feat(reconciliation): match migrated bank history against imported SIE verifikat (#1598)

* feat(reconciliation): match migrated bank history against imported SIE verifikat

A first-class Fortnox/SIE migrator path: after SIE import plus bank connect
or bank CSV upload, historical bank rows are auto-matched (>= 0.9) or
suggestion-matched (0.75-0.89, persisted for review) against the imported
verifikat, with a guided review surface, instead of landing as anonymous
"Att bokfora" rows.

Phase 0: per-cash-account unattended sweep (fixes #1298 cross-account
pooling); widen payment_match_log action CHECK with
linked_to_existing_voucher (silently unlogged since March).
Phase 1: potential_journal_entry_id/method/confidence on transactions with
CHECK + invalidation triggers; persistSuggestions in runReconciliation;
sweep after bank CSV import with SIE overlap (suppressing
auto-categorization); sweep summaries stamped on bank_connections and
bank_file_imports; POST /api/reconciliation/bank/confirm-suggestions with
per-pair server-side revalidation (voucher consumption + bank-leg amount
and direction).
Phase 2: "Granska forslag" review tab on Transactions with chunked bulk
confirm, per-row fallbacks, "Kor matchning igen" (all_accounts sweep mode,
mutually exclusive with dry_run), attn line, pre-migration row marker.
Phase 3: ImportResultStep dual CTA (bank connect + CSV), migrator variant
of the account-picker #917 nudge, sweep outcome on the onboarding
checklist bank step.

Non-selection apply runs on /api/reconciliation/bank/run now floor at 0.9
and persist the review band instead of auto-committing fuzzy matches.
Migrations already applied to staging under the same versions.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(reconciliation): resolve PR review findings in one pass

Swedish accounting review (both previously-deferred holes closed):
- runReconciliation's >= 0.9 auto-apply now writes 'matched' to
  payment_match_log (behandlingshistorik, BFNAR 2013:2 kap 8); the bus
  event alone lands in the 30-day event_log and is not an audit record.
- The three match-route storno-conflict branches detach reconciliation
  links via unlinkReconciliation instead of storno-reversing the linked
  verifikat: a reconciliation link points at an independent verifikat
  that may evidence other affarshandelser, and a wholesale reversal is
  an over-broad rattelse (BFL 5 kap 5 §).
- Historical gap quantified on prod (read-only, recorded in DECISIONS):
  762 unlogged manual links across 52 companies since 2026-03-23.

CodeRabbit:
- confirm-suggestions route: maxDuration 300 for full 500-item batches.
- AccountPickerDialog: migrator-nudge buttons set lookbackTouched so the
  async gap-fill probe cannot override an explicit choice.
- enable-banking post-backfill sweep: persistSuggestions so the review
  band is not dropped.
- bank-file execute: sie_sweep stamp errors are logged, not swallowed.
- ImportResultStep: sandbox keeps the CSV CTA (file import works there).
- payment_match_log CHECK swap: NOT VALID + VALIDATE, no table scan
  under ACCESS EXCLUSIVE.
- logMatchEvent calls awaited (serverless can freeze unawaited work).
- DECISIONS.md stale version reference annotated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(reconciliation): defer reconciliation-link detach until the match commits

Round-2 review findings:
- CodeRabbit: the eager unlinkReconciliation call could orphan a
  transaction if the match flow failed after it. All three match routes
  now persist NOTHING up front: the final transaction update overwrites
  journal_entry_id and clears reconciliation_method in the same write,
  so any failure in between leaves the existing link intact. The release
  is logged as 'unmatched' after the commit.
- Swedish review: the auto_suggested logMatchEvent in runReconciliation
  is now awaited like every other audit write.
- DECISIONS entry split into compliance/CodeRabbit lines and updated to
  describe the deferred detach.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(reconciliation): literal reconciliation_method payloads for the phantom-column scanner

