fix(suppliers): one 10-digit org number key for matching and storage (#2405)

* fix(suppliers): one 10-digit org number key for matching and storage

Why the problem occurred: the supplier register was written in three
spellings (the form asks for XXXXXX-XXXX, the v1 API and the MCP tool stored
whatever the caller sent, the AI extractor emits bare digits) while
matchSupplierByIdentity compared raw strings with .eq(). The canonical rule
existed three times (normalizeOrgNumber, the MCP fuzzy pass's orgNumberKey,
the extractor's toOrg10) and nowhere on the path that decides a match, so
every AI-extracted invoice from a hyphen-registered supplier missed the
strongest key and fell to exact-name matching. Prod holds 1738 hyphenated
rows against 493 bare ones.

What was removed or simplified: orgNumberKey (digits only, 10 kept, last 10
of 12, no Luhn) moves into lib/invariants/org-number.ts and replaces the two
other copies. The matcher scans the company's suppliers with an org_number
and compares keys, the same shape as its vat_number branch, so rows written
before the backfill (and self-hosted instances that never run it) match too.
CreateSupplierSchema, UpdateSupplierSchema and the staged create_supplier
schema store the key; the form renders it through formatOrgNumberDisplay.
A backfill migration strips the formatting from existing rows, skipping
migration-reset source companies.

Why this and not the proposed one: the issue's third layer (CHECK plus a
unique index) would fail to create on prod, which holds 94 duplicate
(company_id, key) groups across 18 companies, one of them 124 rows under a
single placeholder-looking number; that needs a merge decision first and is
filed as #2404. Rejecting anything that is not 10 or 12 digits on write was
also dropped: 68 prod rows carry foreign registration numbers (DK, DE, NL,
FI, GB, IE, US, CZ, IT) in org_number, so Swedish-shaped input is
canonicalised and anything else is stored as typed. Luhn stays lenient on
suppliers because two rows with the same mistyped number are one supplier
and parties is Luhn-strict at promotion already.

Fixes #2391

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013yCehdxm8yUubGAmoDFZag

* fix(suppliers): key only Swedish-shaped org numbers, search and dedup through the key

Skeptic pass on the previous commit. Three refutations, all confirmed:

1. orgNumberKey took the last 10 of any 12 digits and stripped letters. A
   VAT number typed into the org field (SE556012579001, orgnr + 01) keyed to
   6012579001, another company's identity, on every write path and in the
   backfill; 26 prod rows hold exactly that shape (prefixes 55/52/87). A
   Belgian BE0123456789 lost its country letters the same way. The key now
   strips only hyphens and spaces and unprefixes 12 digits only behind
   16/18/19/20; everything else is null, stored and compared as typed. The
   migration carries the same rule.
2. The supplier list search, the v1 ?search= filter and the list column all
   used the raw stored value, so a user searching 556677-88 after the
   backfill found nothing. Both searches now compare without separators and
   the column renders XXXXXX-XXXX.
3. Storage was not canonical on every path: the CSV import and the provider
   migration orchestrator wrote as typed and keyed their re-sync dedup by
   the raw value, so a Fortnox re-sync sending 556677-8899 would have
   duplicated the now-bare row. Both write and key through orgNumberKey.

Also: the matcher scans live suppliers only, so a register holding an
archived hyphenated row next to its live replacement resolves to the live
one instead of whichever id sorts first.

Refs #2391

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013yCehdxm8yUubGAmoDFZag

* fix(suppliers): review pass: foreign numbers survive display and dedup, stub key canonical

CodeRabbit findings on PR #2405, all verified against the code:

- The supplier list rendered through formatOrgNumber, which strips letters
  and would show BE0123456789 as 012345-6789; it now uses
  formatOrgNumberDisplay, which leaves anything not Swedish-shaped alone.
- The CSV import dedup fell back to digits-only, so BE0123456789 and
  FR0123456789 collided; the fallback is now the value as typed, in both
  the parse preview and the execute route.
- The provider migration's supplier-invoice stub map was keyed by the raw
  provider value while the stored row was canonical, so 556677-8899 and
  5566778899 on two invoices produced two stubs; the key goes through
  orgMapKey like the other maps.
- v1 response examples show the stored 10-digit form; the request example
  keeps the hyphenated input.

