* feat: add INK2 declaration improvements, invoice delivery date, and Swedish compliance skills Expand INK2 engine with full INK2S/INK2R support and improved SRU generation. Add delivery_date field to invoices and corresponding PDF/migration support. Add Claude skills for Swedish asset accounting, invoice compliance, SIE import/export, SRU filing, and tax planning. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: address PR review — map BAS 4500–4899, strip CRLF in SRU, document P3 - Map BAS accounts 4500–4599 (legoarbeten), 4700–4899 (diverse varuinköpskostnader) to SRU 7512 so they are not silently dropped from INK2R declarations - Strip \r\n in sanitizeString to prevent CRLF injection in SRU fields - Document P3 period suffix limitation for brutet räkenskapsår Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: correct BAS 4500-4599, 4700-4899 mapping from 7512 to 7511 Per the official BAS-to-SRU mapping, these account ranges are cost of goods (legoarbeten, inkurans, svinn) and belong under 7511 (Råvaror och förnödenheter), not 7512 (Handelsvaror). 7512 remains 4600-4699. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: Swedish VAT compliance — representation VAT, domestic RC, full BAS 26xx mapping, SIE encoding - Representation expenses now default to reduced_12 VAT (ML 13 kap 24-25 §§); income tax deduction was abolished 2017 but VAT deduction at 12% remains - Domestic reverse charge (byggtjänster etc.) uses 2647 instead of 2645, with distinct line descriptions for Swedish vs EU/non-EU RC - VAT declaration maps all BAS 26xx variant accounts (egna uttag 2612/2622/2632, uthyrning 2613/2623/2633, VMB 2616/2626/2636, import 2615/2625/2635, domestic RC 2647, frivillig skattskyldighet 2642) and revenue variants (3108/3105/3004/3100) to correct momsdeklaration rutor - SIE parser: remove unreliable #FORMAT PC8 encoding detection (most software exports UTF-8 with PC8 header), parse #FLAGGA for import-already-done warning, default SIE type to 1 when absent, fix RTRANS/BTRANS documentation - SIE export: add #RAR -1 (previous fiscal year), fix UB = IB + movements - Error messages: add pattern matching for locked period trigger errors Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: address Greptile review — update ruta49 JSDoc, use null sentinel in error map Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: harden storno CAS guard, document integrity, and BFNAR archive compliance - Storno: defer original→reversed until both entries succeed, add CAS guard for concurrent reversals, use cancelEntry() instead of delete - Document: add document.accessed event, enrich archive manifest with metadata, add BFNAR 2013:2 systemdokumentation to full archive export - Verify cron: run daily, configurable batch size, include company_id in audit - Migrations: integrity audit actions, document version chain, metadata immutability, audit deletions, fix immutability for posted/cancelled Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: address Greptile review — allow is_current_version in immutability trigger, log cancelEntry errors - Remove is_current_version from blocked fields in enforce_document_metadata_immutability trigger so create_document_version RPC can supersede documents linked to posted entries - Add error logging to cancelEntry for observability on cleanup failures Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
58 lines
2.3 KiB
PL/PgSQL
58 lines
2.3 KiB
PL/PgSQL
-- Enforce document metadata immutability for documents linked to committed entries
|
|
-- BFL 7 kap requires verifikation underlag to be immutable once committed.
|
|
-- Existing triggers only block DELETE — this blocks metadata UPDATE.
|
|
|
|
CREATE OR REPLACE FUNCTION public.enforce_document_metadata_immutability()
|
|
RETURNS trigger
|
|
LANGUAGE plpgsql
|
|
SECURITY DEFINER
|
|
SET search_path = public
|
|
AS $$
|
|
DECLARE
|
|
v_entry_status text;
|
|
BEGIN
|
|
-- Only enforce on documents already linked to a journal entry
|
|
IF OLD.journal_entry_id IS NULL THEN
|
|
RETURN NEW;
|
|
END IF;
|
|
|
|
SELECT status INTO v_entry_status
|
|
FROM public.journal_entries
|
|
WHERE id = OLD.journal_entry_id;
|
|
|
|
-- Only enforce for committed (posted/reversed) entries
|
|
IF v_entry_status IS NULL OR v_entry_status NOT IN ('posted', 'reversed') THEN
|
|
RETURN NEW;
|
|
END IF;
|
|
|
|
-- Block changes to immutable fields
|
|
-- Allowed: last_integrity_check_at (cron), updated_at (auto-trigger),
|
|
-- superseded_by_id (versioning), prev_version_hash (versioning),
|
|
-- journal_entry_id/journal_entry_line_id (linking)
|
|
IF NEW.file_name IS DISTINCT FROM OLD.file_name
|
|
OR NEW.storage_path IS DISTINCT FROM OLD.storage_path
|
|
OR NEW.file_size_bytes IS DISTINCT FROM OLD.file_size_bytes
|
|
OR NEW.mime_type IS DISTINCT FROM OLD.mime_type
|
|
OR NEW.sha256_hash IS DISTINCT FROM OLD.sha256_hash
|
|
OR NEW.upload_source IS DISTINCT FROM OLD.upload_source
|
|
OR NEW.digitization_date IS DISTINCT FROM OLD.digitization_date
|
|
OR NEW.uploaded_by IS DISTINCT FROM OLD.uploaded_by
|
|
OR NEW.version IS DISTINCT FROM OLD.version
|
|
OR NEW.original_id IS DISTINCT FROM OLD.original_id
|
|
THEN
|
|
-- Log the blocked attempt
|
|
INSERT INTO public.audit_log (user_id, company_id, action, table_name, record_id, description)
|
|
VALUES (OLD.user_id, OLD.company_id, 'SECURITY_EVENT', 'document_attachments', OLD.id,
|
|
'Blocked metadata modification of document linked to ' || v_entry_status || ' entry ' || OLD.journal_entry_id);
|
|
|
|
RAISE EXCEPTION 'Cannot modify metadata of document linked to a % journal entry (BFL 7 kap)', v_entry_status;
|
|
END IF;
|
|
|
|
RETURN NEW;
|
|
END;
|
|
$$;
|
|
|
|
CREATE TRIGGER enforce_document_metadata_immutability
|
|
BEFORE UPDATE ON public.document_attachments
|
|
FOR EACH ROW EXECUTE FUNCTION public.enforce_document_metadata_immutability();
|