Mcp/template data feedback (#617)

* fix(booking-templates): scope template list to the active company

GET /api/settings/booking-templates relied solely on the btl_select RLS
policy, which is membership-wide (user_company_ids) and returns templates
from every company the user belongs to. A user who owns multiple companies
saw all their templates merged regardless of which company was active.

Narrow the list in the API layer (mirroring counterparty-templates) to
system + the active company + the active company's team. RLS stays the
security backstop; this fixes the cross-company merge within a single
user's own view (it was never a cross-tenant data leak).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(import): show proper message for duplicate bank file upload

The bank file import page mis-parsed the structured error envelope
({ error: { code, message, details } }), so a BANK_FILE_DUPLICATE
(409) fell through to the generic "Kunde inte läsa filen" fallback.
The upload step also hardcoded that same string as the error heading,
so duplicates were doubly misreported as parse failures.

- Parse the structured envelope by error.code; surface error.message
  for all codes instead of rendering the error object.
- Add a dedicated BANK_FILE_DUPLICATE message using the importedAt /
  importedCount details the route already returns.
- Add an optional errorTitle prop to BankFileUploadStep (defaults to
  the previous text) and pass "Filen är redan importerad" for dupes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(tests): add comprehensive tests for recordateEntry, inbox-linking, and external-id handling

- Implemented unit tests for recordateEntry in the bookkeeping module to validate various scenarios including date changes, non-posted entries, and fiscal period restrictions.
- Created tests for inbox-linking status in pending operations to ensure correct handling of invoice inbox items and supplier invoices, addressing historical bugs related to status updates.
- Added tests for external-id utilities to ensure consistent handling of monetary amounts and deduplication keys across different transaction sources.
- Introduced new functions in external-id.ts for stable external ID generation and normalization of imported descriptions, enhancing transaction deduplication reliability.

feat(migrations): add new database migrations for transaction handling

- Created migration to exclude storno and correction vouchers from unmatched GL lines, ensuring accurate reconciliation.
- Added a migration to preserve original bank transaction descriptions in a new immutable column, allowing for user edits while maintaining audit trails and deduplication integrity.

* feat(migrations): add function to exclude storno/correction vouchers from unmatched GL lines

* feat(transactions): enhance transaction handling with improved description normalization and preloaded original entries

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Mattsson
2026-06-01 14:45:49 +02:00
committed by GitHub
co-authored by Claude Opus 4.8
parent 2c59c3633f
commit c6c86cded4
54 changed files with 3673 additions and 158 deletions
+31 -4
View File
@@ -1677,6 +1677,27 @@ async function commitCreateSupplierInvoiceFromInbox(
})
}
}
} else {
// createSupplierInvoiceRegistrationEntry returns null ONLY when no
// fiscal period covers invoice_date (every other failure throws into
// the catch below). Without this branch the inbox item gets linked to
// an unbooked supplier invoice — the same 2440/2641 orphan the catch
// guards against. Roll back (items first, see FK note below) and return
// an actionable error instead of silently "succeeding".
await supabase
.from('supplier_invoice_items')
.delete()
.eq('supplier_invoice_id', invoice.id)
await supabase
.from('supplier_invoices')
.delete()
.eq('id', invoice.id)
.eq('company_id', companyId)
return {
error:
'Det finns inget räkenskapsår som täcker fakturadatumet. Lägg upp räkenskapsåret först, eller ändra fakturadatumet.',
status: 400,
}
}
} catch (err) {
// Roll back: orphan supplier_invoices row without its registration JE
@@ -1719,11 +1740,14 @@ async function commitCreateSupplierInvoiceFromInbox(
}
// Terminal state for the inbox row: created_supplier_invoice_id is the
// dedup key for next time this inbox item is touched. status='confirmed'
// removes it from the "needs action" filter in the UI.
// dedup key for next time this inbox item is touched, and it's what the UI
// and list_unmatched_documents use to drop the row out of "needs action".
// Do NOT write status here — the status CHECK only allows received|error
// (migration 20260504180000); writing 'confirmed' makes Postgres reject the
// whole UPDATE, so the link column never lands and the item stays unresolved.
const { error: linkInboxErr } = await supabase
.from('invoice_inbox_items')
.update({ created_supplier_invoice_id: invoice.id, status: 'confirmed' })
.update({ created_supplier_invoice_id: invoice.id })
.eq('id', inboxItemId)
.eq('company_id', companyId)
@@ -2301,9 +2325,12 @@ async function commitCreateVoucher(
// zero-rows-updated result and surfaces a structured warning. We also
// require .eq('created_supplier_invoice_id', null) so a concurrent
// create_supplier_invoice_from_inbox doesn't get clobbered either.
// Only the link column is written — the status CHECK allows received|error
// (migration 20260504180000), so writing 'confirmed' here would fail the
// whole UPDATE and silently leave the inbox item in "needs action".
const { data: updatedRows, error: linkInboxErr } = await supabase
.from('invoice_inbox_items')
.update({ created_journal_entry_id: entry.id, status: 'confirmed' })
.update({ created_journal_entry_id: entry.id })
.eq('id', inboxItemId)
.eq('company_id', companyId)
.is('created_journal_entry_id', null)