feat(import/export): article import + register export (xlsx/csv) (#750)

* feat(import/export): article import + register export (xlsx/csv)

Add CSV/Excel import for the article register (artiklar), mirroring the
existing customer/supplier import pipeline, plus Excel + CSV export for
articles, customers and suppliers.

Import (lib/import/articles + app/api/import/articles):
- Column auto-detection tuned to Fortnox/Visma/Bokio export headers,
  Swedish-decimal price parsing, VAT snapped to {0,6,12,25}, type/unit
  normalization.
- Dedup by article number then name; 23505 soft-skip; auto-number
  backfill; revenue-account override kept only when active, otherwise
  dropped with a warning (never mutates the chart of accounts).
- New "Artiklar" flow in the /import hub.

Export (app/api/export/* + lib/export/register-export):
- Read-only xlsx (default) / csv (?format=csv, UTF-8 BOM) downloads.
- Headers chosen so files round-trip back through the importer.
- "Exportera" menu added to the articles, customers and suppliers pages.

Refs #746. Direct Fortnox/Visma API article fetch tracked in #749.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(import/export): address PR review — lint ratchet + export hardening

- xlsx-export: keep `SheetSpec<any>` on the eslint-disabled line (fixes the
  core-only lint ratchet regression: no-explicit-any 16 -> 15) and define
  UTF8_BOM as an explicit `` escape instead of a raw BOM character.
- export routes (articles/customers/suppliers): move the data queries inside
  the try/catch, add `Cache-Control: no-store`, and emit a `register exported`
  audit log line (entity, format, rowCount).
- articles parse route: validate `column_overrides` against a Zod schema before
  trusting it to drive the parser.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(import): drop öre-round pattern on article column-detector confidence

The confidence score is a 0-1 heuristic, not money, and is only compared
against the 0.8 skip-mapping threshold. Removing the Math.round(x*100)/100
form clears the core-only antipattern ratchet (naive-ore-round 660 -> 659).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(import): flag adjusted VAT rows in the article import edit step

Surface VAT snapping/defaulting per row, not just as a file-level warning:
the parser sets `vat_rate_adjusted`, the edit step highlights those rows'
VAT selector and shows a count banner, and confirming a rate clears the flag.
Addresses the Swedish-compliance review note that silent snapping could
otherwise store a wrong VAT rate at scale.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-06-17 14:38:44 +02:00
committed by GitHub
co-authored by Claude Opus 4.8
parent 7aa37fd3b8
commit 2d6ddeafc5
28 changed files with 2614 additions and 85 deletions
@@ -0,0 +1,99 @@
import { describe, it, expect, vi, beforeEach } from 'vitest'
import * as XLSX from 'xlsx'
import { createMockRequest, parseJsonResponse, createQueuedMockSupabase } from '@/tests/helpers'
import { detectArticleColumns } from '@/lib/import/articles/column-detector'
const { supabase: mockSupabase, enqueue, reset } = createQueuedMockSupabase()
vi.mock('@/lib/supabase/server', () => ({
createClient: () => Promise.resolve(mockSupabase),
}))
vi.mock('@/lib/company/context', () => ({
requireCompanyId: vi.fn().mockResolvedValue('company-1'),
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
}))
const mockFetchAllRows = vi.fn()
vi.mock('@/lib/supabase/fetch-all', () => ({
fetchAllRows: (...a: unknown[]) => mockFetchAllRows(...a),
}))
import { GET } from '../route'
const mockUser = { id: 'user-1', email: 'test@test.se' }
const ARTICLE = {
id: 'a1',
article_number: '100',
name: 'Webdesign',
name_en: 'Web design',
type: 'tjanst',
unit: 'st',
price_excl_vat: 1200,
vat_rate: 25,
revenue_account: '3001',
cost_price: 400,
ean: '7350000000001',
housework_type: null,
notes: 'Kommentar med åäö',
}
beforeEach(() => {
vi.clearAllMocks()
reset()
mockSupabase.auth.getUser.mockResolvedValue({ data: { user: mockUser } })
mockFetchAllRows.mockResolvedValue([ARTICLE])
})
describe('GET /api/export/articles', () => {
it('returns 401 when unauthenticated', async () => {
mockSupabase.auth.getUser.mockResolvedValue({ data: { user: null } })
const res = await GET(createMockRequest('/api/export/articles'))
const { status } = await parseJsonResponse(res)
expect(status).toBe(401)
})
it('returns an xlsx workbook whose headers round-trip through the importer', async () => {
enqueue({ data: { company_name: 'Acme AB' } })
const res = await GET(createMockRequest('/api/export/articles'))
expect(res.status).toBe(200)
expect(res.headers.get('Content-Type')).toContain('spreadsheetml')
const disposition = res.headers.get('Content-Disposition') || ''
expect(disposition).toContain('attachment')
expect(disposition).toContain('artiklar-acme-ab')
expect(disposition).toContain('.xlsx')
const buf = Buffer.from(await res.arrayBuffer())
expect(buf.length).toBeGreaterThan(0)
const wb = XLSX.read(new Uint8Array(buf), { type: 'array' })
const sheet = wb.Sheets[wb.SheetNames[0]]
const rows = XLSX.utils.sheet_to_json<string[]>(sheet, { header: 1 })
const headers = (rows[0] as string[]).map(String)
// Round-trip: the exported headers must re-detect with high confidence.
