* fix(enable-banking): pin Mobile BankID (decoupled) auth_method so Handelsbanken corporate connects We never sent auth_method to Enable Banking, so it fell back to the ASPSP's visible default — REDIRECT for Handelsbanken. For Handelsbanken *corporate* PSUs the redirect flow does not support Mobile BankID, so authorization failed right after the user approved in the BankID app. Mobile BankID at Handelsbanken is a DECOUPLED method flagged hidden_method=true, which Enable Banking only uses when requested explicitly. Resolve the bank's preferred auth method before /auth: query the ASPSP's auth_methods and pick the DECOUPLED (Mobile BankID) method when present, otherwise leave auth_method unset so banks that already work are untouched. The method name is read dynamically per psu_type, so it is robust across sandbox/production naming. - api-client: add approach/hidden_method to AuthMethod, fix ASPSP.auth_methods field name (was available_auth_methods, never populated), add getPreferredAuthMethod(), thread optional authMethod through startAuthorization - index: resolve authMethod in /connect and pass it on both fresh + reconnect - tests: cover method selection and request-body shaping Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * refactor(invoice-inbox): clean up bulk-selection toolbar UI Redesign the selection toolbar shown when inbox items are checked: one solid primary "Bokför valda" button with outlined secondary actions ("Fråga assistenten", "Ta bort") and a plain selection count. Removes the redundant "Avmarkera" button (users uncheck the still-visible box), fixes label clipping, and gives the toolbar more breathing room. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore(entitlements): bypass paywall in local development Add isPaywallBypassed() so all gated capabilities are testable locally without a subscription. Fires only on NODE_ENV=development (npm run dev) or an explicit DISABLE_PAYWALL=true escape hatch — production builds run under NODE_ENV=production and the entitlement suite runs under 'test', so both keep exercising the real gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(tic): resolve enskild firma bolagsuppgifter via 12-digit personnummer TIC's Lens search is fuzzy and only resolves an enskild firma from the 12-digit (century-prefixed) personnummer; a 10-digit form fuzzy-matched an unrelated entity. Expand personnummer to 12 digits before querying and reject hits whose registration number is unrelated to the request. Add a "Hämta" action to the settings Bolagsuppgifter panel to (re)fetch on demand. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(transactions): implement categorize core for bank transaction categorization - Added `categorize-core.ts` to handle categorization of bank transactions, supporting single and bulk operations. - Introduced `categorizeMatchedTransaction` and `bulkBookMatchedInboxItems` functions for transaction processing. - Implemented fiscal period validation and duplicate booking detection. - Enhanced logging and error handling for transaction categorization. feat(scripts): add diagnostic script for Handelsbanken ASPSP metadata - Created `check-handelsbanken-aspsp.mjs` to fetch and display available authentication methods for Handelsbanken. - Outputs metadata for business and personal PSU types, including default authentication methods. fix(migrations): increase statement timeout for SIE bulk delete operations - Updated `20260629160000_sie_bulk_delete_statement_timeout.sql` to set a longer statement timeout for bulk delete RPCs to prevent cancellations during large imports. feat(migrations): add bulk book inbox items to pending operations - Expanded `pending_operations` table to include `bulk_book_inbox_items` operation type in `20260630120000_pending_operations_add_bulk_book_inbox_items.sql`. - Supports bulk booking of matched inbox items against bank transactions. test(pg): add tests for replace_period_opening_balance_link RPC - Implemented tests in `replace-period-opening-balance-link.pg.test.ts` to validate the functionality of the opening-balance correction flow. - Ensured immutability of opening balance links and proper handling of posted vs. non-posted entries. * fix(sie-export): update journal entries and lines handling in SIE export tests * fix(migrations): resolve version collision on 20260629160000 The SIE bulk-delete statement_timeout migration shared version 20260629160000 with journal_entries_list_series_filter (merged from main via #798/#823), causing a schema_migrations_pkey duplicate key error on apply. Rename the branch's migration to 20260629160100. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(compliance): resolve compliance-swarm + review findings - opening-balance/correct: compensating rollback for the non-atomic storno+rebook so a mid-sequence failure never leaves two posted OB entries (ASVS V2.3); durable audit event on every failure path (V16); reference the original verifikationsnummer in the corrected entry per BFL 5 kap 5§; document that requireWrite already enforces write-role + membership (V8.2.1 was a false positive) - reports sources routes: validate the cursor date component as ISO (/^\d{4}-\d{2}-\d{2}$/) before use, 400 on malformed (ASVS V1.2), applied to both the VAT-declaration and trial-balance routes - AgentSessionList: await the rename PATCH, revert the optimistic title and toast on failure (ASVS V4.5) - bank booking: exclude same-batch siblings from the booking-time duplicate guard so bulk-booking distinct same-(date,amount) transactions no longer false-positives; pre-existing duplicate detection is preserved - BulkBookInboxDialog: drop the unsafe currency-based reverse_charge default, add an omvänd skattskyldighet advisory, and type VAT options to the backend VatTreatment union - OpeningBalanceRowEditor: hold onChange in a ref (synced in effect, not during render) so an unstable callback can't cause a render loop Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
