feat(agent): telemetry + CI-gate quick wins from the "AI systems that ship" audit (#677)

* feat(agent): telemetry completeness + durability, CI gates, commit_method provenance

Quick wins from the "Building AI systems that ship" audit:

- mcp.tool_called gains errorMessage (message_sv, truncated 500 chars) on
  all failure exits; new mcp.skill_loaded event on every gnubok_load_skill
  (all tiers) so atom usage is finally measurable
- event_log: (event_type, created_at) index; cleanup cron keeps
  mcp.*/agent.* telemetry 180 days (delivery events stay 30)
- CI: lint ratchet (npm run check:lint — 60 legacy errors baselined,
  fails only on NEW errors) and a pg-real coverage gate (migrations
  touching trigger/RPC/RLS/DEFERRABLE require a *.pg.test.ts change;
  escape hatch: -- pg-test: covered-by/skip)
- journal_entries.commit_method CHECK widened with 'api_key'/'agent';
  the MCP approve path records 'api_key' truthfully instead of
  'user_accept' (agent_first_vision §8 P0-1). 'agent' is reserved — ALL
  MCP traffic (incl. claude.ai OAuth, whose access_token is a minted
  API key) authenticates as api_key today

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(import): derive opening balances from prior-year #UB when SIE lacks #IB (#675)

SIE files exported without #IB 0 rows (only #UB -1) previously imported
with zero opening balances. getEffectiveOpeningBalances() now derives IB
from prior-year UB for balance-sheet accounts when explicit #IB is
absent, surfaces the derivation as an info issue in the import preview,
and excludes share-capital vouchers from opening-balance detection.
Detection regexes are shared between parser and importer so the two
checks cannot drift. 507 lib/import tests pass.

(Authored in a parallel session in this checkout; included per request.)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(review): address PR #677 bot findings — RoPA entry, execFileSync, gate scope note

Triage of the compliance-swarm + Greptile findings:

Applied:
- .compliance/ropa.yaml: new mcp.telemetry processing activity declaring
  the 180-day mcp.*/agent.* retention, lawful basis, data categories, and
  the no-args/no-results minimisation (ISO A.8.10, GDPR Art.5(1)(c) —
  the retention split is now formally documented, referenced from the cron)
- check-pg-test-coverage.mjs: execFileSync with argv array — no shell, so
  a hostile base-ref can't inject (ASVS V13.2.1); verified an injection
  attempt exits 2 without executing
- check-pg-test-coverage.mjs: documented the PR-level (not per-migration)
  scope of the gate so reviewers know to check coverage per migration when
  a PR carries several risky migrations (Greptile P2)

Acknowledged, no change:
- errorMessage PII risk: messages are domain-mapped strings; event_log
  already persists far richer delivery payloads under the same RLS; now
  declared in ropa.yaml
- cron error envelope: errorResponse maps to the canonical safe envelope
  and the endpoint is CRON_SECRET-gated
- two-pass delete "partial state": TTL deletes are idempotent — the next
  daily run sweeps whatever a failed pass left behind
- skill_loaded actorLabel/sessionId: mirrors the pre-existing
  mcp.tool_called payload; sessionId is the join key the analytics exist for

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-06-05 15:47:13 +02:00
committed by GitHub
co-authored by Claude Opus 4.8
parent 076bb169f8
commit bc61862e76
24 changed files with 1733 additions and 62 deletions
+6 -1
View File
@@ -36,7 +36,8 @@ const PERSISTED_EVENT_TYPES: CoreEventType[] = [
'supplier_invoice.match_confirmed',
'supplier_invoice.confirmed',
// MCP telemetry — every tool invocation, tools/list call, and resources/read.
// Lightweight metadata only; 30-day TTL on event_log bounds the volume.
// Lightweight metadata only. mcp.*/agent.* rows are retained 180 days by the
// cleanup cron (error-rate trends need more than the 30-day delivery window).
'mcp.tool_called',
'mcp.tools_list_called',
'mcp.resource_read',
@@ -46,6 +47,10 @@ const PERSISTED_EVENT_TYPES: CoreEventType[] = [
'mcp.workflow_started',
'mcp.workflow_completed',
'mcp.next_hint_followed',
// Every successful gnubok_load_skill, all tiers — which atoms agents
// actually load. Joined against mcp.tool_called error rates to measure
// whether a loaded atom helps or hurts.
'mcp.skill_loaded',
// Agent self-reported feedback — surfaces "this tool was missing", "this
// description was wrong", etc. Quarterly review → roadmap.
'agent.feedback',
+20 -1
View File
@@ -138,7 +138,8 @@ export type CoreEvent =
| { type: 'company.deleted'; payload: { companyId: string; userId: string; archivedAt: string } }
| { type: 'account.deleted'; payload: { userId: string; deletedAt: string } }
// MCP telemetry — fired from the MCP dispatcher.
// Persisted to event_log (30-day TTL) for hot-tool / error-rate / latency analytics.
// Persisted to event_log (180-day TTL for mcp.*/agent.* rows, vs 30 days for
// delivery events) for hot-tool / error-rate / latency analytics.
// Intentionally lightweight: no args, no result body — only metadata.
| { type: 'mcp.tool_called'; payload: {
tool: string // e.g. 'gnubok_create_invoice'
@@ -151,6 +152,9 @@ export type CoreEvent =
isError: boolean // matches the JSON-RPC tool-result isError flag returned to the client
errorCode: string | null // structured error code from tool-result.toToolError when applicable
errorKind: 'execution' | 'scope_denied' | 'unknown_tool' | null
errorMessage: string | null // human-readable error message (truncated to 500 chars), null on success.
// Raw material for clustering real agent failures into curated gotchas —
// errorCode alone can't distinguish "period locked" from "unbalanced".
requestId: string | number | null // JSON-RPC request id (helps correlate with client-side logs)
userId: string
companyId: string
@@ -212,6 +216,21 @@ export type CoreEvent =
userId: string
companyId: string
}}
// Fires on EVERY successful gnubok_load_skill — all tiers, unlike
// mcp.workflow_started which fires only for workflow-tier skills. Records
// WHICH skill/atom bodies agents actually pull, the denominator needed to
// correlate a loaded atom with downstream tool-error rates (a skill can
// make the model worse — measure, don't assume).
| { type: 'mcp.skill_loaded'; payload: {
slug: string // e.g. 'modifier/holding-ab', 'month-end-close'
tier: 'workflow' | 'horizontal' | 'vertical' | 'modifier'
sessionId: string | null
actorType: 'user' | 'api_key' | 'mcp_oauth' | 'cron'
actorId: string | null
actorLabel: string | null
userId: string
companyId: string
}}
// Fires when the agent's next tool call matches the previous response's
// nextHint.tool — measures whether `next` hints are actually followed.