const detected = detectArticleColumns(headers)
expect(detected.confidence).toBeGreaterThanOrEqual(0.8)
expect(detected.name_col).toBeGreaterThanOrEqual(0)
expect(detected.price_col).not.toBeNull()
expect(detected.vat_rate_col).not.toBeNull()
expect(detected.revenue_account_col).not.toBeNull()
})
it('returns a UTF-8 BOM CSV when format=csv', async () => {
enqueue({ data: { company_name: 'Acme AB' } })
const res = await GET(createMockRequest('/api/export/articles', { searchParams: { format: 'csv' } }))
expect(res.status).toBe(200)
expect(res.headers.get('Content-Type')).toContain('text/csv')
expect(res.headers.get('Content-Disposition')).toContain('.csv')
const buf = Buffer.from(await res.arrayBuffer())
// UTF-8 BOM
expect([buf[0], buf[1], buf[2]]).toEqual([0xef, 0xbb, 0xbf])
expect(buf.toString('utf-8')).toContain('Webdesign')
})
})
+94
View File
@@ -0,0 +1,94 @@
import { NextResponse } from 'next/server'
import { withRouteContext } from '@/lib/api/with-route-context'
import { errorResponse } from '@/lib/errors/get-structured-error'
import { fetchAllRows } from '@/lib/supabase/fetch-all'
import { textColumn, currencyColumn, integerColumn } from '@/lib/reports/xlsx-export'
import { buildRegisterExport, parseExportFormat, todayIso } from '@/lib/export/register-export'
import type { Article } from '@/types'
/**
* GET /api/export/articles[?format=csv][&include_inactive=1]
*
* Downloads the article register as xlsx (default) or csv. Read-only — viewers
* may export. Column headers match the article importer's detector keywords so
* the file round-trips (export → edit → re-import).
*/
export const GET = withRouteContext(
'article.export',
async (request, ctx) => {
const { supabase, companyId, log, requestId } = ctx
const url = new URL(request.url)
const format = parseExportFormat(url.searchParams.get('format'))
const includeInactive = url.searchParams.get('include_inactive') === '1'
try {
const { data: companyRow } = await supabase
.from('company_settings')
.select('company_name')
.eq('company_id', companyId)
.single()
const articles = (await fetchAllRows(({ from, to }) => {
let query = supabase
.from('articles')
.select('*')
.eq('company_id', companyId)
if (!includeInactive) query = query.eq('active', true)
return query.order('name', { ascending: true }).range(from, to)
})) as unknown as Article[]
const { buffer, contentType, filename } = buildRegisterExport(
[
{
name: 'Artiklar',
columns: [
textColumn('Artikelnummer'),
textColumn('Benämning'),
textColumn('Benämning (engelska)'),
textColumn('Typ'),
textColumn('Enhet'),
currencyColumn('Försäljningspris'),
integerColumn('Moms %'),
textColumn('Försäljningskonto'),
currencyColumn('Inköpspris'),
textColumn('EAN'),
textColumn('ROT/RUT'),
textColumn('Anteckning'),
],
rows: articles,
mapRow: (a) => [
a.article_number,
a.name,
a.name_en,
a.type,
a.unit,
a.price_excl_vat,
a.vat_rate,
a.revenue_account,
a.cost_price,
a.ean,
a.housework_type,
a.notes,
],
},
],
{ format, slug: 'artiklar', companyName: companyRow?.company_name ?? '', date: todayIso() },
)
// Audit trail: who exported what, when (sensitive bulk register download).
