companies (approved before this column existed) have no recorded moment.
*/
export class AddApprovedAtToCompanies3120000000000 implements MigrationInterface {
name = "AddApprovedAtToCompanies3120000000000";
public async up(queryRunner: QueryRunner): Promise<void> {
await queryRunner.query(
`ALTER TABLE freight.companies
ADD COLUMN IF NOT EXISTS approved_at timestamptz`,
);
}
public async down(queryRunner: QueryRunner): Promise<void> {
await queryRunner.query(
`ALTER TABLE freight.companies
DROP COLUMN IF EXISTS approved_at`,
);
}
}

View File

@@ -0,0 +1,48 @@
import { MigrationInterface, QueryRunner, Table, TableIndex } from 'typeorm';
/**
* Append-only audit of company edits made before the company reaches Active
* (the onboarding phase) — that write path has no approval gate and, until
* now, left no trace of what changed (e.g. a phone number or a document).
*/
export class CreateCompanyRevisions3130000000000 implements MigrationInterface {
name = 'CreateCompanyRevisions3130000000000';
public async up(queryRunner: QueryRunner): Promise<void> {
await queryRunner.createTable(
new Table({
schema: 'freight',
name: 'company_revisions',
columns: [
{ name: 'id', type: 'uuid', isPrimary: true, generationStrategy: 'uuid', default: 'gen_random_uuid()' },
{ name: 'company_id', type: 'uuid' },
{ name: 'actor_id', type: 'uuid', isNullable: true },
{ name: 'summary', type: 'varchar', length: '255' },
{ name: 'changes', type: 'jsonb', default: "'[]'::jsonb" },
{ name: 'created_at', type: 'timestamptz', default: 'now()' },
{ name: 'updated_at', type: 'timestamptz', default: 'now()' },
{ name: 'deleted_at', type: 'timestamptz', isNullable: true },
],
foreignKeys: [
{
columnNames: ['company_id'],
referencedSchema: 'freight',
referencedTableName: 'companies',
referencedColumnNames: ['id'],
onDelete: 'CASCADE',
},
],
}),
true,
);
await queryRunner.createIndex(
'freight.company_revisions',
new TableIndex({ name: 'idx_company_revisions_company', columnNames: ['company_id'] }),
);
}
public async down(queryRunner: QueryRunner): Promise<void> {
await queryRunner.dropTable('freight.company_revisions', true);
}
}

View File

@@ -62,6 +62,7 @@ import { UpdateCompanyProfileStatusDto } from "./dto/update-company-profile-stat
import { RejectChangeRequestDto } from "./dto/reject-change-request.dto";
import { RequestDocumentChangeDto } from "./dto/request-document-change.dto";
import { ChangeRequestResponseDto } from "./dto/change-request-response.dto";
import { CompanyRevisionResponseDto } from "./dto/company-revision-response.dto";
import { FetchETradeDto } from "./dto/fetch-etrade.dto";
import { ETradeResponseDto } from "./dto/etrade-response.dto";
@@ -685,6 +686,17 @@ export class CompaniesController {
return requests.map((r) => new ChangeRequestResponseDto(r));
}
@Get(":companyId/revisions")
@BookingStaff(FREIGHT_PERMS.customers.view)
@ApiOperation({ summary: "Onboarding-phase edit history (version history)" })
async listCompanyRevisions(
@Param("companyId", ParseUUIDPipe) companyId: string,
): Promise<CompanyRevisionResponseDto[]> {
const revisions =
await this.companiesService.listCompanyRevisions(companyId);
return revisions.map((r) => new CompanyRevisionResponseDto(r));
}
@Post("change-requests/:id/approve")
@BookingStaff(FREIGHT_PERMS.customers.verify)
@ApiOperation({
@@ -719,6 +731,25 @@ export class CompaniesController {
return new ChangeRequestResponseDto(request);
}
@Post("change-requests/:id/request-changes")
@BookingStaff(FREIGHT_PERMS.customers.verify)
@ApiOperation({
summary:
"Ask for specific changes on a pending request without rejecting it (row stays open, next edit appends to it)",
})
async requestChangeRequestChanges(
@CurrentUser() user: CurrentIamUser,
@Param("id", ParseUUIDPipe) id: string,
@Body() dto: RejectChangeRequestDto,
): Promise<ChangeRequestResponseDto> {
const request = await this.companiesService.requestChangeRequestChanges(
id,
dto.note,
user.id,
);
return new ChangeRequestResponseDto(request);
}
@Post(":companyId/profiles")
@BookingStaff(FREIGHT_PERMS.customers.update)
@ApiOperation({ summary: "Add a profile (employee) to a company" })

View File

@@ -120,6 +120,13 @@ function makeService(overrides: Partial<Ctx> = {}) {
})),
update: jest.fn(async () => ({ id: "cr-1" })),
},
revisionRepo: {
create: jest.fn(async (row: Record<string, unknown>) => ({
id: "rev-1",
...row,
})),
findByCompanyId: jest.fn(async () => []),
},
profilesRepo: {
findByCompanyId: jest.fn(async () => []),
findByUserId: jest.fn(async () => ({
@@ -144,6 +151,7 @@ function makeService(overrides: Partial<Ctx> = {}) {
deps.companiesRepo as never,
deps.companyProfilesRepo as never,
deps.changeRequestRepo as never,
deps.revisionRepo as never,
deps.profilesRepo as never,
{} as never,
deps.filesService as never,

View File

@@ -15,9 +15,11 @@ import { Company } from "./entities/company.entity";
import { ExternalProfile } from "./entities/external-profile.entity";
import { CompanyProfile } from "./entities/company-profile.entity";
import { CompanyChangeRequest } from "./entities/company-change-request.entity";
import { CompanyRevision } from "./entities/company-revision.entity";
import { Booking } from "../bookings/entities/booking.entity";
import { CompanyProfileRepository } from "./company-profile.repository";
import { CompanyChangeRequestRepository } from "./company-change-request.repository";
import { CompanyRevisionRepository } from "./company-revision.repository";
import { ETradeService } from "./services/etrade.service";
import { CompanyNotifierService } from "./company-notifier.service";
import { VerifaydaModule } from "../verifayda/verifayda.module";
@@ -29,6 +31,7 @@ import { VerifaydaModule } from "../verifayda/verifayda.module";
ExternalProfile,
CompanyProfile,
CompanyChangeRequest,
CompanyRevision,
Booking,
]),
HttpModule,
@@ -49,6 +52,7 @@ import { VerifaydaModule } from "../verifayda/verifayda.module";
ExternalProfileRepository,
CompanyProfileRepository,
CompanyChangeRequestRepository,
CompanyRevisionRepository,
CompanyDashboardRepository,
ETradeService,
CompanyNotifierService,

View File

@@ -91,6 +91,13 @@ function makeService(overrides: Partial<Ctx> = {}) {
})),
update: jest.fn(async () => ({ id: "cr-1" })),
},
revisionRepo: {
create: jest.fn(async (row: Record<string, unknown>) => ({
id: "rev-1",
...row,
})),
findByCompanyId: jest.fn(async () => []),
},
profilesRepo: {
findByCompanyId: jest.fn(async () => []),
findByUserId: jest.fn(async () => ({
@@ -121,6 +128,7 @@ function makeService(overrides: Partial<Ctx> = {}) {
deps.companiesRepo as never,
deps.companyProfilesRepo as never,
deps.changeRequestRepo as never,
deps.revisionRepo as never,
deps.profilesRepo as never,
{} as never,
deps.filesService as never,

View File

@@ -39,6 +39,7 @@ function makeService(existing: ExistingProfile[]) {
companiesRepo as never,
companyProfilesRepo as never,
{} as never,
{} as never,
profilesRepo as never,
{} as never,
{} as never,

