Files
accounted/lib/pending-operations/schemas/article.ts
T
MattssonandClaude Fable 5 43f7ccab9e feat(invoices): allow BAS class 1-3 posting-account overrides and complete the aktiekapital note (#1121)
- invoice/article posting-account overrides accept active class 1-3 accounts;
  class 1-2 (balance-sheet) accounts are rejected on VAT-bearing lines so the
  ruta 05 tax base always books to a 3xxx account
- shared posting-account regex across server schemas, pending-operation
  re-validation, and client forms
- share-capital settings (aktiekapital/antal_aktier) feed the annual-report
  note; kvotvarde derived per ABL 1 kap 6 $; all-or-nothing pair constraint
- signed per-rate VAT breakdown on credit-note PDFs; U+2212 to ASCII hyphen

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:16:00 +02:00

58 lines
2.2 KiB
TypeScript

import { z } from 'zod'
import { INVOICE_POSTING_ACCOUNT_REGEX } from '@/lib/invoices/posting-account'
// Commit-boundary re-validation for staged article operations. A staged
// pending_operations row is re-parsed here before it touches the articles table
// so a tampered row cannot inject unexpected fields or malformed data
// (defense in depth, ASVS V4.5): mirrors lib/pending-operations/schemas/create-supplier.ts.
const invoicePostingAccount = z
.string()
.regex(INVOICE_POSTING_ACCOUNT_REGEX, 'Posting account must be a 4-digit BAS class 1-3 account')
const vatRatePercent = z.union([z.literal(0), z.literal(6), z.literal(12), z.literal(25)])
/** Empty string / null → undefined, then bounded string. */
const optString = (max: number) =>
z.preprocess((v) => (v == null || v === '' ? undefined : v), z.string().max(max).optional())
const trimmedName = z.preprocess(
(v) => (typeof v === 'string' ? v.trim() : v),
z.string().min(1, 'Article name is required').max(200),
)
export const CreateArticleParamsSchema = z.object({
name: trimmedName,
type: z.enum(['vara', 'tjanst']).default('tjanst'),
unit: optString(32),
price_excl_vat: z.number().nonnegative(),
vat_rate: vatRatePercent.default(25),
revenue_account: invoicePostingAccount.nullable().optional(),
cost_price: z.number().nonnegative().nullable().optional(),
ean: optString(32),
housework_type: optString(64),
name_en: optString(200),
notes: optString(2000),
article_number: optString(64),
})
export const UpdateArticleParamsSchema = z.object({
article_id: z.string().uuid(),
name: trimmedName.optional(),
type: z.enum(['vara', 'tjanst']).optional(),
unit: optString(32),
price_excl_vat: z.number().nonnegative().optional(),
vat_rate: vatRatePercent.optional(),
revenue_account: invoicePostingAccount.nullable().optional(),
cost_price: z.number().nonnegative().nullable().optional(),
ean: optString(32),
housework_type: optString(64),
name_en: optString(200),
notes: optString(2000),
article_number: optString(64),
active: z.boolean().optional(),
})
export type CreateArticleParams = z.infer<typeof CreateArticleParamsSchema>
export type UpdateArticleParams = z.infer<typeof UpdateArticleParamsSchema>