// Computed dispatcher-side by comparing the last response shape to the
@@ -232,3 +232,108 @@ describe('finalizeImportRecord — 0-entry downgrade', () => {
expect(result.success).toBe(true)
})
})
describe('executeSIEImport — coverage check with derived IB (issue #675)', () => {
// SIE type 1/2-style file: no vouchers, no #IB 0 — only #UB -1. The
// current-year IB must be derived from #UB -1, and the derived accounts
// must feed the coverage guard (before the fix this set was empty, so the
// guard never inspected UB-1-only files at all).
function makeUb1OnlyFile(): ParsedSIEFile {
return makeParsedFile({
openingBalances: [],
closingBalances: [
{ yearIndex: -1, account: '1930', amount: 37400.78 },
{ yearIndex: -1, account: '2010', amount: -37400.78 },
],
vouchers: [],
stats: {
totalAccounts: 2,
totalVouchers: 0,
totalTransactionLines: 0,
fiscalYearStart: '2024-01-01',
fiscalYearEnd: '2024-12-31',
},
})
}
it('refuses when mappings cover none of the derived IB accounts', async () => {
const { supabase } = createQueuedMockSupabase()
const result = await executeSIEImport(
supabase as unknown as SupabaseClient,
'company-1',
'user-1',
makeUb1OnlyFile(),
[makeMapping('9999', '9999')],
{
filename: 'ub1-only.se',
fileContent: '#dummy',
createFiscalPeriod: false,
importOpeningBalances: true,
importTransactions: true,
},
)
expect(result.success).toBe(false)
expect(result.importId).toBeNull()
expect(result.errors.join(' ')).toMatch(/täcker inga konton/i)
})
it('passes the coverage guard when mappings cover the derived IB accounts', async () => {
const { supabase, enqueueMany } = createQueuedMockSupabase()
// Past the guard the flow proceeds: dup check → stale cleanup → pending
// record insert → chart fetch → period-dup check → find fiscal period
// (null → clean stop with a NON-coverage error, which is all this test
// needs to prove).
enqueueMany([
{ data: null }, // checkDuplicateImport
{ data: null }, // cleanupStaleImportRecords delete
{ data: { id: 'imp-1' } }, // createPendingImportRecord insert
{ data: [] }, // syncMappedAccounts chart fetch
{ data: null }, // chart insert (missing accounts)
{ data: null }, // checkDuplicatePeriodImport
{ data: null }, // find existing fiscal period → stops here
])
const result = await executeSIEImport(
supabase as unknown as SupabaseClient,
'company-1',
'user-1',
makeUb1OnlyFile(),
[makeMapping('1930', '1930'), makeMapping('2010', '2010')],
{
filename: 'ub1-only.se',
fileContent: '#dummy',
createFiscalPeriod: false,
importOpeningBalances: true,
importTransactions: true,
},
)
expect(result.errors.join(' ')).not.toMatch(/täcker inga konton/i)
expect(result.errors.join(' ')).toMatch(/No matching fiscal period found/i)
})
it('skips the IB accounts in the guard when importOpeningBalances is false', async () => {
const { supabase } = createQueuedMockSupabase()
const result = await executeSIEImport(
supabase as unknown as SupabaseClient,
'company-1',
'user-1',
makeUb1OnlyFile(),
[makeMapping('9999', '9999')],
{
filename: 'ub1-only.se',
fileContent: '#dummy',
createFiscalPeriod: false,
importOpeningBalances: false,
importTransactions: true,
},
)
// No vouchers + IB import disabled → sourceAccountsInFile is empty and
// the guard does not fire (existing semantics preserved).
expect(result.errors.join(' ')).not.toMatch(/täcker inga konton/i)
})
})
@@ -0,0 +1,276 @@
/**
* Full-flow regression suite for issue #675.
*
* Some systems export SIE files without current-year #IB 0 records — the
* opening balances exist only implicitly via the SIE continuity invariant
* IB(year 0) = UB(year -1). executeSIEImport must derive the IB from the
* file's #UB -1 records, create a real opening-balance entry whose voucher
* text documents the derivation, and warn the user.
*
* The make-or-break line is the gate in executeSIEImport: it must open on
* the EFFECTIVE opening balances (getEffectiveOpeningBalances), not on raw
* parsed.openingBalances — the raw set is empty for these files.
*/
import { describe, it, expect, vi, beforeEach } from 'vitest'
import { executeSIEImport } from '../sie-import'
import { createJournalEntry } from '@/lib/bookkeeping/engine'
import type { ParsedSIEFile, AccountMapping } from '../types'
import type { SupabaseClient } from '@supabase/supabase-js'
vi.mock('@/lib/bookkeeping/engine', () => ({
createJournalEntry: vi.fn(async () => ({ id: 'ob-entry-1' })),
reverseEntry: vi.fn(),
}))
// --- Helpers ---
type QueuedResult = { data?: unknown; error?: unknown; count?: number | null }
/**
* Table-routing supabase mock: each table has its own FIFO of results
* (consumed per .from(table) call), falling back to { data: null, error:
* null } when the queue is empty. Order-independent across tables, so the
* mock doesn't break when an unrelated query is added elsewhere in the flow.