View File

@@ -1,5 +1,6 @@
import {
Injectable,
Logger,
NotFoundException,
ConflictException,
BadRequestException,
@@ -9,6 +10,11 @@ import { DataSource, EntityManager } from "typeorm";
import { CompaniesRepository } from "./companies.repository";
import { CompanyProfileRepository } from "./company-profile.repository";
import { CompanyChangeRequestRepository } from "./company-change-request.repository";
import { CompanyRevisionRepository } from "./company-revision.repository";
import {
diffCompanyUpdate,
summarizeCompanyChanges,
} from "./company-revision-diff.util";
import { ExternalProfileRepository } from "./external-profile.repository";
import {
CompanyDashboardRepository,
@@ -64,6 +70,10 @@ import {
DocumentChangeIntent,
LicenseChangeIntent,
} from "./entities/company-change-request.entity";
import {
CompanyRevision,
CompanyRevisionChange,
} from "./entities/company-revision.entity";
/** FileRecord `resource` + `code` slots for business-license documents. */
const LICENSE_RESOURCE = "company_profiles";
@@ -176,10 +186,13 @@ export interface UserIdentity {
@Injectable()
export class CompaniesService {
private readonly logger = new Logger(CompaniesService.name);
constructor(
private readonly companiesRepo: CompaniesRepository,
private readonly companyProfilesRepo: CompanyProfileRepository,
private readonly changeRequestRepo: CompanyChangeRequestRepository,
private readonly revisionRepo: CompanyRevisionRepository,
private readonly profilesRepo: ExternalProfileRepository,
private readonly dashboardRepo: CompanyDashboardRepository,
private readonly filesService: FilesService,
@@ -682,7 +695,16 @@ export class CompaniesService {
async updateCompany(id: string, dto: UpdateCompanyDto): Promise<Company> {
const before = await this.findCompanyById(id);
const updated = await this.companiesRepo.update(id, dto);
const patch: UpdateCompanyDto & { approvedAt?: Date } = { ...dto };
// Staff can also promote Pending -> Active directly through this generic
// endpoint (not just via the first-profile-approval path), so stamp it here too.
if (
dto.status === CompanyStatus.Active &&
before.status !== CompanyStatus.Active
) {
patch.approvedAt = new Date();
}
const updated = await this.companiesRepo.update(id, patch);
if (!updated) throw new NotFoundException(`Company ${id} not found`);
// Suspending or blacklisting locks the customer out, so they must be told.
@@ -840,6 +862,34 @@ export class CompaniesService {
return companyUpdates;
}
/**
* Append a version-history entry for an onboarding-phase edit (the company
* is not yet Active, so the change went straight to the live row with no
* approval gate to carry a record of it). Best-effort: a no-op patch or a
* failure to write history must never break the edit that triggered it.
*/
private async recordCompanyRevision(
before: Company,
patch: Record<string, any>,
actorId?: string | null,
extraChanges: CompanyRevisionChange[] = [],
): Promise<void> {
try {
const changes = [...diffCompanyUpdate(before, patch), ...extraChanges];
if (changes.length === 0) return;
await this.revisionRepo.create({
companyId: before.id,
actorId: actorId ?? null,
summary: summarizeCompanyChanges(changes),
changes,
});
} catch (err) {
this.logger.error(
`Failed to record company revision for ${before.id}: ${String(err)}`,
);
}
}
/** Reject a TIN already registered to a *different* company. */
private async assertTinAvailable(
company: Company,
@@ -902,6 +952,7 @@ export class CompaniesService {
);
if (!updated)
throw new NotFoundException(`Company ${company.id} not found`);
await this.recordCompanyRevision(company, companyUpdates, userId);
return new ProfileResponseDto(profile, updated);
}
@@ -945,10 +996,14 @@ export class CompaniesService {
if (existing) {
request =
(await this.changeRequestRepo.update(existing.id, {
// Note is left untouched: if this request was ChangesRequested, the
// reviewer's ask stays visible on the resubmitted (Pending) row —
// clearing it here would hide what was asked for right when the
// reviewer comes back to check whether it was actually addressed.
snapshot: { ...(existing.snapshot ?? {}), ...staged },
submittedBy: userId,
submittedAt: now,
note: null,
status: ChangeRequestStatus.Pending,
})) ?? existing;
this.companyNotifier.changeRequestSubmitted(company, request.id, false);
} else {
@@ -986,6 +1041,53 @@ export class CompaniesService {
return this.changeRequestRepo.findByCompanyId(companyId);
}
/** Onboarding-phase edit history (see {@link recordCompanyRevision}), newest first. */
async listCompanyRevisions(companyId: string): Promise<CompanyRevision[]> {
await this.findCompanyById(companyId);
return this.revisionRepo.findByCompanyId(companyId);
}
/**
* Pair adjacent remove-then-add intents into one before/after revision
* change — that's exactly how a "replace" is staged (see
* `replaceProfileLicenseFile`: `[{op:'remove',...}, {op:'add',...}]`
* pushed together, and later merges only ever append after that pair, so
* adjacency is preserved). A remove or add with no adjacent partner (a pure
* add, or a pure removal) stands alone.
*/
private pairReplaceIntents<
T extends { op: "add" | "remove"; fileId: string; fileName?: string },
>(intents: T[], labelFor: (intent: T) => string): CompanyRevisionChange[] {
const changes: CompanyRevisionChange[] = [];
let i = 0;
while (i < intents.length) {
const current = intents[i];
const next = intents[i + 1];
if (current.op === "remove" && next?.op === "add") {
changes.push({
field: `document:${current.fileId}`,
label: labelFor(next),
from: current.fileName ?? null,
to: next.fileName ?? null,
fromFileId: current.fileId,
toFileId: next.fileId,
});
i += 2;
continue;
}
changes.push({
field: `document:${current.fileId}`,
label: labelFor(current),
from: current.op === "remove" ? (current.fileName ?? null) : null,
to: current.op === "add" ? (current.fileName ?? null) : null,
fromFileId: current.op === "remove" ? current.fileId : null,
toFileId: current.op === "add" ? current.fileId : null,
});
i += 1;
}
return changes;
}
/**
* Approve a pending change request: apply its snapshot to the live Company and
* mark the request approved. Any staged documents are already attached to the
@@ -1015,6 +1117,30 @@ export class CompaniesService {
await this.applyLicenseChanges(request);
await this.applyDocumentChanges(request);
// This is the ONLY place post-approval FIELD/license/PoA-document changes
// land on the live row — without this call, everything the #419
// change-request flow does to those is invisible in Version History.
// `documentFileIds` (the general bulk company-documents upload) is
// deliberately NOT re-recorded here — those documents go live immediately
// at upload time and are already recorded there (see
// `uploadCompanyDocuments`); redoing it here would double the entry.
const documentChanges: CompanyRevisionChange[] = [
...this.pairReplaceIntents(
request.documents?.licenseChanges ?? [],
() => "Business license",
),
...this.pairReplaceIntents(
request.documents?.documentChanges ?? [],
(intent) => intent.code,
),
];
await this.recordCompanyRevision(
company,
companyUpdates,
reviewerId,
documentChanges,
);
return (
(await this.changeRequestRepo.update(id, {
status: ChangeRequestStatus.Approved,
@@ -1025,12 +1151,62 @@ export class CompaniesService {
);
}
/**
* A fresh upload under a single-file document slot (`isMultiple: false`)
* replaces whatever was there, not adds to it — soft-delete the prior live
* file(s) for that code, and describe each replacement (plus each genuinely
* new upload) as a revision change carrying both file ids, so the reviewer
* can open the previous and current file. Multi-file slots are left alone
* (genuinely additive, no single "the" document to diff against). Unrecognised
* codes (no matching field in the nationality's document setting) are also
* left alone — safer to under-clean than to guess wrong. Independent of the
* change-request review outcome: nothing else in this flow ever retires a
* superseded document, on approve OR reject — these documents go live the
* moment they're uploaded.
*/
private async replaceSingleFileCompanyDocuments(
company: Company,
before: FileRecord[],
uploaded: FileRecord[],
): Promise<CompanyRevisionChange[]> {
const setting = await this.fileUploadSettingsService
.getByCode(this.documentSettingCodeFor(company.nationality))
.catch(() => null);
const fields = setting?.fields ?? [];
const singleFileCodes = new Set(
fields.filter((f) => !f.isMultiple).map((f) => f.fileKey),
);
const labelByCode = new Map(fields.map((f) => [f.fileKey, f.fileLabel]));
const uploadedIds = new Set(uploaded.map((f) => f.id));
const changes: CompanyRevisionChange[] = [];
const toRemove: FileRecord[] = [];
for (const file of uploaded) {
if (!singleFileCodes.has(file.code)) continue;
const prior = before.find(
(f) => f.code === file.code && !uploadedIds.has(f.id),
);
changes.push({
field: `document:${file.code}`,
label: labelByCode.get(file.code) ?? file.code,
from: prior?.name ?? null,
to: file.name,
fromFileId: prior?.id ?? null,
toFileId: file.id,
});
if (prior) toRemove.push(prior);
}
await Promise.all(toRemove.map((f) => this.filesService.remove(f.id)));
return changes;
}
/**
* Upload company documents. For an approved company this also opens/updates a
* pending change request (recording the uploaded file ids) so the upload is
* reviewed and the customer is locked until it clears — consistent with the
* field-edit review. During onboarding (company not yet active) it's a plain
* upload with no review.
* upload with no review. Either way the documents go live immediately, so
* the revision history is recorded right away too, not gated on a decision.
*/
async uploadCompanyDocuments(
companyId: string,
@@ -1038,11 +1214,20 @@ export class CompaniesService {
submittedBy?: string,
): Promise<FileRecord[]> {
const company = await this.findCompanyById(companyId);
const before = await this.filesService.findByResource(
companyId,
"companies",
);
const uploaded = await this.filesService.uploadMany(
companyId,
"companies",
files,
);
const documentChanges = await this.replaceSingleFileCompanyDocuments(
company,
before,
uploaded,
);
await this.resolveDocumentChangeRequests(
companyId,
"companies",
@@ -1056,6 +1241,9 @@ export class CompaniesService {
submittedBy,
);
}
if (documentChanges.length > 0) {
await this.recordCompanyRevision(company, {}, submittedBy, documentChanges);
}
return uploaded;
}
@@ -1170,7 +1358,8 @@ export class CompaniesService {
},
submittedBy: submittedBy ?? existing.submittedBy ?? null,
submittedAt: now,
note: null,
// Note left untouched — see the comment in updateProfile's merge branch.
status: ChangeRequestStatus.Pending,
});
if (company) {
this.companyNotifier.changeRequestSubmitted(company, existing.id, false);
@@ -1231,6 +1420,37 @@ export class CompaniesService {
);
}
/**
* Ask for specific fixes without rejecting outright: unlike
* {@link rejectChangeRequest}, staged license/document intents are kept (the
* row stays open), so the customer's next edit is appended to this SAME
* request — via the merge branches in `updateProfile`/`stageDocumentChange`/
* `stageLicenseChange`/`stageDocumentIntent`/`stageIdentityChange` — instead
* of starting a fresh cycle.
*/
async requestChangeRequestChanges(
id: string,
note: string,
reviewerId?: string,
): Promise<CompanyChangeRequest> {
const request = await this.changeRequestRepo.findById(id);
if (!request)
throw new NotFoundException(`Change request ${id} not found`);
if (request.status !== ChangeRequestStatus.Pending) {
throw new BadRequestException(
`Change request ${id} is already ${request.status}`,
);
}
return (
(await this.changeRequestRepo.update(id, {
status: ChangeRequestStatus.ChangesRequested,
note,
reviewedBy: reviewerId ?? null,
reviewedAt: new Date(),
})) ?? request
);
}
async deleteCompany(id: string): Promise<void> {
await this.findCompanyById(id);
await this.companiesRepo.softDelete(id);
@@ -1472,6 +1692,7 @@ export class CompaniesService {
) {
await companyRepo.update(updated.companyId, {
status: CompanyStatus.Active,
approvedAt: new Date(),
});
this.companyNotifier.companyApproved(company);
}
@@ -2264,7 +2485,8 @@ export class CompaniesService {
},
submittedBy: submittedBy ?? existing.submittedBy ?? null,
submittedAt: now,
note: null,
// Note left untouched — see the comment in updateProfile's merge branch.
status: ChangeRequestStatus.Pending,
});
} else {
await this.changeRequestRepo.create({
@@ -2590,7 +2812,8 @@ export class CompaniesService {
snapshot,
submittedBy: userId,
submittedAt: now,
note: null,
// Note left untouched — see the comment in updateProfile's merge branch.
status: ChangeRequestStatus.Pending,
});
this.companyNotifier.changeRequestSubmitted(company, existing.id, false);
return;
@@ -2870,7 +3093,8 @@ export class CompaniesService {
},
submittedBy: submittedBy ?? existing.submittedBy ?? null,
submittedAt: now,
note: null,
// Note left untouched — see the comment in updateProfile's merge branch.
status: ChangeRequestStatus.Pending,
});
} else {
await this.changeRequestRepo.create({

