fix: surface active TIC companies + block duplicate org numbers (#344)
* fix: surface active TIC companies + block duplicate org numbers
Three fixes from live-prod testing:
1. Enrichment filter hid the user's directorships. Now accepts both
Completed and PartiallyCompleted status from TIC (tenants without
CompanyRoles enabled still get SPAR) and the /select-company role
filter no longer requires companyStatus === 'Aktivt' — real TIC
payloads have been observed with different values, and positionEnd
alone is the authoritative "currently a director" signal. Added
PII-free diagnostic logs so the next shape-mismatch is debuggable
from Vercel logs without a round trip.
2. Manual wizard silently allowed duplicate org numbers. Added:
- findExistingCompanyByOrgNumber helper in actions.ts (service role,
bypasses RLS to see cross-tenant rows)
- Server-side guard in createCompanyFromOnboarding — returns
'org_number_exists' before the create RPC so we don't leave ghost
companies
- New /api/company/check-org-number endpoint for debounced client
checks
- Warning + disabled submit in Step2CompanyDetails
- Friendly error toasts in WelcomeOnboarding + BankIdCompanyPicker
- Mirror cleaned org_number onto companies.org_number on creation so
future duplicate checks and lookups are reliable
3. /onboarding ignored ?org_number= when the picker routed there as a
fallback. Now reads searchParams and pre-fills settings; also fixed
a latent bug where Step1's entity-type change wiped the pre-fill on
*first* selection (it should only reset on a genuine change).
Tests: duplicate-org guard (with formatted-input normalization),
check-org-number route (auth + 400 + exists true/false +
normalization).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix: address PR review feedback on duplicate-org guard
Greptile P1 findings + swedish-compliance feedback:
- findExistingCompanyByOrgNumber now throws on Supabase error instead
of silently returning null. Previously a DB outage or RLS
misconfiguration would bypass the entire duplicate guard and allow
duplicates through.
- createCompanyFromOnboarding catches the throw and returns a
user-facing error ("Kunde inte verifiera organisationsnummer"),
failing closed instead of open.
- companies.update({ org_number }) error is now checked and triggers a
rollback. Silent failure would leave the company without an
org_number, breaking all future duplicate checks for that entity.
- New normalizeOrgNumber helper validates 10- or 12-digit input,
strips the century prefix for 12-digit personnummer form, and
rejects anything else. Malformed input would have corrupted SIE4
(#ORGNR) and SRU (INFO.SRU) exports downstream.
- /select-company now uses loose `== null` for positionEnd — TIC has
been observed returning `undefined` for open-ended positions, which
strict `=== null` would silently filter out. Documented the two
downstream isCeased guards so future maintainers don't remove one
without the other.
- createCompanyFromTicRole refuses to provision when lookup.isCeased
(BFL 2 kap — bokföringsskyldighet ends at avregistrering).
BankIdCompanyPicker surfaces this client-side too.
- WelcomeOnboarding + BankIdCompanyPicker recognise new error codes:
org_number_invalid, company_ceased.
Tests: +4 cases covering malformed input rejection, fail-closed
behaviour on DB error, 12-digit personnummer normalization, and the
ceased-company refusal path. Full suite: 2306 passing.
Out of scope for this PR (follow-up):
- Partial unique index on companies(org_number) WHERE archived_at IS
NULL. Closes the race-condition window but needs a migration plus
any existing-duplicate cleanup — too risky for this hotfix.
- Rate limiting on /api/company/check-org-number. Endpoint is
auth-gated so not an immediate concern.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix: add Luhn validation and extract org-number normalization
Third round of PR review feedback (swedish-compliance):
- Add Luhn-10 check-digit validation to normalizeOrgNumber. Rejects
structurally invalid org_numbers (wrong check digit) at the boundary
instead of letting them propagate into SIE4 #ORGNR and SRU INFO.SRU,
where Skatteverket and receiving accounting systems would reject
them later anyway. Reuses the existing luhnValidate helper from
lib/bankgiro/luhn.ts (Bankgirot 10-modulen — same algorithm applies
to both Bolagsverket org numbers and Swedish personnummer).
- Extract normalizeOrgNumber into lib/company-lookup/normalize-org-number.ts
so the server action and /api/company/check-org-number use the same
rule. Previously the API route only stripped hyphens/spaces, so a
12-digit input would miss a stored 10-digit duplicate and mislead the
client debounce check ("not a duplicate" → submit → server rejects).
- /api/company/check-org-number now returns exists=false for
Luhn-invalid input rather than querying the DB. The submit-time
server action surfaces org_number_invalid, which is the right place
for the error.
