fix: surface active TIC companies + block duplicate org numbers (#344)

* fix: surface active TIC companies + block duplicate org numbers

Three fixes from live-prod testing:

1. Enrichment filter hid the user's directorships. Now accepts both
   Completed and PartiallyCompleted status from TIC (tenants without
   CompanyRoles enabled still get SPAR) and the /select-company role
   filter no longer requires companyStatus === 'Aktivt' — real TIC
   payloads have been observed with different values, and positionEnd
   alone is the authoritative "currently a director" signal. Added
   PII-free diagnostic logs so the next shape-mismatch is debuggable
   from Vercel logs without a round trip.

2. Manual wizard silently allowed duplicate org numbers. Added:
   - findExistingCompanyByOrgNumber helper in actions.ts (service role,
     bypasses RLS to see cross-tenant rows)
   - Server-side guard in createCompanyFromOnboarding — returns
     'org_number_exists' before the create RPC so we don't leave ghost
     companies
   - New /api/company/check-org-number endpoint for debounced client
     checks
   - Warning + disabled submit in Step2CompanyDetails
   - Friendly error toasts in WelcomeOnboarding + BankIdCompanyPicker
   - Mirror cleaned org_number onto companies.org_number on creation so
     future duplicate checks and lookups are reliable

3. /onboarding ignored ?org_number= when the picker routed there as a
   fallback. Now reads searchParams and pre-fills settings; also fixed
   a latent bug where Step1's entity-type change wiped the pre-fill on
   *first* selection (it should only reset on a genuine change).

Tests: duplicate-org guard (with formatted-input normalization),
check-org-number route (auth + 400 + exists true/false +
normalization).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: address PR review feedback on duplicate-org guard

Greptile P1 findings + swedish-compliance feedback:

- findExistingCompanyByOrgNumber now throws on Supabase error instead
  of silently returning null. Previously a DB outage or RLS
  misconfiguration would bypass the entire duplicate guard and allow
  duplicates through.
- createCompanyFromOnboarding catches the throw and returns a
  user-facing error ("Kunde inte verifiera organisationsnummer"),
  failing closed instead of open.
- companies.update({ org_number }) error is now checked and triggers a
  rollback. Silent failure would leave the company without an
  org_number, breaking all future duplicate checks for that entity.
- New normalizeOrgNumber helper validates 10- or 12-digit input,
  strips the century prefix for 12-digit personnummer form, and
  rejects anything else. Malformed input would have corrupted SIE4
  (#ORGNR) and SRU (INFO.SRU) exports downstream.
- /select-company now uses loose `== null` for positionEnd — TIC has
  been observed returning `undefined` for open-ended positions, which
  strict `=== null` would silently filter out. Documented the two
  downstream isCeased guards so future maintainers don't remove one
  without the other.
- createCompanyFromTicRole refuses to provision when lookup.isCeased
  (BFL 2 kap — bokföringsskyldighet ends at avregistrering).
  BankIdCompanyPicker surfaces this client-side too.
- WelcomeOnboarding + BankIdCompanyPicker recognise new error codes:
  org_number_invalid, company_ceased.

Tests: +4 cases covering malformed input rejection, fail-closed
behaviour on DB error, 12-digit personnummer normalization, and the
ceased-company refusal path. Full suite: 2306 passing.

Out of scope for this PR (follow-up):
- Partial unique index on companies(org_number) WHERE archived_at IS
  NULL. Closes the race-condition window but needs a migration plus
  any existing-duplicate cleanup — too risky for this hotfix.
- Rate limiting on /api/company/check-org-number. Endpoint is
  auth-gated so not an immediate concern.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix: add Luhn validation and extract org-number normalization

Third round of PR review feedback (swedish-compliance):

- Add Luhn-10 check-digit validation to normalizeOrgNumber. Rejects
  structurally invalid org_numbers (wrong check digit) at the boundary
  instead of letting them propagate into SIE4 #ORGNR and SRU INFO.SRU,
  where Skatteverket and receiving accounting systems would reject
  them later anyway. Reuses the existing luhnValidate helper from
  lib/bankgiro/luhn.ts (Bankgirot 10-modulen — same algorithm applies
  to both Bolagsverket org numbers and Swedish personnummer).

- Extract normalizeOrgNumber into lib/company-lookup/normalize-org-number.ts
  so the server action and /api/company/check-org-number use the same
  rule. Previously the API route only stripped hyphens/spaces, so a
  12-digit input would miss a stored 10-digit duplicate and mislead the
  client debounce check ("not a duplicate" → submit → server rejects).

- /api/company/check-org-number now returns exists=false for
  Luhn-invalid input rather than querying the DB. The submit-time
  server action surfaces org_number_invalid, which is the right place
  for the error.

Test coverage: dedicated normalize-org-number.test.ts (10 cases
covering both-lengths, Luhn, whitespace tolerance, garbage). Updated
existing tests to use Luhn-valid numbers (real Volvo 5560125790,
synthetic personnummer 8001011231). New failing-Luhn test in
actions.test.ts. New 12-digit-normalization and
luhn-invalid-returns-false tests in route.test.ts.

Full suite: 2315 passing.

Not fixed (out of scope for this hotfix):
- 10↔12 digit round-trip fragility for personnummer born 2000+. This
  is a codebase-wide architectural choice (see lib/skatteverket/format.ts
  which uses a two-digit-year heuristic to choose 19/20 at export).
  Migrating to 12-digit storage is a separate refactor.
- Server-side re-fetch of TIC /lookup for isCeased. The trust boundary
  here is user-to-their-own-onboarding, not adversarial; doubling TIC
  API cost isn't proportionate.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-04-22 14:47:58 +02:00
committed by GitHub
co-authored by Claude Opus 4.7
parent f3a3d07ed3
commit 8fd3f112f8
12 changed files with 801 additions and 32 deletions
@@ -0,0 +1,43 @@
import { describe, it, expect } from 'vitest'
import { normalizeOrgNumber } from '../normalize-org-number'
describe('normalizeOrgNumber', () => {
it('accepts valid 10-digit AB org numbers (real Volvo)', () => {
expect(normalizeOrgNumber('5560125790')).toBe('5560125790')
expect(normalizeOrgNumber('556012-5790')).toBe('5560125790')
expect(normalizeOrgNumber(' 556012-5790 ')).toBe('5560125790')
})
it('strips the century prefix from 12-digit input and returns the 10-digit canonical', () => {
expect(normalizeOrgNumber('165560125790')).toBe('5560125790') // 16 = AB prefix
expect(normalizeOrgNumber('198001011231')).toBe('8001011231') // 19 = pre-2000 personnummer
expect(normalizeOrgNumber('19800101-1231')).toBe('8001011231')
})
it('accepts valid 10-digit personnummer-style org numbers', () => {
expect(normalizeOrgNumber('8001011231')).toBe('8001011231')
expect(normalizeOrgNumber('800101-1231')).toBe('8001011231')
})
it('rejects Luhn-invalid org numbers (blocks garbage at the boundary)', () => {
// 5560125791 has the last digit flipped from the real Volvo number
// 5560125790 — Luhn check fails.
expect(normalizeOrgNumber('5560125791')).toBeNull()
expect(normalizeOrgNumber('556012-5791')).toBeNull()
// Typo: swapping adjacent digits in the payload breaks the Luhn check.
expect(normalizeOrgNumber('5506125790')).toBeNull()
})
it('rejects wrong lengths and non-digit content', () => {
expect(normalizeOrgNumber('')).toBeNull()
expect(normalizeOrgNumber('abc123')).toBeNull()
expect(normalizeOrgNumber('12345')).toBeNull() // too short
expect(normalizeOrgNumber('12345678901')).toBeNull() // 11 digits
expect(normalizeOrgNumber('1234567890123')).toBeNull() // 13 digits
})
it('returns null for nullish input', () => {
expect(normalizeOrgNumber(null)).toBeNull()
expect(normalizeOrgNumber(undefined)).toBeNull()
})
})
@@ -0,0 +1,33 @@
import { luhnValidate } from '@/lib/bankgiro/luhn'
/**
* Normalize an org number to gnubok's canonical 10-digit storage form.
*
* Accepts hyphen/space-formatted input in either of the two shapes Swedish
* users commonly type:
* - 10 digits (5560125790 or 8001011231) — stored as-is
* - 12 digits (198001011231) — century prefix stripped
*
* Returns null for any other length, non-digit content, or invalid Luhn
* check digit (the structural rule Bolagsverket and personnummer share).
* Storing a structurally invalid org number would later be caught by
* Skatteverket SRU and any receiving SIE4 system — refusing at the boundary
* keeps gnubok's bookkeeping from accumulating under an unusable identifier.
*
* 10-digit storage matches the rest of the codebase — see
* `lib/skatteverket/format.ts`, which converts 10→12 at export time by
* prefixing with '16' (AB) or '19'/'20' (EF personnummer).
*/
export function normalizeOrgNumber(raw: string | null | undefined): string | null {
if (!raw) return null
const cleaned = raw.replace(/[\s-]/g, '')
let canonical: string
if (/^\d{10}$/.test(cleaned)) {
canonical = cleaned
} else if (/^\d{12}$/.test(cleaned)) {
canonical = cleaned.substring(2)
} else {
return null
}
return luhnValidate(canonical) ? canonical : null
}
+262 -7
View File
@@ -6,17 +6,45 @@ vi.mock('next/cache', () => ({
vi.mock('@/lib/supabase/server', () => ({
createClient: vi.fn(),
createServiceClient: vi.fn(),
}))
vi.mock('@/lib/company/context', () => ({
setActiveCompany: vi.fn().mockResolvedValue(undefined),
}))
import { createClient } from '@/lib/supabase/server'
import { createCompanyFromTicRole } from '../actions'
import { createClient, createServiceClient } from '@/lib/supabase/server'
import { createCompanyFromTicRole, createCompanyFromOnboarding } from '../actions'
import type { CompanyLookupResult } from '@/lib/company-lookup/types'
const mockCreateClient = vi.mocked(createClient)
const mockCreateServiceClient = vi.mocked(createServiceClient)
/**
* Build a service-role client mock. Seed `existingOrgNumber` when you want
* the duplicate-org guard in createCompanyFromOnboarding to find a match.
* Any other service-role query resolves to `{ data: null, error: null }`.
*/
function mockServiceClientForOrgNumber(existingOrgNumber?: string) {
const serviceFrom = vi.fn().mockImplementation(() => {
const chain: Record<string, unknown> = {}
const methods = ['select', 'eq', 'is', 'in', 'order', 'limit', 'maybeSingle']
for (const m of methods) {
chain[m] = () => {
if (m === 'maybeSingle') {
return Promise.resolve({
data: existingOrgNumber ? { id: 'other-company', name: 'Other AB' } : null,
error: null,
})
}
return chain
}
}
chain.then = (resolve: (v: unknown) => void) => resolve({ data: null, error: null })
return chain
})
mockCreateServiceClient.mockReturnValue({ from: serviceFrom } as never)
}
type CapturedCall = { table: string; method: string; args: unknown[] }
@@ -79,6 +107,9 @@ function buildSupabase(opts: {
beforeEach(() => {
vi.clearAllMocks()
// Default: no existing company with this org_number. Individual tests can
// override by calling mockServiceClientForOrgNumber('...') inside the test.
mockServiceClientForOrgNumber(undefined)
})
describe('createCompanyFromTicRole', () => {
@@ -88,7 +119,7 @@ describe('createCompanyFromTicRole', () => {
const result = await createCompanyFromTicRole({
teamId: 'team-1',
orgNumber: '5566778899',
orgNumber: '5560125790',
legalName: 'Acme AB',
legalEntityType: 'AB',
lookup: null,
@@ -121,7 +152,7 @@ describe('createCompanyFromTicRole', () => {
const result = await createCompanyFromTicRole({
teamId: 'team-1',
orgNumber: '5566778899',
orgNumber: '5560125790',
legalName: 'Acme AB',
legalEntityType: 'AB',
lookup: null,
@@ -163,7 +194,7 @@ describe('createCompanyFromTicRole', () => {
const result = await createCompanyFromTicRole({
teamId: 'team-1',
orgNumber: '5566778899',
orgNumber: '5560125790',
legalName: 'Acme Konsult AB',
legalEntityType: 'AB',
lookup,
@@ -178,7 +209,7 @@ describe('createCompanyFromTicRole', () => {
const settings = (settingsUpsert!.args[0] as Record<string, unknown>)
expect(settings.entity_type).toBe('aktiebolag')
expect(settings.company_name).toBe('Acme Konsult AB')
expect(settings.org_number).toBe('5566778899')
expect(settings.org_number).toBe('5560125790')
expect(settings.f_skatt).toBe(true)
expect(settings.vat_registered).toBe(true)
expect(settings.moms_period).toBe('quarterly')
@@ -218,7 +249,7 @@ describe('createCompanyFromTicRole', () => {
await createCompanyFromTicRole({
teamId: 'team-1',
orgNumber: '8001011234',
orgNumber: '8001011231',
legalName: 'Liten EF',
legalEntityType: 'Enskild firma',
lookup,
@@ -233,3 +264,227 @@ describe('createCompanyFromTicRole', () => {
expect(settings.accounting_method).toBe('cash')
})
})
describe('createCompanyFromOnboarding — duplicate org_number guard', () => {
it('refuses to create a company when the org number already exists', async () => {
const { supabase, calls } = buildSupabase({
user: { id: 'user-1' },
rpcResults: {
create_company_with_owner: { data: 'should-not-be-called' },
},
})
mockCreateClient.mockResolvedValue(supabase as never)
mockServiceClientForOrgNumber('5560125790') // pretend this org is already taken
const result = await createCompanyFromOnboarding({
teamId: 'team-1',
settings: {
entity_type: 'aktiebolag',
company_name: 'Acme AB',
org_number: '5560125790',
},
fiscalPeriod: {
startDate: '2026-01-01',
endDate: '2026-12-31',
name: 'Räkenskapsår 2026',
},
})
expect(result.error).toBe('org_number_exists')
expect(result.companyId).toBeUndefined()
// Guard must short-circuit before the create RPC runs — otherwise we'd
// leave a ghost company behind when the duplicate is detected.
const rpcCreate = supabase.rpc.mock.calls.find(([name]) => name === 'create_company_with_owner')
expect(rpcCreate).toBeUndefined()
// And no company_settings upsert should have happened.
expect(calls.find((c) => c.table === 'company_settings' && c.method === 'upsert')).toBeUndefined()
})
it('tolerates formatted org_numbers when detecting duplicates (hyphens/spaces stripped)', async () => {
const { supabase } = buildSupabase({
user: { id: 'user-1' },
rpcResults: { create_company_with_owner: { data: 'x' } },
})
mockCreateClient.mockResolvedValue(supabase as never)
mockServiceClientForOrgNumber('5560125790')
const result = await createCompanyFromOnboarding({
teamId: 'team-1',
settings: {
entity_type: 'aktiebolag',
company_name: 'Acme AB',
// User-typed format — the guard should still catch this as a duplicate.
org_number: '556677-8899',
},
fiscalPeriod: {
startDate: '2026-01-01',
endDate: '2026-12-31',
name: 'Räkenskapsår 2026',
},
})
expect(result.error).toBe('org_number_exists')
})
it('normalizes 12-digit personnummer input down to the 10-digit canonical form', async () => {
const { supabase } = buildSupabase({
user: { id: 'user-1' },
rpcResults: { create_company_with_owner: { data: 'x' } },
})
mockCreateClient.mockResolvedValue(supabase as never)
// The existing company is stored as the 10-digit canonical form.
mockServiceClientForOrgNumber('8001011231')
const result = await createCompanyFromOnboarding({
teamId: 'team-1',
settings: {
entity_type: 'enskild_firma',
company_name: 'Anna EF',
// User types full 12-digit personnummer with century prefix.
org_number: '19800101-1231',
},
fiscalPeriod: {
startDate: '2026-01-01',
endDate: '2026-12-31',
name: 'Räkenskapsår 2026',
},
})
// Should detect the duplicate despite the 12-digit input.
expect(result.error).toBe('org_number_exists')
})
it('rejects malformed org_numbers at the guard boundary', async () => {
const { supabase } = buildSupabase({
user: { id: 'user-1' },
rpcResults: { create_company_with_owner: { data: 'x' } },
})
mockCreateClient.mockResolvedValue(supabase as never)
const result = await createCompanyFromOnboarding({
teamId: 'team-1',
settings: {
entity_type: 'aktiebolag',
company_name: 'Broken AB',
org_number: 'abc123', // not a 10- or 12-digit number
},
fiscalPeriod: {
startDate: '2026-01-01',
endDate: '2026-12-31',
name: 'Räkenskapsår 2026',
},
})
expect(result.error).toBe('org_number_invalid')
// Must NOT have reached the create RPC — otherwise we'd save a malformed
// org_number and poison SIE/SRU exports.
const rpcCreate = supabase.rpc.mock.calls.find(([name]) => name === 'create_company_with_owner')
expect(rpcCreate).toBeUndefined()
})
