feat(bookkeeping): guarded fiscal-year reset + findable Angra import (#1883) (#1897)

* feat(bookkeeping): guarded fiscal-year reset + findable Angra import (#1883)

Two deliverables from the community report where a bad SIE test import
left no way out short of deleting the company:

A) Discoverability: the voucher list shows one attn line linking to
   /import?history=sie whenever the page contains import-sourced
   vouchers, and /import?history=sie deep-links straight into the
   fold-open SIE import history where per-import Angra already lives.

B) Reset of an UNLOCKED fiscal year regardless of how the entries
   arrived: new reset_fiscal_year RPC (same gnubok.allow_delete escape
   hatch as undo_sie_import; no enforcement trigger touched) behind
   GET/POST /api/bookkeeping/fiscal-periods/[id]/reset and a typed
   type-the-year-name confirmation dialog on the fiscal years settings
   list. Refuses on: locked/closed year, company lock date over any part
   of the year, executed year-end, arsredovisning state, later year
   depending on this year's UB, VAT-declared evidence (vat_settlement
   verifikat, SKV lock/submit audit rows, extension workflow keys, fail
   closed) and AGI-declared months. Entries referenced by RESTRICT/NO
   ACTION FKs abort the whole reset (all-or-nothing). Documents are
   detached, never deleted (BFL 7 kap); every delete is audit-logged
   plus one behandlingshistorik summary row.

Fixes #1883

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(bookkeeping): harden fiscal-year reset after skeptic review (#1883)

Blocking skeptic findings on PR #1897, one consolidated pass:

- New snapshot blocker cross_year_reference: an entry outside the year whose
  correction_of_id / reverses_id / reversed_by_id points into the year made
  the delete crash with an uncaught P0001 (immutability trigger refusing the
  ON DELETE SET NULL referential UPDATE) after an eligible:true preview, and
  silently severed draft chains. 12 such chains exist in prod today.
- New snapshot blocker rot_rut_state: a begaran om utbetalning that reached
  Skatteverket (submitted/paid/partially_paid/rejected) was silently
  unlinked via SET NULL, erasing the bokforing behind a filed and possibly
  decided myndighetsarende.
- Rakenskapsinformation preservation (BFL 7 kap): line-level trigger audit
  rows carry no company_id and header rows no amounts, so a reset destroyed
  konton/belopp with no company-readable trace. The RPC now archives the
  full content of every verifikat in company-scoped RESET_SNAPSHOT audit
  rows before deleting (action added to audit_log_action_check, NOT VALID),
  and behandlingshistorik renders them.
- Dimension registry lockstep on reset (mirrors undo_sie_import): flipped
  imports can never be undone again, so their dimensions/values would have
  been orphaned forever.
- EXCEPTION WHEN raise_exception now returns a typed
  FISCAL_YEAR_RESET_LINKED_ENTRIES envelope instead of a bare 500;
  gnubok.allow_delete is cleared before leaving the guarded block.
- Voucher-list attn line fires only for source_type 'import':
  opening_balance is also written by year-end closing and the manual IB
  flows, which mislabelled every year-2+ company as SIE-imported.
- /import?history=sie now scrolls the SIE history into view.
- Reset dialog copy (sv+en) discloses that linked invoices, payments and
  bank transactions become unbooked; new blocker strings in both locales.
- pg fixture fix: document_attachments seeded without company_id (23502);
  new pg tests for both blockers, RESET_SNAPSHOT rows and the lockstep.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-08-25 14:36:18 +02:00
committed by GitHub
co-authored by Claude Fable 5
parent 77cacdcf34
commit 79013cf092
17 changed files with 2359 additions and 2 deletions
+32
View File
@@ -1526,6 +1526,38 @@ const PERIOD: Record<string, StructuredErrorEntry> = {
message_sv: 'Ett stängt räkenskapsår kan inte låsas upp.',
message_en: 'A closed fiscal year cannot be unlocked.',
},
FISCAL_YEAR_RESET_NOT_FOUND: {
httpStatus: 404,
message_sv: 'Räkenskapsåret kunde inte hittas.',
message_en: 'Fiscal year not found.',
},
FISCAL_YEAR_RESET_FORBIDDEN: {
httpStatus: 403,
message_sv: 'Endast företagets ägare eller administratörer kan nollställa ett räkenskapsår.',
message_en: 'Only company owners and admins can reset a fiscal year.',
},
FISCAL_YEAR_RESET_INELIGIBLE: {
httpStatus: 409,
message_sv: 'Räkenskapsåret kan inte nollställas i sitt nuvarande läge.',
message_en: 'The fiscal year cannot be reset in its current state.',
},
FISCAL_YEAR_RESET_CONFIRMATION_MISMATCH: {
httpStatus: 400,
message_sv: 'Räkenskapsårets namn stämmer inte överens.',
message_en: 'The fiscal year name does not match.',
},
FISCAL_YEAR_RESET_LINKED_ENTRIES: {
httpStatus: 409,
message_sv:
'Räkenskapsåret innehåller verifikat som är kopplade till andra poster (t.ex. anläggningstillgångar, periodiseringar eller lönekörningar). Ta bort eller ångra de kopplade flödena först. Inga ändringar har sparats.',
message_en:
'The fiscal year contains vouchers linked to other records (e.g. assets, accrual schedules or salary runs). Undo those flows first. No changes were saved.',
},
FISCAL_YEAR_RESET_FAILED: {
httpStatus: 500,
message_sv: 'Räkenskapsåret kunde inte nollställas. Inga ändringar har sparats.',
message_en: 'Failed to reset the fiscal year. No changes were saved.',
},
// Retired 2026-07-26: PERIOD_CREATE_BLOCKED_BY_OPEN_PERIODS. Creating the
// next räkenskapsår while a prior one is still fully open is no longer an
// error at all: BFL 5 kap 2 § forces the new year's affärshändelser to be