* feat(salary): add remove-employee button to draft salary runs
The DELETE /api/salary/runs/{id}/employees/{employeeId} endpoint already
existed (draft-only, cascades to the employee's line items) but had no UI
trigger, so a mistakenly added employee could only be cleared by deleting
the whole draft. Add a trash-icon action column to the "Anställda" table,
gated on draft status + write permission to match the endpoint's guard,
with a confirm prompt and success/error toast.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(settings): prevent horizontal overflow on mobile
The company settings invite form was a non-wrapping fixed-width flex row that overflowed narrow viewports, forcing the full-screen settings modal to scroll on the x-axis. Stack the form vertically on mobile (sm:flex-row at and above the sm breakpoint) and add the missing min-w-0 guard to the modal content pane.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(bookkeeping): move journal entry filters into a filter dialog
The ledger toolbar showed every filter inline (fiscal year, sort, series,
date range, missing-documents toggle), which felt cluttered. Keep only the
search field visible and move the rest into a "Filtrera" dialog with an
active-filter count badge.
- JournalEntryList now owns the fiscal-year scope, restored from the same
localStorage key FiscalYearSelector writes, so the page no longer renders
the selector separately.
- Filters apply live and the dialog stays open; "Rensa alla filter" clears them.
- Export STORAGE_KEY_PREFIX / ALL_YEARS_VALUE from FiscalYearSelector so the
list reuses the persisted selection without duplicating the key.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(transactions): implement imported transaction guard for deletion
- Added a guard to prevent deletion of transactions that are imported via bank sync or file uploads.
- Introduced `isImportedTransaction` utility to determine if a transaction is user-created or imported.
- Updated DELETE endpoint to return a 409 status for attempts to delete imported transactions.
- Enhanced transaction history and inbox components to reflect the new deletion rules.
- Added tests for transaction origin determination and deletion behavior.
- Updated UI components to include a confirmation dialog for clearing journal entry forms.
- Localized new strings for clearing form functionality in English and Swedish.
* feat(transactions): enhance transaction deletion guard and improve fiscal year visibility
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
54 lines
2.2 KiB
TypeScript
54 lines
2.2 KiB
TypeScript
import { describe, it, expect } from 'vitest'
|
|
import { escapeLikePattern, normalizeOcrReference } from '../duplicate-payment-guard'
|
|
|
|
describe('escapeLikePattern', () => {
|
|
// These cases lock in that a user-supplied needle reaches an ILIKE pattern with
|
|
// its LIKE metacharacters neutralised — each of `%`, `_`, `\` must match only
|
|
// itself and never expand as a wildcard (compliance A.8.28 / ASVS V1.2.5).
|
|
it('escapes a literal percent so it matches only itself', () => {
|
|
expect(escapeLikePattern('50% rabatt')).toBe('50\\% rabatt')
|
|
})
|
|
|
|
it('escapes a literal underscore so it is not a single-char wildcard', () => {
|
|
expect(escapeLikePattern('konto_1930')).toBe('konto\\_1930')
|
|
})
|
|
|
|
it('escapes a literal backslash so it does not consume the next char', () => {
|
|
expect(escapeLikePattern('a\\b')).toBe('a\\\\b')
|
|
})
|
|
|
|
it('escapes backslash, percent and underscore together without double-escaping', () => {
|
|
// Backslash is escaped FIRST, so the escapes added for % and _ are not
|
|
// themselves re-escaped. Each special char maps to exactly "\\" + itself.
|
|
expect(escapeLikePattern('a\\b%c_d')).toBe('a\\\\b\\%c\\_d')
|
|
})
|
|
|
|
it('leaves ordinary text untouched', () => {
|
|
expect(escapeLikePattern('Faktura 2026-0042')).toBe('Faktura 2026-0042')
|
|
})
|
|
|
|
it('caps the needle at 200 characters to bound DB work on oversized input', () => {
|
|
const escaped = escapeLikePattern('a'.repeat(250))
|
|
expect(escaped).toBe('a'.repeat(200))
|
|
expect(escaped.length).toBe(200)
|
|
})
|
|
|
|
it('truncates BEFORE escaping, so the source length is the bound', () => {
|
|
// 250 percent signs → truncated to 200 source chars, each escaped to "\%".
|
|
expect(escapeLikePattern('%'.repeat(250))).toBe('\\%'.repeat(200))
|
|
})
|
|
})
|
|
|
|
describe('normalizeOcrReference', () => {
|
|
it('keeps only digits regardless of separators', () => {
|
|
expect(normalizeOcrReference('2026-0042')).toBe('20260042')
|
|
expect(normalizeOcrReference('2026 / 0042')).toBe('20260042')
|
|
})
|
|
|
|
it('returns an empty string for nullish or empty input', () => {
|
|
expect(normalizeOcrReference(null)).toBe('')
|
|
expect(normalizeOcrReference(undefined)).toBe('')
|
|
expect(normalizeOcrReference('')).toBe('')
|
|
})
|
|
})
|