Fix/supp ag fb (#1023)
* fix: prevent credit notes from entering payment flow * fix: persist and display customer personal numbers * feat: configure automatic invoice reminder days * fix: issue credit notes through send flow * chore: add repository agent guidance * feat(mcp): route tools across user companies * fix(articles): delete unused register entries * feat(invoices): improve issued invoice actions * feat(supplier-invoices): retain uploaded source documents * docs: record implementation decisions * feat: enhance customer personal number handling and validation - Updated CustomerForm to allow personal numbers in the format of "********-1234" for individual customers. - Added validation to ensure personal numbers are only accepted for individual customers in CreateCustomerSchema. - Implemented masking and encryption for personal numbers to enhance data protection. - Introduced new utility functions for masking and encrypting personal numbers. - Added database migration to enforce unique constraints on credit note relationships and prevent duplicate entries. - Enhanced error handling and logging for credit note issuance and invoice processing. - Updated tests to cover new credit note creation guards and personal number handling. * test: enhance list companies test with supabase query mocks
This commit is contained in:
@@ -0,0 +1,25 @@
|
||||
# Data Classification and Handling
|
||||
|
||||
## Restricted data
|
||||
|
||||
Swedish personal identity numbers are Restricted personal data. They are not an
|
||||
Article 9 special category by themselves, but their stable government identifier
|
||||
role requires heightened protection.
|
||||
|
||||
Controls:
|
||||
|
||||
- Customer personal numbers are accepted only for individual customers.
|
||||
- Values are encrypted with AES-256-GCM before database storage.
|
||||
- API and UI output exposes only the last four digits.
|
||||
- Writes require an authenticated company member with write permission.
|
||||
- RLS and explicit `company_id` filters enforce tenant isolation.
|
||||
- There is no endpoint that returns the full value.
|
||||
- Logs and audit event payloads must never contain the full value.
|
||||
|
||||
## Internal business data
|
||||
|
||||
Article master records are Internal business data. An unused article may be
|
||||
deleted because issued invoice lines, archived invoice PDFs, journal entries,
|
||||
and audit events retain the accounting evidence independently. Any article that
|
||||
is referenced by an invoice line is protected by the application check and the
|
||||
database foreign key.
|
||||
Reference in New Issue
Block a user