log.info('register exported', { entity: 'articles', format, rowCount: articles.length })
return new NextResponse(new Uint8Array(buffer), {
headers: {
'Content-Type': contentType,
'Content-Disposition': `attachment; filename="${filename}"`,
'Cache-Control': 'no-store',
},
})
} catch (err) {
log.error('article export failed', err as Error)
return errorResponse(err, log, { requestId })
}
},
)
@@ -0,0 +1,84 @@
import { describe, it, expect, vi, beforeEach } from 'vitest'
import * as XLSX from 'xlsx'
import { createMockRequest, parseJsonResponse, createQueuedMockSupabase } from '@/tests/helpers'
const { supabase: mockSupabase, enqueue, reset } = createQueuedMockSupabase()
vi.mock('@/lib/supabase/server', () => ({
createClient: () => Promise.resolve(mockSupabase),
}))
vi.mock('@/lib/company/context', () => ({
requireCompanyId: vi.fn().mockResolvedValue('company-1'),
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
}))
const mockFetchAllRows = vi.fn()
vi.mock('@/lib/supabase/fetch-all', () => ({
fetchAllRows: (...a: unknown[]) => mockFetchAllRows(...a),
}))
import { GET } from '../route'
const mockUser = { id: 'user-1', email: 'test@test.se' }
const CUSTOMER = {
id: 'c1',
name: 'Acme AB',
customer_type: 'swedish_business',
org_number: '5560217780',
personal_number: null,
email: 'kontakt@acme.se',
phone: '0701234567',
address_line1: 'Storgatan 1',
address_line2: null,
postal_code: '11122',
city: 'Göteborg',
country: 'Sweden',
vat_number: 'SE556021778001',
default_payment_terms: 30,
notes: null,
}
beforeEach(() => {
vi.clearAllMocks()
reset()
mockSupabase.auth.getUser.mockResolvedValue({ data: { user: mockUser } })
mockFetchAllRows.mockResolvedValue([CUSTOMER])
})
describe('GET /api/export/customers', () => {
it('returns 401 when unauthenticated', async () => {
mockSupabase.auth.getUser.mockResolvedValue({ data: { user: null } })
const res = await GET(createMockRequest('/api/export/customers'))
const { status } = await parseJsonResponse(res)
expect(status).toBe(401)
})
it('returns an xlsx customer register', async () => {
enqueue({ data: { company_name: 'Acme AB' } })
const res = await GET(createMockRequest('/api/export/customers'))
expect(res.status).toBe(200)
expect(res.headers.get('Content-Type')).toContain('spreadsheetml')
expect(res.headers.get('Content-Disposition')).toContain('kunder-')
const buf = Buffer.from(await res.arrayBuffer())
const wb = XLSX.read(new Uint8Array(buf), { type: 'array' })
const sheet = wb.Sheets[wb.SheetNames[0]]
const rows = XLSX.utils.sheet_to_json<string[]>(sheet, { header: 1 })
expect((rows[0] as string[])[0]).toBe('Namn')
expect((rows[1] as string[])).toContain('Acme AB')
})
it('returns a CSV with BOM when format=csv', async () => {
enqueue({ data: { company_name: 'Acme AB' } })
const res = await GET(createMockRequest('/api/export/customers', { searchParams: { format: 'csv' } }))
expect(res.status).toBe(200)
expect(res.headers.get('Content-Type')).toContain('text/csv')
const buf = Buffer.from(await res.arrayBuffer())
expect([buf[0], buf[1], buf[2]]).toEqual([0xef, 0xbb, 0xbf])
expect(buf.toString('utf-8')).toContain('Göteborg')
})
})
+93
View File
@@ -0,0 +1,93 @@
import { NextResponse } from 'next/server'
import { withRouteContext } from '@/lib/api/with-route-context'
import { errorResponse } from '@/lib/errors/get-structured-error'
import { fetchAllRows } from '@/lib/supabase/fetch-all'
import { textColumn, integerColumn } from '@/lib/reports/xlsx-export'
import { buildRegisterExport, parseExportFormat, todayIso } from '@/lib/export/register-export'
import type { Customer } from '@/types'
/**
* GET /api/export/customers[?format=csv]
*
* Downloads the customer register as xlsx (default) or csv. Read-only — viewers
* may export. Headers match the customer importer's detector keywords so files
* round-trip.