111 lines
3.2 KiB
Plaintext
111 lines
3.2 KiB
Plaintext
# See https://help.github.com/articles/ignoring-files/ for more about ignoring files.
|
|
|
|
# dependencies
|
|
/node_modules
|
|
/.pnp
|
|
.pnp.*
|
|
.yarn/*
|
|
!.yarn/patches
|
|
!.yarn/plugins
|
|
!.yarn/releases
|
|
!.yarn/versions
|
|
|
|
# testing
|
|
/coverage
|
|
|
|
# next.js
|
|
/.next/
|
|
/out/
|
|
|
|
# production
|
|
/build
|
|
|
|
# misc
|
|
.DS_Store
|
|
*.pem
|
|
nul
|
|
|
|
# debug
|
|
npm-debug.log*
|
|
yarn-debug.log*
|
|
yarn-error.log*
|
|
.pnpm-debug.log*
|
|
|
|
# env files (can opt-in for committing if needed)
|
|
.env*
|
|
!.env.example
|
|
!.env.docker.example
|
|
|
|
# vercel
|
|
.vercel
|
|
|
|
# typescript
|
|
*.tsbuildinfo
|
|
next-env.d.ts
|
|
|
|
# supabase temp files
|
|
supabase/.temp/
|
|
|
|
# claude local settings
|
|
.claude/settings.local.json
|
|
.claude/scheduled_tasks.lock
|
|
|
|
# swarm audit reports (generated by /swarm)
|
|
.swarm/
|
|
|
|
# compliance scan output (SARIF / dossier / PR comment)
|
|
.compliance-reports/
|
|
|
|
# generated service worker (built from public/sw.template.js by
|
|
# scripts/inject-public-branding.mjs — runs via predev/prebuild)
|
|
/public/sw.js
|
|
|
|
# dev docs (internal reference, not published) — EXCEPT the iXBRL taxonomy
|
|
# sources and the official Bolagsverket example, which CI needs: the committed
|
|
# lib/bokslut/ixbrl/taxonomy/generated/ registry is regenerated from them by
|
|
# `npm run taxonomy:check` (core-build.yml) and the golden test pins against
|
|
# the example document.
|
|
/dev_docs/*
|
|
!/dev_docs/bokslut/
|
|
/dev_docs/bokslut/*
|
|
!/dev_docs/bokslut/taxonomi/
|
|
/dev_docs/bokslut/taxonomi/*
|
|
!/dev_docs/bokslut/taxonomi/taxonomi-paket-2024-09-12_rev20250312.zip
|
|
!/dev_docs/bokslut/taxonomi/dokumentation/
|
|
/dev_docs/bokslut/taxonomi/dokumentation/*
|
|
!/dev_docs/bokslut/taxonomi/dokumentation/k2-ab-arsredovisning-elementlista-2024-09-12_rev20250312_sv.xlsx
|
|
!/dev_docs/bokslut/taxonomi/dokumentation/tuple-innehallsmodell-arsredovisning-k2-2024-09-12.xlsx
|
|
!/dev_docs/bokslut/exempel/
|
|
/dev_docs/bokslut/exempel/*
|
|
!/dev_docs/bokslut/exempel/k2/
|
|
/dev_docs/bokslut/exempel/k2/*
|
|
!/dev_docs/bokslut/exempel/k2/faststalld-arsredovisning-exempel-1-rev20240214.xhtml
|
|
|
|
# Extension registry (auto-generated but defaults are committed)
|
|
# Run `npm run setup:extensions` to regenerate after changing extensions.config.json
|
|
# The empty defaults in lib/extensions/_generated/ are committed so core compiles
|
|
# out of the box without running the generator.
|
|
supabase/.branches/
|
|
|
|
# Local-only SIE test fixtures — may contain real/scrubbed company data, never commit
|
|
tests/fixtures/sie/
|
|
|
|
# Local-only DESTRUCTIVE duplicate-cleanup tooling — one-off, run by hand against
|
|
# real räkenskapsinformation. Deliberately NOT committed so it can never run in
|
|
# CI/cron and so its logic isn't mistaken for a supported product feature.
|
|
scripts/delete-duplicate-transactions.ts
|
|
|
|
# Diagnostic/cleanup tooling under /scripts is tracked, but the DATA those
|
|
# scripts read or emit (ledger dumps, reconciliation exports) is real customer
|
|
# räkenskapsinformation — never commit it. Keep the .ts/.sql tooling, ignore the data.
|
|
scripts/*.csv
|
|
|
|
# Local-only DESTRUCTIVE support tool — reopens a closed räkenskapsår by deleting
|
|
# only its bokslut layer (dispositioner + closing entry + next-year IB). Run by
|
|
# hand against real räkenskapsinformation; bypasses BFL immutability triggers, so
|
|
# it must never live in the repo / CI / cron.
|
|
scripts/reopen-bokslut.sql
|
|
|
|
.claude/plans/write-up-a-plan-streamed-fiddle.md
|
|
/ingaende-balanser-test.csv
|