The conditional spreads introduced with the deferred detach pushed the
scanner's unresolvable-expression count past its ceiling (380 > 378).
reconciliation_method: null is correct unconditionally on a confirmed
invoice/supplier match (null is already the value on every row that was
not reconciliation-linked), so the payloads become plain literals the
guard can verify. No behavior change.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-08-13 23:12:27 +02:00
committed by GitHub
co-authored by Claude Fable 5
parent 07e89d9b52
commit 08440fed94
35 changed files with 3223 additions and 99 deletions
@@ -95,6 +95,8 @@ export function AccountPickerDialog({
// user must see why and be able to correct the picks.
const [saveError, setSaveError] = useState<string | null>(null)
const [lastBookedDate, setLastBookedDate] = useState<string | null>(null)
// Earliest completed SIE import coverage start: present = migrator flow.
const [sieCoverageStart, setSieCoverageStart] = useState<string | null>(null)
const [chartAccounts, setChartAccounts] = useState<ChartAccount[]>([])
const [chartError, setChartError] = useState(false)
const [ledgerByUid, setLedgerByUid] = useState<Record<string, string>>({})
@@ -203,23 +205,43 @@ export function AccountPickerDialog({
// fiscal period's end, which can lie months past the last actually booked
// transaction and would make the user skip everything unbooked in between.
// Only matters on the initial activation flow: selection edits don't re-run sync.
//
// Alongside it: the earliest completed SIE import's coverage start. For a
// migrator the right move is the OPPOSITE of skipping the booked overlap:
// fetch the whole period and let the post-sync sweep match bank rows against
// the imported verifikat. The nudge below flips accordingly.
useEffect(() => {
if (!open || !isInitialSelection || !company?.id) {
setLastBookedDate(null)
setSieCoverageStart(null)
return
}
let cancelled = false
;(async () => {
const { data } = await supabase
.from('journal_entries')
.select('entry_date')
.eq('company_id', company.id)
.eq('status', 'posted')
.order('entry_date', { ascending: false })
.limit(1)
.maybeSingle()
const [entryRes, sieRes] = await Promise.all([
supabase
.from('journal_entries')
.select('entry_date')
.eq('company_id', company.id)
.eq('status', 'posted')
.order('entry_date', { ascending: false })
.limit(1)
.maybeSingle(),
supabase
.from('sie_imports')
.select('fiscal_year_start')
.eq('company_id', company.id)
.eq('status', 'completed')
.not('fiscal_year_start', 'is', null)
.order('fiscal_year_start', { ascending: true })
.limit(1)
.maybeSingle(),
])
if (cancelled) return
setLastBookedDate((data as { entry_date?: string } | null)?.entry_date || null)
setLastBookedDate((entryRes.data as { entry_date?: string } | null)?.entry_date || null)
setSieCoverageStart(
(sieRes.data as { fiscal_year_start?: string } | null)?.fiscal_year_start || null,
)
})()
return () => { cancelled = true }
}, [open, isInitialSelection, company?.id, supabase])
@@ -588,7 +610,65 @@ export function AccountPickerDialog({
</p>
</div>
{bookedCoverage && (
{sieCoverageStart ? (
<div className="space-y-2 rounded-md border border-border bg-background/60 p-3">
{/* Migrator flow: a completed SIE import exists, so the booked
overlap is exactly what the post-sync sweep matches bank
rows against. Pulling from the SIE year's start is the
recommended move; skipping the overlap (the non-migrator
nudge) would leave the imported verifikat unreconciled. */}
<div className="flex items-start justify-between gap-3">
<p className="text-xs text-muted-foreground">
Du har importerat bokföring. Hämta bankhistorik från{' '}
<span className="font-medium tabular-nums text-foreground">{sieCoverageStart}</span>{' '}
(importens början) så matchar vi transaktionerna automatiskt mot din importerade
bokföring i stället för att bokföra dem igen.
</p>
<button
type="button"
className="shrink-0 text-xs text-foreground underline underline-offset-2"
onClick={() => {