*/
function buildRoutingSupabase(tableQueues: Record<string, QueuedResult[]>) {
const queues = new Map<string, QueuedResult[]>(
Object.entries(tableQueues).map(([k, v]) => [k, [...v]])
)
const makeChain = (result: { data: unknown; error: unknown; count: number | null }): unknown => {
const handler: ProxyHandler<object> = {
get(_target, prop) {
if (prop === 'then') {
return (resolve: (v: unknown) => void) => resolve(result)
}
return (..._args: unknown[]) => makeChain(result)
},
}
return new Proxy({}, handler)
}
const supabase = {
from: (table: string) => {
const next = queues.get(table)?.shift() ?? {}
return makeChain({
data: next.data ?? null,
error: next.error ?? null,
count: next.count ?? null,
})
},
rpc: async () => ({ data: null, error: null }),
storage: {
from: () => ({ upload: async () => ({ error: null }) }),
},
}
return supabase as unknown as SupabaseClient
}
function makeParsedFile(overrides?: Partial<ParsedSIEFile>): ParsedSIEFile {
return {
header: {
sieType: 4,
flagga: 0,
program: 'TestProg',
programVersion: '1.0',
generatedDate: '2024-01-01',
format: 'PC8',
companyName: 'Continuity AB',
orgNumber: '5566778899',
address: null,
fiscalYears: [
{ yearIndex: 0, start: '2024-01-01', end: '2024-12-31' },
{ yearIndex: -1, start: '2023-01-01', end: '2023-12-31' },
],
currency: 'SEK',
kontoPlanType: null,
},
accounts: [
{ number: '1930', name: 'Företagskonto' },
{ number: '2010', name: 'Eget kapital' },
],
// Issue #675 shape: no #IB 0 at all — only prior-year IB/UB and current UB.
openingBalances: [{ yearIndex: -1, account: '1930', amount: 9483.08 }],
closingBalances: [
{ yearIndex: -1, account: '1930', amount: 37400.78 },
{ yearIndex: -1, account: '2010', amount: -37400.78 },
{ yearIndex: 0, account: '1930', amount: 160406.0 },
{ yearIndex: 0, account: '2010', amount: -160406.0 },
],
resultBalances: [],
vouchers: [],
issues: [],
stats: {
totalAccounts: 2,
totalVouchers: 0,
totalTransactionLines: 0,
fiscalYearStart: '2024-01-01',
fiscalYearEnd: '2024-12-31',
},
...overrides,
}
}
function makeMapping(source: string, target: string): AccountMapping {
return {
sourceAccount: source,
sourceName: `Account ${source}`,
targetAccount: target,
targetName: `Target ${target}`,
confidence: 1,
matchType: 'exact',
isOverride: false,
}
}
function standardQueues() {
return {
sie_imports: [
{ data: null }, // checkDuplicateImport — no duplicate
{}, // cleanupStaleImportRecords delete
{ data: { id: 'imp-1' } }, // createPendingImportRecord insert
{ data: null }, // checkDuplicatePeriodImport — no duplicate
// finalizeImportRecord updates ride on defaults
],
chart_of_accounts: [
{
// syncMappedAccounts paged fetch — both accounts already exist
data: [
{ account_number: '1930', account_name: 'Företagskonto' },
{ account_number: '2010', account_name: 'Eget kapital' },
],
},
],
fiscal_periods: [
{ data: { id: 'fp-1' } }, // find existing fiscal period
{ data: { opening_balances_set: false, opening_balance_entry_id: null } }, // IB-block check
// link update + resync next-period lookup ride on defaults (null)
],
journal_entries: [
{ count: 0 }, // companyHasPriorActivity — first-ever import
],
}
}
const standardOptions = {
filename: 'continuity.se',
fileContent: '#dummy',
createFiscalPeriod: false,
importOpeningBalances: true,
importTransactions: true,
updateAccountNames: false,
}
const standardMappings = [makeMapping('1930', '1930'), makeMapping('2010', '2010')]
// --- Tests ---
describe('executeSIEImport — derived IB from #UB -1 (issue #675)', () => {
beforeEach(() => {
vi.clearAllMocks()
})
it('creates the opening-balance entry from #UB -1 when #IB 0 is missing', async () => {
const supabase = buildRoutingSupabase(standardQueues())
const result = await executeSIEImport(
supabase,
'company-1',
'user-1',
makeParsedFile(),
standardMappings,
standardOptions,
)
expect(result.errors).toEqual([])
expect(result.success).toBe(true)
expect(result.openingBalanceEntryId).toBe('ob-entry-1')
expect(result.journalEntriesCreated).toBe(1)
expect(result.warnings.join(' ')).toMatch(/kontinuitetsprincipen/)
expect(createJournalEntry).toHaveBeenCalledTimes(1)
const input = vi.mocked(createJournalEntry).mock.calls[0][3]
expect(input.source_type).toBe('opening_balance')
expect(input.fiscal_period_id).toBe('fp-1')
expect(input.entry_date).toBe('2024-01-01')
expect(input.description).toBe(
'Ingående balanser från SIE-import (härledda från föregående års utgående balans)'
)
expect(input.lines).toEqual([
{ account_number: '1930', debit_amount: 37400.78, credit_amount: 0, line_description: 'IB 1930' },
{ account_number: '2010', debit_amount: 0, credit_amount: 37400.78, line_description: 'IB 2010' },
])
})
it('uses the plain description and no continuity warning for explicit #IB 0', async () => {
const supabase = buildRoutingSupabase(standardQueues())
const parsed = makeParsedFile({
openingBalances: [
{ yearIndex: 0, account: '1930', amount: 37400.78 },
{ yearIndex: 0, account: '2010', amount: -37400.78 },
],
})
const result = await executeSIEImport(
supabase,
'company-1',
'user-1',
parsed,
standardMappings,
standardOptions,
)
expect(result.success).toBe(true)
expect(result.warnings.join(' ')).not.toMatch(/kontinuitetsprincipen/)
const input = vi.mocked(createJournalEntry).mock.calls[0][3]
expect(input.description).toBe('Ingående balanser från SIE-import')
})
it('respects the continuation guard — no derived IB when the company has prior activity', async () => {
const queues = standardQueues()
queues.journal_entries = [{ count: 5 }] // posted entries exist
const supabase = buildRoutingSupabase(queues)
const result = await executeSIEImport(
supabase,
'company-1',
'user-1',
makeParsedFile(),
standardMappings,
standardOptions,
)
expect(createJournalEntry).not.toHaveBeenCalled()
expect(result.openingBalanceEntryId).toBeNull()
expect(result.warnings.join(' ')).toMatch(/hoppades över eftersom bolaget redan har bokförda verifikationer/)
// Zero entries created → the finalizer safety net downgrades the run so
// the file slot stays free for a retry (existing behavior).
