Fix SIE multi-year P&L accumulation, Fortnox supplier filter, processing_history (#267)
* fix: prevent P&L accumulation when importing multi-year SIE files The opening-balance fallback summed all prior journal lines without distinguishing balance sheet (class 1-2) from P&L (class 3-8). When users imported one SIE file per year without running year-end closing between them, resultatkonton accumulated across years instead of resetting at each räkenskapsårsskifte. Reported by a customer. Skip class 3-8 in the fallback path. P&L accounts must reset to zero each fiscal year (årets resultat → 2099 → equity). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: only import unpaid supplier invoices from Fortnox Fortnox's /supplierinvoices list endpoint doesn't reliably expose FullyPaid, which caused historic paid invoices to be imported as unpaid. Switch to the ?filter=unpaid query and surface that scope in the migration options UI. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * feat: add processing_history table for behandlingshistorik Append-only event log per BFNAR 2013:2 kap 8. Includes: - processing_history table with seq, correlation/causation chaining, aggregate (Document/BankTransaction/MatchProposal/Verifikation/etc.), open event_type validated against processing_event_types registry. - Immutability via audit_log_immutable trigger (no UPDATE/DELETE). - RLS scoped to user_company_ids; writes via service role only. - appendProcessingHistory() helper with PII guard rejecting payloads containing personnummer/orgnr patterns. - Shared TS types in types/index.ts. No consumers wired yet — this is the persistence layer only. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore: add swedish-project-accounting skill Reference skill covering projektredovisning: dimensional tagging, WIP accounting, K2/K3 revenue recognition (successiv vinstavräkning, färdigställandemetoden), entreprenadavtal, BAS patterns (1470, 1620, 2420, 2450, 4970), and SIE4 #DIM 6 encoding. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: rename processing_history migration to avoid timestamp collision Main already has 20260418120000_allow_retroactive_first_fiscal_year.sql from #265. Bumping this migration's timestamp to 20260418130000 to keep schema_migrations.version unique. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: address Greptile review on processing_history - Add BEFORE DELETE immutability trigger so the service role can't silently remove rows. Mirrors the pattern from migration 014 (audit_log_no_update + audit_log_no_delete) and satisfies the immutability claim in BFNAR 2013:2 kap 8. Delivered as a follow-up migration since the original was already applied in some envs. - Tighten PII patterns with \b word boundaries to avoid false positives on Bankgiro numbers (123456-7890) and invoice references like 202312-1234. - Extend PII validation to actor.label, which previously bypassed the payload guard despite the docblock explicitly forbidding names/emails/personnummer there. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
8ed943198f
commit
44082ff845
@@ -0,0 +1,171 @@
|
||||
/**
|
||||
* Processing history (behandlingshistorik) — append helper.
|
||||
*
|
||||
* Appends events to the processing_history table within the caller's
|
||||
* database transaction. Throws on failure so that the table writes
|
||||
* and the audit trail are atomically consistent.
|
||||
*
|
||||
* PII BOUNDARY: payload MUST contain pseudonymous IDs only (user UUIDs,
|
||||
* company UUIDs, counterparty IDs). Never names, emails, personnummer,
|
||||
* addresses, or phone numbers. These live in their source tables (profiles,
|
||||
* customers, suppliers) and are referenced by ID. GDPR erasure pseudonymizes
|
||||
* the source tables; processing_history events become undecipherable by
|
||||
* reference, which is the required behavior per v0.2 §10.
|
||||
*/
|
||||
|
||||
import type { SupabaseClient } from '@supabase/supabase-js'
|
||||
import type {
|
||||
ProcessingHistoryAggregateType,
|
||||
ProcessingHistoryActor,
|
||||
} from '@/types'
|
||||
import { z } from 'zod'
|
||||
|
||||
// ── PII validator ───────────────────────────────────────────────
|
||||
// Rejects payloads containing Swedish personal identity numbers.
|
||||
// Personnummer: YYMMDD-NNNN or YYMMDDNNNN (6+4 digits)
|
||||
// Samordningsnummer: Same format but day +60
|
||||
// Organisationsnummer: NNNNNN-NNNN (10 digits, but we catch the pattern)
|
||||
|
||||
// Word boundaries prevent false positives on Bankgiro (123456-7890) and
|
||||
// invoice references like 202312-1234 that share the digit shape but aren't PII.
|
||||
const PII_PATTERNS = [
|
||||
/\b\d{6}-?\d{4}\b/, // personnummer, samordningsnummer
|
||||
/\b\d{8}-?\d{4}\b/, // 12-digit variant (YYYYMMDD-NNNN) or orgnr
|
||||
]
|
||||
|
||||
function containsPii(value: unknown): boolean {
|
||||
if (typeof value === 'string') {
|
||||
return PII_PATTERNS.some(pattern => pattern.test(value))
|
||||
}
|
||||
if (Array.isArray(value)) {
|
||||
return value.some(containsPii)
|
||||
}
|
||||
if (value !== null && typeof value === 'object') {
|
||||
return Object.values(value).some(containsPii)
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
const piiSafePayload = z.record(z.string(), z.unknown()).refine(
|
||||
(payload) => !containsPii(payload),
|
||||
{ message: 'Payload contains PII (personnummer/samordningsnummer/orgnr pattern). Use pseudonymous IDs only.' }
|
||||
)
|
||||
|
||||
function assertActorPiiSafe(actor: ProcessingHistoryActor): void {
|
||||
if (actor.label && PII_PATTERNS.some(p => p.test(actor.label!))) {
|
||||
throw new Error(
|
||||
'actor.label contains PII (personnummer/samordningsnummer/orgnr pattern). Use a pseudonymous descriptor only.'