Refs #2391

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013yCehdxm8yUubGAmoDFZag

* docs(api-skill): regenerate suppliers reference for the canonical org_number example

Refs #2391

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013yCehdxm8yUubGAmoDFZag

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-09-08 10:59:20 +02:00
committed by GitHub
co-authored by Claude Fable 5.1
parent eea410c42b
commit 2303f75a7b
23 changed files with 586 additions and 82 deletions
+29
View File
@@ -868,6 +868,35 @@ describe('CreateSupplierSchema', () => {
expect(result.data.email).toBeUndefined()
}
})
// #2391: the form asks for XXXXXX-XXXX, the extractor emits bare digits;
// storage is the 10-digit key so the matcher's exact key finds the row.
it('stores a Swedish org number as its 10-digit key whatever the caller typed', () => {
for (const typed of ['556677-8899', '5566778899', '556677 8899', '165566778899']) {
const result = CreateSupplierSchema.safeParse(validSupplier({ org_number: typed }))
expect(result.success, typed).toBe(true)
if (result.success) expect(result.data.org_number).toBe('5566778899')
}
})
it('stores a foreign registration number or a VAT number as typed', () => {
for (const typed of ['DK12345678', 'BE0123456789', 'SE556677889901', '556677889901']) {
const result = CreateSupplierSchema.safeParse(
validSupplier({ supplier_type: 'eu_business', country: 'DK', org_number: typed }),
)
expect(result.success, typed).toBe(true)
if (result.success) expect(result.data.org_number).toBe(typed)
}
})
it('canonicalises org_number on update too', () => {
const result = UpdateSupplierSchema.safeParse({ org_number: '556677-8899' })
expect(result.success).toBe(true)
if (result.success) expect(result.data.org_number).toBe('5566778899')
const untouched = UpdateSupplierSchema.safeParse({ name: 'Renamed AB' })
expect(untouched.success).toBe(true)
if (untouched.success) expect(untouched.data.org_number).toBeUndefined()
})
})
// ============================================================
+13 -1
View File
@@ -9,6 +9,7 @@ import {
fiscalYearSchema,
} from '@/lib/invariants/zod'
import { ISO_DATE_RE, ISO_DATE_MESSAGE_SV } from '@/lib/invariants/iso-date'
import { orgNumberKey } from '@/lib/invariants/org-number'
import { countCalendarMonths } from '@/lib/bookkeeping/accruals/compute'
import { DimensionsBagSchema } from '@/lib/bookkeeping/dimension-resolver'
import { validateEmployeeBankAccount } from '@/lib/salary/payment/bank-account'
@@ -1211,6 +1212,17 @@ function emptyStringAsUndefined<T extends z.ZodTypeAny>(inner: T) {
)
}
/**
* suppliers.org_number is stored as the 10-digit key (#2391): the form asks
* for XXXXXX-XXXX and the AI extractor emits bare digits, and the matcher
* compares through the same key, so storage is canonical whatever the caller
* typed. Only Swedish-shaped input (10 or 12 digits once separators are
* stripped) is rewritten; a foreign registration number or an unrecognised
* value is stored as typed, because eu_business and non_eu_business
* suppliers keep their home-registry number in this column.
*/
const supplierOrgNumber = z.string().transform((v) => orgNumberKey(v) ?? v.trim())
export const CreateSupplierSchema = z.object({
name: z.string().min(1, 'Supplier name is required'),
supplier_type: SupplierTypeSchema,
@@ -1221,7 +1233,7 @@ export const CreateSupplierSchema = z.object({
postal_code: z.string().optional(),
city: z.string().optional(),
country: CountryCodeSchema,
org_number: z.string().optional(),
org_number: supplierOrgNumber.optional(),
vat_number: z.string().optional(),
bankgiro: z.string().optional(),
plusgiro: z.string().optional(),
@@ -1,6 +1,7 @@
import { describe, it, expect } from 'vitest'
import {
normalizeOrgNumber,
orgNumberKey,
isValidOrgNumber,
isOrgNumberShaped,
hasInvalidOrgNumberCheckDigit,
