Fix SIE multi-year P&L accumulation, Fortnox supplier filter, processing_history (#267)

* fix: prevent P&L accumulation when importing multi-year SIE files

The opening-balance fallback summed all prior journal lines without
distinguishing balance sheet (class 1-2) from P&L (class 3-8). When
users imported one SIE file per year without running year-end closing
between them, resultatkonton accumulated across years instead of
resetting at each räkenskapsårsskifte. Reported by a customer.

Skip class 3-8 in the fallback path. P&L accounts must reset to zero
each fiscal year (årets resultat → 2099 → equity).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: only import unpaid supplier invoices from Fortnox

Fortnox's /supplierinvoices list endpoint doesn't reliably expose
FullyPaid, which caused historic paid invoices to be imported as
unpaid. Switch to the ?filter=unpaid query and surface that scope
in the migration options UI.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat: add processing_history table for behandlingshistorik

Append-only event log per BFNAR 2013:2 kap 8. Includes:
- processing_history table with seq, correlation/causation chaining,
  aggregate (Document/BankTransaction/MatchProposal/Verifikation/etc.),
  open event_type validated against processing_event_types registry.
- Immutability via audit_log_immutable trigger (no UPDATE/DELETE).
- RLS scoped to user_company_ids; writes via service role only.
- appendProcessingHistory() helper with PII guard rejecting payloads
  containing personnummer/orgnr patterns.
- Shared TS types in types/index.ts.

No consumers wired yet — this is the persistence layer only.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: add swedish-project-accounting skill

Reference skill covering projektredovisning: dimensional tagging,
WIP accounting, K2/K3 revenue recognition (successiv vinstavräkning,
färdigställandemetoden), entreprenadavtal, BAS patterns (1470,
1620, 2420, 2450, 4970), and SIE4 #DIM 6 encoding.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: rename processing_history migration to avoid timestamp collision

Main already has 20260418120000_allow_retroactive_first_fiscal_year.sql
from #265. Bumping this migration's timestamp to 20260418130000 to
keep schema_migrations.version unique.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: address Greptile review on processing_history

- Add BEFORE DELETE immutability trigger so the service role can't
  silently remove rows. Mirrors the pattern from migration 014
  (audit_log_no_update + audit_log_no_delete) and satisfies the
  immutability claim in BFNAR 2013:2 kap 8. Delivered as a follow-up
  migration since the original was already applied in some envs.

- Tighten PII patterns with \b word boundaries to avoid false
  positives on Bankgiro numbers (123456-7890) and invoice references
  like 202312-1234.