*/
export const GET = withRouteContext(
'customer.export',
async (request, ctx) => {
const { supabase, companyId, log, requestId } = ctx
const format = parseExportFormat(new URL(request.url).searchParams.get('format'))
try {
const { data: companyRow } = await supabase
.from('company_settings')
.select('company_name')
.eq('company_id', companyId)
.single()
const customers = (await fetchAllRows(({ from, to }) =>
supabase
.from('customers')
.select('*')
.eq('company_id', companyId)
.order('name', { ascending: true })
.range(from, to),
)) as unknown as Customer[]
const { buffer, contentType, filename } = buildRegisterExport(
[
{
name: 'Kunder',
columns: [
textColumn('Namn'),
textColumn('Org-/personnummer'),
textColumn('Kundtyp'),
textColumn('E-post'),
textColumn('Telefon'),
textColumn('Adress'),
textColumn('Adressrad 2'),
textColumn('Postnummer'),
textColumn('Ort'),
textColumn('Land'),
textColumn('VAT-nummer'),
integerColumn('Betalningsvillkor'),
textColumn('Anteckning'),
],
rows: customers,
mapRow: (c) => [
c.name,
c.org_number ?? c.personal_number,
c.customer_type,
c.email,
c.phone,
c.address_line1,
c.address_line2,
c.postal_code,
c.city,
c.country,
c.vat_number,
c.default_payment_terms,
c.notes,
],
},
],
{ format, slug: 'kunder', companyName: companyRow?.company_name ?? '', date: todayIso() },
)
log.info('register exported', { entity: 'customers', format, rowCount: customers.length })
return new NextResponse(new Uint8Array(buffer), {
headers: {
'Content-Type': contentType,
'Content-Disposition': `attachment; filename="${filename}"`,
'Cache-Control': 'no-store',
},
})
} catch (err) {
log.error('customer export failed', err as Error)
return errorResponse(err, log, { requestId })
}
},
)
@@ -0,0 +1,79 @@
import { describe, it, expect, vi, beforeEach } from 'vitest'
import * as XLSX from 'xlsx'
import { createMockRequest, parseJsonResponse, createQueuedMockSupabase } from '@/tests/helpers'
const { supabase: mockSupabase, enqueue, reset } = createQueuedMockSupabase()
vi.mock('@/lib/supabase/server', () => ({
createClient: () => Promise.resolve(mockSupabase),
}))
vi.mock('@/lib/company/context', () => ({
requireCompanyId: vi.fn().mockResolvedValue('company-1'),
getActiveCompanyId: vi.fn().mockResolvedValue('company-1'),
}))
const mockFetchAllRows = vi.fn()
vi.mock('@/lib/supabase/fetch-all', () => ({
fetchAllRows: (...a: unknown[]) => mockFetchAllRows(...a),
}))
import { GET } from '../route'
const mockUser = { id: 'user-1', email: 'test@test.se' }
const SUPPLIER = {
id: 's1',
name: 'Leverantör AB',
supplier_type: 'swedish_business',
org_number: '5560217780',
vat_number: 'SE556021778001',
email: 'faktura@lev.se',
phone: null,
address_line1: null,
address_line2: null,
postal_code: null,
city: 'Malmö',
country: 'Sweden',
bankgiro: '5050-1055',
plusgiro: null,
bank_account: null,
iban: null,
bic: null,
default_payment_terms: 30,
default_currency: 'SEK',
notes: null,
}
beforeEach(() => {
vi.clearAllMocks()
reset()
mockSupabase.auth.getUser.mockResolvedValue({ data: { user: mockUser } })
mockFetchAllRows.mockResolvedValue([SUPPLIER])
})
describe('GET /api/export/suppliers', () => {
it('returns 401 when unauthenticated', async () => {
mockSupabase.auth.getUser.mockResolvedValue({ data: { user: null } })
const res = await GET(createMockRequest('/api/export/suppliers'))
const { status } = await parseJsonResponse(res)