@@ -60,6 +61,45 @@ describe('shape versus check digit', () => {
})
})
describe('orgNumberKey', () => {
it('reduces every spelling of the same identity to 10 digits', () => {
expect(orgNumberKey(AB_10)).toBe(AB_10)
expect(orgNumberKey('556012-5790')).toBe(AB_10)
expect(orgNumberKey('556012 5790')).toBe(AB_10)
expect(orgNumberKey('165560125790')).toBe(AB_10)
expect(orgNumberKey('16556012-5790')).toBe(AB_10)
expect(orgNumberKey(' 556012 - 5790 ')).toBe(AB_10)
expect(orgNumberKey('19800101-1231')).toBe(EF_10)
expect(orgNumberKey('198001011231')).toBe(EF_10)
})
it('keeps a VAT number typed into the org field out of the key space', () => {
// 556012579001 is orgnr + "01"; its last 10 digits are another identity.
expect(orgNumberKey('556012579001')).toBeNull()
expect(orgNumberKey('SE556012579001')).toBeNull()
expect(orgNumberKey('SE 556012-5790 01')).toBeNull()
})
it('does not strip letters: a foreign 10-digit registration is not a Swedish number', () => {
expect(orgNumberKey('BE0123456789')).toBeNull()
expect(orgNumberKey('SE5560125790')).toBeNull()
})
it('does not check the Luhn digit: two rows with the same mistyped number are one supplier', () => {
expect(orgNumberKey('5560125791')).toBe('5560125791')
expect(normalizeOrgNumber('5560125791')).toBeNull()
})
it('returns null for anything not org-number shaped', () => {
expect(orgNumberKey('DK12345678')).toBeNull()
expect(orgNumberKey('12345')).toBeNull()
expect(orgNumberKey('12345678901')).toBeNull()
expect(orgNumberKey('')).toBeNull()
expect(orgNumberKey(null)).toBeNull()
expect(orgNumberKey(undefined)).toBeNull()
})
})
describe('formatOrgNumberDisplay', () => {
it('renders NNNNNN-NNNN from any accepted input form', () => {
expect(formatOrgNumberDisplay(AB_10)).toBe('556012-5790')
+1 -1
View File
@@ -35,7 +35,7 @@ export {
export {
stripOrgNumberFormatting,
orgNumberKey,
isOrgNumberShaped,
normalizeOrgNumber,
isValidOrgNumber,
+33
View File
@@ -57,6 +57,39 @@ export function isOrgNumberShaped(raw: string | null | undefined): boolean {
return /^\d{10}$/.test(cleaned) || /^\d{12}$/.test(cleaned)
}
/**
* Lenient identity key for a Swedish org number: the 10 significant digits,
* or null when the input is not org-number shaped.
*
* Strips separators (hyphens, spaces), keeps 10 digits as they are and takes
* the last 10 of a 12-digit century-prefixed form: "16" for organisations,
* "18"/"19"/"20" for the personnummer an enskild firma uses. Only those
* prefixes: a 12-digit value that starts with anything else is a Swedish VAT
* number typed into the wrong field (556012579001 = orgnr + "01"), and its
* last 10 digits are somebody else's identity. Letters are not stripped for
* the same reason: BE0123456789 is a Belgian enterprise number, not the
* Swedish 0123456789. Anything not shaped like a Swedish org number keys to
* null and is stored and compared exactly as typed.
*
* No Luhn check on purpose: this key answers "do these two strings denote
* the same counterparty", and two rows holding the same mistyped number are
* still one supplier. Use {@link normalizeOrgNumber} where a number is
* accepted into the system as valid; use this where existing values are
* compared or canonicalised.
*
* `suppliers.org_number` is stored in this form: the supplier matcher, the
* write schemas (web, v1, MCP, CSV import, provider migration) and the
* extractor's self-invoice guard all go through it, so a hyphenated register
* entry and a bare extracted number meet (#2391).
*/
export function orgNumberKey(raw: string | null | undefined): string | null {
if (!raw) return null
const cleaned = stripOrgNumberFormatting(raw)
if (/^\d{10}$/.test(cleaned)) return cleaned
if (/^(16|18|19|20)\d{10}$/.test(cleaned)) return cleaned.slice(2)
return null
}
/**
* Normalize an org number to Accounted's canonical 10-digit storage form.
*
