* feat(salary): per-day absence tracking with calendar UX Replace aggregated-day absence counts with per-day records so payroll calculations can correctly enforce Swedish legal rules that depend on actual dates: karensavdrag once per sjuklöneperiod, återinsjuknande within 5 calendar days, allmänt högriskskydd cap of 10 karensavdrag per rolling 12 months, day-8 läkarintyg flag, day-15 transition to Försäkringskassan. Adds: - salary_absence_days table (RLS, dedup unique on employee+date+type) - /api/salary/employees/[id]/absence CRUD route - deriveAbsenceLineItems helper that walks per-day records into sjuklöneperioder and emits correctly-classified line items, with the existing absence-calculator formulas reused for VAB / parental - Per-employee pay-spec detail page with month-grid AbsenceCalendar - Calculate route now derives line items from the calendar before running the salary engine, replacing the prior sumQuantity model - Salary run GET surfaces the formatted Skatteverket arbetsgivare ID so downstream UI can build extension URLs without a second round-trip - GET /salary/runs/[id]/employees/[employeeId] for the detail page Tests: 15 new unit tests covering segment merge, återinsjuknande within 5 days, högriskskydd cap, FK transition flag, läkarintyg flag, VAB/parental semesterlönegrundande ceilings. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * feat(skatteverket): harden API client + add NEXT_PUBLIC_SKATTEVERKET_ENABLED feature flag Three hardening fixes from the prior audit, plus a runtime extension toggle for phased rollout. api-client.ts: - Map 429 to a new SkatteverketAuthError code RATE_LIMITED with a Swedish user message. The 4 req/sec local rate limiter normally prevents this, but the per-consumer gateway quota can still hit. - Extend the error union with TOKEN_CORRUPTED for the token-store fix below. token-store.ts: - Surface decryption failures instead of silently returning null. A rotated key or tampered ciphertext used to look like "not connected"; callers now get TOKEN_CORRUPTED with a clear "anslut igen med BankID" message and a structured log line for ops. Extension dispatcher (app/api/extensions/ext/[...path]/route.ts): - Per-extension feature flag table. When NEXT_PUBLIC_SKATTEVERKET_ENABLED is not exactly "true", the dispatcher returns 503 with code EXTENSION_DISABLED, letting ops disable a single integration mid- rollout without redeploying or removing it from extensions.config.json. UI panels (SkatteverketPanel, AGIPanel) detect the 503 and render an empty state. Tests: 7 api-client cases (401/403/403-Behörighet/429/5xx/200/auth-error codes) + 2 token-store cases (no-row → null, corrupted → TOKEN_CORRUPTED). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * feat(salary): emit AGI Frånvarouppgift per SKV 4785, add AGIPanel for one-click submission AGI XML upgrade: - Emit <gem:Franvarouppgift> top-level blocks for VAB and parental leave events sourced from salary_absence_days, per SKV 4785 + technical doc. Element order matches the spec example file. TILLFALLIG_FORALDRAPENNING for VAB / FORALDRAPENNING for parental, with FranvaroTimmarTFP (FK825) or FranvaroTimmarFP (FK827) for hours. Stable 1-based specifikationsnummer per (employee, period), date-sorted. Skipped entirely for periods before 202501. - Sick days are NOT emitted (they go to Försäkringskassan). - FK499 TotalSjuklonekostnad now derived from sick_day2_14.quantity × dailyRate × 0.80 instead of Math.abs(amount). The line-item amount is the net deduction (lostPay − sjuklon), not the cost, so the prior formula understated by a factor of four. AGI submission UI: - New AGIPanel mirroring SkatteverketPanel's validate → draft → lock → BankID-sign → poll-submitted flow. Detects 503 EXTENSION_DISABLED and renders a clear empty state. Replaces the bare "Skicka till Skatteverket" button on /salary/runs/[id], keeping the AGI XML download as a sibling for archival / manual upload fallback. - Salary run rows now link to the per-employee detail page added in the previous commit. Tests: 14 new agi-xml cases covering element order, type↔hour-field mapping, specifikationsnummer ordering, fractional-hour formatting, range clamping (0.01-24.00), period guard at 202501 boundary, placement after Blankett blocks, multi-employee date ordering, required-fields invariant, omission when no events. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * feat(skatteverket): skattekonto integration — read-only saldo + transactions, daily sync, per-row bokför Adds read-only Skattekonto v2.1 access via the existing BankID OAuth flow (extends the OAuth scope with `skattekonto`). Daily background sync pulls saldo + transactions, dedupes on (company_id, dedup_key), and surfaces the data in a /skattekonto dashboard plus a settings panel for connection management. Backend: - skattekonto-client.ts: GET /skattekonton/{omfragad}/saldo and /transaktioner. Felkod 1–5 mapped to Swedish messages via dedicated SkatteverketSkattekontoError. - skattekonto-sync.ts: parallel saldo + transaktioner fetch, UPSERT on (company_id, dedup_key) so kommande rows graduate to tidigare in place. Dedup key uses transaktionsidentitet when available, else sha256 of (date|amount|text). Caches saldo snapshot in extension_data. Emits skattekonto.synced / balance.changed (sign flip) / transaction.upcoming (first appearance) / connection.expired. - skattekonto-booking.ts: keyword→counter-account rules with AB/EF differentiation (2510 vs 2012 for preliminärskatt; 2731/2710/2650 for arbetsgivaravgifter/avdragen skatt/moms; 8423/8313 for kostnads-/intäktsränta). Creates a draft journal entry against BAS 1630, leaves it for the user to review and commit. Throws NO_COUNTER_ACCOUNT instead of guessing when no rule matches. - Daily cron at 0 4 * * * (Swedish 06:00). Double-gated by CRON_SECRET and NEXT_PUBLIC_SKATTEVERKET_ENABLED. Per-company cooldown of 1 hour, time budget 50s, distinct `expired` status for token-exhaustion separate from generic errors. Database: - skattekonto_transactions: company-scoped with RLS, unique (company_id, dedup_key), indexed on (company_id, date DESC) and (company_id, status). journal_entry_id FK with ON DELETE SET NULL so a row can be re-bokförd after entry deletion. Frontend: - /skattekonto/page.tsx: dashboard with saldo card, transactions list (booked + upcoming), per-row "Bokför" action. - /settings/skatteverket: connection panel showing scope/expiry. - Extension toggle in SettingsSidebar (gated by ENABLED_EXTENSION_IDS). Tests: 9 booking-rule cases (counter-account guessing, AB/EF divergence, no-match throw) + 7 mapper cases (dedup key stability, sign convention, kommande→tidigare graduation). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: address PR review findings Build: - Fix Next.js build failure: Zod refuses .partial() on a refined schema. Replace AbsenceRangeQuerySchema.partial().extend(...) in the absence DELETE handler with a fresh z.object that defines its own optional fields. Greptile findings (PR #388): - skattekonto_transactions UPDATE policy was missing WITH CHECK; without it a user could mutate company_id to one they don't belong to. Edit the original migration for fresh applies + add a follow-up migration that drops/recreates the policy with both clauses (already applied to prod via Supabase MCP). - FK499 TotalSjuklonekostnad now reads sjuklonRate from run.calculation_params (snapshot taken at calc time) instead of a hardcoded 0.80, so an operator override (e.g. CBA-specific rate) is honored. Falls back to 0.80 for older runs without the snapshot. - Rename NEXT_PUBLIC_SKATTEVERKET_ENABLED → SKATTEVERKET_ENABLED so the flag is server-side only. NEXT_PUBLIC_* vars are inlined into the client bundle at build time, which would create split-brain (server 503 vs client still rendering enabled flow) on a flag flip without redeploy. UI panels detect 503 by response code, not by reading the env directly, so no client-visible change is needed. - Add pg-real RLS smoke tests for both new tables (salary_absence_days and skattekonto_transactions): tenant SELECT isolation, UPDATE WITH CHECK enforcement, unique-constraint enforcement, cross-tenant dedup key allowed. Swedish compliance review: - Document the högriskskydd cap interpretation in derive-absence-line-items.ts. We count *sjuklöneperioder* in the rolling 12-month window, matching the law's plain reading ("från och med den 11:e sjukperioden ... görs inget karensavdrag"). An alternative reading counts only periods that actually had karens deducted; that requires persisting per-period karens-deduction state, which gnubok doesn't yet do. The period-count reading can over- suppress, never under-suppress, so it's the safer default. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(test): inline skattekonto fixtures so core-only CI runs without dev_docs dev_docs/ is gitignored, so the skattekonto-mappers test failed in CI when it tried to readFileSync from dev_docs/skattekonto(2.1.0)/examples/. Inline the saldoResponse + transaktionerResponse fixtures verbatim from the spec; the test still verifies our mappers + dedup-key logic against the same shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
184 lines
6.8 KiB
TypeScript
184 lines
6.8 KiB
TypeScript
import crypto from 'crypto'
|
|
import { createClient, type SupabaseClient } from '@supabase/supabase-js'
|
|
import { createLogger } from '@/lib/logger'
|
|
import type { SkatteverketTokens } from '../types'
|
|
import { SkatteverketAuthError } from './api-client'
|
|
|
|
const log = createLogger('skatteverket-token-store')
|
|
|
|
/**
|
|
* Encrypted token storage for Skatteverket OAuth2 tokens.