expect(status).toBe(401)
})
it('returns an xlsx supplier register with banking columns', async () => {
enqueue({ data: { company_name: 'Acme AB' } })
const res = await GET(createMockRequest('/api/export/suppliers'))
expect(res.status).toBe(200)
expect(res.headers.get('Content-Disposition')).toContain('leverantorer-')
const buf = Buffer.from(await res.arrayBuffer())
const wb = XLSX.read(new Uint8Array(buf), { type: 'array' })
const sheet = wb.Sheets[wb.SheetNames[0]]
const rows = XLSX.utils.sheet_to_json<string[]>(sheet, { header: 1 })
const headers = (rows[0] as string[]).map(String)
expect(headers).toContain('Bankgiro')
expect(headers).toContain('Valuta')
expect((rows[1] as string[])).toContain('Leverantör AB')
})
})
+105
View File
@@ -0,0 +1,105 @@
import { NextResponse } from 'next/server'
import { withRouteContext } from '@/lib/api/with-route-context'
import { errorResponse } from '@/lib/errors/get-structured-error'
import { fetchAllRows } from '@/lib/supabase/fetch-all'
import { textColumn, integerColumn } from '@/lib/reports/xlsx-export'
import { buildRegisterExport, parseExportFormat, todayIso } from '@/lib/export/register-export'
import type { Supplier } from '@/types'
/**
* GET /api/export/suppliers[?format=csv]
*
* Downloads the supplier register as xlsx (default) or csv. Read-only — viewers
* may export. Headers match the supplier importer's detector keywords so files
* round-trip.
*/
export const GET = withRouteContext(
'supplier.export',
async (request, ctx) => {
const { supabase, companyId, log, requestId } = ctx
const format = parseExportFormat(new URL(request.url).searchParams.get('format'))
try {
const { data: companyRow } = await supabase
.from('company_settings')
.select('company_name')
.eq('company_id', companyId)
.single()
const suppliers = (await fetchAllRows(({ from, to }) =>
supabase
.from('suppliers')
.select('*')
.eq('company_id', companyId)
.order('name', { ascending: true })
.range(from, to),
)) as unknown as Supplier[]
const { buffer, contentType, filename } = buildRegisterExport(
[
{
name: 'Leverantörer',
columns: [
textColumn('Namn'),
textColumn('Org-/personnummer'),
textColumn('Leverantörstyp'),
textColumn('E-post'),
textColumn('Telefon'),
textColumn('Adress'),
textColumn('Adressrad 2'),
textColumn('Postnummer'),
textColumn('Ort'),
textColumn('Land'),
textColumn('VAT-nummer'),
textColumn('Bankgiro'),
textColumn('Plusgiro'),
textColumn('Bankkonto'),
textColumn('IBAN'),
textColumn('BIC'),
integerColumn('Betalningsvillkor'),
textColumn('Valuta'),
textColumn('Anteckning'),
],
rows: suppliers,
mapRow: (s) => [
s.name,
s.org_number,
s.supplier_type,
s.email,
s.phone,
s.address_line1,
s.address_line2,
s.postal_code,
s.city,
s.country,
s.vat_number,
s.bankgiro,
s.plusgiro,
s.bank_account,
s.iban,
s.bic,
s.default_payment_terms,
s.default_currency,
s.notes,
],
},
],
{ format, slug: 'leverantorer', companyName: companyRow?.company_name ?? '', date: todayIso() },
)
log.info('register exported', { entity: 'suppliers', format, rowCount: suppliers.length })
return new NextResponse(new Uint8Array(buffer), {
headers: {
'Content-Type': contentType,
'Content-Disposition': `attachment; filename="${filename}"`,
'Cache-Control': 'no-store',
},
})
} catch (err) {
log.error('supplier export failed', err as Error)
return errorResponse(err, log, { requestId })
}
},
)