expect(result.success).toBe(false)
expect(result.errors.join(' ')).toMatch(/0 verifikationer/)
})
it('creates no IB entry when the file has neither #IB 0 nor #UB -1', async () => {
const supabase = buildRoutingSupabase(standardQueues())
const parsed = makeParsedFile({
openingBalances: [],
closingBalances: [
{ yearIndex: 0, account: '1930', amount: 160406.0 },
{ yearIndex: 0, account: '2010', amount: -160406.0 },
],
})
const result = await executeSIEImport(
supabase,
'company-1',
'user-1',
parsed,
standardMappings,
standardOptions,
)
expect(createJournalEntry).not.toHaveBeenCalled()
expect(result.openingBalanceEntryId).toBeNull()
})
})
+166
View File
@@ -1072,4 +1072,170 @@ describe('importVouchers — per-voucher series preservation', () => {
expect(journalEntryInserts[0].source_voucher_series).toBeNull()
expect(journalEntryInserts[0].source_voucher_number).toBe(1)
})
describe('opening-balance voucher tagging vs derived IB (issue #675)', () => {
const obMap = new Map([
['1930', '1930'],
['2010', '2010'],
])
it('tags a qualifying OB voucher opening_balance even when #UB -1 records exist', async () => {
// Precedence 2 beats 3: the OB-voucher candidate makes
// getEffectiveOpeningBalances yield no balances, so hasCurrentYearIb is
// false and the voucher keeps serving as the IB. Without that yield, a
// derived IB entry AND this voucher would both book the same amounts.
const { supabase, journalEntryInserts } = buildCapturingSupabase()
const parsed = makeParsedFile({
openingBalances: [],
closingBalances: [
{ yearIndex: -1, account: '1930', amount: 37400.78 },
{ yearIndex: -1, account: '2010', amount: -37400.78 },
],
vouchers: [
{
series: 'A',
number: 1,
date: new Date(2024, 0, 1),
description: 'Ingående balans',
lines: [
{ account: '1930', amount: 37400.78 },
{ account: '2010', amount: -37400.78 },
],
},
],
})
const result = await importVouchers(
supabase,
'company-1',
'user-1',
'period-1',
parsed,
obMap,
'A',
)
expect(result.created).toBe(1)
expect(journalEntryInserts[0].source_type).toBe('opening_balance')
})
it('keeps an FY-start voucher without IB wording as import when IB is derived from #UB -1', async () => {
const { supabase, journalEntryInserts } = buildCapturingSupabase()
const parsed = makeParsedFile({
openingBalances: [],
closingBalances: [
{ yearIndex: -1, account: '1930', amount: 37400.78 },
{ yearIndex: -1, account: '2010', amount: -37400.78 },
],
vouchers: [
{
series: 'A',
number: 1,
date: new Date(2024, 0, 1),
description: 'Omföring',
lines: [
{ account: '1930', amount: 1000 },
{ account: '2010', amount: -1000 },
],
},
],
})
await importVouchers(
supabase,
'company-1',
'user-1',
'period-1',
parsed,
obMap,
'A',
)
expect(journalEntryInserts[0].source_type).toBe('import')
})
})
})
describe('IB derivation from #UB -1 (issue #675)', () => {
const derivedOverrides: Partial<ParsedSIEFile> = {
openingBalances: [],
closingBalances: [
{ yearIndex: -1, account: '1930', amount: 37400.78 },
{ yearIndex: -1, account: '2440', amount: -37400.78 },
{ yearIndex: 0, account: '1930', amount: 160406.0 },
{ yearIndex: 0, account: '2440', amount: -160406.0 },
],
}
describe('generateImportPreview', () => {
it('computes opening balance totals from the derived set', () => {
const parsed = makeParsedFile(derivedOverrides)
const preview = generateImportPreview(parsed, [
makeMapping('1930', '1930'),
makeMapping('2440', '2440'),
])
// Derived from #UB -1: 37400.78 debit / 37400.78 credit. This is also
// what enables the IB toggle in ImportReviewStep (openingBalanceTotal > 0).
expect(preview.openingBalanceTotal).toBe(37400.78)
expect(preview.trialBalance.totalDebit).toBe(37400.78)
expect(preview.trialBalance.totalCredit).toBe(37400.78)
expect(preview.trialBalance.isBalanced).toBe(true)
})
it('appends an info issue explaining the derivation without mutating parsed.issues', () => {
const parsed = makeParsedFile(derivedOverrides)
const preview = generateImportPreview(parsed, [makeMapping('1930', '1930')])
const infoMessages = preview.issues.filter((i) => i.severity === 'info')
expect(infoMessages.map((i) => i.message).join(' ')).toMatch(/härleds från föregående års utgående balans/i)
expect(parsed.issues).toHaveLength(0)
})
it('does not append the derivation issue when explicit #IB 0 exists', () => {
const parsed = makeParsedFile()
const preview = generateImportPreview(parsed, [makeMapping('1930', '1930')])
expect(preview.issues).toHaveLength(0)
})
})
describe('validateIBBalance', () => {
it('builds journal lines from the derived #UB -1 set', () => {
const parsed = makeParsedFile(derivedOverrides)
const accountMap = new Map([
['1930', '1930'],
['2440', '2440'],
])
const result = validateIBBalance(parsed, accountMap)
expect(result.lines).toEqual([
{ account_number: '1930', debit_amount: 37400.78, credit_amount: 0, line_description: 'IB 1930' },
{ account_number: '2440', debit_amount: 0, credit_amount: 37400.78, line_description: 'IB 2440' },
])
expect(result.roundingAdjustment).toBe(0)
expect(result.fileImbalance).toBe(0)
})
it('reports the imbalance when the derived set carries an unallocated prior-year result', () => {
const parsed = makeParsedFile({
openingBalances: [],
closingBalances: [
{ yearIndex: -1, account: '1930', amount: 37400.78 },
{ yearIndex: -1, account: '2440', amount: -30000.0 },
],
})
const accountMap = new Map([
['1930', '1930'],
['2440', '2440'],
])
const result = validateIBBalance(parsed, accountMap)
// 37400.78 − 30000.00 → diff booked to 2099 by createOpeningBalanceEntry
expect(result.roundingAdjustment).toBe(7400.78)
expect(result.fileImbalance).toBe(7400.78)
})
})
})
+200 -1
View File
@@ -1,5 +1,12 @@
import { describe, it, expect } from 'vitest'
import { parseSIEFile, validateSIEFile, detectEncoding, decodeBuffer } from '../sie-parser'
import {
parseSIEFile,
validateSIEFile,
detectEncoding,
decodeBuffer,
getEffectiveOpeningBalances,
hasOpeningBalanceVoucherCandidate,
} from '../sie-parser'
// --- SIE content fixtures ---
@@ -1090,3 +1097,195 @@ describe('parseSIEFile — silent-failure diagnostic warnings', () => {
expect(spurious).toHaveLength(0)
})
})
describe('getEffectiveOpeningBalances — derive IB from #UB -1 (issue #675)', () => {
// Issue #675 (ro66an): some systems export no #IB 0 records — the current
// year's IB exists only via the continuity invariant IB(0) = UB(-1).