Test coverage: dedicated normalize-org-number.test.ts (10 cases
covering both-lengths, Luhn, whitespace tolerance, garbage). Updated
existing tests to use Luhn-valid numbers (real Volvo 5560125790,
synthetic personnummer 8001011231). New failing-Luhn test in
actions.test.ts. New 12-digit-normalization and
luhn-invalid-returns-false tests in route.test.ts.
Full suite: 2315 passing.
Not fixed (out of scope for this hotfix):
- 10↔12 digit round-trip fragility for personnummer born 2000+. This
is a codebase-wide architectural choice (see lib/skatteverket/format.ts
which uses a two-digit-year heuristic to choose 19/20 at export).
Migrating to 12-digit storage is a separate refactor.
- Server-side re-fetch of TIC /lookup for isCeased. The trust boundary
here is user-to-their-own-onboarding, not adversarial; doubling TIC
API cost isn't proportionate.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
f3a3d07ed3
commit
8fd3f112f8
@@ -0,0 +1,120 @@
|
||||
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
||||
import { createMockRequest, parseJsonResponse } from '@/tests/helpers'
|
||||
|
||||
vi.mock('@/lib/supabase/server', () => ({
|
||||
createClient: vi.fn(),
|
||||
createServiceClient: vi.fn(),
|
||||
}))
|
||||
|
||||
import { createClient, createServiceClient } from '@/lib/supabase/server'
|
||||
import { GET } from '../route'
|
||||
|
||||
const mockCreateClient = vi.mocked(createClient)
|
||||
const mockCreateServiceClient = vi.mocked(createServiceClient)
|
||||
|
||||
function mockAuth(user: { id: string } | null) {
|
||||
mockCreateClient.mockResolvedValue({
|
||||
auth: { getUser: vi.fn().mockResolvedValue({ data: { user } }) },
|
||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
||||
} as any)
|
||||
}
|
||||
|
||||
/**
|
||||
* Service-role mock. Returns a match only if the incoming `.eq('org_number', X)`
|
||||
* value matches `existing`. Anything else (or empty `existing`) returns null.
|
||||
*/
|
||||
function mockService(existing?: string) {
|
||||
let lastOrgNumber: string | null = null
|
||||
const chain: Record<string, unknown> = {}
|
||||
const methods = ['select', 'eq', 'is', 'limit', 'maybeSingle']
|
||||
for (const m of methods) {
|
||||
chain[m] = (...args: unknown[]) => {
|
||||
if (m === 'eq' && args[0] === 'org_number') {
|
||||
lastOrgNumber = String(args[1])
|
||||
}
|
||||
if (m === 'maybeSingle') {
|
||||
return Promise.resolve({
|
||||
data: existing && lastOrgNumber === existing ? { id: 'other' } : null,
|
||||
error: null,
|
||||
})
|
||||
}
|
||||
return chain
|
||||
}
|
||||
}
|
||||
mockCreateServiceClient.mockReturnValue({
|
||||
from: vi.fn().mockReturnValue(chain),
|
||||
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
||||
} as any)
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks()
|
||||
})
|
||||
|
||||
describe('GET /api/company/check-org-number', () => {
|
||||
it('returns 401 when unauthenticated', async () => {
|
||||
mockAuth(null)
|
||||
mockService()
|
||||
const req = createMockRequest('/api/company/check-org-number?org_number=5560125790')
|
||||
const { status } = await parseJsonResponse(await GET(req))
|
||||
expect(status).toBe(401)
|
||||
})
|
||||
|
||||
it('returns 400 when org_number is missing', async () => {
|
||||
mockAuth({ id: 'user-1' })
|
||||
mockService()
|
||||
const req = createMockRequest('/api/company/check-org-number')
|
||||
const { status } = await parseJsonResponse(await GET(req))
|
||||
expect(status).toBe(400)
|
||||
})
|
||||
|
||||
it('returns exists=false when the org number is not registered', async () => {
|
||||
mockAuth({ id: 'user-1' })
|
||||
mockService(undefined) // no existing match
|
||||
const req = createMockRequest('/api/company/check-org-number?org_number=5560125790')
|
||||
const { status, body } = await parseJsonResponse(await GET(req))
|
||||
expect(status).toBe(200)
|
||||
expect((body as { data: { exists: boolean } }).data.exists).toBe(false)
|
||||
})
|
||||
|
||||
it('returns exists=true when the org number is already registered', async () => {
|
||||
mockAuth({ id: 'user-1' })
|
||||
mockService('5560125790')
|
||||
const req = createMockRequest('/api/company/check-org-number?org_number=5560125790')
|
||||
const { status, body } = await parseJsonResponse(await GET(req))
|
||||
expect(status).toBe(200)
|
||||
expect((body as { data: { exists: boolean } }).data.exists).toBe(true)
|
||||
})
|
||||
|
||||
it('normalizes formatted org numbers before lookup (strips hyphens/spaces)', async () => {
|
||||
mockAuth({ id: 'user-1' })
|
||||
mockService('5560125790')
|
||||
const req = createMockRequest('/api/company/check-org-number?org_number=556012-5790')
|
||||
const { status, body } = await parseJsonResponse(await GET(req))
|
||||
expect(status).toBe(200)
|
||||
expect((body as { data: { exists: boolean } }).data.exists).toBe(true)
|
||||
})
|
||||
|
||||
it('normalizes 12-digit input to 10-digit canonical before lookup', async () => {
|
||||
// Stored form is 10-digit canonical (8001011231); user types 12-digit
|
||||
// personnummer with century prefix.