View File

@@ -1,4 +1,4 @@
import { Repository } from "typeorm";
import { FindOperator, Repository } from "typeorm";
import { CompanyChangeRequestRepository } from "./company-change-request.repository";
import {
@@ -10,6 +10,16 @@ type Row = Pick<CompanyChangeRequest, "id" | "status"> & { createdAt: Date };
const COMPANY_ID = "company-1";
/** Matches a row's status against either a plain value or an `In([...])` operator. */
function statusMatches(
rowStatus: ChangeRequestStatus,
where: ChangeRequestStatus | FindOperator<ChangeRequestStatus> | undefined,
): boolean {
if (where === undefined) return true;
if (where instanceof FindOperator) return where.value.includes(rowStatus);
return rowStatus === where;
}
/**
* Stands in for the TypeORM repository over a fixed set of rows, honouring the
* `where.status` filter and the `createdAt DESC` ordering findOne relies on.
@@ -17,13 +27,17 @@ const COMPANY_ID = "company-1";
function mockRepositoryOver(rows: Row[]) {
return {
findOne: jest.fn(
({ where }: { where: Partial<Row> & { companyId: string } }) =>
({
where,
}: {
where: { companyId: string; status?: Row["status"] | FindOperator<Row["status"]> };
}) =>
Promise.resolve(
rows
.filter(
(row) =>
where.companyId === COMPANY_ID &&
(where.status === undefined || row.status === where.status),
statusMatches(row.status, where.status),
)
.sort((a, b) => b.createdAt.getTime() - a.createdAt.getTime())[0] ??
null,
@@ -57,6 +71,21 @@ describe("CompanyChangeRequestRepository.findLatestOpenByCompanyId", () => {
expect(result?.id).toBe("pending");
});
it("treats a changes-requested request as open, same as pending", async () => {
const changesRequested: Row = {
id: "changes-requested",
status: ChangeRequestStatus.ChangesRequested,
createdAt: new Date("2026-01-02T00:00:00.000Z"),
};
const result = await subject([
rejected,
changesRequested,
]).findLatestOpenByCompanyId(COMPANY_ID);
expect(result?.id).toBe("changes-requested");
});
it("returns the latest rejected request when nothing is pending", async () => {
const result = await subject([rejected]).findLatestOpenByCompanyId(
COMPANY_ID,

View File

@@ -1,12 +1,18 @@
import { Injectable } from "@nestjs/common";
import { InjectRepository } from "@nestjs/typeorm";
import { Repository } from "typeorm";
import { In, Repository } from "typeorm";
import { BaseRepository } from "@edr/api-common";
import {
ChangeRequestStatus,
CompanyChangeRequest,
} from "./entities/company-change-request.entity";
/** Statuses that mean "still open, awaiting the customer's next edit" — Pending and ChangesRequested behave identically here, they just carry a note or not. */
const OPEN_FOR_EDIT_STATUSES = [
ChangeRequestStatus.Pending,
ChangeRequestStatus.ChangesRequested,
];
@Injectable()
export class CompanyChangeRequestRepository extends BaseRepository<CompanyChangeRequest> {
constructor(
@@ -16,12 +22,12 @@ export class CompanyChangeRequestRepository extends BaseRepository<CompanyChange
super(repo);
}
/** The company's current pending request, if any. */
/** The company's current open request (Pending or ChangesRequested), if any — the row the next edit appends to. */
async findPendingByCompanyId(
companyId: string,
): Promise<CompanyChangeRequest | null> {
return this.repository.findOne({
where: { companyId, status: ChangeRequestStatus.Pending },
where: { companyId, status: In(OPEN_FOR_EDIT_STATUSES) },
order: { createdAt: "DESC" },
});
}

View File

@@ -0,0 +1,90 @@
import type { Company } from "./entities/company.entity";
import type { CompanyRevisionChange } from "./entities/company-revision.entity";
/** Human label per audited company field — anything not listed here is skipped (internal/lock fields like `*FaydaSub`). */
export const COMPANY_FIELD_LABELS: Record<string, string> = {
name: "Company name",
phone: "Phone",
email: "Email",
address: "Address",
country: "Country",
tin: "TIN",
vatNumber: "VAT number",
fanNumber: "FAN number",
nationality: "Nationality",
website: "Website",
licenceNumber: "Licence number",
region: "Region",
zone: "Zone",
woreda: "Woreda",
kebele: "Kebele",
houseNo: "House No",
contactPersonName: "Contact person name",
contactPersonPhone: "Contact person phone",
contactPersonEmail: "Contact person email",
contactPersonPosition: "Contact person position",
generalManagerName: "General manager name",
generalManagerPhone: "General manager phone",
generalManagerEmail: "General manager email",
poaName: "PoA name",
poaPhone: "PoA phone",
poaEmail: "PoA email",
poaLocation: "PoA location",
poaAddress: "PoA address",
documents: "Document",
};
function displayValue(value: unknown): string | null {
if (value === null || value === undefined || value === "") return null;
if (typeof value === "boolean") return value ? "Yes" : "No";
return String(value);
}
/**
* Compare the company row before a write against the patch about to be
* applied (the same shape `mapProfileDtoToCompanyUpdates` returns: scalar
* columns plus a merged `attributes` blob). Only fields with a known label
* are reported, so identity-lock bookkeeping (`ownerFaydaSub`, etc.) never
* shows up as noise.
*/
export function diffCompanyUpdate(
before: Company,
patch: Record<string, any>,
): CompanyRevisionChange[] {
const changes: CompanyRevisionChange[] = [];
const { attributes: attrPatch, ...columnPatch } = patch;
for (const [field, nextRaw] of Object.entries(columnPatch)) {
const label = COMPANY_FIELD_LABELS[field];
if (!label) continue;
const next = displayValue(nextRaw);
const previous = displayValue((before as unknown as Record<string, unknown>)[field]);
if (next === previous) continue;
changes.push({ field, label, from: previous, to: next });
}
if (attrPatch) {
const beforeAttrs = before.attributes ?? {};
for (const [field, nextRaw] of Object.entries(attrPatch)) {
const label = COMPANY_FIELD_LABELS[field];
if (!label) continue;
const next = displayValue(nextRaw);
const previous = displayValue(beforeAttrs[field]);
if (next === previous) continue;
changes.push({ field, label, from: previous, to: next });
}
}
return changes;
}
/** Short human summary of a change set, e.g. "phone, address changed". */
export function summarizeCompanyChanges(
changes: CompanyRevisionChange[],
): string {
if (changes.length === 0) return "No changes";
const labels = changes.map((c) => c.label.toLowerCase());
return labels.length <= 3
? `${labels.join(", ")} changed`
: `${labels.length} fields changed`;
}

