* feat(invoicing): artikelregister (product/article catalog) with per-article revenue account Add a lean, non-inventory article catalog (artikelregister) so users can define reusable invoice-line presets (name, unit, price excl VAT, VAT rate) with an optional per-article BAS class-3 revenue-account override. - DB: articles table (RLS via user_company_ids(), audit + updated_at triggers, unique-per-company article_number), generate_article_number RPC (atomic + idempotent), company_settings counter, nullable invoice_items.revenue_account + article_id, pending_operations CHECK expansion. - Engine: generatePerRateLines groups revenue by (vat_rate, account) — byte-identical with no override, balance-safe when split (last account absorbs the rounding remainder), reverse_charge/export still force 3308/3305. - API: /api/articles CRUD (soft-deactivate); override validated against chart_of_accounts (active class-3) and frozen onto invoice lines at create. - Propagation: override carried through send/mark-sent/credit/convert/cash and the staged commit paths (recurring deferred — documented inline). - MCP: gnubok_list/create/update_article (staged, scoped, risk-tiered). - UI: articles register (list/detail/form) + nav + bilingual i18n + invoice-line article picker & "Spara som artikel" quick-create. - Tests: engine regression, route, and pg-real (RPC/RLS/triggers). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(mcp): strip ILIKE _ wildcard from gnubok_list_articles search Underscore is a single-character ILIKE wildcard; stripping it (alongside the existing %,()\* set) keeps a stray char in the article search from matching every row. Read-only + RLS-scoped, so no security impact — addresses PR #703 reviewer + compliance-swarm CC6.3 notes. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
57 lines
2.1 KiB
TypeScript
57 lines
2.1 KiB
TypeScript
import { z } from 'zod'
|
|
|
|
// Commit-boundary re-validation for staged article operations. A staged
|
|
// pending_operations row is re-parsed here before it touches the articles table
|
|
// so a tampered row cannot inject unexpected fields or malformed data
|
|
// (defense in depth, ASVS V4.5) — mirrors lib/pending-operations/schemas/create-supplier.ts.
|
|
|
|
const revenueAccount = z
|
|
.string()
|
|
.regex(/^3\d{3}$/, 'Revenue account must be a 4-digit BAS class-3 account (3xxx)')
|
|
|
|
const vatRatePercent = z.union([z.literal(0), z.literal(6), z.literal(12), z.literal(25)])
|
|
|
|
/** Empty string / null → undefined, then bounded string. */
|
|
const optString = (max: number) =>
|
|
z.preprocess((v) => (v == null || v === '' ? undefined : v), z.string().max(max).optional())
|
|
|
|
const trimmedName = z.preprocess(
|
|
(v) => (typeof v === 'string' ? v.trim() : v),
|
|
z.string().min(1, 'Article name is required').max(200),
|
|
)
|
|
|
|
export const CreateArticleParamsSchema = z.object({
|
|
name: trimmedName,
|
|
type: z.enum(['vara', 'tjanst']).default('tjanst'),
|
|
unit: optString(32),
|
|
price_excl_vat: z.number().nonnegative(),
|
|
vat_rate: vatRatePercent.default(25),
|
|
revenue_account: revenueAccount.nullable().optional(),
|
|
cost_price: z.number().nonnegative().nullable().optional(),
|
|
ean: optString(32),
|
|
housework_type: optString(64),
|
|
name_en: optString(200),
|
|
notes: optString(2000),
|
|
article_number: optString(64),
|
|
})
|
|
|
|
export const UpdateArticleParamsSchema = z.object({
|
|
article_id: z.string().uuid(),
|
|
name: trimmedName.optional(),
|
|
type: z.enum(['vara', 'tjanst']).optional(),
|
|
unit: optString(32),
|
|
price_excl_vat: z.number().nonnegative().optional(),
|
|
vat_rate: vatRatePercent.optional(),
|
|
revenue_account: revenueAccount.nullable().optional(),
|
|
cost_price: z.number().nonnegative().nullable().optional(),
|
|
ean: optString(32),
|
|
housework_type: optString(64),
|
|
name_en: optString(200),
|
|
notes: optString(2000),
|
|
article_number: optString(64),
|
|
active: z.boolean().optional(),
|
|
})
|
|
|
|
export type CreateArticleParams = z.infer<typeof CreateArticleParamsSchema>
|
|
export type UpdateArticleParams = z.infer<typeof UpdateArticleParamsSchema>
|