Files
accounted/app/api/reports/general-ledger/xlsx/route.ts
T
Jakob WennbergandClaude Fable 5 01dbef4015 feat(dimensions): PR4 reports — dimension-filtered P&L + Resultat per projekt/kostnadsställe (#862)
* feat(dimensions): PR4 reports — dimension-filtered P&L everywhere + Resultat per projekt/kostnadsställe

The Project P&L milestone of the dimensions plan (dev_docs §7 PR4).

One choke point lights up everything: generateTrialBalance gains
options.dimensions (SIE dim → code map) pushed down as jsonb containment
(dimensions @>, served by idx_jel_dimensions_gin) on both line queries, with
company-wide opening balances dropped when filtered (they cannot be
dimension-scoped; P&L-safe by whitelist). Resultatrapport, resultaträkning,
huvudbok, monthly-breakdown and the TB drill-down inherit the filter; the
KPI route filters only its P&L-side inputs (income statement, months,
expense composition) — never cash/VAT.

New report lib/reports/dimension-pnl.ts — "Resultat per projekt/
kostnadsställe" (Fortnox Resultatrapport projekt): value-as-column matrix
over one dimension with an explicit "(Utan dimension)" bucket computed as
the residual against the same trial-balance pass resultatrapport uses, so
every row and the Totalt column reconcile with the unfiltered
resultatrapport by construction. Registered in REPORT_CATALOG (visible only
when dimensions_enabled), slug-routed view + xlsx export.

UI: DimensionFilter (dimension + value picker, persistent "Filtrerad — ej
fullständig rapport" chip) mounts in FocusedReport for catalog entries
flagged dimensions: true; huvudbok rows show line dim codes.

Statutory exclusion pinned by TEST, not convention:
lib/reports/__tests__/dimension-statutory-guard.test.ts fails if the filter
parser leaks into balance sheet, balansrapport, kassaflöde, VAT, SIE or
full-archive routes/generators, or if the catalog whitelist widens.

MCP: new gnubok_get_dimension_pnl (reports:read); dimensions filter arg on
get_trial_balance/get_income_statement/get_general_ledger with
resolve-don't-select (names → registry codes, resolution echoes);
query_journal totals fixed to aggregate the FULL match set (was silently
slice-scoped while claiming otherwise) with an honest totals_scope field,
plus group_by / group_by_dimension aggregation.

Also: voucher-detail dim-6 badge now uses the registry name instead of the
non-standard "PR" abbreviation (#859 review follow-up).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(dimensions): address #862 review — export disclosure, prior-column suppression, period-label honesty, route hardening

- Filtered XLSX/PDF exports now carry the partial-view disclosure past the
  file boundary (BFNAR 2013:2): filename suffix (-dim6-p001), a
  "Filtrerad … — ej fullständig rapport" row on every sheet, and a header
  note/title line in the PDFs.
- Resultatrapport drops the prior-year column when a dimension filter is
  active — project codes are time-limited under K2/K3, so "this code last
  year" may be a different project (same rule as narrowed date ranges).
- dimension-pnl no longer accepts fromDate: the matrix is cumulative from
  period_start by design (closing-balance semantics), and the period label
  now states exactly that instead of echoing a lower bound that was never
  applied. Routes/MCP tool updated to toDate-only.
- dimension-pnl routes 404 on an unknown/foreign period id and cap dim_no
  to 4 digits (matching the MCP tool's PostgREST-path guard, which the
  generator now also enforces itself).
- Statutory-guard test's generateTrialBalance call-site scan is paren-aware
  instead of a 300-char window; added fully-untagged and injection-guard
  test cases.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 15:20:47 +02:00