const SIE_NO_IB0 = [
'#FLAGGA 0',
'#SIETYP 4',
'#FNAMN "Continuity AB"',
'#RAR 0 20240101 20241231',
'#RAR -1 20230101 20231231',
'#KONTO 1930 "Företagskonto"',
'#KONTO 2010 "Eget kapital"',
'#IB -1 1930 9483.08',
'#UB 0 1930 160406.00',
'#UB -1 1930 37400.78',
'#UB -1 2010 -37400.78',
].join('\n')
it('derives current-year IB from #UB -1 when no #IB 0 exists (issue example)', () => {
const parsed = parseSIEFile(SIE_NO_IB0)
const { balances, derivedFromPriorYearUB } = getEffectiveOpeningBalances(parsed)
expect(derivedFromPriorYearUB).toBe(true)
expect(balances).toEqual([
{ yearIndex: 0, account: '1930', amount: 37400.78 },
{ yearIndex: 0, account: '2010', amount: -37400.78 },
])
})
it('never uses #IB -1 (previous year IB) as the derivation source', () => {
const parsed = parseSIEFile(SIE_NO_IB0)
const { balances } = getEffectiveOpeningBalances(parsed)
expect(balances.some((b) => b.amount === 9483.08)).toBe(false)
})
it('returns explicit #IB 0 untouched when present — #UB -1 is never merged in', () => {
const content = [
SIE_NO_IB0,
'#IB 0 1930 37400.78',
'#IB 0 2010 -37400.78',
].join('\n')
const parsed = parseSIEFile(content)
const { balances, derivedFromPriorYearUB } = getEffectiveOpeningBalances(parsed)
expect(derivedFromPriorYearUB).toBe(false)
expect(balances).toHaveLength(2)
expect(balances.every((b) => b.yearIndex === 0)).toBe(true)
})
it('yields to an opening-balance voucher candidate — no derivation (precedence 2 beats 3)', () => {
// The voucher serves as IB during import (tagged source_type
// 'opening_balance'); deriving from #UB -1 as well would double-count.
// Also the timezone regression test: the voucher date is a local-time
// Date, so a toISOString()-based comparison would miss the FY start on
// machines west or east of UTC and wrongly re-enable derivation.
const content = [
SIE_NO_IB0,
'#VER A 1 20240101 "Ingående balans"',
'{',
'#TRANS 1930 {} 37400.78',
'#TRANS 2010 {} -37400.78',
'}',
].join('\n')
const parsed = parseSIEFile(content)
expect(hasOpeningBalanceVoucherCandidate(parsed)).toBe(true)
const { balances, derivedFromPriorYearUB } = getEffectiveOpeningBalances(parsed)
expect(derivedFromPriorYearUB).toBe(false)
expect(balances).toEqual([])
})
it('does not treat a share-capital voucher on FY start as an OB candidate', () => {
const content = [
SIE_NO_IB0,
'#VER A 1 20240101 "Insättning aktiekapital ingående balans"',
'{',
'#TRANS 1930 {} 25000.00',
'#TRANS 2081 {} -25000.00',
'}',
].join('\n')
const parsed = parseSIEFile(content)
expect(hasOpeningBalanceVoucherCandidate(parsed)).toBe(false)
expect(getEffectiveOpeningBalances(parsed).derivedFromPriorYearUB).toBe(true)
})
it('does not treat a voucher with P&L lines as an OB candidate', () => {
const content = [
SIE_NO_IB0,
'#VER A 1 20240101 "Ingående balans"',
'{',
'#TRANS 1930 {} 1000.00',
'#TRANS 3001 {} -1000.00',
'}',
].join('\n')
const parsed = parseSIEFile(content)
expect(hasOpeningBalanceVoucherCandidate(parsed)).toBe(false)
expect(getEffectiveOpeningBalances(parsed).derivedFromPriorYearUB).toBe(true)
})
it('does not treat an IB-worded voucher on another date as an OB candidate', () => {
const content = [
SIE_NO_IB0,
'#VER A 1 20240315 "Ingående balans"',
'{',
'#TRANS 1930 {} 1000.00',
'#TRANS 2010 {} -1000.00',
'}',
].join('\n')
const parsed = parseSIEFile(content)
expect(hasOpeningBalanceVoucherCandidate(parsed)).toBe(false)
expect(getEffectiveOpeningBalances(parsed).derivedFromPriorYearUB).toBe(true)
})
it('filters P&L accounts out of the derived set (result accounts open at zero)', () => {
const content = [
SIE_NO_IB0,
'#UB -1 3001 -5000.00',
].join('\n')
const parsed = parseSIEFile(content)
const { balances } = getEffectiveOpeningBalances(parsed)
expect(balances.some((b) => b.account === '3001')).toBe(false)
expect(balances).toHaveLength(2)
})
it('returns nothing when neither #IB 0 nor #UB -1 exists', () => {
const content = [
'#FLAGGA 0',
'#SIETYP 4',
'#FNAMN "First Year AB"',
'#RAR 0 20240101 20241231',
'#KONTO 1930 "Företagskonto"',
'#IB -1 1930 9483.08',
'#UB 0 1930 160406.00',
].join('\n')
const parsed = parseSIEFile(content)
const { balances, derivedFromPriorYearUB } = getEffectiveOpeningBalances(parsed)
expect(derivedFromPriorYearUB).toBe(false)
expect(balances).toEqual([])
})
it('carries quantity along on derived balances', () => {
const content = [
SIE_NO_IB0.replace('#UB -1 1930 37400.78', '#UB -1 1930 37400.78 5'),
].join('\n')
const parsed = parseSIEFile(content)
const { balances } = getEffectiveOpeningBalances(parsed)
expect(balances.find((b) => b.account === '1930')?.quantity).toBe(5)
})
describe('validateSIEFile with derived IB', () => {
it('warns that IB will be derived from #UB -1', () => {
const parsed = parseSIEFile(SIE_NO_IB0)
const validation = validateSIEFile(parsed)
expect(validation.valid).toBe(true)
