feat: arcim inbox (Resend Inbound) + smart-match extension + commit metadata (#286)
* feat: multi-series SIE import, reusable FiscalYearSelector, library templates in picker - SIE import preserves each voucher's source series (B/C/I/V/...), essential for Fortnox migrations where series carry semantic meaning (kundfakturor, inbetalningar, etc.). Target numbering still goes through next_voucher_number per series; source (series, number) is stored in the migration mapping for BFNAR 2013:2 audit trail. - Execute route reads company_settings.default_voucher_series as the fallback for vouchers arriving without a series (SIE4I). - Extract shared FiscalYearSelector component; adopt in /reports and /bookkeeping. - Transaction TemplatePicker now surfaces user-created library templates (company + team scope) alongside the static registry, with a helper to convert simple library templates into the BookingTemplate shape. - Exclude 8999 "Årets resultat" from income statement financial section and monthly breakdown so year-end closing entries don't cancel the net result. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * test: skip Bokio SIE regression when fixtures are absent /dev_docs is gitignored (contains anonymised customer exports), so the integration test can't find its input files in CI. Gate the suite on fixture presence so it still runs locally. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: address Greptile review feedback - convertLibraryToBookingTemplate: default entity_applicability to 'all' when the source template has no entity_type, so TemplatePicker doesn't silently hide it for companies with a set entity type. - FiscalYearSelector: fire onReady in the no-company early-return branch so consumers (e.g. ReportsPage) don't get stuck in a loading skeleton while the company context is still hydrating. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * feat: arcim inbox + smart-match extension + commit metadata Three threads, all gated off in extensions.config.json (invoice-inbox and inbox-smart-match are not in the enabled list for this PR). invoice-inbox: Gmail OAuth -> Resend Inbound (v2.0.0) - Remove gmail-scanner / gmail-helpers - Add resend-inbound.ts (webhook verify, attachment fetch) and inbox-provisioning.ts (per-company @arcim.io address with rotation) - Replace /gmail/* routes with /inbox/address and admin-only /inbox/rotate - Workspace UI: card layout + MatchBlock surfacing AI transaction matches - classify-document: tightened discount/total prompt; cap confidence at 50% when line items do not reconcile with amount_incl_vat - Manifest requires RESEND_API_KEY, RESEND_INBOUND_DOMAIN, RESEND_INBOUND_WEBHOOK_SECRET inbox-smart-match (new extension) - Event-driven AI matching of receipts to bank transactions - Listens on inbox_item.classified (match now) and transaction.synced (retro-match receipts waiting for a transaction) - Uses service-role client; processing_history append is scoped by company_id from the event payload commit metadata + audit plumbing - journal_entries gains commit_method and rubric_version columns - commit_journal_entry RPC accepts both (BFNAR 2013:2 behandlingshistorik) - processing-history PII detector strips UUID-shaped substrings before personnummer pattern matching (UUIDs were triggering false positives) - New generic inbox_item.classified event Migrations - arcim_inbox: company_inboxes table, resend_email_id, email_body_text, auto-provision trigger, drops obsolete email_connections - journal_entry_commit_metadata: new columns + updated RPC - inbox_attachment_composite: resend_attachment_id + composite unique index - inbox_smart_match: correlation_id, match_reasoning, expanded match_method CHECK, pending-match and correlation indexes Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
dfb953638c
commit
0076aa85f8
@@ -66,6 +66,8 @@ describe('voucher number atomicity', () => {
|
||||
expect(supabase.rpc).toHaveBeenCalledWith('commit_journal_entry', {
|
||||
p_company_id: 'co-1',
|
||||
p_entry_id: 'entry-1',
|
||||
p_commit_method: null,
|
||||
p_rubric_version: null,
|
||||
})
|
||||
|
||||
// from() was never called — the RPC handles everything atomically
|
||||
@@ -102,6 +104,8 @@ describe('voucher number atomicity', () => {
|
||||
expect(supabase.rpc).toHaveBeenCalledWith('commit_journal_entry', {
|
||||
p_company_id: 'co-1',
|
||||
p_entry_id: 'entry-1',
|
||||
p_commit_method: null,
|
||||
p_rubric_version: null,
|
||||
})
|
||||
// from() called once to fetch the complete entry with lines
|
||||
expect(supabase.from).toHaveBeenCalledWith('journal_entries')
|
||||
|
||||
@@ -245,7 +245,9 @@ export async function commitEntry(
|
||||
supabase: SupabaseClient,
|
||||
companyId: string,
|
||||
userId: string,
|
||||
entryId: string
|
||||
entryId: string,
|
||||
commitMethod?: string,
|
||||
rubricVersion?: string
|
||||
): Promise<JournalEntry> {
|
||||
|
||||
// Atomic: increment voucher sequence + update status in one transaction.