View File

@@ -0,0 +1,23 @@
import { Injectable } from "@nestjs/common";
import { InjectRepository } from "@nestjs/typeorm";
import { Repository } from "typeorm";
import { BaseRepository } from "@edr/api-common";
import { CompanyRevision } from "./entities/company-revision.entity";
@Injectable()
export class CompanyRevisionRepository extends BaseRepository<CompanyRevision> {
constructor(
@InjectRepository(CompanyRevision)
repo: Repository<CompanyRevision>,
) {
super(repo);
}
/** Revision history for a company, newest first. */
async findByCompanyId(companyId: string): Promise<CompanyRevision[]> {
return this.repository.find({
where: { companyId },
order: { createdAt: "DESC" },
});
}
}

View File

@@ -13,9 +13,12 @@ export class CompanyInfoResponseDto {
/**
* Open profile-edit review, if any. Drives the portal-wide lock (pending →
* settings + new-contract/booking creation disabled) and the reapply banner.
* `changes_requested` is the soft variant of `rejected`: same edit-and-resubmit
* call to action, but the customer's edit appends to this SAME request
* instead of starting a fresh one.
*/
review: {
status: 'pending' | 'rejected';
status: 'pending' | 'rejected' | 'changes_requested';
note: string | null;
} | null;
@@ -30,12 +33,13 @@ export class CompanyInfoResponseDto {
const open =
changeRequest &&
(changeRequest.status === ChangeRequestStatus.Pending ||
changeRequest.status === ChangeRequestStatus.Rejected)
changeRequest.status === ChangeRequestStatus.Rejected ||
changeRequest.status === ChangeRequestStatus.ChangesRequested)
? changeRequest
: null;
this.review = open
? {
status: open.status as 'pending' | 'rejected',
status: open.status as 'pending' | 'rejected' | 'changes_requested',
note: open.note ?? null,
}
: null;

View File

@@ -0,0 +1,23 @@
import {
CompanyRevision,
CompanyRevisionChange,
} from "../entities/company-revision.entity";
/** One version-history entry, shown on the backoffice customer detail page. */
export class CompanyRevisionResponseDto {
id: string;
companyId: string;
actorId: string | null;
summary: string;
changes: CompanyRevisionChange[];
createdAt: Date;
constructor(revision: CompanyRevision) {
this.id = revision.id;
this.companyId = revision.companyId;
this.actorId = revision.actorId ?? null;
this.summary = revision.summary;
this.changes = revision.changes ?? [];
this.createdAt = revision.createdAt;
}
}

View File

@@ -68,10 +68,12 @@ export class ProfileResponseDto {
/**
* Open profile-edit review, if any. `reviewStatus === "pending"` locks the
* settings page; `"rejected"` surfaces the note and prefills the (declined)
* proposed values from `pendingChanges` so the customer can amend & resubmit.
* settings page; `"rejected"`/`"changes_requested"` both surface the note and
* prefill the proposed values from `pendingChanges` so the customer can amend
* & resubmit — `"changes_requested"` just appends the edit to this same
* request instead of starting a fresh one.
*/
reviewStatus: "pending" | "rejected" | null;
reviewStatus: "pending" | "rejected" | "changes_requested" | null;
reviewNote: string | null;
pendingChanges: Record<string, any> | null;
@@ -127,7 +129,8 @@ export class ProfileResponseDto {
const openReview =
changeRequest &&
(changeRequest.status === ChangeRequestStatus.Pending ||
changeRequest.status === ChangeRequestStatus.Rejected)
changeRequest.status === ChangeRequestStatus.Rejected ||
changeRequest.status === ChangeRequestStatus.ChangesRequested)
? changeRequest
: null;
this.reviewStatus =
@@ -135,7 +138,9 @@ export class ProfileResponseDto {
? "pending"
: openReview?.status === ChangeRequestStatus.Rejected
? "rejected"
: null;
: openReview?.status === ChangeRequestStatus.ChangesRequested
? "changes_requested"
: null;
this.reviewNote = openReview?.note ?? null;
this.pendingChanges = openReview?.snapshot ?? null;
this.identity = buildCompanyIdentityState(company);

View File

@@ -97,6 +97,7 @@ export class ResponseCompanyDto {
createdAt: Date;
updatedAt: Date;
approvedAt: Date | null;
constructor(company: Company) {
this.id = company.id;
@@ -135,5 +136,6 @@ export class ResponseCompanyDto {
this.identity = buildCompanyIdentityState(company);
this.createdAt = company.createdAt;
this.updatedAt = company.updatedAt;
this.approvedAt = company.approvedAt ?? null;
}
}

View File

@@ -5,14 +5,18 @@ import { Company } from "./company.entity";
/**
* Lifecycle of a customer's proposed profile change. Edits made on the portal
* settings page by an already-approved company are staged here (not written to
* the live Company row) until a backoffice reviewer approves — at which point
* the snapshot is applied — or rejects with a note, after which the customer can
* amend and resubmit.
* the live Company row) until a backoffice reviewer resolves it:
* - Approved — the snapshot is applied to the live Company row.
* - Rejected — terminal for this row; the customer's next edit starts a fresh one.
* - ChangesRequested — soft: the row stays open with the reviewer's note attached,
* so the customer's next edit is appended (merged) into this SAME row instead
* of starting a new cycle.
*/
export enum ChangeRequestStatus {
Pending = "pending",
Approved = "approved",
Rejected = "rejected",
ChangesRequested = "changes_requested",
}
/**

View File

@@ -0,0 +1,46 @@
import { BaseEntity } from "@edr/api-common";
import { Column, Entity, Index, JoinColumn, ManyToOne } from "typeorm";
import { Company } from "./company.entity";
/**
* One recorded field/document change, as shown on the customer's version
* history. A document change carries `fromFileId`/`toFileId` alongside the
* display names, so the reviewer can open the previous and current file —
* not just read that "a document changed."
*/
export interface CompanyRevisionChange {
field: string;
label: string;
from: string | null;
to: string | null;
fromFileId?: string | null;
toFileId?: string | null;
}
/**
* Append-only audit of edits made to a company record BEFORE it reaches
* `Active` (the onboarding phase), where {@link CompaniesService.updateProfile}
* and {@link CompaniesService.uploadCompanyDocuments} write straight to the
* live row with no approval gate — and, until this entity, no trace at all.
* Post-approval edits already get history via `CompanyChangeRequest`; this
* covers the gap before that gate exists.
*/
@Entity({ schema: "freight", name: "company_revisions" })
@Index(["companyId"])
export class CompanyRevision extends BaseEntity {
@Column({ name: "company_id", type: "uuid" })
companyId!: string;
@ManyToOne(() => Company, { onDelete: "CASCADE" })
@JoinColumn({ name: "company_id" })
company?: Company;
@Column({ name: "actor_id", type: "uuid", nullable: true })
actorId?: string | null;
@Column({ name: "summary", type: "varchar", length: 255 })
summary!: string;
@Column({ name: "changes", type: "jsonb", default: () => `'[]'::jsonb` })
changes!: CompanyRevisionChange[];
}

View File

@@ -61,6 +61,10 @@ export class Company extends BaseEntity {
})
status!: CompanyStatus;
/** Set when the company is first promoted Pending → Active. Null for companies approved before this column existed. */
@Column({ name: "approved_at", type: "timestamptz", nullable: true })
approvedAt?: Date | null;
@Column({ name: "tin", type: "varchar", length: 10, unique: true })
tin!: string;

View File

@@ -51,7 +51,11 @@ export class FilesController {
@Query("download") download: string | undefined,
@Res() res: Response,
) {
const record = await this.filesService.findById(fileId);
// Includes soft-deleted records: a superseded document (replaced via a
// single-file document slot, or resolved as part of a license/PoA swap)
// is only reachable by UUID through the change-request/version-history
// diff, where reviewers need to open the "previous" file to compare it.
const record = await this.filesService.findByIdIncludingDeleted(fileId);
// Chat attachments are cross-tenant sensitive and this route has no
// ownership check, so a leaked/guessed UUID would hand one company's file to
@@ -63,7 +67,9 @@ export class FilesController {
);
}
const { stream } = await this.filesService.streamById(fileId);
const { stream } = await this.filesService.streamById(fileId, {
includeDeleted: true,
});
const forceDownload = download === "1" || download === "true";
const disposition = forceDownload ? "attachment" : "inline";