@@ -12,6 +12,29 @@ import { describe, it, expect } from 'vitest'
import { CreateSupplierParamsSchema } from '../create-supplier'
import { generateReverseChargeBasisLines } from '@/lib/bookkeeping/vat-entries'
describe('CreateSupplierParamsSchema org_number', () => {
// #2391: the staged path stores the same 10-digit key as the dashboard.
it('stores the 10-digit key for every accepted spelling', () => {
for (const typed of ['556677-8899', '5566778899', '165566778899', ' 556677-8899 ']) {
const parsed = CreateSupplierParamsSchema.parse({ name: 'Testbrand AB', org_number: typed })
expect(parsed.org_number, typed).toBe('5566778899')
}
})
it('leaves a 12-digit value that is not a century form as typed', () => {
// A VAT number (orgnr + 01) passes the shape check but is not an identity
// the key may rewrite.
const parsed = CreateSupplierParamsSchema.parse({ name: 'Testbrand AB', org_number: '556677889901' })
expect(parsed.org_number).toBe('556677889901')
})
it('still rejects a value that is not a Swedish org number', () => {
expect(() =>
CreateSupplierParamsSchema.parse({ name: 'Testbrand AB', org_number: 'DK12345678' }),
).toThrow(/org number/)
})
})
describe('CreateSupplierParamsSchema vat_number', () => {
it('accepts an EU business supplier with no VAT number (below its national threshold)', () => {
const parsed = CreateSupplierParamsSchema.parse({
@@ -26,6 +26,7 @@
*/
import { z } from 'zod'
import { validateBankgiroNumber } from '@/lib/bankgiro/luhn'
import { orgNumberKey } from '@/lib/invariants/org-number'
import { parseVatNumber } from '@/lib/vat/vies-client'
const IBAN_RE = /^[A-Z]{2}\d{2}[A-Z0-9]{11,30}$/
@@ -54,6 +55,8 @@ function optString(inner: z.ZodTypeAny) {
const emailField = optString(z.string().email('Invalid email format').max(255))
const phoneField = optString(z.string().max(50))
// Stored as the 10-digit key the supplier matcher compares through (#2391):
// the shape check above guarantees the key exists.
const orgNumberField = optString(
z
.string()
@@ -61,7 +64,8 @@ const orgNumberField = optString(
.refine(
(v) => SE_ORG_NUMBER_RE.test(v.replace(/\s/g, '')),
'Invalid Swedish org number format (expected XXXXXX-XXXX or 12 digits)',
),
)
.transform((v) => orgNumberKey(v) ?? v),
)
const vatNumberField = optString(
z
+111 -8
View File
@@ -10,19 +10,25 @@ import {
/**
* Minimal suppliers-table stub. The matcher issues three shapes of query and
* they are distinguishable by terminator: org_number and name end in
* maybeSingle(), the vat_number scan ends in range() and is awaited directly.
* they are distinguishable by terminator: the exact org_number lookup (only
* for values that are not Swedish org numbers) and the name lookup end in
* maybeSingle(); the org_number and vat_number scans go through
* fetchAllRows, end in range(), and are told apart by the `.not(column)`
* filter that precedes them.
*/
function makeSupabase(rows: {
byOrgNumber?: { id: string } | null
byName?: { id: string } | null
withOrgNumber?: { id: string; org_number: string | null }[]
withVatNumber?: { id: string; vat_number: string | null }[]
orgScanError?: { message: string }
vatScanError?: { message: string }
}) {
const calls: { column: string; value: unknown }[] = []
const chain = (): Record<string, unknown> => {
const self: Record<string, unknown> = {}
let scanColumn: string | null = null
self.select = () => self
self.eq = (column: string, value: unknown) => {
if (column !== 'company_id') calls.push({ column, value })
@@ -32,7 +38,15 @@ function makeSupabase(rows: {
calls.push({ column: `ilike:${column}`, value })
return self
}
self.not = () => self
self.not = (column: string) => {
scanColumn = column
calls.push({ column: `scan:${column}`, value: null })
return self
}
self.is = (column: string, value: unknown) => {
calls.push({ column: `is:${column}`, value })