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// ── Input type ──────────────────────────────────────────────────
|
||||
|
||||
export interface AppendEventInput {
|
||||
companyId: string
|
||||
correlationId: string
|
||||
causationId?: string
|
||||
aggregateType: ProcessingHistoryAggregateType
|
||||
aggregateId: string
|
||||
eventType: string
|
||||
payload: Record<string, unknown>
|
||||
payloadSchemaVersion?: number
|
||||
actor: ProcessingHistoryActor
|
||||
rubricVersion?: string
|
||||
occurredAt: Date // mandatory — no default. Caller must set explicitly.
|
||||
}
|
||||
|
||||
// ── Append functions ────────────────────────────────────────────
|
||||
|
||||
/**
|
||||
* Append a single event to processing_history within the caller's transaction.
|
||||
*
|
||||
* Uses the provided SupabaseClient (which should be the same client used for
|
||||
* table writes in the command handler). Throws on failure so that both the
|
||||
* table writes and the audit trail roll back together.
|
||||
*
|
||||
* Returns the generated event_id (pre-generated client-side for causation chaining).
|
||||
*/
|
||||
export async function appendProcessingHistory(
|
||||
supabase: SupabaseClient,
|
||||
input: AppendEventInput
|
||||
): Promise<string> {
|
||||
// Validate payload + actor.label contain no PII
|
||||
piiSafePayload.parse(input.payload)
|
||||
assertActorPiiSafe(input.actor)
|
||||
|
||||
const eventId = crypto.randomUUID()
|
||||
|
||||
const { error } = await supabase
|
||||
.from('processing_history')
|
||||
.insert({
|
||||
event_id: eventId,
|
||||
company_id: input.companyId,
|
||||
correlation_id: input.correlationId,
|
||||
causation_id: input.causationId ?? null,
|
||||
aggregate_type: input.aggregateType,
|
||||
aggregate_id: input.aggregateId,
|
||||
event_type: input.eventType,
|
||||
payload: input.payload,
|
||||
payload_schema_version: input.payloadSchemaVersion ?? 1,
|
||||
actor: input.actor,
|
||||
rubric_version: input.rubricVersion ?? null,
|
||||
occurred_at: input.occurredAt.toISOString(),
|
||||
})
|
||||
|
||||
if (error) {
|
||||
throw new Error(
|
||||
`Failed to append processing_history event ${input.eventType}: ${error.message}`
|
||||
)
|
||||
}
|
||||
|
||||
return eventId
|
||||
}
|
||||
|
||||
/**
|
||||
* Append multiple events atomically within the caller's transaction.
|
||||
* Used for batch operations (e.g., migration commits, multi-event command handlers).
|
||||
*
|
||||
* Returns array of generated event_ids in input order.
|
||||
*/
|
||||
export async function appendProcessingHistoryBatch(
|
||||
supabase: SupabaseClient,
|
||||
inputs: AppendEventInput[]
|
||||
): Promise<string[]> {
|
||||
if (inputs.length === 0) return []
|
||||
|
||||
const eventIds = inputs.map(() => crypto.randomUUID())
|
||||
|
||||
// Validate all payloads + actor labels before any DB write
|
||||
for (const input of inputs) {
|
||||
piiSafePayload.parse(input.payload)
|
||||
assertActorPiiSafe(input.actor)
|
||||
}
|
||||
|
||||
const rows = inputs.map((input, i) => ({
|
||||
event_id: eventIds[i],
|
||||
company_id: input.companyId,
|
||||
correlation_id: input.correlationId,
|
||||
causation_id: input.causationId ?? null,
|
||||
aggregate_type: input.aggregateType,
|
||||
aggregate_id: input.aggregateId,
|
||||
event_type: input.eventType,
|
||||
payload: input.payload,
|
||||
payload_schema_version: input.payloadSchemaVersion ?? 1,
|
||||
actor: input.actor,
|
||||
rubric_version: input.rubricVersion ?? null,
|
||||
occurred_at: input.occurredAt.toISOString(),
|
||||
}))
|
||||
|
||||
const { error } = await supabase
|
||||
.from('processing_history')
|
||||
.insert(rows)
|
||||
|
||||
if (error) {
|
||||
throw new Error(
|
||||
`Failed to append processing_history batch (${inputs.length} events): ${error.message}`
|
||||
)
|
||||
}
|
||||
|
||||
return eventIds
|
||||
}
|
||||
@@ -26,7 +26,10 @@ export const FORTNOX_RESOURCE_CONFIGS: Partial<Record<ResourceType, FortnoxResou
|
||||
supportsLastModified: true,
|
||||
},
|
||||
[ResourceType.SupplierInvoices]: {
|
||||
listEndpoint: '/supplierinvoices',
|
||||
// Only fetch unpaid/open supplier invoices. Historic paid invoices add
|
||||
// noise and Fortnox's list endpoint doesn't reliably expose FullyPaid,
|
||||
// which caused paid invoices to be imported as unpaid.