View File

@@ -245,6 +245,23 @@ export class FilesService {
return record;
}
/**
* Same as {@link findById}, but also matches a soft-deleted record — a
* superseded document (replaced via a single-file slot, or a resolved
* license/PoA swap) is exactly this: gone from every live listing, but its
* id is still handed to reviewers in the change-request/version-history
* diff so they can open the "previous" file for comparison. Only the
* preview/download route should use this; every other caller wants the
* default (soft-deleted = not found).
*/
async findByIdIncludingDeleted(id: string): Promise<FileRecord> {
const record = await this.filesRepository.findById(id, {
withDeleted: true,
});
if (!record) throw new NotFoundException(`File ${id} not found`);
return record;
}
/**
* Record a reviewer verdict on one document. `change_requested` keeps the note
* (the customer sees it verbatim); any other verdict clears it, so a stale
@@ -360,8 +377,11 @@ export class FilesService {
async streamById(
id: string,
opts: { includeDeleted?: boolean } = {},
): Promise<{ stream: Readable; record: FileRecord }> {
const record = await this.findById(id);
const record = opts.includeDeleted
? await this.findByIdIncludingDeleted(id)
: await this.findById(id);
const objectName = this.minioService.getObjectNameFromUrl(record.url);
const stream = await this.minioService.getFileStream(objectName);
return { stream, record };

View File

@@ -2,7 +2,6 @@ import {
Alert,
Anchor,
Badge,
Box,
Button,
Card,
Group,
@@ -27,11 +26,11 @@ import { useAuth } from "@/auth/useAuth";
import { FREIGHT_PERMS, hasPermission } from "@/lib/permissions";
import { fetchViewableFile } from "@/services/files.service";
import { api } from "@/services/api";
import type { Company, CompanyChangeRequest } from "@/types/customer";
import type { Company } from "@/types/customer";
import { formatDate, humanize } from "./format";
/** Friendly labels for the proposed-change snapshot keys (UpdateProfileDto). */
const FIELD_LABELS: Record<string, string> = {
export const FIELD_LABELS: Record<string, string> = {
companyName: "Company name",
companyEmail: "Company email",
companyPhone: "Company phone",
@@ -69,7 +68,7 @@ const FIELD_LABELS: Record<string, string> = {
};
/** Best-effort current value on the live company for a proposed field key. */
function currentValue(company: Company, key: string): string {
export function currentValue(company: Company, key: string): string {
const c = company as unknown as Record<string, unknown>;
const attrs = (company.attributes ?? {}) as Record<string, unknown>;
const map: Record<string, unknown> = {
@@ -160,7 +159,7 @@ function FaydaIdentityDiff({
);
}
function DiffRow({
export function DiffRow({
label,
from,
to,
@@ -201,8 +200,9 @@ function DiffRow({
/**
* Backoffice review surface for a customer's staged profile edits. Shows the
* pending change request as a proposed-vs-current diff with Approve / Reject
* (with note) actions, plus a short history of past decisions.
* pending change request as a proposed-vs-current diff with Approve / Reject /
* Request changes actions. Past decisions live in the History tab's unified
* timeline (see {@link CompanyTimeline}), not here.
*/
export function ChangeRequestReview({ company }: { company: Company }) {
const { user } = useAuth();
@@ -216,16 +216,21 @@ export function ChangeRequestReview({ company }: { company: Company }) {
const reject = useMutation(
api.customers.rejectChangeRequest.mutationOptions(),
);
const requestChanges = useMutation(
api.customers.requestChangeRequestChanges.mutationOptions(),
);
const { view, viewer } = useFileViewer();
const [rejectId, setRejectId] = useState<string | null>(null);
const [actionTarget, setActionTarget] = useState<{
id: string;
kind: "reject" | "request-changes";
} | null>(null);
const [note, setNote] = useState("");
const requests = query.data ?? [];
const pending = requests.find((r) => r.status === "pending");
const history = requests.filter((r) => r.status !== "pending").slice(0, 5);
if (!pending && history.length === 0) return null;
if (!pending) return null;
const proposedKeys = pending
? Object.keys(pending.snapshot ?? {}).filter((k) => k !== "faydaIdentity")
@@ -237,13 +242,14 @@ export function ChangeRequestReview({ company }: { company: Company }) {
const licenseChanges = pending?.licenseChanges ?? [];
const documentChanges = pending?.documentChanges ?? [];
const confirmReject = () => {
if (!rejectId) return;
reject.mutate(
{ id: rejectId, note: note.trim() },
const confirmAction = () => {
if (!actionTarget) return;
const mutation = actionTarget.kind === "reject" ? reject : requestChanges;
mutation.mutate(
{ id: actionTarget.id, note: note.trim() },
{
onSuccess: () => {
setRejectId(null);
setActionTarget(null);
setNote("");
},
},
@@ -270,6 +276,18 @@ export function ChangeRequestReview({ company }: { company: Company }) {
</Text>
</Group>
{pending.note && (
<Alert
color="yellow"
variant="light"
icon={<AlertTriangle size={16} />}
>
Changes were requested on an earlier round of this same
submission: <strong>{pending.note}</strong> check whether
this resubmission actually addresses it before approving.
</Alert>
)}
{proposedKeys.length > 0 ? (
<SimpleGrid cols={{ base: 1, sm: 2, lg: 3 }} spacing="lg">
{proposedKeys.map((key) => (
@@ -418,12 +436,22 @@ export function ChangeRequestReview({ company }: { company: Company }) {
variant="light"
color="red"
onClick={() => {
setRejectId(pending.id);
setActionTarget({ id: pending.id, kind: "reject" });
setNote("");
}}
>
Reject
</Button>
<Button
variant="light"
color="yellow"
onClick={() => {
setActionTarget({ id: pending.id, kind: "request-changes" });
setNote("");
}}
>
Request changes
</Button>
<Button
color="edr-green"
loading={approve.isPending}
@@ -437,51 +465,31 @@ export function ChangeRequestReview({ company }: { company: Company }) {
</Card>
)}
{history.length > 0 && (
<Card withBorder>
<Stack gap="sm">
<Text fw={600} c="edr-text">
Review history
</Text>
{history.map((r: CompanyChangeRequest) => (
<Group key={r.id} gap="sm" wrap="nowrap" align="flex-start">
<Badge
color={r.status === "approved" ? "edr-green" : "red"}
variant="light"
radius="md"
tt="capitalize"
>
{r.status}
</Badge>
<Box style={{ flex: 1 }}>
<Text size="sm" c="edr-text">
{formatDate(r.reviewedAt ?? r.updatedAt)}
</Text>
{r.note && (
<Text size="xs" c="dimmed">
Note: {r.note}
</Text>
)}
</Box>
</Group>
))}
</Stack>
</Card>
)}
<Modal
opened={rejectId !== null}
onClose={() => setRejectId(null)}
title="Reject changes"
opened={actionTarget !== null}
onClose={() => setActionTarget(null)}
title={
actionTarget?.kind === "reject" ? "Reject changes" : "Request changes"
}
centered
radius="lg"
>
<Stack gap="md">
<Alert color="red" variant="light" icon={<AlertTriangle size={18} />}>
The customer will see this note and can amend and resubmit.
<Alert
color={actionTarget?.kind === "reject" ? "red" : "yellow"}
variant="light"
icon={<AlertTriangle size={18} />}
>
{actionTarget?.kind === "reject"
? "The customer will see this note and can amend and resubmit."
: "The customer will see this note and can keep editing this same request — no need to start over."}
</Alert>
<Textarea
label="Reason for rejection"
label={
actionTarget?.kind === "reject"
? "Reason for rejection"
: "What needs to change"
}
placeholder="e.g. The company address doesn't match the trade license."
autosize
minRows={3}
@@ -492,18 +500,20 @@ export function ChangeRequestReview({ company }: { company: Company }) {
<Group justify="flex-end" gap="sm">
<Button
variant="default"
onClick={() => setRejectId(null)}
disabled={reject.isPending}
onClick={() => setActionTarget(null)}
disabled={reject.isPending || requestChanges.isPending}
>
Cancel
</Button>
<Button
color="red"
loading={reject.isPending}
color={actionTarget?.kind === "reject" ? "red" : "yellow"}
loading={reject.isPending || requestChanges.isPending}
disabled={note.trim().length === 0}
onClick={confirmReject}
onClick={confirmAction}
>
Reject changes
{actionTarget?.kind === "reject"
? "Reject changes"
: "Request changes"}
</Button>
</Group>
</Stack>