return self
}
self.order = () => self
self.limit = () => self
self.maybeSingle = () => {
@@ -42,13 +56,20 @@ function makeSupabase(rows: {
}
return Promise.resolve({ data: rows.byName ?? null, error: null })
}
// The vat_number scan goes through fetchAllRows, which awaits .range().
self.range = () =>
Promise.resolve(
self.range = () => {
if (scanColumn === 'org_number') {
return Promise.resolve(
rows.orgScanError
? { data: null, error: rows.orgScanError }
: { data: rows.withOrgNumber ?? [], error: null },
)
}
return Promise.resolve(
rows.vatScanError
? { data: null, error: rows.vatScanError }
: { data: rows.withVatNumber ?? [], error: null },
)
}
return self
}
@@ -130,7 +151,7 @@ describe('matchSupplierByIdentity', () => {
it('prefers org_number over everything else', async () => {
const { supabase } = makeSupabase({
byOrgNumber: { id: 'by-org' },
withOrgNumber: [{ id: 'by-org', org_number: '5566778899' }],
withVatNumber: [{ id: 'by-vat', vat_number: 'SE556012579001' }],
byName: { id: 'by-name' },
})
@@ -142,6 +163,88 @@ describe('matchSupplierByIdentity', () => {
expect(match).toEqual({ supplierId: 'by-org', matchedOn: 'org_number' })
})
// #2391: the form stores 556677-8899, the extractor emits 5566778899.
it('matches org_number across every spelling of the same identity', async () => {
const register = [
{ id: 'hyphen', org_number: '556677-8899' },
{ id: 'other', org_number: '5560125790' },
{ id: 'twelve', org_number: '198001011231' },
]
const cases: [string, string][] = [
['5566778899', 'hyphen'],
['556677-8899', 'hyphen'],
['165566778899', 'hyphen'],
['16556677-8899', 'hyphen'],
['556677 8899', 'hyphen'],
['800101-1231', 'twelve'],
['8001011231', 'twelve'],
]
for (const [extracted, expected] of cases) {
const { supabase, calls } = makeSupabase({ withOrgNumber: register, byName: { id: 'by-name' } })
const match = await matchSupplierByIdentity(supabase, 'company-1', {
orgNumber: extracted,
name: 'A brand name that is not the registered one',
})
expect(match, extracted).toEqual({ supplierId: expected, matchedOn: 'org_number' })
expect(calls.some((c) => c.column === 'ilike:name'), extracted).toBe(false)
}
})
it('scans live suppliers only', async () => {
const { supabase, calls } = makeSupabase({
withOrgNumber: [{ id: 'live', org_number: '5566778899' }],
})
await matchSupplierByIdentity(supabase, 'company-1', { orgNumber: '556677-8899' })
expect(calls).toContainEqual({ column: 'is:archived_at', value: null })
})
it('does not treat a VAT number or a foreign number as a Swedish org number', async () => {
// 556677889901 is orgnr + 01; its last 10 digits are somebody else.
const { supabase, calls } = makeSupabase({
withOrgNumber: [{ id: 'wrong', org_number: '6677889901' }],
byOrgNumber: null,
})
for (const value of ['SE556677889901', '556677889901', 'BE0123456789']) {
const match = await matchSupplierByIdentity(supabase, 'company-1', { orgNumber: value })
expect(match, value).toBeNull()
}
expect(calls.some((c) => c.column === 'scan:org_number')).toBe(false)
})
it('never matches junk in the register against a real org number', async () => {
const { supabase } = makeSupabase({
withOrgNumber: [
{ id: 'junk', org_number: '12345' },
{ id: 'foreign', org_number: 'DK12345678' },
],
byName: null,
})
const match = await matchSupplierByIdentity(supabase, 'company-1', { orgNumber: '5566778899' })
expect(match).toBeNull()
})
it('falls back to an exact lookup for a value that is not a Swedish org number', async () => {
const { supabase, calls } = makeSupabase({ byOrgNumber: { id: 'foreign' } })
const match = await matchSupplierByIdentity(supabase, 'company-1', { orgNumber: 'DK12345678' })
expect(match).toEqual({ supplierId: 'foreign', matchedOn: 'org_number' })
expect(calls).toContainEqual({ column: 'org_number', value: 'DK12345678' })