|
||||
listEndpoint: '/supplierinvoices?filter=unpaid',
|
||||
listKey: 'SupplierInvoices',
|
||||
detailEndpoint: '/supplierinvoices/{id}',
|
||||
detailKey: 'SupplierInvoice',
|
||||
|
||||
@@ -69,19 +69,50 @@ describe('getOpeningBalances', () => {
|
||||
opening_balance_entry_id: null,
|
||||
}
|
||||
|
||||
it('computes balances from all prior entries', async () => {
|
||||
it('carries forward balance sheet accounts (class 1-2) only', async () => {
|
||||
mockFetchAllRows.mockResolvedValue([
|
||||
{ account_number: '1930', debit_amount: 100000, credit_amount: 5000 },
|
||||
{ account_number: '2440', debit_amount: 0, credit_amount: 25000 },
|
||||
// P&L accounts (class 3-8) must NOT carry forward — they reset
|
||||
// to zero each fiscal year via årets resultat.
|
||||
{ account_number: '3001', debit_amount: 0, credit_amount: 80000 },
|
||||
{ account_number: '5410', debit_amount: 12000, credit_amount: 0 },
|
||||
{ account_number: '8310', debit_amount: 0, credit_amount: 1500 },
|
||||
])
|
||||
|
||||
const { balances, obEntryId } = await getOpeningBalances(supabase, 'company-1', period)
|
||||
|
||||
expect(balances.get('1930')).toEqual({ debit: 100000, credit: 5000 })
|
||||
expect(balances.get('3001')).toEqual({ debit: 0, credit: 80000 })
|
||||
expect(balances.get('2440')).toEqual({ debit: 0, credit: 25000 })
|
||||
expect(balances.has('3001')).toBe(false)
|
||||
expect(balances.has('5410')).toBe(false)
|
||||
expect(balances.has('8310')).toBe(false)
|
||||
expect(obEntryId).toBeNull()
|
||||
})
|
||||
|
||||
it('does not accumulate P&L across multi-year SIE imports', async () => {
|
||||
// Simulates importing SIE files for 2022 and 2023, then opening 2024:
|
||||
// BS movements over both years should net to a single IB; P&L from
|
||||
// both years must be discarded.
|
||||
mockFetchAllRows.mockResolvedValue([
|
||||
// 2022 IB + activity on a BS account
|
||||
{ account_number: '1930', debit_amount: 50000, credit_amount: 0 },
|
||||
{ account_number: '1930', debit_amount: 30000, credit_amount: 10000 },
|
||||
// 2023 activity on the same BS account
|
||||
{ account_number: '1930', debit_amount: 20000, credit_amount: 5000 },
|
||||
// 2022 + 2023 P&L activity that previously accumulated incorrectly
|
||||
{ account_number: '3001', debit_amount: 0, credit_amount: 200000 },
|
||||
{ account_number: '3001', debit_amount: 0, credit_amount: 250000 },
|
||||
{ account_number: '5410', debit_amount: 50000, credit_amount: 0 },
|
||||
])
|
||||
|
||||
const { balances } = await getOpeningBalances(supabase, 'company-1', period)
|
||||
|
||||
expect(balances.get('1930')).toEqual({ debit: 100000, credit: 15000 })
|
||||
expect(balances.has('3001')).toBe(false)
|
||||
expect(balances.has('5410')).toBe(false)
|
||||
})
|
||||
|
||||
it('aggregates multiple lines per account', async () => {
|
||||
mockFetchAllRows.mockResolvedValue([
|
||||
{ account_number: '1510', debit_amount: 5000, credit_amount: 0 },
|
||||
|
||||
@@ -77,6 +77,13 @@ export async function getOpeningBalances(
|
||||
)
|
||||
|
||||
for (const line of priorLines) {
|
||||
// P&L accounts (class 3-8) reset to zero at each year transition —
|
||||
// their balances are absorbed into årets resultat (2099) and rolled
|
||||
// into equity. Carrying them forward as IB causes resultatkonton to
|
||||
// accumulate across years (BFNAR 2013:2 violation).
|
||||
const cls = parseInt(line.account_number.charAt(0), 10)
|
||||
if (cls >= 3 && cls <= 8) continue
|
||||
|
||||
const existing = balances.get(line.account_number) || { debit: 0, credit: 0 }
|
||||
existing.debit += Number(line.debit_amount) || 0
|
||||
existing.credit += Number(line.credit_amount) || 0
|
||||
|
||||
Reference in New Issue
Block a user