E2E #11: the account picker's fiscal-year default sent a 365-day request
for a 405-day-old fiscal year; Swedbank answered by TERMINATING the
session: zero transactions, connection expired, no error surfaced
(initial_sync_requested_from 2025-08-26, returned min/max null). 90
days worked.
- Default lookback mode is now 'fast' (90 days), labeled rekommenderas
on a first connect; the fiscal-year option stays but carries an inline
'vissa banker avbryter kopplingen' note when its span exceeds 90 days,
and the long-range helper names the real failure mode + the SIE/CSV
path for older history.
- SIE drop card: stage + arm in ONE click (three clicks was one too
many): after the verdict, the single button reads 'Bokför:
oåterkalleligt (BFL 5 kap 5 §)' and the deliberate click commits with
confirmed=true.
- Skill: never re-ask an answered question; when a connect card
rendered, do not paste the URL as text too.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
E2E #10 (the first fully successful drop-card run) left the staged
import stranded until the user prodded the agent, and the agent then
improvised an excellent post-import audit (skattekonto reconciliation,
missing 1630, over-stated payroll liabilities). Codify both:
1. The drop card now carries the approval: after staging, the button
becomes 'Godkänn bokföringen' with a two-click BFL confirmation
(confirmed=true armed on the deliberate second click, exactly the
pending-operations widget pattern), then 'Bokfört' + a ui/updateContext
pointing the agent at trial balance and voucher-gap follow-ups.
2. Skill: when the user writes after a card was shown, the FIRST call is
list_pending_operations (an empty ledger does not mean the file never
arrived); new Step 4b 'efterkontroll' codifies the audit pass
(trial balance vs SIE, skattekonto vs 1630 with 8423/8314/6992 for
ränta/avgifter, auto-created bank account names, underlag coverage,
voucher gaps); memory-first extended with memory-back (save orgnr,
bank, fiscal year, moms period after creation so the next
conversation needs zero questions).
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
E2E #6: the flow ordered SIE-first correctly, but the agent never
discovered gnubok_create_sie_upload, ran a local preflight, and sent the
user to the web wizard again; it also rendered a duplicate generic bank
card before the Swedbank-specific one.
1. New sie-drop widget (ui://sie-drop/app.html), rendered
definition-level by gnubok_create_sie_upload: the user drags the
.se/.sie file onto the card, the widget reads the EXACT bytes
(FileReader), computes sha256 (WebCrypto), calls
gnubok_sie_preflight via tools/call with file_content_base64 +
sha256, shows the verdict, and on Importera stages
gnubok_import_sie with the preflight's mappings. No network from
the iframe, no model reproduction: byte path goes through the host
bridge only, narrated into chat via ui/updateContext.
2. The inline size cap now applies only WITHOUT sha256: a hash-verified
payload is byte-exact by proof, so the widget's 100 KB+ base64
passes while unhashed model-retyped content stays refused.
3. Discovery + ordering fixes: create_sie_upload/preflight/import
descriptions name the card path explicitly; create_company's
history_note points at the card; connect_bank description says pass
bank on the FIRST call when the user has named it (the duplicate
generic card came from a bare call followed by the nudged retry).
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>