expect(validation.warnings.join(' ')).toMatch(/härleds från föregående års utgående balans/i)
})
it('runs the imbalance check on the derived set (unallocated prior-year result)', () => {
const content = [
'#FLAGGA 0',
'#SIETYP 4',
'#FNAMN "Obalans AB"',
'#RAR 0 20240101 20241231',
'#KONTO 1930 "Företagskonto"',
// Derived IB sums to +37400.78 — prior-year result never allocated
'#UB -1 1930 37400.78',
].join('\n')
const parsed = parseSIEFile(content)
const validation = validateSIEFile(parsed)
expect(validation.warnings.join(' ')).toMatch(/balanserar inte/i)
expect(validation.warnings.join(' ')).toMatch(/37400\.78/)
})
it('does not warn about derivation when explicit #IB 0 exists', () => {
const content = [SIE_NO_IB0, '#IB 0 1930 37400.78', '#IB 0 2010 -37400.78'].join('\n')
const parsed = parseSIEFile(content)
const validation = validateSIEFile(parsed)
expect(validation.warnings.join(' ')).not.toMatch(/härleds från föregående års utgående balans/i)
})
})
})
+75 -27
View File
@@ -19,7 +19,17 @@ import type {
import type { CreateJournalEntryLineInput } from '@/types'
import { mappingsToMap, getMappingStats } from './account-mapper'
import { syncMappedAccounts } from './account-sync'
import { calculateFileHash } from './sie-parser'
import {
calculateFileHash,
getEffectiveOpeningBalances,
isBalanceSheetAccount,
OPENING_BALANCE_DESCRIPTION_RE,
SHARE_CAPITAL_DESCRIPTION_RE,
} from './sie-parser'
// Re-export from the parser (moved there to avoid an import cycle —
// getEffectiveOpeningBalances needs it) so existing importers keep working.
export { isBalanceSheetAccount } from './sie-parser'
import { getBASReference } from '@/lib/bookkeeping/bas-reference'
import { classifyAccount } from '@/lib/bookkeeping/account-classifier'
import { computeSRUCode } from '@/lib/bookkeeping/bas-data/sru-mapping'
@@ -43,8 +53,12 @@ export function generateImportPreview(
parsed: ParsedSIEFile,
mappings: AccountMapping[]
): ImportPreview {
// Calculate opening balance totals
const currentYearBalances = parsed.openingBalances.filter((b) => b.yearIndex === 0)
// Calculate opening balance totals from the effective set — for files
// without #IB 0 this is the IB derived from #UB -1 (issue #675), so the
// preview (and the IB toggle in ImportReviewStep, keyed off
// openingBalanceTotal > 0) reflects what the import will actually book.
const { balances: currentYearBalances, derivedFromPriorYearUB } =
getEffectiveOpeningBalances(parsed)
let totalDebit = 0
let totalCredit = 0
@@ -79,7 +93,17 @@ export function generateImportPreview(
lowConfidence: mappingStats.lowConfidence,
},
excludedSystemAccounts: [],
issues: parsed.issues,
issues: derivedFromPriorYearUB
? [
...parsed.issues,
{
severity: 'info',
line: 0,
message:
'Ingående balanser härleds från föregående års utgående balans (#UB -1) — filen saknar #IB-poster för aktuellt räkenskapsår.',
},
]
: parsed.issues,
}
}
@@ -464,7 +488,8 @@ export function validateIBBalance(
fileImbalance: number
excludedAccountsTotal: number
} {
const currentYearBalances = parsed.openingBalances.filter((b) => b.yearIndex === 0)
// Effective set: explicit #IB 0, or IB derived from #UB -1 (issue #675).
const currentYearBalances = getEffectiveOpeningBalances(parsed).balances
// First: check the raw file-level IB balance (all accounts, before mapping)
const rawTotal = currentYearBalances.reduce((sum, b) => sum + b.amount, 0)
@@ -525,7 +550,9 @@ async function createOpeningBalanceEntry(
accountMap: Map<string, string>,
roundingAdjustment: number
): Promise<string | null> {
const currentYearBalances = parsed.openingBalances.filter((b) => b.yearIndex === 0)
// Effective set: explicit #IB 0, or IB derived from #UB -1 (issue #675).
const { balances: currentYearBalances, derivedFromPriorYearUB } =
getEffectiveOpeningBalances(parsed)
if (currentYearBalances.length === 0) {
return null
@@ -583,7 +610,11 @@ async function createOpeningBalanceEntry(
const entry = await createJournalEntry(supabase, companyId, userId, {
fiscal_period_id: fiscalPeriodId,
entry_date: entryDate,
description: 'Ingående balanser från SIE-import',
// When derived, say so on the voucher itself — permanent documentation
// of where the amounts came from (BFNAR 2013:2 behandlingshistorik).
description: derivedFromPriorYearUB
? 'Ingående balanser från SIE-import (härledda från föregående års utgående balans)'
: 'Ingående balanser från SIE-import',
source_type: 'opening_balance',
voucher_series: 'A',
lines,
@@ -912,17 +943,25 @@ export async function importVouchers(
const preparedVouchers: PreparedVoucher[] = []
// A SIE file represents the opening balance either as #IB records (handled
// separately by createOpeningBalanceEntry → source_type='opening_balance') or,
// in some source systems, as an ordinary #VER dated on the fiscal-year start.
