Files
accounted/lib/company/tic-refresh.ts
T
MattssonandClaude Opus 4.8 f63d3e3100 Bug/open banking flow (#854)
* fix(enable-banking): pin Mobile BankID (decoupled) auth_method so Handelsbanken corporate connects

We never sent auth_method to Enable Banking, so it fell back to the ASPSP's
visible default — REDIRECT for Handelsbanken. For Handelsbanken *corporate*
PSUs the redirect flow does not support Mobile BankID, so authorization failed
right after the user approved in the BankID app. Mobile BankID at Handelsbanken
is a DECOUPLED method flagged hidden_method=true, which Enable Banking only uses
when requested explicitly.

Resolve the bank's preferred auth method before /auth: query the ASPSP's
auth_methods and pick the DECOUPLED (Mobile BankID) method when present,
otherwise leave auth_method unset so banks that already work are untouched.
The method name is read dynamically per psu_type, so it is robust across
sandbox/production naming.

- api-client: add approach/hidden_method to AuthMethod, fix ASPSP.auth_methods
  field name (was available_auth_methods, never populated), add
  getPreferredAuthMethod(), thread optional authMethod through startAuthorization
- index: resolve authMethod in /connect and pass it on both fresh + reconnect
- tests: cover method selection and request-body shaping

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* refactor(invoice-inbox): clean up bulk-selection toolbar UI

Redesign the selection toolbar shown when inbox items are checked:
one solid primary "Bokför valda" button with outlined secondary
actions ("Fråga assistenten", "Ta bort") and a plain selection
count. Removes the redundant "Avmarkera" button (users uncheck the
still-visible box), fixes label clipping, and gives the toolbar more
breathing room.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore(entitlements): bypass paywall in local development

Add isPaywallBypassed() so all gated capabilities are testable locally
without a subscription. Fires only on NODE_ENV=development (npm run dev)
or an explicit DISABLE_PAYWALL=true escape hatch — production builds run
under NODE_ENV=production and the entitlement suite runs under 'test',
so both keep exercising the real gate.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(tic): resolve enskild firma bolagsuppgifter via 12-digit personnummer

TIC's Lens search is fuzzy and only resolves an enskild firma from the 12-digit (century-prefixed) personnummer; a 10-digit form fuzzy-matched an unrelated entity. Expand personnummer to 12 digits before querying and reject hits whose registration number is unrelated to the request. Add a "Hämta" action to the settings Bolagsuppgifter panel to (re)fetch on demand.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(transactions): implement categorize core for bank transaction categorization

- Added `categorize-core.ts` to handle categorization of bank transactions, supporting single and bulk operations.
- Introduced `categorizeMatchedTransaction` and `bulkBookMatchedInboxItems` functions for transaction processing.
- Implemented fiscal period validation and duplicate booking detection.
- Enhanced logging and error handling for transaction categorization.

feat(scripts): add diagnostic script for Handelsbanken ASPSP metadata

- Created `check-handelsbanken-aspsp.mjs` to fetch and display available authentication methods for Handelsbanken.
- Outputs metadata for business and personal PSU types, including default authentication methods.

fix(migrations): increase statement timeout for SIE bulk delete operations

- Updated `20260629160000_sie_bulk_delete_statement_timeout.sql` to set a longer statement timeout for bulk delete RPCs to prevent cancellations during large imports.

feat(migrations): add bulk book inbox items to pending operations

- Expanded `pending_operations` table to include `bulk_book_inbox_items` operation type in `20260630120000_pending_operations_add_bulk_book_inbox_items.sql`.
- Supports bulk booking of matched inbox items against bank transactions.

test(pg): add tests for replace_period_opening_balance_link RPC

- Implemented tests in `replace-period-opening-balance-link.pg.test.ts` to validate the functionality of the opening-balance correction flow.
- Ensured immutability of opening balance links and proper handling of posted vs. non-posted entries.

* fix(sie-export): update journal entries and lines handling in SIE export tests

* fix(migrations): resolve version collision on 20260629160000

The SIE bulk-delete statement_timeout migration shared version
20260629160000 with journal_entries_list_series_filter (merged from
main via #798/#823), causing a schema_migrations_pkey duplicate key
error on apply. Rename the branch's migration to 20260629160100.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(compliance): resolve compliance-swarm + review findings

- opening-balance/correct: compensating rollback for the non-atomic
  storno+rebook so a mid-sequence failure never leaves two posted OB
  entries (ASVS V2.3); durable audit event on every failure path
  (V16); reference the original verifikationsnummer in the corrected
  entry per BFL 5 kap 5§; document that requireWrite already enforces
  write-role + membership (V8.2.1 was a false positive)
- reports sources routes: validate the cursor date component as ISO
  (/^\d{4}-\d{2}-\d{2}$/) before use, 400 on malformed (ASVS V1.2),
  applied to both the VAT-declaration and trial-balance routes
- AgentSessionList: await the rename PATCH, revert the optimistic
  title and toast on failure (ASVS V4.5)
- bank booking: exclude same-batch siblings from the booking-time
  duplicate guard so bulk-booking distinct same-(date,amount)
  transactions no longer false-positives; pre-existing duplicate
  detection is preserved
- BulkBookInboxDialog: drop the unsafe currency-based reverse_charge
  default, add an omvänd skattskyldighet advisory, and type VAT
  options to the backend VatTreatment union
- OpeningBalanceRowEditor: hold onChange in a ref (synced in effect,
  not during render) so an unstable callback can't cause a render loop

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 18:13:00 +02:00

89 lines
3.6 KiB
TypeScript

'use server'
import { cookies, headers } from 'next/headers'
import { revalidatePath } from 'next/cache'
import { createClient } from '@/lib/supabase/server'
import { normalizeOrgNumber } from '@/lib/company-lookup/normalize-org-number'
import { ensureTicSnapshot } from '@/lib/agent/composer/tic-fetch'
export interface RefreshCompanyProfileResult {
ok?: true
snapshot?: Record<string, unknown> | null
fetchedAt?: string
// