feat: enable banking hardening, arcim inference, SIE fixes, onboarding (#32)

* feat: import system improvements, INK2 fix, and Swedish text corrections

- SIE parser: Windows-1252 and CP437 encoding detection and decoding
- Bank file parser: add Nordea Business (Företag) CSV format
- Bank file parser: improve format detection for SEB, Länsförsäkringar, generic CSV
- INK2 engine: calculate årets resultat (7222) from income statement for open fiscal years
- Dashboard: parallel Supabase queries, simplified dashboard page
- Fix Swedish characters (å, ä, ö) in BAS data descriptions, validation messages, AI consent disclosures
- Import wizard UI improvements across all steps
- Migration: add 'bas_range' match type to sie_account_mappings constraint
- Extensive new tests for SIE parser encoding and bank file parser

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: arcim migration wizard UX fixes, Sentry setup, and extension scaffolding

Arcim migration wizard improvements:
- Progress bar now excludes non-interactive steps (migrating/result)
- Fix OAuth text to match target="_blank" behavior (new tab, not redirect)
- Display month names instead of "Månad X" in preview
- Fix Swedish typo "förifylla" in no-company-info message
- Replace native checkboxes with shadcn Switch in options step
- Add ConfirmationDialog before starting migration
- Show progress percentage during migration
- Add "Nästa steg" guidance and navigation links in result step
- Add "Försök igen" button in error state (returns to options)
- Add Bokio company ID help text (GUID from URL)
- Add Fortnox integration add-on hint on connection failure

Also includes: SIE import system improvements, INK2 fixes, Swedish text
corrections, Sentry error tracking setup, and arcim-migration extension
scaffolding.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address PR review feedback

- Fix OAuth error recovery blank page (restore provider from URL params)
- Pass real userId to MigrationWizard instead of empty string
- Remove ~50 debug console.log statements from sie-import.ts
- Fix comment referencing account 3740 → 3741

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: comprehensive UI design audit and normalization

Dashboard audit:
- Fix muted-foreground contrast (4.31:1 → 5.08:1) for WCAG AA
- Add prefers-reduced-motion media query for all animations
- Replace border-l-2 accent anti-pattern with subtle full-border colors
- Add aria-expanded to toggle buttons, role="status" to live counters
- Fix touch targets on deadline buttons (28px → 36px)
- Vary section spacing for rhythm (mb-12/mb-10/mb-8)
- Remove unused imports and dead code

Transactions audit + hardening:
- Add pagination (200 per page) with "Ladda fler" button
- Replace height animation with transform-only exit animation
- Show batch progress in floating action bar during processing
- Fix batch bar mobile overlap (bottom-20 on mobile)
- Replace clickable badges with proper button elements
- Add safe area padding to fullscreen swipe view
- Add response.ok check to suggestion fetch
- Add truncation to invoice number buttons

Invoicing audit:
- Remove border-l-4 accent pattern from invoice cards
- Replace string concatenation with cn() utility

Systemic sweep (34 files):
- All page headings: font-bold → font-display font-medium (Fraunces)
- All stat numbers: font-bold → font-display font-medium tabular-nums
- All hard-coded blue/amber/emerald colors → design tokens
- Remove all dark mode overrides (tokens handle automatically)
- Tint pure white card background to 99%

Design context added to CLAUDE.md with brand personality,
aesthetic direction, and 5 design principles.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: bookkeeping flow audit — design system, accessibility, UX

- Replace raw <select> with shadcn Select component (JournalEntryForm)
- Add confirmation dialog for account deletion (ChartOfAccountsManager)
- Remove console.error from production code (JournalEntryList, JournalEntryForm)
- Fix contradictory h-7/min-h-[44px] button sizing → h-10 (ChartOfAccountsManager)
- Increase BAS catalog "Lägg till" touch target h-7 → h-9
- Improve loading state with spinner (JournalEntryList)
- Improve empty state with icon, description, and guidance (JournalEntryList)
- Add response.ok check on journal entry fetch
- Add aria-expanded to entry expand buttons
- Add tabular-nums to desktop debit/credit columns

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: onboarding and empty state improvements

Onboarding:
- Replace font-serif with font-display (Fraunces) for brand consistency
- Remove console.error calls from production code

Empty states:
- Fix broken /transactions/new link in EmptyTransactions (route doesn't exist)
- Add actionHref fallback to EmptyCustomers when no onAction prop provided
- Improve EmptyTransactions description copy

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: clarify Swedish UX copy — terminology, errors, descriptions