it('rejects right-length org_numbers with invalid Luhn check digit', async () => {
const { supabase } = buildSupabase({
user: { id: 'user-1' },
rpcResults: { create_company_with_owner: { data: 'x' } },
})
mockCreateClient.mockResolvedValue(supabase as never)
const result = await createCompanyFromOnboarding({
teamId: 'team-1',
settings: {
entity_type: 'aktiebolag',
company_name: 'Fake AB',
// 10 digits but Luhn check digit is wrong (real Volvo is 5560125790;
// the trailing 1 is an intentional off-by-one). Skatteverket SRU
// validators and receiving SIE4 consumers would reject this, so we
// refuse at the boundary.
org_number: '5560125791',
},
fiscalPeriod: {
startDate: '2026-01-01',
endDate: '2026-12-31',
name: 'Räkenskapsår 2026',
},
})
expect(result.error).toBe('org_number_invalid')
const rpcCreate = supabase.rpc.mock.calls.find(([name]) => name === 'create_company_with_owner')
expect(rpcCreate).toBeUndefined()
})
it('fails closed when the duplicate lookup errors out (does not silently allow duplicates)', async () => {
const { supabase } = buildSupabase({
user: { id: 'user-1' },
rpcResults: { create_company_with_owner: { data: 'x' } },
})
mockCreateClient.mockResolvedValue(supabase as never)
// Seed a service client that errors on maybeSingle — simulating a DB
// outage or RLS misconfiguration.
mockCreateServiceClient.mockReturnValue({
from: vi.fn().mockReturnValue({
select: vi.fn().mockReturnThis(),
eq: vi.fn().mockReturnThis(),
is: vi.fn().mockReturnThis(),
limit: vi.fn().mockReturnThis(),
maybeSingle: vi.fn().mockResolvedValue({
data: null,
error: { message: 'connection lost' },
}),
}),
// eslint-disable-next-line @typescript-eslint/no-explicit-any
} as any)
const result = await createCompanyFromOnboarding({
teamId: 'team-1',
settings: {
entity_type: 'aktiebolag',
company_name: 'Acme AB',
org_number: '5560125790',
},
fiscalPeriod: {
startDate: '2026-01-01',
endDate: '2026-12-31',
name: 'Räkenskapsår 2026',
},
})
// Must return a user-facing error, NOT silently proceed with creation.
expect(result.companyId).toBeUndefined()
expect(result.error).toBeTruthy()
// And the create RPC must not have been called.
const rpcCreate = supabase.rpc.mock.calls.find(([name]) => name === 'create_company_with_owner')
expect(rpcCreate).toBeUndefined()
})
})
describe('createCompanyFromTicRole — ceased companies', () => {
it('refuses to provision when TIC lookup reports the company is ceased', async () => {
const lookup: CompanyLookupResult = {
companyName: 'Avregistrerat AB',
isCeased: true, // <- key field
address: null,
registration: { fTax: false, vat: false },
bankAccounts: [],
email: null,
phone: null,
sniCodes: [],
}
const { supabase, calls } = buildSupabase({ user: { id: 'user-1' } })
mockCreateClient.mockResolvedValue(supabase as never)
const result = await createCompanyFromTicRole({
teamId: 'team-1',
orgNumber: '5560125790',
legalName: 'Avregistrerat AB',
legalEntityType: 'AB',
lookup,
})
expect(result.error).toBe('company_ceased')
const writes = calls.filter((c) => ['insert', 'upsert', 'delete', 'update'].includes(c.method))
expect(writes).toEqual([])
})
})
+84 -1
View File
@@ -1,12 +1,43 @@
'use server'
import { createClient } from '@/lib/supabase/server'
import { createClient, createServiceClient } from '@/lib/supabase/server'
import { setActiveCompany } from '@/lib/company/context'
import { revalidatePath } from 'next/cache'
import { computeFiscalPeriod } from '@/lib/company/compute-fiscal-period'
import { mapEntityType } from '@/lib/company-lookup/entity-type-map'
import { normalizeOrgNumber } from '@/lib/company-lookup/normalize-org-number'
import type { CompanyLookupResult } from '@/lib/company-lookup/types'
/**
* Check whether an org number is already registered in any non-archived
* gnubok company. Uses the service role because RLS hides rows the caller
* isn't a member of — and "other users' duplicates" is exactly what we
* need to detect. Returns null when `orgNumber` is empty/malformed. Throws