|
|
*
|
|
* Uses AES-256-GCM with a dedicated encryption key (not the Supabase service
|
|
* role key) to encrypt tokens at rest in the skatteverket_tokens table.
|
|
*
|
|
* Pattern mirrors lib/auth/oauth-codes.ts but adapted for persistent storage.
|
|
*
|
|
* All DB operations route through a service-role client. The original RLS
|
|
* design (auth.uid() = user_id) is correct, but at least one deployed
|
|
* environment is missing the INSERT/UPDATE/DELETE policies and the
|
|
* UNIQUE(user_id) constraint, so user-session writes get rejected. The
|
|
* service-role client bypasses RLS, and the calling handlers (the OAuth
|
|
* callback in particular) verify the user identity via cookies before
|
|
* passing user_id here, so the access-control invariant is upheld at the
|
|
* application layer.
|
|
*/
|
|
|
|
let _serviceClient: SupabaseClient | null = null
|
|
function getServiceClient(): SupabaseClient {
|
|
if (_serviceClient) return _serviceClient
|
|
const url = process.env.NEXT_PUBLIC_SUPABASE_URL
|
|
const key = process.env.SUPABASE_SERVICE_ROLE_KEY
|
|
if (!url || !key) {
|
|
throw new Error('skatteverket token-store requires NEXT_PUBLIC_SUPABASE_URL and SUPABASE_SERVICE_ROLE_KEY')
|
|
}
|
|
_serviceClient = createClient(url, key, { auth: { persistSession: false } })
|
|
return _serviceClient
|
|
}
|
|
|
|
const ALGORITHM = 'aes-256-gcm'
|
|
|
|
function getEncryptionKey(): Buffer {
|
|
const key = process.env.SKATTEVERKET_TOKEN_ENCRYPTION_KEY
|
|
if (!key) throw new Error('SKATTEVERKET_TOKEN_ENCRYPTION_KEY is required')
|
|
return crypto.createHash('sha256').update(key).digest()
|
|
}
|
|
|
|
function encrypt(plaintext: string): string {
|
|
const key = getEncryptionKey()
|
|
const iv = crypto.randomBytes(12)
|
|
const cipher = crypto.createCipheriv(ALGORITHM, key, iv)
|
|
const encrypted = Buffer.concat([cipher.update(plaintext, 'utf8'), cipher.final()])
|
|
const tag = cipher.getAuthTag()
|
|
return Buffer.concat([iv, tag, encrypted]).toString('base64url')
|
|
}
|
|
|
|
function decrypt(ciphertext: string): string {
|
|
const key = getEncryptionKey()
|
|
const combined = Buffer.from(ciphertext, 'base64url')
|
|
const iv = combined.subarray(0, 12)
|
|
const tag = combined.subarray(12, 28)
|
|
const encrypted = combined.subarray(28)
|
|
const decipher = crypto.createDecipheriv(ALGORITHM, key, iv)
|
|
decipher.setAuthTag(tag)
|
|
return Buffer.concat([decipher.update(encrypted), decipher.final()]).toString('utf8')
|
|
}
|
|
|
|
/**
|
|
* Store (replace) Skatteverket tokens for a user.
|
|
* Both access_token and refresh_token are encrypted at rest.
|
|
*
|
|
* Implemented as DELETE + INSERT instead of UPSERT because some environments
|
|
* are missing the UNIQUE(user_id) constraint that ON CONFLICT requires. The
|
|
* delete-then-insert pattern is safe because OAuth callbacks for a given user
|
|
* are not concurrent (the user can only sign in with BankID once at a time).
