Bug/vat selection warning (#583)

* refactor: update VAT handling logic for non-registered sellers and improve related comments

* chore: gate automated email flows behind 503 responses

Disables user-facing access to invoice payment reminders and salary
payslip email sending. Underlying lib code (reminder-processor,
PDF templates, notification_settings) is preserved for easy re-enable.

- Invoice reminders cron route returns 503; settings UI section removed.
- Payslip send route returns 503; original implementation kept as
  _sendPayslipsImpl for future re-enable.
- Push notifications were already extension-disabled, no change needed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: remove Recapt feedback widget

Strips the third-party Recapt SDK and its floating feedback bubble from
the app. The in-app contact form keeps working via the existing email
channel (/api/support/contact). Drops the Recapt entries from the CSP
and the subprocessor list in the privacy policy.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat: reject meaningless rättelser in correctEntry

Guard against zero-economic-effect corrections in the storno engine:
- Reject when proposed lines net to zero on every account (e.g. 1930
  debit 100 / 1930 credit 100), which would erase the original posting
  without representing any affärshändelse (BFL 5 kap. 5 §).
- Reject when proposed lines are an exact multiset match of the original
  entry — a rättelse must actually change something.

New MeaninglessCorrectionError wired through bookkeepingErrorResponse
(HTTP 400) and the Swedish error translator.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat: add date-range picker to resultat- and balansrapport

Adds optional from/to date filtering to the four operational financial
reports (resultatrapport, balansrapport, income-statement, balance-sheet)
so users can view a month, quarter, or custom range inside a fiscal year
without leaving the report. Defaults to YTD; "Hela året" preserves the
prior full-period behaviour (URL-identical, cache-stable).

- trial-balance engine accepts optional fromDate/toDate, rolling prior
  in-period activity into IB and clamping period activity to the window
- 12 API routes accept and validate from_date/to_date query params
- ReportDateRange chip picker persists preset per company, only renders
  on the four relevant tabs
- FiscalYearSelector now emits the period object so the range picker
  has bounds without an extra fetch
- PDF/XLSX filenames reflect the chosen range
- Resultatrapport drops the prior-year column when narrowed (full-year
  vs partial-year would mislead)
- 11 new tests (engine + parser); all existing report tests pass

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat: add support for marking journal entries as "no document required"

- Introduced a new sidecar table `journal_entry_no_doc_required` to track entries that do not require separate documentation (e.g., bank fees, interest).
- Implemented API routes for creating and deleting exemptions, including validation and authorization checks.
- Added a toggle component in the UI to allow users to mark entries as exempt, with an optional reason.
- Updated relevant tests to cover the new functionality, including RLS checks and cascading deletes.
- Enhanced existing schemas and types to accommodate the new `vat_amount` field for supplier invoice items.

* fix: address PR review findings on no-doc-required + VAT changes

- pg-real cascade test wraps DELETE in gnubok.allow_delete='true' txn so the
  immutability trigger bypass fires (mirrors delete_last_voucher RPC).
- Clamp supplier-invoice item vat_amount to <= line_total * vat_rate via Zod
  refinement (with 1-öre rounding tolerance) so the manual override can't
  inflate the 2641 debit beyond the statutory ceiling.
- groupVatByRate falls back to line_total * rate when stored vat_amount is 0
  with a positive rate, so legacy/import paths leaving the column at its
  NOT NULL DEFAULT 0 don't silently understate ruta 48.
- ReportDateRange todayIso() and preset endpoints use local date components
  instead of toISOString() (UTC) — fixes the midnight-to-02:00 off-by-one
  that truncated a day from YTD / this-month / this-quarter for Swedish
  users.
- NoDocRequiredToggle restores the previous reason on failed POST/DELETE so
  the rolled-back toggle state stays consistent with the rendered reason.
- Document the company-scoped (not user-scoped) DELETE authorization policy
  on the no-document-required route.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-05-28 01:56:09 +02:00
committed by GitHub
co-authored by Claude Opus 4.7
parent 627109b5bd
commit a9b43ebeb7
73 changed files with 2552 additions and 714 deletions
+51
View File
@@ -682,6 +682,57 @@ describe('CreateSupplierInvoiceItemSchema', () => {
expect(result.success).toBe(true)
}
})
it('accepts vat_amount up to line_total * vat_rate', () => {
const result = CreateSupplierInvoiceItemSchema.safeParse(
validSupplierInvoiceItem({ amount: 5000, vat_rate: 0.25, vat_amount: 1250 })
)
expect(result.success).toBe(true)
})
it('accepts partial-deduction vat_amount (bilförmån 50%)', () => {
const result = CreateSupplierInvoiceItemSchema.safeParse(
validSupplierInvoiceItem({ amount: 5000, vat_rate: 0.25, vat_amount: 625 })
)
expect(result.success).toBe(true)
})
it('rejects vat_amount above line_total * vat_rate', () => {
const result = CreateSupplierInvoiceItemSchema.safeParse(
validSupplierInvoiceItem({ amount: 5000, vat_rate: 0.25, vat_amount: 2000 })
)
expect(result.success).toBe(false)
})
it('accepts vat_amount with 1-öre rounding tolerance', () => {
const result = CreateSupplierInvoiceItemSchema.safeParse(
validSupplierInvoiceItem({ amount: 100.04, vat_rate: 0.25, vat_amount: 25.02 })
)
expect(result.success).toBe(true)
})
it('works with quantity * unit_price line total', () => {
const overByABit = CreateSupplierInvoiceItemSchema.safeParse(
validSupplierInvoiceItem({
amount: undefined,
quantity: 4,
unit_price: 100,
vat_rate: 0.25,
vat_amount: 200,
})
)
expect(overByABit.success).toBe(false)
const exact = CreateSupplierInvoiceItemSchema.safeParse(
validSupplierInvoiceItem({
amount: undefined,
quantity: 4,
unit_price: 100,
vat_rate: 0.25,
vat_amount: 100,
})
)
expect(exact.success).toBe(true)
})
})
describe('MarkSupplierInvoicePaidSchema', () => {
+23 -1
View File
@@ -349,11 +349,33 @@ export const CreateSupplierInvoiceItemSchema = z.object({
amount: z.number().optional(),
account_number: accountNumber,
vat_rate: z.number().min(0).max(100).optional(),
// Manual VAT override. When provided, the engine books this exact amount to
// 2641/2645 instead of recomputing line_total × vat_rate. Use for partial-
// deductible cases (bilförmån 50%, representation 300 kr-tak), foreign-
// currency rounding, or POS receipts where supplier-side rounding makes the
// VAT off by öre.
vat_amount: z.number().min(0).optional(),
vat_code: z.string().optional(),
quantity: z.number().optional(),
unit: z.string().optional(),
unit_price: z.number().optional(),
})
}).refine(
(item) => {
if (item.vat_amount == null) return true
const lineTotal = item.amount != null
? item.amount
: (item.quantity ?? 1) * (item.unit_price ?? 0)
const vatRate = item.vat_rate ?? 0.25
const maxVat = Math.round(lineTotal * vatRate * 100) / 100
// 1-öre tolerance covers POS rounding; anything beyond is an upstream bug
// or a client trying to inflate 2641 debit beyond the statutory ceiling.
return item.vat_amount <= maxVat + 0.01
},
{
message: 'vat_amount cannot exceed line_total × vat_rate',
path: ['vat_amount'],
},
)
export const CreateSupplierInvoiceSchema = z.object({
supplier_id: uuid,