* if the underlying query fails — callers must not silently treat that as
* "no duplicate," or the whole guard gets bypassed on transient DB errors.
*/
async function findExistingCompanyByOrgNumber(
orgNumber: string | null | undefined,
): Promise<{ id: string; name: string } | null> {
const cleaned = normalizeOrgNumber(orgNumber)
if (!cleaned) return null
const service = createServiceClient()
const { data, error } = await service
.from('companies')
.select('id, name')
.eq('org_number', cleaned)
.is('archived_at', null)
.limit(1)
.maybeSingle()
if (error) {
throw new Error(`Duplicate-org lookup failed: ${error.message}`)
}
return data ?? null
}
export async function switchCompany(companyId: string): Promise<{ error?: string }> {
const supabase = await createClient()
const { data: { user } } = await supabase.auth.getUser()
@@ -60,6 +91,34 @@ export async function createCompanyFromOnboarding(params: {
const companyName = (params.settings.company_name as string | undefined) || 'Mitt företag'
// Duplicate-org guard. We don't have a DB unique constraint on
// companies.org_number (can't add one safely without cleaning up any
// existing duplicates first), so enforce uniqueness at the application
// boundary. Must run before the create RPC so we don't leave a ghost
// company if the duplicate is detected mid-flow.
//
// normalizeOrgNumber returns null for malformed input — we refuse rather
// than storing a value that would break SIE/SRU exports later.
const rawOrgNumber = params.settings.org_number as string | undefined
const cleanedOrgNumber = normalizeOrgNumber(rawOrgNumber)
if (rawOrgNumber && rawOrgNumber.trim() && !cleanedOrgNumber) {
return { error: 'org_number_invalid' }
}
if (cleanedOrgNumber) {
try {
const existing = await findExistingCompanyByOrgNumber(cleanedOrgNumber)
if (existing) {
return { error: 'org_number_exists' }
}
} catch (err) {
// Guard must fail closed: if we can't confirm uniqueness, don't create
// a company. A silent pass-through would let transient DB errors
// through as duplicates (exactly the bug Greptile flagged).
console.error('[createCompanyFromOnboarding] duplicate-org lookup failed', err)
return { error: 'Kunde inte verifiera organisationsnummer. Försök igen.' }
}
}
// 1. Create company + owner membership atomically via RPC
const { data: newCompanyId, error: companyError } = await supabase.rpc('create_company_with_owner', {
p_name: companyName,
@@ -82,6 +141,22 @@ export async function createCompanyFromOnboarding(params: {
await supabase.from('companies').delete().eq('id', newCompanyId)
}
// Mirror the normalized org_number onto the companies row so future
// duplicate checks and cross-references are reliable. MUST be error-checked
// and rolled back on failure — otherwise the freshly-created company would
// exist without an org_number and the duplicate guard would never match it
// for any future user (the very guard this code is enforcing).
if (cleanedOrgNumber) {
const { error: orgUpdateError } = await supabase
.from('companies')
.update({ org_number: cleanedOrgNumber })
.eq('id', newCompanyId)
if (orgUpdateError) {
await rollback('org_number update failed', orgUpdateError)
return { error: 'Kunde inte spara organisationsnummer. Försök igen.' }
}
}
// 2. Seed chart of accounts
const { error: coaError } = await supabase.rpc('seed_chart_of_accounts', {
p_company_id: newCompanyId,
@@ -194,6 +269,14 @@ export async function createCompanyFromTicRole(params: {
return { error: 'lookup_missing' }
}
// Ceased/struck-off companies must not be provisioned. Under BFL 2 kap,
// bokföringsskyldighet ends when a company is avregistrerad; creating a
// new gnubok accounting entity for a non-existent legal entity would let
// users file momsdeklarationer or årsredovisning for it.
if (params.lookup.isCeased) {
return { error: 'company_ceased' }
}
// SPAR address fallback if the TIC lookup didn't include one.
const { data: enrichmentRow } = await supabase
.from('extension_data')