Terminology consistency:
- "Försenad" → "Förfallen" for overdue invoices (customers/[id])
- "bokföringsorder" → actionable description in bookkeeping page
- "verifikation har bifogats" → "underlag har bifogats" in doc warning
- "Fortsätt ändå" → "Bokför utan underlag" (specific action)

Error messages — replace generic "Fel" + "Något gick fel" with specific:
- "Något gick fel vid bokföring" → "Transaktionen kunde inte bokföras"
- "Något gick fel vid matchning" → "Transaktionen kunde inte matchas"
- "Kunde inte hämta X" → "Kunde inte ladda X" + recovery hint
- Add "Försök igen" guidance to all error toasts

Page descriptions — replace redundant with actionable:
- Invoices: "Skapa och hantera" → "Skicka, följ betalningar, skapa kreditnotor"
- Bookkeeping: list of features → actionable description

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: design critique — dashboard affordance, reports description

Dashboard:
- Add ChevronRight indicator to clickable summary cards
  (Att få betalt, Koppla bank) to distinguish from static cards
- Add cursor-pointer to linked cards

Reports:
- Replace feature list description with actionable guidance
  "Huvudbok, grundbok..." → "Generera skattedeklarationer..."

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: replace generic "Fel" error toasts with specific messages

Deadlines: 5 generic "Fel" → specific per-action titles
  (create, toggle, edit, delete, load)
Expenses detail: 5 generic "Fel" → specific per-action titles
  (load, approve, pay, credit, delete)
Expenses new: 3 generic "Fel" → instructional validation messages
  (supplier name, supplier selection, invoice number)
Customers: 1 generic "Fel" → specific load error with recovery hint

All error toasts now follow pattern:
  title = what failed, description = how to recover

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: replace all remaining generic "Fel" error toasts (37 instances)

Systematic sweep across 12 dashboard pages replacing generic
title: 'Fel' with context-specific error titles:

- Load errors: "Kunde inte ladda [resurs]"
- Action errors: "[Åtgärd] misslyckades"
- Validation: "[Fält] saknas"

Every error toast now tells the user what failed without needing
to read the description. Recovery hints added where missing.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: import flow — normalize stat typography, remove console.warn

- Replace font-bold with font-display font-medium on 13 stat numbers
  across SIEPreviewStep, BankFilePreviewStep, BankFileConfirmStep,
  ImportResultStep (missed by systemic sweep since these are in
  components/import/, not app/(dashboard)/)
- Add tabular-nums to stat numbers displaying counts/currency
- Remove console.warn in ArcimMigrationWorkspace

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: final cleanup — console statements, remaining font-bold stats

Remove production console statements:
- Step1EntityType: remove debug console.warn (dead code after onNext)
- TransactionBookingDialog: remove console.error on doc link failure
- JournalEntryAttachments: remove 3 console.error calls

Normalize remaining font-bold stat displays:
- SwipeCategorizationView: 3 instances (completion, amount displays)
- NEDeclarationView: yearly result heading + value

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: address Greptile review feedback

loadMoreTransactions: add inbox item enrichment matching fetchTransactions
- Paginated transactions now fetch invoice_inbox_items in parallel
- Fixes missing document indicator, template suggestions, and inbox
  match card for transactions loaded via "Ladda fler"

fetchAllPages: add maxPages guard (default 500) to prevent infinite loop
- If Arcim gateway returns hasMore:true indefinitely, the loop now
  exits after 500 pages instead of running forever

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: minimize CLAUDE.md — remove derivable content, fix stale data

Remove ~230 lines (51% reduction) of content that duplicates what's
already in the source code (directory tree, function tables, type
definitions, migration lists). Update migration count (63→65), add
missing test helpers, fix cron job list. Keep all high-value sections:
accounting guard rails, BAS accounts, VAT rutor, design context.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: enable banking hardening, arcim entity inference, SIE import fixes, and onboarding improvements

- Enable Banking: OAuth CSRF state tokens, JWT caching, retry with timeouts, raw PSD2 response archival (BFL 7 kap), expired/error connection UI, consent expiry notifications, pagination safety limits
- Arcim migration: Smarter entity type inference from org numbers, VAT prefixes, company name suffixes (GmbH, Ltd, etc.), and country codes
- SIE import: Parser and import fixes with new migration
- BAS accounts: Added vehicle accounts (1241, 1242, 1249, 1259)
- Dashboard: New SIE import and stale uncategorized transaction queries
- Onboarding: Enhanced NewUserChecklist
- Period service: Improvements with updated tests
- Transaction ingest: Updated logic and tests

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: address Greptile review — credit note type, EU country codes, notification thresholds, migration timestamps

