fix(skatteverket): skattekonto-OCR is 13 digits, and the AGI panel stops guessing that you have not signed (#1888)
* fix(skatteverket): skattekonto-OCR is 13 digits, and the AGI panel stops guessing that you have not signed Two reports from the same salary run (Fabian, Specific AI Sweden AB). 1. The payment file carried an OCR Skatteverket does not accept. generateSkattekontoOcr built the reference from the TEN-digit org number plus a Luhn check digit (11 digits). Skatteverket's reference is the TWELVE-digit identity plus a check digit: an organisationsnummer carries the "16" prefix, a personnummer its century. For 559547-0021 we emitted 55954700211 where Skatteverket prints 1655954700217. The twelve-digit form is the same "redovisare" identity the AGI and moms APIs take, so it now goes through the shared toRedovisare12 converter instead of a second local rule: the payment file and the declaration it pays must not disagree about who the taxpayer is. That needs the entity type, which the route now reads alongside org_number. The route also prefers saldo.ocrNummer from the cached skattekonto snapshot over the derived value. It is Skatteverket's own answer for the account we actually sync, it covers identities the converter has no rule for (samordningsnummer, GD-nummer), and it covers the companies whose companies.org_number has drifted from company_settings.org_number. 2. AGI status stayed on "väntar på BankID-signatur i Mina Sidor" after the user had signed. Reading the kvittens needs a live Skatteverket session, and the personal token lives ~65 minutes, so by the time anyone signs in Mina Sidor the 2-hourly kvittens cron finds a dead token and skips quietly. The panel kept asserting a state it could no longer observe. It now says so instead, and the reconnect action already on the panel is the fix: runPostConnectRefresh reconciles pending declarations on a fresh consent. sessionExpiredStatus also counts the needs_reconsent health flag, which a cron can set while the access token is still inside its hour; without it the panel reported a dead connection as healthy. Background reconciliation without a reconnect needs the läsombud grant, which is a registration decision and not part of this change. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs(skatteverket): say why the entity_type collapse in the payment-file route is total companies.entity_type is NOT NULL with CHECK IN ('enskild_firma', 'aktiebolag'), so the ternary cannot silently mis-tag an enskild firma as a legal entity and give a personnummer the "16" prefix. Two review bots read it as an unguarded default; write down the constraint that makes it safe instead of leaving the next reader to re-derive it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs(decisions): record why the cached skattekonto OCR needs no freshness gate Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
Jakob Wennberg
parent
cbfb2201ff
commit
d80103a2f5
@@ -45,7 +45,7 @@ vi.mock('@/lib/branding/service', () => ({
|
||||
}))
|
||||
|
||||
vi.mock('@/lib/skatteverket/skattekonto-ocr', () => ({
|
||||
generateSkattekontoOcr: vi.fn().mockReturnValue('1234567890'),
|
||||
resolveSkattekontoOcr: vi.fn().mockResolvedValue('1655954700217'),
|
||||
SKATTEKONTO_BANKGIRO: '5050-1055',
|
||||
}))
|
||||
|
||||
@@ -107,7 +107,7 @@ describe('GET /api/skatteverket/tax-payments/[period]/payment-file', () => {
|
||||
|
||||
it('generates the LB file (happy path)', async () => {
|
||||
enqueue({ data: { id: 'agi-1', total_tax: 1000, total_avgifter: 500 } }) // agi
|
||||
enqueue({ data: { name: 'Test AB', org_number: '5566778899' } }) // companies
|
||||
enqueue({ data: { name: 'Test AB', org_number: '5566778899', entity_type: 'aktiebolag' } }) // companies
|
||||
enqueue({ data: { bankgiro: '123-4567' } }) // company_settings
|
||||
enqueue({ data: null, error: null }) // update tax_payment_file_generated_at
|
||||
|
||||
@@ -129,7 +129,7 @@ describe('GET /api/skatteverket/tax-payments/[period]/payment-file', () => {
|
||||
// the matching salary booking credited 2731 with the same number: the
|
||||
// payment must be exactly their sum.
|
||||
enqueue({ data: { id: 'agi-1', total_tax: 12268, total_avgifter: 16073 } }) // agi
|
||||
enqueue({ data: { name: 'Test AB', org_number: '5566778899' } }) // companies
|
||||
enqueue({ data: { name: 'Test AB', org_number: '5566778899', entity_type: 'aktiebolag' } }) // companies
|
||||
enqueue({ data: { bankgiro: '123-4567' } }) // company_settings
|
||||
enqueue({ data: null, error: null }) // update tax_payment_file_generated_at
|
||||
|
||||
@@ -148,7 +148,7 @@ describe('GET /api/skatteverket/tax-payments/[period]/payment-file', () => {
|
||||
// (the öre parks as a small skattekonto överskott, the pre-existing
|
||||
// equilibrium). Truncating here would strand the öre on 2731 instead.