// Explicit choice: the async gap-fill probe must not
// override it if it resolves after this click.
lookbackTouched.current = true
setLookbackMode('custom')
setCustomSubMode('date')
setCustomDate(sieCoverageStart)
}}
disabled={isSaving}
>
Hämta från detta datum
</button>
</div>
{daysBetween(sieCoverageStart) > 90 && (
<p className="text-xs text-muted-foreground">
De flesta banker lämnar bara ut ca 90 dagars historik via bankkopplingen. Når
hämtningen inte hela vägen tillbaka kan du ladda upp kontoutdrag (CSV) under{' '}
<span className="font-medium">Importera</span> för den äldre perioden, matchningen
fungerar likadant.
</p>
)}
{bookedCoverage && (
<p className="text-xs text-muted-foreground">
Vill du ändå hoppa över det som redan är bokfört kan du{' '}
<button
type="button"
className="text-foreground underline underline-offset-2"
onClick={() => {
lookbackTouched.current = true
setLookbackMode('custom')
setCustomSubMode('date')
setCustomDate(bookedCoverage.suggestedStartDate)
}}
disabled={isSaving}
>
börja från {bookedCoverage.suggestedStartDate}
</button>{' '}
i stället.
</p>
)}
</div>
) : bookedCoverage && (
<div className="flex items-start justify-between gap-3 rounded-md border border-border bg-background/60 p-3">
{/* Stated as a fact with an opt-in shortcut, not as "vi
föreslår": the selected default below is the fiscal-year
+32 -9
View File
@@ -13,6 +13,10 @@ import {
} from './lib/api-client'
import { syncAccountTransactions } from './lib/sync'
import { findReusableSessions, countLiveSiblings } from './lib/session-sharing'
import {
runUnattendedReconciliationSweep,
toSweepSummary,
} from '@/lib/reconciliation/unattended-sweep'
import {
runReconciliation,
DEFAULT_UNATTENDED_CONFIDENCE_THRESHOLD,
@@ -762,22 +766,38 @@ export const enableBankingExtension: Extension = {
// When SIE overlap is detected, run a batch reconciliation sweep.
// The greedy algorithm considers all candidates globally (highest-
// confidence first) and catches matches the inline per-transaction
// pass may have missed due to processing order.
// pass may have missed due to processing order. One scoped run per
// enabled cash account (issue #1298): the pooled run could persist a
// cross-account journal_entry_id.
// Skip for viewers: reconciliation updates transactions which viewers cannot do.
if (sieOverlap && totalImported > 0 && !isViewer) {
try {
const reconResult = await runReconciliation(supabase, companyId, user.id, {
dateFrom: fromDate,
dateTo: toDate,
// This sweep applies without a human reviewing a dry-run, so
// never commit low-confidence (fuzzy / date-range) matches.
confidenceThreshold: DEFAULT_UNATTENDED_CONFIDENCE_THRESHOLD,
})
const reconResult = await runUnattendedReconciliationSweep(
supabase,
companyId,
user.id,
{ dateFrom: fromDate, dateTo: toDate },
)
// Stamp the outcome so the UI can render "Vi matchade X av Y" and
// the review surface knows there is something to granska.
await supabase
.from('bank_connections')
.update({
last_sie_sweep: toSweepSummary(reconResult, {
dateFrom: fromDate,
dateTo: toDate,
}),
})
.eq('id', connection.id)
if (reconResult.applied > 0 || reconResult.skippedBelowThreshold > 0) {
log.info('Post-sync batch reconciliation matched additional transactions', {
applied: reconResult.applied,
skippedBelowThreshold: reconResult.skippedBelowThreshold,
total: reconResult.matches.length,
accounts: reconResult.accounts.map((a) => ({
accountNumber: a.accountNumber,
applied: a.applied,
skippedBelowThreshold: a.skippedBelowThreshold,
})),
})
}
} catch {
@@ -1483,6 +1503,9 @@ export const enableBankingExtension: Extension = {
// Unattended run: nobody reviews a dry-run first, so never
// commit low-confidence (fuzzy / date-range) matches.
confidenceThreshold: DEFAULT_UNATTENDED_CONFIDENCE_THRESHOLD,
// ...but don't DROP them either: the 0.75-0.89 band feeds
// the "Granska förslag" review surface.
persistSuggestions: true,
})
totalAutoMatched += reconResult.applied
if (reconResult.applied > 0 || reconResult.skippedBelowThreshold > 0) {