- Fix dead ternary: credit notes now correctly stored as 'credit_note' instead of 'invoice'
- Add 'GR' (Greece ISO 3166-1) to EU_COUNTRIES alongside 'EL' (VAT prefix)
- Fix consent notification condition: fire at exactly 7 days or ≤3 days, not every day in 7-day window
- Deduplicate migration timestamps: rename SIE migration to 20260316120100

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-03-16 14:21:32 +01:00
committed by GitHub
co-authored by Claude Opus 4.6
parent 56fb117d16
commit 98cd253bce
37 changed files with 2197 additions and 413 deletions
@@ -0,0 +1,109 @@
import { describe, it, expect, vi, beforeEach } from 'vitest'
// Mock dependencies — factory must not reference outer variables
const mockCreateSession = vi.fn()
const mockGetAccountBalance = vi.fn()
vi.mock('@/extensions/general/enable-banking/lib/api-client', () => ({
createSession: (...args: unknown[]) => mockCreateSession(...args),
getAccountBalance: (...args: unknown[]) => mockGetAccountBalance(...args),
}))
// Use hoisted to safely create mock objects referenced in vi.mock factories
const { mockFrom } = vi.hoisted(() => {
const mockFrom = vi.fn()
return { mockFrom }
})
vi.mock('@/lib/supabase/server', () => ({
createServiceClient: vi.fn().mockResolvedValue({
from: mockFrom,
}),
}))
vi.stubEnv('NEXT_PUBLIC_APP_URL', 'http://localhost:3000')
import { GET } from '../route'
function makeRequest(params: Record<string, string>) {
const url = new URL('http://localhost:3000/api/extensions/enable-banking/callback')
for (const [k, v] of Object.entries(params)) {
url.searchParams.set(k, v)
}
return new Request(url.toString())
}
function mockChain(result: { data?: unknown; error?: unknown }) {
const chain: Record<string, unknown> = {}
for (const m of ['select', 'eq', 'single', 'update', 'order', 'limit']) {
chain[m] = vi.fn().mockReturnValue(chain)
}
chain.single = vi.fn().mockResolvedValue({ data: result.data ?? null, error: result.error ?? null })
// For chains ending without .single()
chain.then = (resolve: (v: unknown) => void) => resolve({ data: result.data ?? null, error: result.error ?? null })
return chain
}
describe('GET /api/extensions/enable-banking/callback', () => {
beforeEach(() => {
vi.clearAllMocks()
})
it('rejects when state does not match any pending connection', async () => {
mockFrom.mockImplementation(() =>
mockChain({ data: null, error: { message: 'not found' } })
)
const response = await GET(makeRequest({ code: 'auth-code', state: 'unknown-state' }))
expect(response.status).toBe(307)
const location = response.headers.get('location') || ''
expect(location).toContain('bank_error=invalid_state')
})
it('activates connection and clears oauth_state on success', async () => {
let callIndex = 0
mockFrom.mockImplementation(() => {
callIndex++
if (callIndex === 1) {
// Find pending connection by oauth_state
return mockChain({ data: { id: 'conn-1', user_id: 'user-1' }, error: null })
}
if (callIndex === 2) {
// Update connection
return mockChain({ data: null, error: null })
}
// Company settings lookup
return mockChain({ data: { onboarding_complete: true }, error: null })
})
mockCreateSession.mockResolvedValue({
session_id: 'sess-1',
accounts: [],
access: { valid_until: '2024-12-31T00:00:00Z' },
aspsp: { name: 'TestBank', country: 'SE' },
})
const response = await GET(makeRequest({ code: 'auth-code', state: 'valid-state' }))
expect(response.status).toBe(307)
const location = response.headers.get('location') || ''
expect(location).toContain('bank_connected=true')
expect(location).toContain('connection_id=conn-1')
})
it('redirects with error when bank returns error param', async () => {
const response = await GET(makeRequest({ error: 'access_denied', error_description: 'User cancelled' }))
expect(response.status).toBe(307)
const location = response.headers.get('location') || ''
expect(location).toContain('bank_error=User%20cancelled')
})
it('redirects with error when code or state is missing', async () => {
const response = await GET(makeRequest({ code: 'auth-code' }))
expect(response.status).toBe(307)
const location = response.headers.get('location') || ''
expect(location).toContain('bank_error=missing_parameters')
})
})
@@ -14,7 +14,7 @@ export async function GET(request: Request) {
const { searchParams } = new URL(request.url)
const code = searchParams.get('code')
const state = searchParams.get('state') // This is the user_id we passed during authorization
