* fix(vat): drop personnummer century so enskild firma VAT number is SE+12 not SE+14
Onboarding derived the VAT number as SE${orgNumber}01. For an enskild firma the
org number is a 12-digit personnummer, producing SE + 14 digits, which fails the
^SE\d{12}$ validation — the pre-filled value is re-submitted on save and the tax
settings page becomes unsavable.
New shared helper lib/vat/vat-number.ts (normalize/validate/derive, reusing
normalizeOrgNumber to drop the century + Luhn-validate). UpdateSettingsSchema,
the onboarding wizard, the onboarding upsert in lib/company/actions.ts, and the
arcim-migration provider import all route through it. Backfill migration repairs
existing SE+14 rows to SE+12 (idempotent, scoped to ^SE\d{14}$ only).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore(arcim): warn when a provider VAT number is dropped as malformed
The provider VAT guard silently discarded a value that doesn't normalise to a
valid SE+12 momsregistreringsnummer. Emit a structured warn (provider +
company, no raw value — it can embed a personnummer) so consistently-bad
provider data is observable rather than invisible. Addresses the OWASP V16
logging finding on the arcim VAT-normalisation change in this PR.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
46 lines
1.8 KiB
TypeScript
46 lines
1.8 KiB
TypeScript
import { normalizeOrgNumber } from '@/lib/company-lookup/normalize-org-number'
|
|
|
|
/**
|
|
* Swedish VAT registration number (momsregistreringsnummer) helpers.
|
|
*
|
|
* Canonical format per Skatteverket: "SE" + 10-digit identity + "01" = SE
|
|
* followed by exactly 12 digits, no spaces.
|
|
* - Aktiebolag: the 10-digit organisationsnummer, used as-is.
|
|
* - Enskild firma: the personnummer reduced to its 10-digit form (YYMMDD-NNNN).
|
|
* A 12-digit personnummer (YYYYMMDD-NNNN) has its birth-century prefix
|
|
* ('19'/'20') DROPPED first — including it would yield SE + 14 digits, which
|
|
* is invalid. This is the bug that shipped from the onboarding wizard.
|
|
*
|
|
* The "01" suffix is the registration serial; it is effectively always "01" for
|
|
* a single registration.
|
|
*/
|
|
|
|
const SE_VAT_PATTERN = /^SE\d{12}$/
|
|
|
|
/**
|
|
* Normalise raw user/provider input to the canonical spaceless, uppercase form.
|
|
* Strips whitespace and hyphens (e.g. "se 556677-8899 01" → "SE556677889901").
|
|
*/
|
|
export function normalizeVatNumber(raw: string): string {
|
|
return raw.replace(/[\s-]/g, '').toUpperCase()
|
|
}
|
|
|
|
/** Structural validity check: literal "SE" followed by exactly 12 digits. */
|
|
export function isValidSwedishVatNumber(value: string): boolean {
|
|
return SE_VAT_PATTERN.test(value)
|
|
}
|
|
|
|
/**
|
|
* Derive a Swedish VAT number from an organisationsnummer or personnummer.
|
|
*
|
|
* Reuses {@link normalizeOrgNumber} to reach the canonical 10-digit identity
|
|
* (century dropped for 12-digit personnummer, Luhn-validated), then appends the
|
|
* "01" serial. Returns null when the input has no usable, structurally valid
|
|
* 10/12-digit identity — callers should leave the VAT number blank rather than
|
|
* persist a guess.
|
|
*/
|
|
export function deriveSwedishVatNumber(orgNumber: string | null | undefined): string | null {
|
|
const canonical = normalizeOrgNumber(orgNumber)
|
|
return canonical ? `SE${canonical}01` : null
|
|
}
|