* feat(dimensions): PR4 reports — dimension-filtered P&L everywhere + Resultat per projekt/kostnadsställe The Project P&L milestone of the dimensions plan (dev_docs §7 PR4). One choke point lights up everything: generateTrialBalance gains options.dimensions (SIE dim → code map) pushed down as jsonb containment (dimensions @>, served by idx_jel_dimensions_gin) on both line queries, with company-wide opening balances dropped when filtered (they cannot be dimension-scoped; P&L-safe by whitelist). Resultatrapport, resultaträkning, huvudbok, monthly-breakdown and the TB drill-down inherit the filter; the KPI route filters only its P&L-side inputs (income statement, months, expense composition) — never cash/VAT. New report lib/reports/dimension-pnl.ts — "Resultat per projekt/ kostnadsställe" (Fortnox Resultatrapport projekt): value-as-column matrix over one dimension with an explicit "(Utan dimension)" bucket computed as the residual against the same trial-balance pass resultatrapport uses, so every row and the Totalt column reconcile with the unfiltered resultatrapport by construction. Registered in REPORT_CATALOG (visible only when dimensions_enabled), slug-routed view + xlsx export. UI: DimensionFilter (dimension + value picker, persistent "Filtrerad — ej fullständig rapport" chip) mounts in FocusedReport for catalog entries flagged dimensions: true; huvudbok rows show line dim codes. Statutory exclusion pinned by TEST, not convention: lib/reports/__tests__/dimension-statutory-guard.test.ts fails if the filter parser leaks into balance sheet, balansrapport, kassaflöde, VAT, SIE or full-archive routes/generators, or if the catalog whitelist widens. MCP: new gnubok_get_dimension_pnl (reports:read); dimensions filter arg on get_trial_balance/get_income_statement/get_general_ledger with resolve-don't-select (names → registry codes, resolution echoes); query_journal totals fixed to aggregate the FULL match set (was silently slice-scoped while claiming otherwise) with an honest totals_scope field, plus group_by / group_by_dimension aggregation. Also: voucher-detail dim-6 badge now uses the registry name instead of the non-standard "PR" abbreviation (#859 review follow-up). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(dimensions): address #862 review — export disclosure, prior-column suppression, period-label honesty, route hardening - Filtered XLSX/PDF exports now carry the partial-view disclosure past the file boundary (BFNAR 2013:2): filename suffix (-dim6-p001), a "Filtrerad … — ej fullständig rapport" row on every sheet, and a header note/title line in the PDFs. - Resultatrapport drops the prior-year column when a dimension filter is active — project codes are time-limited under K2/K3, so "this code last year" may be a different project (same rule as narrowed date ranges). - dimension-pnl no longer accepts fromDate: the matrix is cumulative from period_start by design (closing-balance semantics), and the period label now states exactly that instead of echoing a lower bound that was never applied. Routes/MCP tool updated to toDate-only. - dimension-pnl routes 404 on an unknown/foreign period id and cap dim_no to 4 digits (matching the MCP tool's PostgREST-path guard, which the generator now also enforces itself). - Statutory-guard test's generateTrialBalance call-site scan is paren-aware instead of a 300-char window; added fully-untagged and injection-guard test cases. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
124 lines
5.1 KiB
TypeScript
124 lines
5.1 KiB
TypeScript
import { describe, it, expect } from 'vitest'
|
|
import { readFileSync, readdirSync, statSync } from 'node:fs'
|
|
import { join } from 'node:path'
|
|
import { REPORT_CATALOG, DIMENSION_FILTER_SLUGS } from '../catalog'
|
|
|
|
// ============================================================
|
|
// Statutory exclusion guard (dimensions PR4).
|
|
//
|
|
// A dimension-filtered statutory output is a WRONG output: a filtered
|
|
// balance sheet doesn't balance, a filtered VAT declaration under-reports,
|
|
// a filtered SIE export is not the company's bokföring. The whitelist of
|
|
// filterable reports is therefore pinned by TEST, not by convention — this
|
|
// suite fails when the filter leaks into a statutory report route or
|
|
// generator, or when someone widens the catalog whitelist without touching
|
|
// this file.
|
|
// ============================================================
|
|
|
|
const ROOT = process.cwd()
|
|
|
|
/** The only reports allowed to accept the dimension value filter. */
|
|
const FILTERABLE_SLUGS = ['resultatrapport', 'income-statement', 'huvudbok', 'kpi']
|
|
|
|
/** Routes allowed to import the route-side filter parser. */
|
|
const ALLOWED_PARSER_IMPORTERS = new Set([
|
|
'app/api/reports/resultatrapport/route.ts',
|
|
'app/api/reports/resultatrapport/xlsx/route.ts',
|
|
'app/api/reports/resultatrapport/pdf/route.ts',
|
|
'app/api/reports/income-statement/route.ts',
|
|
'app/api/reports/income-statement/xlsx/route.ts',
|
|
'app/api/reports/income-statement/pdf/route.ts',
|
|
'app/api/reports/general-ledger/route.ts',
|
|
'app/api/reports/general-ledger/xlsx/route.ts',
|
|
'app/api/reports/kpi/route.ts',
|
|
'app/api/reports/monthly-breakdown/route.ts',
|
|
'app/api/reports/trial-balance/account/[accountNumber]/sources/route.ts',
|
|
])
|
|
|
|
/** Statutory generators that must never gain a containment filter. */
|
|
const STATUTORY_GENERATORS = [
|
|
'lib/reports/balance-sheet.ts',
|
|
'lib/reports/balansrapport.ts',
|
|
'lib/reports/kassaflodesanalys.ts',
|
|
'lib/reports/vat-declaration.ts',
|
|
'lib/reports/sie-export.ts',
|
|
'lib/reports/full-archive-export.ts',
|
|
]
|
|
|
|
function walk(dir: string, out: string[] = []): string[] {
|
|
for (const entry of readdirSync(dir)) {
|
|
const full = join(dir, entry)
|
|
if (statSync(full).isDirectory()) walk(full, out)
|
|
else if (full.endsWith('.ts') || full.endsWith('.tsx')) out.push(full)
|
|
}
|
|
return out
|
|
}
|
|
|
|
describe('dimension filter — statutory exclusion', () => {
|
|
it('the catalog whitelist is exactly the four P&L-safe reports', () => {
|
|
const flagged = REPORT_CATALOG.filter((r) => r.dimensions).map((r) => r.slug).sort()
|
|
expect(flagged).toEqual([...FILTERABLE_SLUGS].sort())
|
|
expect([...DIMENSION_FILTER_SLUGS].sort()).toEqual([...FILTERABLE_SLUGS].sort())
|
|
})
|
|
|
|
it('the dimension-pnl report is gated on dimensions being enabled, never entity/employees', () => {
|
|
const entry = REPORT_CATALOG.find((r) => r.slug === 'dimension-pnl')
|
|
expect(entry).toBeDefined()
|
|
expect(entry?.needsDimensions).toBe(true)
|
|
// Free tier for everyone (founder decision 2026-07-02) — no other gate.
|
|
expect(entry?.entityType).toBeUndefined()
|
|
expect(entry?.needsEmployees).toBeUndefined()
|
|
})
|
|
|
|
it('no statutory report route imports the dimension filter parser', () => {
|
|
const reportRoutes = walk(join(ROOT, 'app/api/reports'))
|
|
const importers = reportRoutes
|
|
.filter((f) => readFileSync(f, 'utf8').includes('lib/reports/dimension-filter'))
|
|
.map((f) => f.slice(ROOT.length + 1))
|
|
.sort()
|
|
|
|
// Exactly the P&L-safe routes — nothing more (statutory leak), nothing
|
|
// less (a whitelisted route silently dropping the filter would show an
|
|
// unfiltered report under a "Filtrerad" chip).
|
|
expect(importers).toEqual([...ALLOWED_PARSER_IMPORTERS].sort())
|
|
})
|
|
|
|
it('statutory generators never apply a dimensions containment filter', () => {
|
|
for (const rel of STATUTORY_GENERATORS) {
|
|
const src = readFileSync(join(ROOT, rel), 'utf8')
|
|
expect(src, `${rel} must not filter on line dimensions`).not.toMatch(
|
|
/contains\(\s*['"]dimensions['"]/,
|
|
)
|
|
expect(src, `${rel} must not accept a dimensionFilter/dimensions option`).not.toMatch(
|
|
/dimensionFilter|options\?\.dimensions/,
|
|
)
|
|
}
|
|
})
|
|
|
|
it('statutory generators do not receive dimensions through generateTrialBalance', () => {
|
|
// They may call generateTrialBalance, but never with a dimensions option.
|
|
// The scan is paren-aware (walks to the call's closing paren), not a
|
|
// fixed character window — a long options object cannot slip the key
|
|
// past the guard (#862 review).
|
|
for (const rel of STATUTORY_GENERATORS) {
|
|
const src = readFileSync(join(ROOT, rel), 'utf8')
|
|
let idx = src.indexOf('generateTrialBalance(')
|
|
while (idx !== -1) {
|
|
const argsStart = idx + 'generateTrialBalance('.length
|
|
let depth = 1
|
|
let end = argsStart
|
|
while (end < src.length && depth > 0) {
|
|
if (src[end] === '(') depth++
|
|
else if (src[end] === ')') depth--
|
|
end++
|
|
}
|
|
const argList = src.slice(argsStart, end)
|
|
expect(argList, `${rel} passes dimensions to generateTrialBalance`).not.toContain(
|
|
'dimensions',
|
|
)
|
|
idx = src.indexOf('generateTrialBalance(', end)
|
|
}
|
|
}
|
|
})
|
|
})
|