const state = searchParams.get('state') // Cryptographic oauth_state token
const error = searchParams.get('error')
const errorDescription = searchParams.get('error_description')
@@ -35,8 +35,25 @@ export async function GET(request: Request) {
const supabase = await createServiceClient()
try {
// Look up pending connection by oauth_state (CSRF-safe)
const { data: pendingConnection, error: findError } = await supabase
.from('bank_connections')
.select('id, user_id')
.eq('oauth_state', state)
.eq('status', 'pending')
.single()
if (findError || !pendingConnection) {
console.error('No pending connection for oauth_state:', findError)
return NextResponse.redirect(
`${baseUrl}/settings?bank_error=${encodeURIComponent('invalid_state')}`
)
}
const userId = pendingConnection.user_id
const sessionData = await createSession(code)
const { session_id, accounts, access, aspsp } = sessionData
const { session_id, accounts, access } = sessionData
const consentExpiresAt = access.valid_until
const accountsWithBalances: StoredAccount[] = await Promise.all(
@@ -63,61 +80,28 @@ export async function GET(request: Request) {
})
)
const { data: pendingConnection, error: findError } = await supabase
const { error: updateError } = await supabase
.from('bank_connections')
.select('id')
.eq('user_id', state)
.eq('status', 'pending')
.order('created_at', { ascending: false })
.limit(1)
.single()
.update({
session_id,
status: 'active',
accounts_data: accountsWithBalances,
consent_expires: consentExpiresAt,
last_synced_at: new Date().toISOString(),
oauth_state: null, // Clear to prevent replay
})
.eq('id', pendingConnection.id)
let connectionId: string
if (findError || !pendingConnection) {
console.error('Could not find pending connection:', findError)
const { data: inserted, error: insertError } = await supabase
.from('bank_connections')
.insert({
user_id: state,
provider: `${aspsp.name.toLowerCase().replace(/\s+/g, '-')}-${aspsp.country.toLowerCase()}`,
bank_name: aspsp.name,
session_id,
status: 'active',
accounts_data: accountsWithBalances,
consent_expires: consentExpiresAt,
last_synced_at: new Date().toISOString(),
})
.select('id')
.single()
if (insertError || !inserted) {
console.error('Insert error:', insertError)
throw new Error('Failed to create connection')
}
connectionId = inserted.id
} else {
const { error: updateError } = await supabase
.from('bank_connections')
.update({
session_id,
status: 'active',
accounts_data: accountsWithBalances,
consent_expires: consentExpiresAt,
last_synced_at: new Date().toISOString(),
})
.eq('id', pendingConnection.id)
if (updateError) {
throw new Error('Failed to update connection')
}
connectionId = pendingConnection.id
if (updateError) {
throw new Error('Failed to update connection')
}
const connectionId = pendingConnection.id
const { data: userSettings } = await supabase
.from('company_settings')
.select('onboarding_complete')
.eq('user_id', state)
.eq('user_id', userId)
.single()
const redirectTarget = userSettings?.onboarding_complete
@@ -131,8 +115,8 @@ export async function GET(request: Request) {
try {
await supabase
.from('bank_connections')
.update({ status: 'error' })
.eq('user_id', state)
.update({ status: 'error', oauth_state: null })
.eq('oauth_state', state)
.eq('status', 'pending')
} catch {
// Ignore cleanup errors
@@ -1,7 +1,13 @@
import { createClient } from '@supabase/supabase-js'
import { createClient, type SupabaseClient } from '@supabase/supabase-js'
import { NextResponse } from 'next/server'
import { syncAccountTransactions } from '@/extensions/general/enable-banking/lib/sync'
import { isConsentExpiringSoon, getDaysUntilExpiry } from '@/extensions/general/enable-banking/lib/api-client'
import { getEmailService } from '@/lib/email/service'
import {
generateConsentExpiryEmailHtml,
generateConsentExpiryEmailText,
generateConsentExpiryEmailSubject,
} from '@/lib/email/consent-notification-templates'
import { ensureInitialized } from '@/lib/init'
import type { StoredAccount } from '@/extensions/general/enable-banking/types'
@@ -12,7 +18,7 @@ ensureInitialized()
* Automatic daily bank transaction sync
* Runs at 05:00 UTC (07:00 Swedish time)
*
* Processes up to 10 connections per run (Vercel Hobby 60s timeout).
* Processes up to 50 connections per run (Vercel Pro 300s timeout).
* Prioritizes connections not synced for the longest time.
* Deduplication via external_id makes repeated runs safe.
*/