expect(calls.some((c) => c.column === 'scan:org_number')).toBe(false)
})
it('falls through to vat_number and name when the org_number scan fails', async () => {
const consoleSpy = vi.spyOn(console, 'error').mockImplementation(() => {})
const { supabase } = makeSupabase({
orgScanError: { message: 'connection reset' },
withVatNumber: [{ id: 'by-vat', vat_number: 'SE556677889901' }],
})
const match = await matchSupplierByIdentity(supabase, 'company-1', {
orgNumber: '5566778899',
vatNumber: 'SE556677889901',
})
expect(match).toEqual({ supplierId: 'by-vat', matchedOn: 'vat_number' })
consoleSpy.mockRestore()
})
it('falls back to vat_number when there is no org number: the Adobe case', async () => {
const { supabase } = makeSupabase({
byOrgNumber: null,
@@ -220,7 +323,7 @@ describe('matchSupplierByIdentity', () => {
describe('matchSupplierId', () => {
it('returns just the id', async () => {
const { supabase } = makeSupabase({ byOrgNumber: { id: 'by-org' } })
const { supabase } = makeSupabase({ withOrgNumber: [{ id: 'by-org', org_number: '556677-8899' }] })
await expect(
matchSupplierId(supabase, 'company-1', { orgNumber: '5566778899' }),
).resolves.toBe('by-org')
+36 -4
View File
@@ -18,6 +18,7 @@
import type { SupabaseClient } from '@supabase/supabase-js'
import { fetchAllRows } from '@/lib/supabase/fetch-all'
import { orgNumberKey } from '@/lib/invariants/org-number'
export type SupplierIdentity = {
orgNumber?: string | null
@@ -104,7 +105,40 @@ export async function matchSupplierByIdentity(
companyId: string,
identity: SupplierIdentity,
): Promise<SupplierMatch | null> {
if (identity.orgNumber) {
// The register was written by hand in the form's XXXXXX-XXXX shape, by the
// v1 API and MCP in whatever the caller sent, and the extractor emits bare
// digits: comparing raw strings missed every hyphenated row (#2391). New
// writes store the canonical key, but the comparison stays key-based so
// rows written before the backfill, and self-hosted instances that have
// not run it, match too. Normalising in SQL is not possible through
// PostgREST, so the scan happens here over the suppliers that have an
// org_number at all: a small set even for companies with thousands of
// suppliers, and the same shape as the vat_number scan below. Archived
// suppliers are skipped: a register that holds the same number twice (an
// archived hyphenated row next to its live bare replacement) must resolve
// to the live one, not to whichever id sorts first.
const orgKey = orgNumberKey(identity.orgNumber)
if (orgKey) {
try {
const rows = await fetchAllRows<{ id: string; org_number: string | null }>(
({ from, to }) =>
supabase
.from('suppliers')
.select('id, org_number')
.eq('company_id', companyId)
.not('org_number', 'is', null)
.is('archived_at', null)
.order('id', { ascending: true })
.range(from, to),
)
const hit = rows.find((row) => orgNumberKey(row.org_number) === orgKey)
if (hit) return { supplierId: hit.id, matchedOn: 'org_number' }
} catch (error) {
console.error('[match-supplier] org_number lookup failed:', error)
}
} else if (identity.orgNumber) {
// Not a Swedish org number (a foreign registration number passed through
// agent-supplied extracted_data): only an exact match can be trusted.
const { data } = await supabase
.from('suppliers')
.select('id')
@@ -115,9 +149,7 @@ export async function matchSupplierByIdentity(
if (data) return { supplierId: data.id as string, matchedOn: 'org_number' }
}
// Normalising in SQL is not possible through PostgREST, so the comparison
// happens here over the suppliers that have a vat_number at all: a small
// set even for companies with thousands of suppliers.
// Same shape as the org_number scan: compare canonical keys in memory.
if (vatNumberKey(identity.vatNumber)) {
try {
const rows = await fetchAllRows<{ id: string; vat_number: string | null }>(