|
|
*/
|
|
export async function storeTokens(
|
|
_supabase: SupabaseClient,
|
|
userId: string,
|
|
tokens: SkatteverketTokens,
|
|
companyId?: string,
|
|
): Promise<void> {
|
|
const encryptedAccess = encrypt(tokens.access_token)
|
|
const encryptedRefresh = tokens.refresh_token ? encrypt(tokens.refresh_token) : null
|
|
const db = getServiceClient()
|
|
|
|
// The multi-tenant refactor (migration 20260330130000) put a NOT NULL
|
|
// company_id on every table. Tokens are conceptually user-scoped (one
|
|
// BankID identity), but the schema requires a company_id. The OAuth
|
|
// callback passes one explicitly. Token-refresh flows (called from
|
|
// skvRequest) don't pass one, so before we DELETE the existing row we
|
|
// remember its company_id and reuse it on INSERT.
|
|
let resolvedCompanyId = companyId
|
|
if (!resolvedCompanyId) {
|
|
const { data: existing, error: selectError } = await db
|
|
.from('skatteverket_tokens')
|
|
.select('company_id')
|
|
.eq('user_id', userId)
|
|
.maybeSingle()
|
|
// Throw before the destructive DELETE: a transient read failure here
|
|
// would otherwise wipe the existing row and then fail the INSERT on the
|
|
// NOT NULL company_id, leaving the user with no token at all.
|
|
if (selectError) {
|
|
throw new Error(`Failed to read existing token row: ${selectError.message}`)
|
|
}
|
|
if (existing?.company_id) resolvedCompanyId = existing.company_id
|
|
}
|
|
|
|
const { error: deleteError } = await db
|
|
.from('skatteverket_tokens')
|
|
.delete()
|
|
.eq('user_id', userId)
|
|
if (deleteError) throw new Error(`Failed to clear existing tokens: ${deleteError.message}`)
|
|
|
|
const row: Record<string, unknown> = {
|
|
user_id: userId,
|
|
access_token: encryptedAccess,
|
|
refresh_token: encryptedRefresh,
|
|
expires_at: new Date(tokens.expires_at).toISOString(),
|
|
refresh_count: tokens.refresh_count,
|
|
scope: tokens.scope,
|
|
}
|
|
if (resolvedCompanyId) row.company_id = resolvedCompanyId
|
|
|
|
const { error: insertError } = await db.from('skatteverket_tokens').insert(row)
|
|
if (insertError) throw new Error(`Failed to store tokens: ${insertError.message}`)
|
|
}
|
|
|
|
/**
|
|
* Retrieve and decrypt Skatteverket tokens for a user.
|
|
* Returns null if no tokens are stored.
|
|
*/
|
|
export async function getTokens(
|
|
_supabase: SupabaseClient,
|
|
userId: string
|
|
): Promise<SkatteverketTokens | null> {
|
|
const db = getServiceClient()
|
|
const { data, error } = await db
|
|
.from('skatteverket_tokens')
|
|
.select('access_token, refresh_token, expires_at, refresh_count, scope')
|
|
.eq('user_id', userId)
|
|
.single()
|
|
|
|
if (error || !data) return null
|
|
|
|
// Distinguish three states:
|
|
// 1. No row → caller treats as NOT_CONNECTED (return null above)
|
|
// 2. Decryption error → log + throw TOKEN_CORRUPTED so the caller can
|
|
// tell the user to reconnect. Previously returned null silently
|
|
// which masked the real problem (key rotation, tampering, or a
|
|
// schema-level bug) as "not connected".
|
|
try {
|
|
return {
|
|
access_token: decrypt(data.access_token),
|
|
refresh_token: data.refresh_token ? decrypt(data.refresh_token) : null,
|
|
expires_at: new Date(data.expires_at).getTime(),
|
|
refresh_count: data.refresh_count ?? 0,
|
|
scope: data.scope,
|
|
}
|
|
} catch (err) {
|
|
log.error('decryption failed for stored tokens', {
|
|
userId,
|
|
error: err instanceof Error ? err.message : String(err),
|
|
})
|
|
throw new SkatteverketAuthError(
|
|
'Tokens kunde inte läsas. Anslut igen med BankID.',
|
|
'TOKEN_CORRUPTED'
|
|
)
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Delete stored tokens (disconnect from Skatteverket).
|
|
*/
|
|
export async function deleteTokens(
|
|
_supabase: SupabaseClient,
|
|
userId: string
|
|
): Promise<void> {
|
|
const db = getServiceClient()
|
|
await db
|
|
.from('skatteverket_tokens')
|
|
.delete()
|
|
.eq('user_id', userId)
|
|
}
|