@@ -68,6 +74,7 @@ export async function GET(request: Request) {
const startTime = Date.now()
const TIME_BUDGET_MS = 50_000 // 50s — leave 10s margin for Vercel timeout
const baseUrl = process.env.NEXT_PUBLIC_APP_URL || 'http://localhost:3000'
const results: {
connectionId: string
@@ -96,6 +103,11 @@ export async function GET(request: Request) {
.update({ status: 'expired' })
.eq('id', connection.id)
// Send expiry notification
await sendConsentExpiryNotification(
supabase, connection, 0, true, baseUrl
)
results.push({
connectionId: connection.id,
userId: connection.user_id,
@@ -111,6 +123,13 @@ export async function GET(request: Request) {
const expiringSoon = isConsentExpiringSoon(connection.consent_expires)
// Send consent expiry notifications at 7-day and 3-day thresholds
if (expiringSoon && daysLeft !== null && (daysLeft <= 3 || daysLeft === 7)) {
await sendConsentExpiryNotification(
supabase, connection, daysLeft, false, baseUrl
)
}
const toDate = new Date().toISOString().split('T')[0]
const fromDate = new Date(Date.now() - 7 * 24 * 60 * 60 * 1000)
.toISOString()
@@ -133,11 +152,13 @@ export async function GET(request: Request) {
const totalDuplicates = syncResults.reduce((sum, r) => sum + r.duplicates, 0)
const totalErrors = syncResults.reduce((sum, r) => sum + r.errors, 0)
// Successful sync: update connection and clear any previous error state
await supabase
.from('bank_connections')
.update({
accounts_data: accounts,
last_synced_at: new Date().toISOString(),
...(connection.error_message ? { error_message: null } : {}),
})
.eq('id', connection.id)
@@ -152,7 +173,15 @@ export async function GET(request: Request) {
daysUntilExpiry: daysLeft,
})
} catch (error) {
const message = error instanceof Error ? error.message : 'Unknown error'
console.error(`Sync failed for connection ${connection.id}:`, error)
// Persist error status on sync failure
await supabase
.from('bank_connections')
.update({ status: 'error', error_message: message })
.eq('id', connection.id)
results.push({
connectionId: connection.id,
userId: connection.user_id,
@@ -181,3 +210,65 @@ export async function GET(request: Request) {
results,
})
}
/**
* Send consent expiry notification email.
* Guards with last_expiry_notification_at to avoid spamming (2-day cooldown).
*/
// eslint-disable-next-line @typescript-eslint/no-explicit-any
async function sendConsentExpiryNotification(
supabase: SupabaseClient<any>,
connection: Record<string, unknown>,
daysLeft: number,
isExpired: boolean,
baseUrl: string
): Promise<void> {
try {
// Check cooldown: skip if notified within last 2 days
const lastNotified = connection.last_expiry_notification_at as string | null
if (lastNotified) {
const hoursSinceNotified = (Date.now() - new Date(lastNotified).getTime()) / (1000 * 60 * 60)
if (hoursSinceNotified < 48) return
}
const emailService = getEmailService()
if (!emailService.isConfigured()) return
const userId = connection.user_id as string
// Look up user email
const { data: userData } = await supabase.auth.admin.getUserById(userId)
if (!userData?.user?.email) return
// Look up company name
const { data: companySettings } = await supabase
.from('company_settings')
.select('company_name')
.eq('user_id', userId)
.single()
const emailData = {
bankName: connection.bank_name as string,
daysUntilExpiry: daysLeft,
renewalUrl: `${baseUrl}/settings?tab=banking`,
companyName: companySettings?.company_name || 'gnubok',
isExpired,
}
await emailService.sendEmail({
to: userData.user.email,
subject: generateConsentExpiryEmailSubject(emailData),
html: generateConsentExpiryEmailHtml(emailData),
text: generateConsentExpiryEmailText(emailData),
})
// Update last notification timestamp
await supabase
.from('bank_connections')
.update({ last_expiry_notification_at: new Date().toISOString() })
.eq('id', connection.id as string)
} catch (error) {
// Notification failure must not break the cron job
console.error(`[bank-sync-cron] Failed to send consent expiry notification:`, error)
}
}
+1 -1
View File
@@ -57,7 +57,7 @@ export async function POST(request: Request) {
if (duplicate) {
return NextResponse.json({
error: 'duplicate',
message: `This file has already been imported on ${new Date(duplicate.imported_at!).toLocaleDateString('sv-SE')}`,
message: `This file has already been imported on ${duplicate.imported_at ? new Date(duplicate.imported_at).toLocaleDateString('sv-SE') : 'okänt datum'}`,
importId: duplicate.id,
}, { status: 409 })
}