View File

@@ -0,0 +1,299 @@
import { Alert, Anchor, Badge, Card, Group, SimpleGrid, Stack, Text } from "@mantine/core";
import { useQuery } from "@tanstack/react-query";
import { FilePlus2, FileX2, History } from "lucide-react";
import { useFileViewer } from "@edr/ui-common";
import { fetchViewableFile } from "@/services/files.service";
import { api } from "@/services/api";
import type {
Company,
CompanyChangeRequest,
CompanyRevision,
CompanyRevisionChange,
DocumentChangeIntent,
LicenseChangeIntent,
} from "@/types/customer";
import { DiffRow, FIELD_LABELS, currentValue } from "./ChangeRequestReview";
import { formatDate, humanize } from "./format";
interface DocDiff {
key: string;
label: string;
fromFile: { id: string; name: string } | null;
toFile: { id: string; name: string } | null;
}
interface FieldDiff {
key: string;
label: string;
from: string;
to: string;
}
interface TimelineEntry {
id: string;
kind: "approved" | "rejected" | "changes_requested" | "revision";
at: string;
note?: string | null;
summary?: string;
fieldDiffs: FieldDiff[];
docDiffs: DocDiff[];
}
const KIND_BADGE: Record<TimelineEntry["kind"], { label: string; color: string }> = {
approved: { label: "Approved", color: "edr-green" },
rejected: { label: "Rejected", color: "red" },
changes_requested: { label: "Changes requested", color: "yellow" },
revision: { label: "Recorded", color: "blue" },
};
/**
* Pair adjacent remove-then-add intents into one before/after doc diff — a
* "replace" is always staged as `[{op:'remove'}, {op:'add'}]` pushed together
* (see `replaceProfileLicenseFile` and friends), and later merges only ever
* append after that pair, so adjacency survives. A remove or add with no
* adjacent partner stands alone.
*/
function pairIntents(
intents: (LicenseChangeIntent | DocumentChangeIntent)[],
labelFor: (intent: LicenseChangeIntent | DocumentChangeIntent) => string,
): DocDiff[] {
const diffs: DocDiff[] = [];
let i = 0;
while (i < intents.length) {
const current = intents[i];
const next = intents[i + 1];
if (current.op === "remove" && next?.op === "add") {
diffs.push({
key: `${current.fileId}-${next.fileId}`,
label: labelFor(next),
fromFile: { id: current.fileId, name: current.fileName ?? "Document" },
toFile: { id: next.fileId, name: next.fileName ?? "Document" },
});
i += 2;
continue;
}
diffs.push({
key: `${current.fileId}-${i}`,
label: labelFor(current),
fromFile:
current.op === "remove"
? { id: current.fileId, name: current.fileName ?? "Document" }
: null,
toFile:
current.op === "add"
? { id: current.fileId, name: current.fileName ?? "Document" }
: null,
});
i += 1;
}
return diffs;
}
/**
* Historical field diffs on a change request only ever recorded the proposed
* ("to") value — there is no stored "before" snapshot — so `from` reads the
* CURRENT company value. That's exact for the most recent entry; for an older
* one it can drift if the field changed again since. A real limitation of the
* data model, not something this view can reconstruct.
*/
function fromChangeRequest(
r: CompanyChangeRequest,
company: Company,
): TimelineEntry {
const proposedKeys = Object.keys(r.snapshot ?? {}).filter(
(k) => k !== "faydaIdentity",
);
const fieldDiffs: FieldDiff[] = proposedKeys.map((key) => ({
key,
label: FIELD_LABELS[key] ?? humanize(key),
from: currentValue(company, key),
to:
r.snapshot[key] === null || r.snapshot[key] === undefined || r.snapshot[key] === ""
? "—"
: String(r.snapshot[key]),
}));
const docDiffs: DocDiff[] = [
...pairIntents(r.licenseChanges, () => "Business license"),
...pairIntents(r.documentChanges, (c) =>
humanize((c as DocumentChangeIntent).code),
),
...r.documentFileIds.map((fileId, i) => ({
key: fileId,
label: "Document",
fromFile: null,
toFile: { id: fileId, name: `Document ${i + 1}` },
})),
];
return {
id: r.id,
kind: r.status as TimelineEntry["kind"],
at: r.reviewedAt ?? r.updatedAt,
note: r.note,
fieldDiffs,
docDiffs,
};
}
function fromRevision(rev: CompanyRevision): TimelineEntry {
const isDocChange = (c: CompanyRevisionChange) => c.field.startsWith("document:");
const fieldDiffs: FieldDiff[] = rev.changes
.filter((c) => !isDocChange(c))
.map((c) => ({ key: c.field, label: c.label, from: c.from ?? "—", to: c.to ?? "—" }));
const docDiffs: DocDiff[] = rev.changes
.filter(isDocChange)
.map((c) => ({
key: c.field,
label: c.label,
fromFile: c.fromFileId ? { id: c.fromFileId, name: c.from ?? "Document" } : null,
toFile: c.toFileId ? { id: c.toFileId, name: c.to ?? "Document" } : null,
}));
return {
id: rev.id,
kind: "revision",
at: rev.createdAt,
summary: rev.summary,
fieldDiffs,
docDiffs,
};
}
/**
* One combined, chronological timeline of everything that's happened to a
* company's record: onboarding-phase edits (no approval gate, from
* `CompanyRevision`) and post-approval settings changes (reviewed via
* `CompanyChangeRequest`) used to live in two separate, differently-shaped
* lists — merged here into one sorted feed so "what changed and when" has a
* single answer instead of two places to check.
*/
export function CompanyTimeline({ company }: { company: Company }) {
const { view, viewer } = useFileViewer();
const changeRequestsQuery = useQuery(
api.customers.changeRequests.queryOptions({ input: { id: company.id } }),
);
const revisionsQuery = useQuery(
api.customers.revisions.queryOptions({ input: { id: company.id } }),
);
const entries: TimelineEntry[] = [
...(changeRequestsQuery.data ?? [])
.filter((r) => r.status !== "pending")
.map((r) => fromChangeRequest(r, company)),
...(revisionsQuery.data ?? []).map(fromRevision),
].sort((a, b) => new Date(b.at).getTime() - new Date(a.at).getTime());
const openFile = (file: { id: string; name: string }) =>
void fetchViewableFile(file.id, file.name).then(view);
if (entries.length === 0) {
return (
<Card withBorder>
<Stack align="center" gap={6} py="xl">
<History size={24} className="text-edr-muted" />
<Text size="sm" c="dimmed">
No changes recorded yet.
</Text>
</Stack>
</Card>
);
}
return (
<Stack gap="md">
{entries.map((entry) => {
const badge = KIND_BADGE[entry.kind];
return (
<Card key={entry.id} withBorder>
<Stack gap="sm">
<Group justify="space-between" wrap="nowrap" align="flex-start">
<Group gap="sm">
<Badge color={badge.color} variant="light" radius="md">
{badge.label}
</Badge>
{entry.summary && (
<Text size="sm" c="edr-text" tt="capitalize">
{entry.summary}
</Text>
)}
</Group>
<Text size="xs" c="dimmed">
{formatDate(entry.at)}
</Text>
</Group>
{entry.note && (
<Alert color="yellow" variant="light">
<Text size="sm">
<strong>Note:</strong> {entry.note}
</Text>
</Alert>
)}
{entry.fieldDiffs.length > 0 && (
<SimpleGrid cols={{ base: 1, sm: 2, lg: 3 }} spacing="lg">
{entry.fieldDiffs.map((f) => (
<DiffRow key={f.key} label={f.label} from={f.from} to={f.to} />
))}
</SimpleGrid>
)}
{entry.docDiffs.length > 0 && (
<Stack gap={8}>
{entry.docDiffs.map((d) => (
<Group key={d.key} gap={8} wrap="nowrap">
<Text size="xs" fw={600} c="edr-muted" tt="uppercase">
{d.label}
</Text>
{d.fromFile && (
<Group gap={4} wrap="nowrap">
<FileX2 size={14} className="text-edr-muted" />
<Anchor
component="button"
type="button"
size="sm"
td="line-through"
onClick={() => openFile(d.fromFile!)}
>
{d.fromFile.name}
</Anchor>
</Group>
)}
{d.fromFile && d.toFile && (
<Text size="sm" c="edr-muted">
</Text>
)}
{d.toFile && (
<Group gap={4} wrap="nowrap">
<FilePlus2 size={14} className="text-edr-muted" />
<Anchor
component="button"
type="button"
size="sm"
onClick={() => openFile(d.toFile!)}
>
{d.toFile.name}
</Anchor>
</Group>
)}
</Group>
))}
</Stack>
)}
{entry.fieldDiffs.length === 0 && entry.docDiffs.length === 0 && (
<Text size="sm" c="dimmed">
No details recorded for this entry.
</Text>
)}
</Stack>
</Card>
);
})}
{viewer}
</Stack>
);
}

View File

@@ -13,6 +13,7 @@ export {
ChangeRequestReview,
ChangeRequestPendingBadge,
} from "./ChangeRequestReview";
export { CompanyTimeline } from "./CompanyTimeline";
export {
RequestDocumentChangeModal,
type RequestDocumentChangeModalProps,

View File

@@ -42,6 +42,8 @@ export const QUERY_KEYS = {
["customers", "detail", id, "reset-target"] as const,
changeRequests: (id: string) =>
["customers", "detail", id, "change-requests"] as const,
revisions: (id: string) =>
["customers", "detail", id, "revisions"] as const,
},
INVOICES: {

View File

@@ -78,10 +78,13 @@ export const URL_CONSTANTS = {
`/companies/company-profiles/${profileId}/status`,
CHANGE_REQUESTS: (companyId: string) =>
`/companies/${companyId}/change-requests`,
REVISIONS: (companyId: string) => `/companies/${companyId}/revisions`,
CHANGE_REQUEST_APPROVE: (id: string) =>
`/companies/change-requests/${id}/approve`,
CHANGE_REQUEST_REJECT: (id: string) =>
`/companies/change-requests/${id}/reject`,
CHANGE_REQUEST_REQUEST_CHANGES: (id: string) =>
`/companies/change-requests/${id}/request-changes`,
DOCUMENT_REQUEST_CHANGE: (fileId: string) =>
`/companies/documents/${fileId}/request-change`,
BOOKINGS_CUSTOMER_VIEW: (id: string) =>