// When there are NO current-year #IB records, detect a clearly-labelled IB
// voucher and tag it opening_balance so bank reconciliation excludes it from
// the period movement (otherwise it lands as 'import' and surfaces as a phantom
// separately by createOpeningBalanceEntry → source_type='opening_balance'),
// as IB derived from #UB -1 when #IB 0 is missing (issue #675, also via
// createOpeningBalanceEntry) or, in some source systems, as an ordinary #VER
// dated on the fiscal-year start. When there is NO current-year IB from
// either of the first two paths, detect a clearly-labelled IB voucher and
// tag it opening_balance so bank reconciliation excludes it from the period
// movement (otherwise it lands as 'import' and surfaces as a phantom
// difference equal to the IB). Deliberately conservative — requires the IB
// wording AND a balance-sheet-only voucher on FY start, and never a
// share-capital deposit. A missed IB still falls back to the manual "Märk som
// ingående balans" action in Bankavstämning, so we never risk hiding a real
// bank movement by over-classifying.
const hasCurrentYearIb = parsed.openingBalances.some((b) => b.yearIndex === 0)
//
// Using the effective set keeps this gate consistent with the helper's
// precedence: when an OB-voucher candidate exists the helper yields no
// balances (the voucher serves as IB and gets tagged here); when IB was
// derived from #UB -1 the gate is closed so the same amounts can never be
// booked twice.
const hasCurrentYearIb = getEffectiveOpeningBalances(parsed).balances.length > 0
const fyStart = parsed.stats.fiscalYearStart
for (const voucher of parsed.vouchers) {
@@ -1062,8 +1101,8 @@ export async function importVouchers(
!!fyStart && fyStart.slice(0, 10) === voucherDateStr &&
lines.length > 0 &&
lines.every((l) => isBalanceSheetAccount(l.account_number)) &&
/ing[åa]ende balans|ing[åa]ende saldo|opening balance/i.test(voucher.description || '') &&
!/aktiekapital/i.test(voucher.description || '')
OPENING_BALANCE_DESCRIPTION_RE.test(voucher.description || '') &&
!SHARE_CAPITAL_DESCRIPTION_RE.test(voucher.description || '')
preparedVouchers.push({
sourceId: voucherId,
@@ -1354,14 +1393,6 @@ export async function importVouchers(
return results
}
/**
* Determine if an account is balance sheet (class 1-2) or P&L (class 3-8)
*/
export function isBalanceSheetAccount(accountNumber: string): boolean {
const firstDigit = parseInt(accountNumber.charAt(0), 10)
return firstDigit >= 1 && firstDigit <= 2
}
/**
* Compute per-series voucher number ranges from the voucher number mapping.
* SIE imports can span multiple series (B, C, V, ...), each with its own
@@ -1427,8 +1458,11 @@ async function createMigrationAdjustmentEntry(
// For P&L accounts (class 3-8): expectedMovement = RES (ignore IB/UB)
const expectedMovements = new Map<string, number>()
// Process IB — only for balance sheet accounts
for (const ib of parsed.openingBalances.filter((b) => b.yearIndex === 0)) {
// Process IB — only for balance sheet accounts. Effective set: explicit
// #IB 0, or IB derived from #UB -1 (issue #675) — so the expected BS
// movement is UB(0) − UB(-1), the correct one-year movement, instead of
// treating the whole opening balance as unexplained movement.
for (const ib of getEffectiveOpeningBalances(parsed).balances) {
const target = accountMap.get(ib.account)
if (!target) continue
if (!isBalanceSheetAccount(target)) {
@@ -1866,7 +1900,9 @@ export async function executeSIEImport(
const sourceAccountsInFile = new Set<string>()
for (const v of parsed.vouchers) for (const l of v.lines) sourceAccountsInFile.add(l.account)
if (options.importOpeningBalances) {
for (const b of parsed.openingBalances.filter((b) => b.yearIndex === 0)) {
// Effective set: also covers UB-1-only files (issue #675), whose
// derived IB accounts would otherwise bypass this guard entirely.
for (const b of getEffectiveOpeningBalances(parsed).balances) {
sourceAccountsInFile.add(b.account)
}
}
@@ -2065,7 +2101,12 @@ export async function executeSIEImport(
// In both cases, the correct treatment is to book the diff to 2099 with
// explicit documentation. We never reject based on IB imbalance — the
// original goal was to stop SILENT equity alteration, not prevent it.
if (options.importOpeningBalances && parsed.openingBalances.length > 0 && result.fiscalPeriodId) {
//
// Gate on the EFFECTIVE set: for files without #IB 0, the IB derived
// from #UB -1 (issue #675) must still open this block — gating on raw
// parsed.openingBalances would silently skip the derived IB entirely.
const effectiveIB = getEffectiveOpeningBalances(parsed)
if (options.importOpeningBalances && effectiveIB.balances.length > 0 && result.fiscalPeriodId) {
// Check if opening balances already exist for this period
const { data: period } = await supabase
.from('fiscal_periods')
@@ -2097,6 +2138,13 @@ export async function executeSIEImport(
const ibValidation = validateIBBalance(parsed, accountMap)
if (ibValidation.lines.length > 0) {
if (effectiveIB.derivedFromPriorYearUB) {
result.warnings.push(
'SIE-filen saknar ingående balanser (#IB) för räkenskapsåret. ' +
'Ingående balanser härleddes från föregående års utgående balanser (#UB -1) enligt kontinuitetsprincipen.'
)
}
const absAdj = Math.abs(ibValidation.roundingAdjustment)
if (absAdj > 0.01) {
+110 -4
View File
@@ -777,6 +777,104 @@ export function parseSIEFile(content: string): ParsedSIEFile {
}
}
/**
* Wording that identifies a voucher as the year's opening balance
* (ingående balans). Shared between the parser's OB-voucher candidate
* detection below and the importer's isLikelyOpeningBalance tagging
* (lib/import/sie-import.ts) so the two checks can never drift apart.
*/
export const OPENING_BALANCE_DESCRIPTION_RE = /ing[åa]ende balans|ing[åa]ende saldo|opening balance/i
/**
* Vouchers mentioning share capital are never treated as opening balances —
* a share-capital deposit dated on the FY start is a real bank movement.
*/
export const SHARE_CAPITAL_DESCRIPTION_RE = /aktiekapital/i
/**
* Determine if an account is balance sheet (class 1-2) or P&L (class 3-8)
*/
export function isBalanceSheetAccount(accountNumber: string): boolean {
const firstDigit = parseInt(accountNumber.charAt(0), 10)
return firstDigit >= 1 && firstDigit <= 2
}
/**
* Format a Date to "YYYY-MM-DD" using LOCAL components.
* parseSIEDate() builds local-time Dates, so toISOString() would shift the
* day across the UTC boundary in non-UTC timezones — never use it here.
