* fix(reports): stabilize fetchAllRows paging to stop doubled/dropped balances (#790, #791)
PostgREST `.range()` paging is only correct when the underlying query has a
stable TOTAL order. Several aggregating report queries (general ledger, trial
balance, grundbok, supplier/AR ledgers, etc.) paginated without `.order()`, so
on datasets larger than one 1000-row page Postgres could return rows in a
different order between requests — silently DUPLICATING or SKIPPING rows on a
page boundary and doubling or dropping financial totals.
- fetch-all.ts: document the ordering invariant and add an optional
`dedupeBy` defense-in-depth that drops cross-page duplicates and warns when
it fires (surfaces a missing `.order()` in logs instead of corrupting money).
- Add a stable `.order()` (line PK or account_number) to every paginated query
in lib/reports/ and the account-balances route; pass `dedupeBy` on the
money-aggregating line queries.
- Add fetch-all unit tests and update report test fixtures to carry row ids.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(api): declare the real { data, meta } envelope on v1 single/write/204 endpoints (#794)
The OpenAPI generator derives each endpoint's documented body purely from its
registered `response.success` Zod schema, and that schema is never validated at
runtime — so a route could advertise a shape its handler never sends. #802
fixed this for list endpoints; the same drift was latent on single-resource and
write endpoints, which declared the bare resource schema instead of the
`{ data, meta }` envelope the handlers actually return.
- registry.ts: extend `ResponseMetaSchema` with the optional `audit` block and
`partial_expansions` list that writes/expansions emit; add the `NoBodyResponse`
sentinel so 204 DELETE handlers document a bare 204 instead of a phantom 200.
- Wrap every single/write endpoint's `response.success` in `dataEnvelope(...)`
(or `NoBodyResponse` for 204s) across the v1 routes.
- Add a response-envelope contract test that fails CI if any JSON endpoint
forgets to wrap its schema, with binary downloads and 204s as the only
exemptions.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(reports): extend paging dedupeBy to rc-basis-gaps and opening-balances
Address PR review: these two money-aggregating line queries already had the
stable `.order('id')` (so paging was correct) but didn't carry `id` in the
select, so they couldn't use the `dedupeBy` defense-in-depth that general-ledger
and trial-balance got. Select `id` and pass `dedupeBy: r => r.id` so the whole
report layer applies the ordering invariant consistently.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: prevent silent data truncation in report generators
Supabase PostgREST silently truncates queries at 1000 rows. Several
report generators used bare .select() without fetchAllRows(), causing
incomplete financial data — a BFL compliance violation.
Wrapped 10 queries across 7 files with fetchAllRows():
- monthly-breakdown: journal_entry_lines (easily >1000/period)
- ar-ledger: unpaid invoices
- supplier-ledger: unpaid supplier invoices
- salary-journal: salary_run_employees (+ optimized with !inner join)
- vacation-liability: employees + salary_run_employees
- full-archive-export: document_attachments + journal_entry IDs
- ingest.ts: supplier invoices for auto-matching
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: address Greptile review — try/catch and client-side safety checks
- Wrap full-archive-export document fetch in try/catch to match the
VAT section pattern — a failed document query should not prevent
the rest of the archive from being generated.
- Restore client-side year/status safety checks in salary-journal and
vacation-liability as defense-in-depth against PostgREST !inner
filter regressions, per BFL lönejournal and BFNAR 2016:10 compliance.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: implement salary module with personnummer encryption, salary entries, tax tables, and AGI tracking
- Added personnummer encryption and decryption functions for secure storage.
- Created salary entries handling for journal entries including gross salary, tax withholding, and employer contributions.
- Implemented tax table lookup functionality for calculating tax amounts based on monthly income.
- Developed SQL migration for salary module including tables for payroll configuration, tax rates, employees, salary runs, salary run employees, salary line items, and AGI declarations.
- Established row-level security policies for all new tables to ensure company-scoped access.
* feat: add salary calculation modules for 2026
- Implemented engångsskatt calculation for one-time payments with tax brackets.
- Added löneväxling functionality for salary sacrifice to pension, including employer savings and warnings.
- Created pain.001 generator for salary batch payments in compliance with Swedish banking standards.
- Developed PDF template for payslips, including detailed breakdowns and employer costs.
- Generated seed data for Swedish tax tables for 2026, including SQL insert statements.
- Implemented traktamente calculations for per diem and mileage allowances, adhering to Skatteverket regulations.
- Added seed script for populating tax tables in the database.
* feat: Update meal reduction percentages in traktamente calculation
fix: Remove obsolete seed script for 2026 tax tables
feat: Extend SalaryRunStatus type to include 'corrected' status
feat: Implement KU10 XML generation endpoint for annual employee income statements
feat: Add endpoint for creating corrections to booked salary runs
feat: Implement endpoint for sending payslip PDFs to employees
feat: Create KU10 XML generator for annual reporting
feat: Add salary transaction matcher for auto-linking bank transactions to salary entries
chore: Add database migration for salary correction support
* feat: replace select elements with custom Select component for employment and salary types
* feat: enhance salary calculations with pension entry and avgifter category support