View File

@@ -23,6 +23,7 @@ import {
Download,
Eye,
FileText,
History,
Hourglass,
IdCard,
LayoutGrid,
@@ -40,6 +41,7 @@ import {
ChangeRequestPendingBadge,
ChangeRequestReview,
CompanyStatusBadge,
CompanyTimeline,
CompanyTypeBadge,
InvoiceStatusBadge,
PaymentStatusBadge,
@@ -64,6 +66,7 @@ import {
} from "@/services/files.service";
import { api } from "@/services/api";
import type {
Company,
CompanyProfile,
CustomerBooking,
CustomerDocument,
@@ -78,6 +81,32 @@ import {
type ColumnDef,
} from "@edr/ui-common";
/** Plain-text summary of the company's eTrade-sourced record, downloaded client-side (eTrade returns data, not a document). */
function downloadTinRecord(company: Company) {
const lines = [
`TIN: ${company.tin}`,
`Company name: ${company.name}`,
`Licence number: ${company.licenceNumber ?? ""}`,
`Status: ${company.statusDescription ?? ""}`,
`Date registered: ${company.dateRegistered ?? ""}`,
`Renewed from: ${company.renewedFrom ?? ""}`,
`Renewal date: ${company.renewalDate ?? ""}`,
`Renewed to: ${company.renewedTo ?? ""}`,
`Address: ${[company.region, company.zone, company.woreda, company.kebele, company.houseNo].filter(Boolean).join(", ")}`,
];
const blob = new Blob([lines.join("\n")], {
type: "text/plain;charset=utf-8",
});
const url = URL.createObjectURL(blob);
const a = document.createElement("a");
a.href = url;
a.download = `tin-${company.tin}.txt`;
document.body.appendChild(a);
a.click();
a.remove();
setTimeout(() => URL.revokeObjectURL(url), 60_000);
}
function InfoField({ label, value }: { label: string; value?: string | null }) {
return (
<Stack gap={2}>
@@ -689,6 +718,9 @@ export default function CustomerDetailPage() {
<Tabs.Tab value="invoices" leftSection={<Receipt size={16} />}>
Invoices
</Tabs.Tab>
<Tabs.Tab value="history" leftSection={<History size={16} />}>
History
</Tabs.Tab>
</Tabs.List>
{/* OVERVIEW */}
@@ -757,6 +789,18 @@ export default function CustomerDetailPage() {
<InfoField label="TIN" value={company.tin} />
<InfoField label="VAT number" value={company.vatNumber} />
<InfoField label="FAN number" value={company.fanNumber} />
<InfoField
label="Submitted on"
value={formatDate(company.createdAt)}
/>
<InfoField
label="Approved on"
value={
company.approvedAt
? formatDate(company.approvedAt)
: "Not yet approved"
}
/>
<InfoField
label="Owner identity"
value={
@@ -800,18 +844,29 @@ export default function CustomerDetailPage() {
<Card>
<Stack gap="lg">
<Group gap="xs" wrap="nowrap">
<Text fw={600} c="edr-text">
eTrade registration
</Text>
{hasEtradeRecord ? (
<Badge size="sm" color="edr-green" variant="light">
Verified with eTrade
</Badge>
) : (
<Badge size="sm" color="gray" variant="light">
No eTrade record
</Badge>
<Group gap="xs" wrap="nowrap" justify="space-between">
<Group gap="xs" wrap="nowrap">
<Text fw={600} c="edr-text">
eTrade registration
</Text>
{hasEtradeRecord ? (
<Badge size="sm" color="edr-green" variant="light">
Verified with eTrade
</Badge>
) : (
<Badge size="sm" color="gray" variant="light">
No eTrade record
</Badge>
)}
</Group>
{hasEtradeRecord && (
<ActionIcon
variant="default"
aria-label="Download TIN record"
onClick={() => downloadTinRecord(company)}
>
<Download size={16} />
</ActionIcon>
)}
</Group>
{hasEtradeRecord ? (
@@ -1235,6 +1290,11 @@ export default function CustomerDetailPage() {
</Box>
</Box>
</Tabs.Panel>
{/* HISTORY */}
<Tabs.Panel value="history" pt="lg">
<CompanyTimeline company={company} />
</Tabs.Panel>
</Tabs>
<RequestDocumentChangeModal

View File

@@ -245,6 +245,16 @@ export default function CustomersPage() {
</Text>
),
},
{
id: "approved",
header: "Approved",
meta: { headerClassName: "text-right", cellClassName: "text-right" },
cell: ({ row }) => (
<Text size="sm" c="dimmed">
{row.original.approvedAt ? formatDate(row.original.approvedAt) : "—"}
</Text>
),
},
],
[],
);

View File

@@ -8,6 +8,7 @@ import type {
CompanyChangeRequest,
CompanyListFilter,
CompanyProfile,
CompanyRevision,
CompanyStats,
CustomerBooking,
CustomerDocument,
@@ -2778,6 +2779,13 @@ export const api = {
({ id }) => QUERY_KEYS.CUSTOMERS.changeRequests(id),
),
revisions: endpoint<{ id: string }, CompanyRevision[]>(
"customers",
"revisions",
({ id }) => customersService.revisions(id),
({ id }) => QUERY_KEYS.CUSTOMERS.revisions(id),
),
approveChangeRequest: endpoint<{ id: string }, CompanyChangeRequest>(
"customers",
"approveChangeRequest",
@@ -2802,6 +2810,21 @@ export const api = {
],
),
requestChangeRequestChanges: endpoint<
{ id: string; note: string },
CompanyChangeRequest
>(
"customers",
"requestChangeRequestChanges",
({ id, note }) => customersService.requestChangeRequestChanges(id, note),
undefined,
(_input, data) => [
QUERY_KEYS.CUSTOMERS.changeRequests(data.companyId),
QUERY_KEYS.CUSTOMERS.byId(data.companyId),
QUERY_KEYS.CUSTOMERS.ROOT,
],
),
/**
* Ask the customer to correct one document. Invalidates the documents list
* and the company itself, since an open request blocks role approval.

View File

@@ -5,6 +5,7 @@ import type {
CompanyChangeRequest,
CompanyListFilter,
CompanyProfile,
CompanyRevision,
CompanyStats,
CustomerBooking,
CustomerDocument,
@@ -146,6 +147,13 @@ export const customersService = {
.then((r) => r.data);
},
/** Onboarding-phase edit history for a company (version history), newest first. */
revisions(companyId: string): Promise<CompanyRevision[]> {
return apiClient
.get<CompanyRevision[]>(URL_CONSTANTS.COMPANIES.REVISIONS(companyId))
.then((r) => r.data);
},
/** Approve a pending change request — applies the proposed changes. */
approveChangeRequest(id: string): Promise<CompanyChangeRequest> {
return apiClient
@@ -165,6 +173,19 @@ export const customersService = {
.then((r) => r.data);
},
/** Ask for specific changes without rejecting — the request stays open for the customer's next edit to append to. */
requestChangeRequestChanges(
id: string,
note: string,
): Promise<CompanyChangeRequest> {
return apiClient
.post<CompanyChangeRequest>(
URL_CONSTANTS.COMPANIES.CHANGE_REQUEST_REQUEST_CHANGES(id),
{ note },
)
.then((r) => r.data);
},
/**
* Ask the customer to correct one uploaded document. Narrower than rejecting
* the whole role: the customer keeps their other documents and only re-uploads

View File

@@ -69,7 +69,11 @@ export interface CompanyProfile {
}
/** Lifecycle of a staged customer profile-edit review. */
export type ChangeRequestStatus = "pending" | "approved" | "rejected";
export type ChangeRequestStatus =
| "pending"
| "approved"
| "rejected"
| "changes_requested";
/** A staged business-license add/remove on one profile, awaiting review. */
export interface LicenseChangeIntent {
@@ -110,6 +114,33 @@ export interface CompanyChangeRequest {
updatedAt: string;
}
/**
* One field/document change recorded on a company revision. A document change
* carries `fromFileId`/`toFileId` alongside the display names, so the
* previous and current file can both be opened, not just named.
*/
export interface CompanyRevisionChange {
field: string;
label: string;
from: string | null;
to: string | null;
fromFileId?: string | null;
toFileId?: string | null;
}
/**
* Onboarding-phase edit history — records what changed on a company record
* before it reached Active, the write path that has no approval gate.
*/
export interface CompanyRevision {
id: string;
companyId: string;
actorId: string | null;
summary: string;
changes: CompanyRevisionChange[];
createdAt: string;
}
/** The channel a customer's password-reset link is delivered over. */
export type ResetChannel = "email" | "phone";
@@ -215,6 +246,7 @@ export interface Company {
onboardingCompleted?: boolean;
createdAt: string;
updatedAt: string;
approvedAt?: string | null;
}
/**