*/
function formatLocalDate(date: Date): string {
const year = date.getFullYear()
const month = String(date.getMonth() + 1).padStart(2, '0')
const day = String(date.getDate()).padStart(2, '0')
return `${year}-${month}-${day}`
}
/**
* True when the file contains a voucher that looks like the year's opening
* balance: dated on the fiscal-year start, only balance-sheet accounts,
* IB wording in the description and no share-capital mention.
*
* Raw-file mirror of the importer's isLikelyOpeningBalance check
* (lib/import/sie-import.ts), but deliberately MORE eager: it runs on
* source account numbers with no knowledge of account mappings, so a
* candidate containing an unmapped line still counts here even though the
* importer would later skip that voucher as unmapped. In that residual case
* no IB is created at all — the user falls back to the manual
* "Märk som ingående balans" action in Bankavstämning.
*/
export function hasOpeningBalanceVoucherCandidate(parsed: ParsedSIEFile): boolean {
const fyStart = parsed.stats.fiscalYearStart
if (!fyStart) return false
return parsed.vouchers.some(
(v) =>
v.lines.length > 0 &&
formatLocalDate(v.date) === fyStart.slice(0, 10) &&
v.lines.every((l) => isBalanceSheetAccount(l.account)) &&
OPENING_BALANCE_DESCRIPTION_RE.test(v.description || '') &&
!SHARE_CAPITAL_DESCRIPTION_RE.test(v.description || '')
)
}
/**
* Resolve the opening balances the import should actually book (issue #675).
*
* Some systems export no #IB 0 records at all — the current year's IB exists
* only implicitly via the SIE continuity invariant IB(year 0) = UB(year -1).
* Every IB consumer goes through this helper so the precedence below is the
* single source of truth:
*
* 1. Explicit #IB 0 records — trusted as-is, never merged with #UB -1.
* 2. An opening-balance #VER candidate — the voucher itself serves as IB
* during voucher import (tagged source_type 'opening_balance');
* deriving from #UB -1 as well would double-count every
* balance-sheet account.
* 3. #UB -1 records, re-labeled to yearIndex 0 and filtered to
* balance-sheet accounts (result accounts must always open at zero).
* 4. Nothing — the file genuinely carries no opening balances.
*/
export function getEffectiveOpeningBalances(parsed: ParsedSIEFile): {
balances: SIEBalance[]
derivedFromPriorYearUB: boolean
} {
const explicit = parsed.openingBalances.filter((b) => b.yearIndex === 0)
if (explicit.length > 0) {
return { balances: explicit, derivedFromPriorYearUB: false }
}
if (hasOpeningBalanceVoucherCandidate(parsed)) {
return { balances: [], derivedFromPriorYearUB: false }
}
const derived = parsed.closingBalances
.filter((b) => b.yearIndex === -1 && isBalanceSheetAccount(b.account))
.map((b) => ({ ...b, yearIndex: 0 }))
return { balances: derived, derivedFromPriorYearUB: derived.length > 0 }
}
/**
* Validate a parsed SIE file
*/
@@ -866,10 +964,18 @@ export function validateSIEFile(parsed: ParsedSIEFile): ValidationResult {
)
}
// Check opening balance is balanced (for balance sheet accounts)
const ibTotal = parsed.openingBalances
.filter((b) => b.yearIndex === 0)
.reduce((sum, b) => sum + b.amount, 0)
// Check opening balance is balanced (for balance sheet accounts).
// Uses the effective set so files without #IB 0 — where IB is derived from
// #UB -1 (issue #675) — still get the 2099-adjustment heads-up.
const effectiveIB = getEffectiveOpeningBalances(parsed)
if (effectiveIB.derivedFromPriorYearUB) {
warnings.push(
'Filen saknar ingående balanser (#IB) för aktuellt räkenskapsår — de härleds från föregående års utgående balans (#UB -1) vid import.'
)
}
const ibTotal = effectiveIB.balances.reduce((sum, b) => sum + b.amount, 0)
if (Math.abs(ibTotal) > 0.01) {
warnings.push(`Ingående balanser balanserar inte (differens: ${ibTotal.toFixed(2)} kr). En automatisk justeringspost mot konto 2099 skapas vid import.`)
+17 -11
View File
@@ -104,14 +104,19 @@ export interface CommitOptions {
userEmail?: string
/**
* commit_method recorded on any journal_entries created by this operation.
* Must match the CHECK constraint on journal_entries.commit_method:
* 'user_accept' | 'bulk_accept' | 'timing_ceiling' | 'migration' | 'legacy'.
* Single-approval route passes 'user_accept' (default); bulk-approval passes
* 'bulk_accept'. Defaults to 'user_accept' since the dispatcher is only
* invoked from human-approval paths after agent auto-commit was removed
* (migration 20260505190027_drop_agent_auto_commit).
* Must match the CHECK constraint on journal_entries.commit_method
* (migration 20260618120001): 'user_accept' | 'bulk_accept' |
* 'timing_ceiling' | 'migration' | 'legacy' | 'agent' | 'api_key'.
*
* Web-UI single-approval passes 'user_accept'; bulk-approval passes
* 'bulk_accept'. MCP approvals pass the relaying credential — 'api_key'
* (gnubok-mcp bridge) or 'agent' (OAuth connector) — so the immutable layer
* records that the acknowledgment was agent-relayed rather than a
* first-party human session (agent_first_vision.md §8 P0-1). Every path is
* still human-approval-gated; agent auto-commit was removed in
* 20260505190027_drop_agent_auto_commit.
*/
commitMethod?: 'user_accept' | 'bulk_accept'
commitMethod?: 'user_accept' | 'bulk_accept' | 'agent' | 'api_key'
}
// ── Helper: ensure fiscal period covers the date ──────────────────
@@ -2470,10 +2475,11 @@ async function commitCreateVoucher(
notes: (params.notes as string) || undefined,
lines,
},
// commit_method records HOW it was committed, not who staged it. MCP-
// staged ops still go through human approval, so 'user_accept' (or
// 'bulk_accept' from the bulk route) is the correct value. The DB CHECK
// constraint rejects anything else (migration 20260420120001).
// commit_method records HOW it was committed, not who staged it.
// Web routes pass 'user_accept'/'bulk_accept'; the MCP approve path
// passes 'api_key'/'agent' so agent-relayed acknowledgments are
// distinguishable in the immutable layer. The DB CHECK constraint
// rejects anything else (migrations 20260420120001, 20260618120001).
opts.commitMethod ?? 'user_accept'
)