- Extend PII validation to actor.label, which previously bypassed
  the payload guard despite the docblock explicitly forbidding
  names/emails/personnummer there.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-04-18 13:26:41 +02:00
committed by GitHub
co-authored by Claude Opus 4.7
parent 8ed943198f
commit 44082ff845
14 changed files with 2021 additions and 4 deletions
+171
View File
@@ -0,0 +1,171 @@
/**
* Processing history (behandlingshistorik) — append helper.
*
* Appends events to the processing_history table within the caller's
* database transaction. Throws on failure so that the table writes
* and the audit trail are atomically consistent.
*
* PII BOUNDARY: payload MUST contain pseudonymous IDs only (user UUIDs,
* company UUIDs, counterparty IDs). Never names, emails, personnummer,
* addresses, or phone numbers. These live in their source tables (profiles,
* customers, suppliers) and are referenced by ID. GDPR erasure pseudonymizes
* the source tables; processing_history events become undecipherable by
* reference, which is the required behavior per v0.2 §10.
*/
import type { SupabaseClient } from '@supabase/supabase-js'
import type {
ProcessingHistoryAggregateType,
ProcessingHistoryActor,
} from '@/types'
import { z } from 'zod'
// ── PII validator ───────────────────────────────────────────────
// Rejects payloads containing Swedish personal identity numbers.
// Personnummer: YYMMDD-NNNN or YYMMDDNNNN (6+4 digits)
// Samordningsnummer: Same format but day +60
// Organisationsnummer: NNNNNN-NNNN (10 digits, but we catch the pattern)
// Word boundaries prevent false positives on Bankgiro (123456-7890) and
// invoice references like 202312-1234 that share the digit shape but aren't PII.
const PII_PATTERNS = [
/\b\d{6}-?\d{4}\b/, // personnummer, samordningsnummer
/\b\d{8}-?\d{4}\b/, // 12-digit variant (YYYYMMDD-NNNN) or orgnr
]
function containsPii(value: unknown): boolean {
if (typeof value === 'string') {
return PII_PATTERNS.some(pattern => pattern.test(value))
}
if (Array.isArray(value)) {
return value.some(containsPii)
}
if (value !== null && typeof value === 'object') {
return Object.values(value).some(containsPii)
}
return false
}
const piiSafePayload = z.record(z.string(), z.unknown()).refine(
(payload) => !containsPii(payload),
{ message: 'Payload contains PII (personnummer/samordningsnummer/orgnr pattern). Use pseudonymous IDs only.' }
)
function assertActorPiiSafe(actor: ProcessingHistoryActor): void {
if (actor.label && PII_PATTERNS.some(p => p.test(actor.label!))) {
throw new Error(
'actor.label contains PII (personnummer/samordningsnummer/orgnr pattern). Use a pseudonymous descriptor only.'
)
}
}
// ── Input type ──────────────────────────────────────────────────
export interface AppendEventInput {
companyId: string
correlationId: string
causationId?: string
aggregateType: ProcessingHistoryAggregateType
aggregateId: string
eventType: string
payload: Record<string, unknown>
payloadSchemaVersion?: number
actor: ProcessingHistoryActor
rubricVersion?: string
occurredAt: Date // mandatory — no default. Caller must set explicitly.
}
// ── Append functions ────────────────────────────────────────────
/**
* Append a single event to processing_history within the caller's transaction.
*
* Uses the provided SupabaseClient (which should be the same client used for
* table writes in the command handler). Throws on failure so that both the
* table writes and the audit trail roll back together.
*
* Returns the generated event_id (pre-generated client-side for causation chaining).
*/
export async function appendProcessingHistory(
supabase: SupabaseClient,
input: AppendEventInput
): Promise<string> {
// Validate payload + actor.label contain no PII
piiSafePayload.parse(input.payload)
assertActorPiiSafe(input.actor)
const eventId = crypto.randomUUID()
const { error } = await supabase
.from('processing_history')
.insert({
event_id: eventId,
company_id: input.companyId,
correlation_id: input.correlationId,
causation_id: input.causationId ?? null,
aggregate_type: input.aggregateType,
aggregate_id: input.aggregateId,
event_type: input.eventType,
payload: input.payload,
payload_schema_version: input.payloadSchemaVersion ?? 1,
actor: input.actor,
rubric_version: input.rubricVersion ?? null,
occurred_at: input.occurredAt.toISOString(),
})
if (error) {
throw new Error(
`Failed to append processing_history event ${input.eventType}: ${error.message}`
)
}
return eventId
}
/**
* Append multiple events atomically within the caller's transaction.
* Used for batch operations (e.g., migration commits, multi-event command handlers).
*
* Returns array of generated event_ids in input order.
*/