|
||||
mockAuth({ id: 'user-1' })
|
||||
mockService('8001011231')
|
||||
const req = createMockRequest('/api/company/check-org-number?org_number=198001011231')
|
||||
const { status, body } = await parseJsonResponse(await GET(req))
|
||||
expect(status).toBe(200)
|
||||
expect((body as { data: { exists: boolean } }).data.exists).toBe(true)
|
||||
})
|
||||
|
||||
it('returns exists=false for Luhn-invalid input (not a duplicate of anything)', async () => {
|
||||
// The submit-time server action will reject this as org_number_invalid;
|
||||
// here we just confirm the check endpoint doesn't produce a misleading
|
||||
// "exists=true" result by accidentally matching an invalid number.
|
||||
mockAuth({ id: 'user-1' })
|
||||
mockService('5560125790') // a real registered number
|
||||
const req = createMockRequest('/api/company/check-org-number?org_number=5560125791')
|
||||
const { status, body } = await parseJsonResponse(await GET(req))
|
||||
expect(status).toBe(200)
|
||||
expect((body as { data: { exists: boolean } }).data.exists).toBe(false)
|
||||
})
|
||||
})
|
||||
@@ -0,0 +1,55 @@
|
||||
import { NextResponse } from 'next/server'
|
||||
import { createClient, createServiceClient } from '@/lib/supabase/server'
|
||||
import { normalizeOrgNumber } from '@/lib/company-lookup/normalize-org-number'
|
||||
|
||||
/**
|
||||
* GET /api/company/check-org-number?org_number=XXXXXXXXXX
|
||||
*
|
||||
* Returns `{ data: { exists: boolean } }` indicating whether the given
|
||||
* organisation number is already registered in any non-archived gnubok
|
||||
* company. Used by the onboarding wizard to warn users before they try to
|
||||
* create a duplicate.
|
||||
*
|
||||
* Normalizes the input with the same rule as the server action
|
||||
* (`normalizeOrgNumber`) so that a 12-digit form typed in the UI still
|
||||
* matches a 10-digit stored canonical. Returns `exists: false` for
|
||||
* malformed input — the submit-time server action will reject it with
|
||||
* `org_number_invalid`, which is the right place to surface the error.
|
||||
*
|
||||
* Requires authentication so the endpoint can't be used to enumerate the
|
||||
* full set of org numbers on the platform. Uses the service role internally
|
||||
* because RLS hides rows the caller isn't a member of — which is exactly
|
||||
* what we need to detect ("owned by someone else").
|
||||
*/
|
||||
export async function GET(request: Request) {
|
||||
const supabase = await createClient()
|
||||
const { data: { user } } = await supabase.auth.getUser()
|
||||
if (!user) return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
|
||||
|
||||
const url = new URL(request.url)
|
||||
const raw = url.searchParams.get('org_number') ?? ''
|
||||
if (!raw) {
|
||||
return NextResponse.json({ error: 'org_number is required' }, { status: 400 })
|
||||
}
|
||||
|
||||
const canonical = normalizeOrgNumber(raw)
|
||||
if (!canonical) {
|
||||
// Invalid format/Luhn — not a duplicate of anything by definition.
|
||||
return NextResponse.json({ data: { exists: false } })
|
||||
}
|
||||
|
||||
const service = createServiceClient()
|
||||
const { data, error } = await service
|
||||
.from('companies')
|
||||
.select('id')
|
||||
.eq('org_number', canonical)
|
||||
.is('archived_at', null)
|
||||
.limit(1)
|
||||
.maybeSingle()
|
||||
|
||||
if (error) {
|
||||
return NextResponse.json({ error: error.message }, { status: 500 })
|
||||
}
|
||||
|
||||
return NextResponse.json({ data: { exists: !!data } })
|
||||
}
|
||||
Reference in New Issue
Block a user