View File

@@ -28,6 +28,31 @@ interface ETradeInfoProps {
const isValidTin = (tin: string) => tin.length === 10;
/** Plain-text summary of the fetched eTrade record, downloaded client-side (eTrade returns data, not a document). */
function downloadTinRecord(tin: string, data: CompanyRegistrationData) {
const lines = [
`TIN: ${tin}`,
`Company name: ${data.companyName}`,
`Licence number: ${data.licenceNumber}`,
`Status: ${data.statusDescription}`,
`Date registered: ${data.dateRegistered}`,
`Renewed from: ${data.renewedFrom}`,
`Renewal date: ${data.renewalDate}`,
`Renewed to: ${data.renewedTo}`,
`Address: ${[data.region, data.zone, data.woreda, data.kebele, data.houseNo].filter(Boolean).join(", ")}`,
`Manager: ${data.managerName}`,
];
const blob = new Blob([lines.join("\n")], { type: "text/plain;charset=utf-8" });
const url = URL.createObjectURL(blob);
const a = document.createElement("a");
a.href = url;
a.download = `tin-${tin}.txt`;
document.body.appendChild(a);
a.click();
a.remove();
setTimeout(() => URL.revokeObjectURL(url), 60_000);
}
export default function ETradeInfo({
tin,
register,
@@ -123,6 +148,17 @@ export default function ETradeInfo({
{isLoading ? "Getting..." : "Get Data"}
</Button>
)}
{status === "verified" && mutation.data && !mutation.data.tinTaken && (
<Button
variant="light"
color="edr-green"
onClick={() => downloadTinRecord(tin, mutation.data!)}
leftSection={<Download size={16} />}
mt="24px"
>
Download
</Button>
)}
</Group>
{notFound && (

View File

@@ -1,6 +1,6 @@
import { useQuery } from "@tanstack/react-query";
import { Link } from "react-router-dom";
import { AlertTriangle, ArrowRight, Clock } from "lucide-react";
import { AlertTriangle, ArrowRight, CheckCircle2, Clock } from "lucide-react";
import { api } from "@/services/api";
import useAuth from "@/hooks/useAuth";
import type { OnboardingRequirements } from "@/services/companies.service";
@@ -150,18 +150,46 @@ export default function OnboardingResumeBanner({
/**
* Post-onboarding review banner. Surfaces (in priority order):
* 0. The account is suspended/blacklisted — hard lock.
* 1. A pending profile-edit review — the whole account is locked until an admin
* approves the submitted changes.
* 2. A rejected profile-edit review — links to Settings to amend & resubmit.
* 3. Per-operational-profile approval — bookings unlock as each role clears.
* 2. Backoffice requested changes — soft: same edit-and-resubmit call to
* action as a rejection, but the edit appends to the same request.
* 3. A rejected profile-edit review — links to Settings to amend & resubmit
* (starts a fresh request).
* 4/5. Company- and per-operational-profile approval — bookings unlock as
* each role clears.
* Self-hides when there's nothing outstanding.
*/
export function AccountReviewBanner() {
const { company, reviewStatus, reviewNote } = useAuth();
const { company, companyStatus, reviewStatus, reviewNote } = useAuth();
const profiles = company?.company?.companyProfiles ?? [];
const pending = profiles.filter((p) => p.status === "pending");
const approved = profiles.filter((p) => p.status === "active");
// 0. Account suspended/blacklisted — the hardest lock, takes priority over
// everything else since nothing below matters if the account is shut down.
if (companyStatus === "suspended" || companyStatus === "blacklisted") {
return (
<div className="border-b border-red-200 bg-red-50 px-6 py-3">
<div className="mx-auto flex max-w-6xl items-center gap-3">
<span className="flex h-9 w-9 shrink-0 items-center justify-center rounded-full bg-red-100 text-red-700">
<AlertTriangle size={18} />
</span>
<span className="flex flex-col gap-0.5">
<span className="text-sm font-semibold text-red-900">
Your account has been suspended
</span>
<span className="text-xs text-red-800">
Contact EDR support to resolve this before you can continue
working.
</span>
</span>
</div>
</div>
);
}
// 1. Profile-edit review pending — the account-wide lock.
if (reviewStatus === "pending") {
return (
@@ -184,7 +212,41 @@ export function AccountReviewBanner() {
);
}
// 2. Profile-edit review rejected — prompt to fix & resubmit.
// 2. Backoffice asked for specific changes — soft: same edit-and-resubmit
// call to action as a rejection, but the copy stays collaborative since
// the edit appends to this same request instead of starting over.
if (reviewStatus === "changes_requested") {
return (
<div className="border-b border-amber-200 bg-amber-50 px-6 py-3">
<div className="mx-auto flex max-w-6xl flex-wrap items-center justify-between gap-3">
<div className="flex items-center gap-3">
<span className="flex h-9 w-9 shrink-0 items-center justify-center rounded-full bg-amber-100 text-amber-700">
<AlertTriangle size={18} />
</span>
<span className="flex flex-col gap-0.5">
<span className="text-sm font-semibold text-amber-900">
Changes requested on your submission
</span>
<span className="text-xs text-amber-800">
{reviewNote
? `Reviewer note: ${reviewNote}`
: "Please update the requested details and resubmit for review."}
</span>
</span>
</div>
<Link
to="/settings"
className="inline-flex items-center gap-2 rounded-lg bg-amber-600 px-4 py-2 text-sm font-semibold text-white shadow-sm transition-transform hover:scale-[1.02]"
>
Review &amp; resubmit
<ArrowRight size={16} />
</Link>
</div>
</div>
);
}
// 3. Profile-edit review rejected — prompt to fix & resubmit.
if (reviewStatus === "rejected") {
return (
<div className="border-b border-red-200 bg-red-50 px-6 py-3">
@@ -216,8 +278,45 @@ export function AccountReviewBanner() {
);
}
// 3. Per-operational-profile approval (existing behaviour).
if (profiles.length === 0 || pending.length === 0) return null;
// 4. Company approved and awaiting its first operational profile — nothing
// profile-specific to report yet, but the account itself is pending.
if (profiles.length === 0) {
if (companyStatus === "pending") {
return (
<div className="border-b border-amber-200 bg-amber-50 px-6 py-3">
<div className="mx-auto flex max-w-6xl items-center gap-3">
<span className="flex h-9 w-9 shrink-0 items-center justify-center rounded-full bg-amber-100 text-amber-700">
<Clock size={18} />
</span>
<span className="text-sm font-semibold text-amber-900">
Your account is pending approval
</span>
</div>
</div>
);
}
return null;
}
// 5. Per-operational-profile approval (existing behaviour).
if (pending.length === 0) {
// Nothing outstanding — a quiet confirmation that the account is live.
if (companyStatus === "active") {
return (
<div className="border-b border-emerald-200 bg-emerald-50 px-6 py-3">
<div className="mx-auto flex max-w-6xl items-center gap-3">
<span className="flex h-9 w-9 shrink-0 items-center justify-center rounded-full bg-emerald-100 text-emerald-700">
<CheckCircle2 size={18} />
</span>
<span className="text-sm font-semibold text-emerald-900">
Your account is approved
</span>
</div>
</div>
);
}
return null;
}
const pendingLabel = pending
.map((p) => p.type.replace(/_/g, " "))

View File

@@ -294,6 +294,26 @@ export default function SettingsPage() {
Attorney stay editable.
</Alert>
)}
{reviewStatus === "changes_requested" && (
<Alert
color="yellow"
variant="light"
icon={<AlertTriangle size={18} />}
title="Changes requested on your submission"
>
<Stack gap={4}>
{profile.reviewNote && (
<Text size="sm">
<strong>Reviewer note:</strong> {profile.reviewNote}
</Text>
)}
<Text size="sm">
Please update the requested details below and save again to
resubmit for review.
</Text>
</Stack>
</Alert>
)}
{reviewStatus === "rejected" && (
<Alert
color="red"

View File

@@ -94,10 +94,12 @@ export interface CompanyInfoResponse {
company: CompanyResponse;
/**
* Open profile-edit review, if any. `pending` locks the settings page + new
* contract/booking creation; `rejected` surfaces the note for reapply.
* contract/booking creation; `rejected`/`changes_requested` both surface the
* note for reapply — `changes_requested` just means the edit appends to the
* same request instead of starting a fresh one.
*/
review?: {
status: "pending" | "rejected";
status: "pending" | "rejected" | "changes_requested";
note: string | null;
} | null;
}
@@ -106,7 +108,7 @@ export interface CompanyInfoResponse {
export interface ChangeRequestResponse {
id: string;
companyId: string;
status: "pending" | "approved" | "rejected";
status: "pending" | "approved" | "rejected" | "changes_requested";
snapshot: Record<string, any>;
documentFileIds: string[];
note: string | null;

View File

@@ -51,10 +51,12 @@ export interface ProfileResponse {
profileId: string;
/**
* Open profile-edit review. `pending` → the settings page is read-only until an
* admin decides; `rejected` → the note explains why and the forms prefill the
* declined values so the customer can amend & resubmit.
* admin decides; `rejected`/`changes_requested` → the note explains why and
* the forms prefill the declined values so the customer can amend & resubmit
* (`changes_requested` appends that edit to this same request instead of
* starting a fresh one).
*/
reviewStatus?: "pending" | "rejected" | null;
reviewStatus?: "pending" | "rejected" | "changes_requested" | null;
reviewNote?: string | null;
pendingChanges?: Record<string, any> | null;
}