export async function appendProcessingHistoryBatch(
supabase: SupabaseClient,
inputs: AppendEventInput[]
): Promise<string[]> {
if (inputs.length === 0) return []
const eventIds = inputs.map(() => crypto.randomUUID())
// Validate all payloads + actor labels before any DB write
for (const input of inputs) {
piiSafePayload.parse(input.payload)
assertActorPiiSafe(input.actor)
}
const rows = inputs.map((input, i) => ({
event_id: eventIds[i],
company_id: input.companyId,
correlation_id: input.correlationId,
causation_id: input.causationId ?? null,
aggregate_type: input.aggregateType,
aggregate_id: input.aggregateId,
event_type: input.eventType,
payload: input.payload,
payload_schema_version: input.payloadSchemaVersion ?? 1,
actor: input.actor,
rubric_version: input.rubricVersion ?? null,
occurred_at: input.occurredAt.toISOString(),
}))
const { error } = await supabase
.from('processing_history')
.insert(rows)
if (error) {
throw new Error(
`Failed to append processing_history batch (${inputs.length} events): ${error.message}`
)
}
return eventIds
}
+4 -1
View File
@@ -26,7 +26,10 @@ export const FORTNOX_RESOURCE_CONFIGS: Partial<Record<ResourceType, FortnoxResou
supportsLastModified: true,
},
[ResourceType.SupplierInvoices]: {
listEndpoint: '/supplierinvoices',
// Only fetch unpaid/open supplier invoices. Historic paid invoices add
// noise and Fortnox's list endpoint doesn't reliably expose FullyPaid,
// which caused paid invoices to be imported as unpaid.
listEndpoint: '/supplierinvoices?filter=unpaid',
listKey: 'SupplierInvoices',
detailEndpoint: '/supplierinvoices/{id}',
detailKey: 'SupplierInvoice',
+33 -2
View File
@@ -69,19 +69,50 @@ describe('getOpeningBalances', () => {
opening_balance_entry_id: null,
}
it('computes balances from all prior entries', async () => {
it('carries forward balance sheet accounts (class 1-2) only', async () => {
mockFetchAllRows.mockResolvedValue([
{ account_number: '1930', debit_amount: 100000, credit_amount: 5000 },
{ account_number: '2440', debit_amount: 0, credit_amount: 25000 },
// P&L accounts (class 3-8) must NOT carry forward — they reset
// to zero each fiscal year via årets resultat.
{ account_number: '3001', debit_amount: 0, credit_amount: 80000 },
{ account_number: '5410', debit_amount: 12000, credit_amount: 0 },
{ account_number: '8310', debit_amount: 0, credit_amount: 1500 },
])
const { balances, obEntryId } = await getOpeningBalances(supabase, 'company-1', period)
expect(balances.get('1930')).toEqual({ debit: 100000, credit: 5000 })
expect(balances.get('3001')).toEqual({ debit: 0, credit: 80000 })
expect(balances.get('2440')).toEqual({ debit: 0, credit: 25000 })
expect(balances.has('3001')).toBe(false)
expect(balances.has('5410')).toBe(false)
expect(balances.has('8310')).toBe(false)
expect(obEntryId).toBeNull()
})
it('does not accumulate P&L across multi-year SIE imports', async () => {
// Simulates importing SIE files for 2022 and 2023, then opening 2024:
// BS movements over both years should net to a single IB; P&L from
// both years must be discarded.
mockFetchAllRows.mockResolvedValue([
// 2022 IB + activity on a BS account
{ account_number: '1930', debit_amount: 50000, credit_amount: 0 },
{ account_number: '1930', debit_amount: 30000, credit_amount: 10000 },
// 2023 activity on the same BS account
{ account_number: '1930', debit_amount: 20000, credit_amount: 5000 },
// 2022 + 2023 P&L activity that previously accumulated incorrectly
{ account_number: '3001', debit_amount: 0, credit_amount: 200000 },
{ account_number: '3001', debit_amount: 0, credit_amount: 250000 },
{ account_number: '5410', debit_amount: 50000, credit_amount: 0 },
])
const { balances } = await getOpeningBalances(supabase, 'company-1', period)
expect(balances.get('1930')).toEqual({ debit: 100000, credit: 15000 })
expect(balances.has('3001')).toBe(false)
expect(balances.has('5410')).toBe(false)
})
it('aggregates multiple lines per account', async () => {
mockFetchAllRows.mockResolvedValue([
{ account_number: '1510', debit_amount: 5000, credit_amount: 0 },
+7
View File
@@ -77,6 +77,13 @@ export async function getOpeningBalances(
)
for (const line of priorLines) {
// P&L accounts (class 3-8) reset to zero at each year transition —
// their balances are absorbed into årets resultat (2099) and rolled
// into equity. Carrying them forward as IB causes resultatkonton to
// accumulate across years (BFNAR 2013:2 violation).
const cls = parseInt(line.account_number.charAt(0), 10)
if (cls >= 3 && cls <= 8) continue
const existing = balances.get(line.account_number) || { debit: 0, credit: 0 }
existing.debit += Number(line.debit_amount) || 0
existing.credit += Number(line.credit_amount) || 0