|
||||
enqueue({ data: { id: 'agi-1', total_tax: 12268, total_avgifter: 16073.84 } }) // agi
|
||||
enqueue({ data: { name: 'Test AB', org_number: '5566778899' } }) // companies
|
||||
enqueue({ data: { name: 'Test AB', org_number: '5566778899', entity_type: 'aktiebolag' } }) // companies
|
||||
enqueue({ data: { bankgiro: '123-4567' } }) // company_settings
|
||||
enqueue({ data: null, error: null }) // update tax_payment_file_generated_at
|
||||
|
||||
@@ -163,7 +163,7 @@ describe('GET /api/skatteverket/tax-payments/[period]/payment-file', () => {
|
||||
|
||||
it('generates a pain.001 file when format=pain001', async () => {
|
||||
enqueue({ data: { id: 'agi-1', total_tax: 1000, total_avgifter: 500 } }) // agi
|
||||
enqueue({ data: { name: 'Test AB', org_number: '5566778899' } }) // companies
|
||||
enqueue({ data: { name: 'Test AB', org_number: '5566778899', entity_type: 'aktiebolag' } }) // companies
|
||||
enqueue({ data: null, error: null }) // update tax_payment_file_generated_at
|
||||
|
||||
const response = await GET(
|
||||
@@ -185,14 +185,14 @@ describe('GET /api/skatteverket/tax-payments/[period]/payment-file', () => {
|
||||
payee: { type: 'bankgiro', bankgiro: '50501055' },
|
||||
payeeName: 'Skatteverket',
|
||||
amount: 1500,
|
||||
reference: { type: 'ocr', value: '1234567890' },
|
||||
reference: { type: 'ocr', value: '1655954700217' },
|
||||
})
|
||||
})
|
||||
|
||||
it('returns 400 when the pain.001 debtor is missing an IBAN', async () => {
|
||||
mockResolveBatchDebtor.mockResolvedValue({ ok: false, missing: 'iban' })
|
||||
enqueue({ data: { id: 'agi-1', total_tax: 1000, total_avgifter: 500 } }) // agi
|
||||
enqueue({ data: { name: 'Test AB', org_number: '5566778899' } }) // companies
|
||||
enqueue({ data: { name: 'Test AB', org_number: '5566778899', entity_type: 'aktiebolag' } }) // companies
|
||||
|
||||
const response = await GET(
|
||||
createMockRequest('/api/skatteverket/tax-payments/2026-04/payment-file', {
|
||||
|
||||
@@ -5,7 +5,7 @@ import { getErrorMessage } from '@/lib/errors/get-error-message'
|
||||
import { generateBankgiroPaymentBgLb } from '@/lib/salary/payment/bg-lb-generator'
|
||||
import { generateSupplierPain001 } from '@/lib/payments/pain001-supplier'
|
||||
import { resolveBatchDebtor } from '@/lib/payments/batch-service'
|
||||
import { generateSkattekontoOcr, SKATTEKONTO_BANKGIRO } from '@/lib/skatteverket/skattekonto-ocr'
|
||||
import { resolveSkattekontoOcr, SKATTEKONTO_BANKGIRO } from '@/lib/skatteverket/skattekonto-ocr'
|
||||
import { validateBankgiroNumber } from '@/lib/bankgiro/luhn'
|
||||
import { getBranding } from '@/lib/branding/service'
|
||||
import { roundOre } from '@/lib/money'
|
||||
@@ -86,7 +86,7 @@ export const GET = withRouteContext<{ params: Promise<{ period: string }> }>(
|
||||
|
||||
const { data: company } = await supabase
|
||||
.from('companies')
|
||||
.select('name, org_number')
|
||||
.select('name, org_number, entity_type')
|
||||
.eq('id', companyId)
|
||||
.single()
|
||||
|
||||
@@ -97,9 +97,25 @@ export const GET = withRouteContext<{ params: Promise<{ period: string }> }>(
|
||||
)
|
||||
}
|
||||
|
||||
// The reference is the company's twelve-digit identity plus a Luhn check
|
||||
// digit (13 digits), not the ten-digit form: Skatteverket rejects the short
|
||||
// one. Skatteverket's own reported OCR wins when the skattekonto has been
|
||||
// synced; the derived value is the fallback.
|
||||
//
|
||||
// The entity_type collapse below is total, not a guess at a default:
|
||||
// companies.entity_type is NOT NULL with CHECK IN ('enskild_firma',
|
||||
// 'aktiebolag'), so there is no third value and no null to mis-tag. It
|
||||
// matters because it picks the prefix: a personnummer must keep its century
|
||||
// where an organisationsnummer takes "16", and getting that wrong yields a
|
||||
// Luhn-valid OCR for the wrong taxpayer.
|
||||
let ocr: string
|
||||
try {
|
||||
ocr = generateSkattekontoOcr(company.org_number)
|
||||
ocr = await resolveSkattekontoOcr(
|
||||
supabase,
|
||||
companyId,
|
||||
company.org_number,
|
||||
company.entity_type === 'enskild_firma' ? 'enskild_firma' : 'aktiebolag',
|
||||
)
|
||||
} catch (err) {
|
||||
return NextResponse.json({ error: getErrorMessage(err) }, { status: 400 })
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user