171 lines
5.2 KiB
TypeScript

import { createClient } from '@/lib/supabase/server'
import { NextResponse } from 'next/server'
import { generateGeneralLedger } from '@/lib/reports/general-ledger'
import { requireCompanyId } from '@/lib/company/context'
import { parseDimensionFilterParams, dimensionFilterDisclosure, dimensionFilterFileSuffix } from '@/lib/reports/dimension-filter'
import {
reportToWorkbook,
textColumn,
currencyColumn,
dateColumn,
xlsxFilename,
} from '@/lib/reports/xlsx-export'
interface FlatRow {
account_number: string
account_name: string
date: Date | string
voucher: string
description: string
source_type: string
debit: number
credit: number
balance: number
}
function toDate(s: string): Date | string {
// Preserve original ISO string in the cell if parsing fails (avoids NaN
// dates polluting the workbook).
const d = new Date(s)
return isNaN(d.getTime()) ? s : d
}
export async function GET(request: Request) {
const supabase = await createClient()
const { data: { user } } = await supabase.auth.getUser()
if (!user) {
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
}
const companyId = await requireCompanyId(supabase, user.id)
const { searchParams } = new URL(request.url)
const periodId = searchParams.get('period_id')
const accountFrom = searchParams.get('account_from') || undefined
const accountTo = searchParams.get('account_to') || undefined
if (!periodId) {
return NextResponse.json({ error: 'period_id is required' }, { status: 400 })
}
const { data: companyRow } = await supabase
.from('company_settings')
.select('company_name')
.eq('company_id', companyId)
.single()
const dimFilter = parseDimensionFilterParams(searchParams)
if (!dimFilter.ok) {
return NextResponse.json({ error: dimFilter.error }, { status: 400 })
}
try {
const report = await generateGeneralLedger(supabase, companyId, periodId, accountFrom, accountTo, {
dimensions: dimFilter.dimensions,
})
// Flatten accounts + their lines into a single sheet. Each account contributes
// an opening-balance row, its lines (with running balance), and a closing
// row — matching how huvudbok is read in Fortnox/Visma.
const rows: FlatRow[] = []
for (const acc of report.accounts) {
rows.push({
account_number: acc.account_number,
account_name: acc.account_name,
date: '',
voucher: '',
description: 'Ingående balans',
source_type: '',
debit: 0,
credit: 0,
balance: acc.opening_balance,
})
for (const line of acc.lines) {
rows.push({
account_number: acc.account_number,
account_name: acc.account_name,
date: toDate(line.date),
voucher: `${line.voucher_series}${line.voucher_number}`,
description: line.description,
source_type: line.source_type,
debit: line.debit,
credit: line.credit,
balance: line.balance,
})
}
rows.push({
account_number: acc.account_number,
account_name: acc.account_name,
date: '',
voucher: '',
description: 'Utgående balans',
source_type: '',
debit: acc.total_debit,
credit: acc.total_credit,
balance: acc.closing_balance,
})
}
// Partial-view disclosure: a filtered huvudbok starts balance accounts
// at zero IB (opening balances cannot be dimension-scoped) — the export
// must say so or a project-filtered ledger reads as a full one.
const disclosure = dimensionFilterDisclosure(dimFilter.dimensions)
if (disclosure) {
rows.unshift({
account_number: disclosure,
account_name: '',
date: null as unknown as Date,
voucher: '',
description: 'Ingående balanser ingår inte i filtrerad vy',
source_type: '',
debit: null as unknown as number,
credit: null as unknown as number,
balance: null as unknown as number,
})
}
const buffer = reportToWorkbook<FlatRow>([
{
name: 'Huvudbok',
columns: [
textColumn('Konto'),
textColumn('Kontonamn'),
dateColumn('Datum'),
textColumn('Verifikat'),
textColumn('Beskrivning'),
textColumn('Källa'),
currencyColumn('Debet'),
currencyColumn('Kredit'),
currencyColumn('Saldo'),
],
rows,
mapRow: (r) => [
r.account_number,
r.account_name,
r.date instanceof Date ? r.date : null,
r.voucher,
r.description,
r.source_type,
r.debit,
r.credit,
r.balance,
],
},
])
const filename = xlsxFilename(`huvudbok${dimensionFilterFileSuffix(dimFilter.dimensions)}`, companyRow?.company_name ?? '', report.period.end)
return new NextResponse(new Uint8Array(buffer), {
headers: {
'Content-Type': 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet',
'Content-Disposition': `attachment; filename="${filename}"`,
},
})
} catch (err) {
return NextResponse.json(
{ error: err instanceof Error ? err.message : 'Kunde inte generera huvudbok' },
{ status: 500 }
)
}
}