Skip to content

feat: add glomish as a Fina Connect pairing partner (daily-sales inge… - #52

Merged
compgeniuses merged 1 commit into
mainfrom
dev
Sep 14, 2026
Merged

compgeniuses merged 1 commit into
mainfrom
dev

Conversation

@compgeniuses

Copy link
Copy Markdown
Contributor

…stion)

Register a glomish adapter (features fina_connect + daily_sales.ingest; testConnection hits glomish /api/v1/verify) and render a Glomish integration card in Settings alongside the existing FinaBill card, so a glomish instance can pair and auto-push daily sales.

Generalize connect-service per partner: per-target URLs (GLOMISH_API_URL / GLOMISH_APP_URL), key names from the partner system, and webhook subscription registration for finabill + glomish partners (drops the targetSystem === 'finabill' gate).

Security fixes: hide 'state' from the public session lookup (exposed only after pairing-code proof via the new getConnectSessionWithState) and port the SSRF url-guard into approveAsPartner so credentials are never posted to arbitrary URLs.

Also require initiatorSystem + initiatorApiUrl on /api/connect/complete, and remove the now-unused SIBLING constant.

Description

Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context.

Fixes #(issue)

Type of change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update
  • Refactor (no functional changes)

How Has This Been Tested?

Please describe the tests that you ran to verify your changes.

  • Unit tests
  • Integration tests
  • End-to-end tests
  • Manual testing

Test Configuration:

  • Node.js version:
  • PostgreSQL version:
  • OS:

Checklist:

  • My code follows the project's code style
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation (if applicable)
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • Any dependent changes have been merged and published in downstream modules

Screenshots (if appropriate):

Additional context:

Add any other context about the pull request here.

…stion)

Register a glomish adapter (features fina_connect + daily_sales.ingest; testConnection hits glomish /api/v1/verify) and render a Glomish integration card in Settings alongside the existing FinaBill card, so a glomish instance can pair and auto-push daily sales.

Generalize connect-service per partner: per-target URLs (GLOMISH_API_URL / GLOMISH_APP_URL), key names from the partner system, and webhook subscription registration for finabill + glomish partners (drops the targetSystem === 'finabill' gate).

Security fixes: hide 'state' from the public session lookup (exposed only after pairing-code proof via the new getConnectSessionWithState) and port the SSRF url-guard into approveAsPartner so credentials are never posted to arbitrary URLs.

Also require initiatorSystem + initiatorApiUrl on /api/connect/complete, and remove the now-unused SIBLING constant.
@compgeniuses
compgeniuses merged commit 2f56cf4 into main Sep 14, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant