Files
accounted/lib/reports/__tests__/dimension-statutory-guard.test.ts
T
Jakob WennbergandClaude Fable 5 01dbef4015 feat(dimensions): PR4 reports — dimension-filtered P&L + Resultat per projekt/kostnadsställe (#862)
* feat(dimensions): PR4 reports — dimension-filtered P&L everywhere + Resultat per projekt/kostnadsställe

The Project P&L milestone of the dimensions plan (dev_docs §7 PR4).

One choke point lights up everything: generateTrialBalance gains
options.dimensions (SIE dim → code map) pushed down as jsonb containment
(dimensions @>, served by idx_jel_dimensions_gin) on both line queries, with
company-wide opening balances dropped when filtered (they cannot be
dimension-scoped; P&L-safe by whitelist). Resultatrapport, resultaträkning,
huvudbok, monthly-breakdown and the TB drill-down inherit the filter; the
KPI route filters only its P&L-side inputs (income statement, months,
expense composition) — never cash/VAT.

New report lib/reports/dimension-pnl.ts — "Resultat per projekt/
kostnadsställe" (Fortnox Resultatrapport projekt): value-as-column matrix
over one dimension with an explicit "(Utan dimension)" bucket computed as
the residual against the same trial-balance pass resultatrapport uses, so
every row and the Totalt column reconcile with the unfiltered
resultatrapport by construction. Registered in REPORT_CATALOG (visible only
when dimensions_enabled), slug-routed view + xlsx export.

UI: DimensionFilter (dimension + value picker, persistent "Filtrerad — ej
fullständig rapport" chip) mounts in FocusedReport for catalog entries
flagged dimensions: true; huvudbok rows show line dim codes.

Statutory exclusion pinned by TEST, not convention:
lib/reports/__tests__/dimension-statutory-guard.test.ts fails if the filter
parser leaks into balance sheet, balansrapport, kassaflöde, VAT, SIE or
full-archive routes/generators, or if the catalog whitelist widens.

MCP: new gnubok_get_dimension_pnl (reports:read); dimensions filter arg on
get_trial_balance/get_income_statement/get_general_ledger with
resolve-don't-select (names → registry codes, resolution echoes);
query_journal totals fixed to aggregate the FULL match set (was silently
slice-scoped while claiming otherwise) with an honest totals_scope field,
plus group_by / group_by_dimension aggregation.

Also: voucher-detail dim-6 badge now uses the registry name instead of the
non-standard "PR" abbreviation (#859 review follow-up).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(dimensions): address #862 review — export disclosure, prior-column suppression, period-label honesty, route hardening

- Filtered XLSX/PDF exports now carry the partial-view disclosure past the
  file boundary (BFNAR 2013:2): filename suffix (-dim6-p001), a
  "Filtrerad … — ej fullständig rapport" row on every sheet, and a header
  note/title line in the PDFs.
- Resultatrapport drops the prior-year column when a dimension filter is
  active — project codes are time-limited under K2/K3, so "this code last
  year" may be a different project (same rule as narrowed date ranges).
- dimension-pnl no longer accepts fromDate: the matrix is cumulative from
  period_start by design (closing-balance semantics), and the period label
  now states exactly that instead of echoing a lower bound that was never
  applied. Routes/MCP tool updated to toDate-only.
- dimension-pnl routes 404 on an unknown/foreign period id and cap dim_no
  to 4 digits (matching the MCP tool's PostgREST-path guard, which the
  generator now also enforces itself).
- Statutory-guard test's generateTrialBalance call-site scan is paren-aware
  instead of a 300-char window; added fully-untagged and injection-guard
  test cases.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 15:20:47 +02:00

124 lines
5.1 KiB
TypeScript

import { describe, it, expect } from 'vitest'
import { readFileSync, readdirSync, statSync } from 'node:fs'
import { join } from 'node:path'
import { REPORT_CATALOG, DIMENSION_FILTER_SLUGS } from '../catalog'
// ============================================================
// Statutory exclusion guard (dimensions PR4).
//
// A dimension-filtered statutory output is a WRONG output: a filtered
// balance sheet doesn't balance, a filtered VAT declaration under-reports,
// a filtered SIE export is not the company's bokföring. The whitelist of
// filterable reports is therefore pinned by TEST, not by convention — this
// suite fails when the filter leaks into a statutory report route or
// generator, or when someone widens the catalog whitelist without touching
// this file.
// ============================================================
const ROOT = process.cwd()
/** The only reports allowed to accept the dimension value filter. */
const FILTERABLE_SLUGS = ['resultatrapport', 'income-statement', 'huvudbok', 'kpi']
/** Routes allowed to import the route-side filter parser. */
const ALLOWED_PARSER_IMPORTERS = new Set([
'app/api/reports/resultatrapport/route.ts',
'app/api/reports/resultatrapport/xlsx/route.ts',
'app/api/reports/resultatrapport/pdf/route.ts',
'app/api/reports/income-statement/route.ts',
'app/api/reports/income-statement/xlsx/route.ts',
'app/api/reports/income-statement/pdf/route.ts',
'app/api/reports/general-ledger/route.ts',
'app/api/reports/general-ledger/xlsx/route.ts',
'app/api/reports/kpi/route.ts',
'app/api/reports/monthly-breakdown/route.ts',
'app/api/reports/trial-balance/account/[accountNumber]/sources/route.ts',
])
/** Statutory generators that must never gain a containment filter. */
const STATUTORY_GENERATORS = [
'lib/reports/balance-sheet.ts',
'lib/reports/balansrapport.ts',
'lib/reports/kassaflodesanalys.ts',
'lib/reports/vat-declaration.ts',
'lib/reports/sie-export.ts',
'lib/reports/full-archive-export.ts',
]
function walk(dir: string, out: string[] = []): string[] {
for (const entry of readdirSync(dir)) {
const full = join(dir, entry)
if (statSync(full).isDirectory()) walk(full, out)
else if (full.endsWith('.ts') || full.endsWith('.tsx')) out.push(full)
}
return out
}
describe('dimension filter — statutory exclusion', () => {
it('the catalog whitelist is exactly the four P&L-safe reports', () => {
const flagged = REPORT_CATALOG.filter((r) => r.dimensions).map((r) => r.slug).sort()
expect(flagged).toEqual([...FILTERABLE_SLUGS].sort())
expect([...DIMENSION_FILTER_SLUGS].sort()).toEqual([...FILTERABLE_SLUGS].sort())
})
it('the dimension-pnl report is gated on dimensions being enabled, never entity/employees', () => {
const entry = REPORT_CATALOG.find((r) => r.slug === 'dimension-pnl')
expect(entry).toBeDefined()
expect(entry?.needsDimensions).toBe(true)
// Free tier for everyone (founder decision 2026-07-02) — no other gate.
expect(entry?.entityType).toBeUndefined()
expect(entry?.needsEmployees).toBeUndefined()
})
it('no statutory report route imports the dimension filter parser', () => {
const reportRoutes = walk(join(ROOT, 'app/api/reports'))
const importers = reportRoutes
.filter((f) => readFileSync(f, 'utf8').includes('lib/reports/dimension-filter'))
.map((f) => f.slice(ROOT.length + 1))
.sort()
// Exactly the P&L-safe routes — nothing more (statutory leak), nothing
// less (a whitelisted route silently dropping the filter would show an
// unfiltered report under a "Filtrerad" chip).
expect(importers).toEqual([...ALLOWED_PARSER_IMPORTERS].sort())
})
it('statutory generators never apply a dimensions containment filter', () => {
for (const rel of STATUTORY_GENERATORS) {
const src = readFileSync(join(ROOT, rel), 'utf8')
expect(src, `${rel} must not filter on line dimensions`).not.toMatch(
/contains\(\s*['"]dimensions['"]/,
)
expect(src, `${rel} must not accept a dimensionFilter/dimensions option`).not.toMatch(
/dimensionFilter|options\?\.dimensions/,
)
}
})
it('statutory generators do not receive dimensions through generateTrialBalance', () => {
// They may call generateTrialBalance, but never with a dimensions option.
// The scan is paren-aware (walks to the call's closing paren), not a
// fixed character window — a long options object cannot slip the key
// past the guard (#862 review).
for (const rel of STATUTORY_GENERATORS) {
const src = readFileSync(join(ROOT, rel), 'utf8')
let idx = src.indexOf('generateTrialBalance(')
while (idx !== -1) {
const argsStart = idx + 'generateTrialBalance('.length
let depth = 1
let end = argsStart
while (end < src.length && depth > 0) {
if (src[end] === '(') depth++
else if (src[end] === ')') depth--
end++
}
const argList = src.slice(argsStart, end)
expect(argList, `${rel} passes dimensions to generateTrialBalance`).not.toContain(
'dimensions',
)
idx = src.indexOf('generateTrialBalance(', end)
}
}
})
})