|
||||
@@ -253,6 +255,8 @@ export async function commitEntry(
|
||||
const { data: rpcResult, error: commitError } = await supabase.rpc('commit_journal_entry', {
|
||||
p_company_id: companyId,
|
||||
p_entry_id: entryId,
|
||||
p_commit_method: commitMethod ?? null,
|
||||
p_rubric_version: rubricVersion ?? null,
|
||||
})
|
||||
|
||||
if (commitError) {
|
||||
@@ -286,10 +290,12 @@ export async function createJournalEntry(
|
||||
supabase: SupabaseClient,
|
||||
companyId: string,
|
||||
userId: string,
|
||||
input: CreateJournalEntryInput
|
||||
input: CreateJournalEntryInput,
|
||||
commitMethod?: string,
|
||||
rubricVersion?: string
|
||||
): Promise<JournalEntry> {
|
||||
const draft = await createDraftEntry(supabase, companyId, userId, input)
|
||||
return commitEntry(supabase, companyId, userId, draft.id)
|
||||
return commitEntry(supabase, companyId, userId, draft.id, commitMethod, rubricVersion)
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -74,6 +74,8 @@ export type CoreEvent =
|
||||
| { type: 'supplier_invoice.received'; payload: { inboxItem: InvoiceInboxItem; userId: string; companyId: string } }
|
||||
| { type: 'supplier_invoice.extracted'; payload: { inboxItem: InvoiceInboxItem; confidence: number; userId: string; companyId: string } }
|
||||
| { type: 'supplier_invoice.confirmed'; payload: { inboxItem: InvoiceInboxItem; supplierInvoice: SupplierInvoice; userId: string; companyId: string } }
|
||||
// Generic inbox classification (fires for all document_types after classify)
|
||||
| { type: 'inbox_item.classified'; payload: { inboxItem: InvoiceInboxItem; documentType: 'supplier_invoice' | 'receipt' | 'government_letter' | 'unknown'; confidence: number | null; correlationId: string; userId: string; companyId: string } }
|
||||
// Salary
|
||||
| { type: 'salary_run.created'; payload: { salaryRunId: string; periodYear: number; periodMonth: number; userId: string; companyId: string } }
|
||||
| { type: 'salary_run.approved'; payload: { salaryRunId: string; approvedBy: string; userId: string; companyId: string } }
|
||||
|
||||
@@ -48,8 +48,8 @@ describe('sectors registry', () => {
|
||||
expect(SECTORS.length).toBe(1)
|
||||
})
|
||||
|
||||
it('should have 10 total extensions', () => {
|
||||
expect(getAllExtensions().length).toBe(10)
|
||||
it('should have 11 total extensions', () => {
|
||||
expect(getAllExtensions().length).toBe(11)
|
||||
})
|
||||
|
||||
it('should have unique slugs within each sector', () => {
|
||||
@@ -94,7 +94,7 @@ describe('sectors registry', () => {
|
||||
|
||||
it('getExtensionsBySector returns extensions for a sector', () => {
|
||||
const extensions = getExtensionsBySector('general')
|
||||
expect(extensions.length).toBe(10)
|
||||
expect(extensions.length).toBe(11)
|
||||
})
|
||||
|
||||
it('all extensions have required fields', () => {
|
||||
|
||||
@@ -33,9 +33,21 @@ const PII_PATTERNS = [
|
||||
/\b\d{8}-?\d{4}\b/, // 12-digit variant (YYYYMMDD-NNNN) or orgnr
|
||||
]
|
||||
|
||||
// UUIDs (RFC 4122, 8-4-4-4-12 hex layout) frequently contain all-digit segments
|
||||
// that incorrectly match the 8+4 personnummer pattern — e.g. `57484518-3409-...`.
|
||||
// Strip UUID-shaped substrings before PII matching so legitimate identifiers
|
||||
// aren't rejected. Personnummer always sit outside the UUID shape, so this keeps
|
||||
// the original safety intent intact.
|
||||
const UUID_PATTERN = /[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}/gi
|
||||
|
||||
function stringContainsPii(value: string): boolean {
|
||||
const stripped = value.replace(UUID_PATTERN, '')
|
||||
return PII_PATTERNS.some(pattern => pattern.test(stripped))
|
||||
}
|
||||
|
||||
function containsPii(value: unknown): boolean {
|
||||
if (typeof value === 'string') {
|
||||
return PII_PATTERNS.some(pattern => pattern.test(value))
|
||||
return stringContainsPii(value)
|
||||
}
|
||||
if (Array.isArray(value)) {
|
||||
return value.some(containsPii)
|
||||
@@ -52,7 +64,7 @@ const piiSafePayload = z.record(z.string(), z.unknown()).refine(
|
||||
)
|
||||
|
||||
function assertActorPiiSafe(actor: ProcessingHistoryActor): void {
|
||||
if (actor.label && PII_PATTERNS.some(p => p.test(actor.label!))) {
|
||||
if (actor.label && stringContainsPii(actor.label)) {
|
||||
throw new Error(
|
||||
'actor.label contains PII (personnummer/samordningsnummer/orgnr pattern). Use a pseudonymous descriptor only.'
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user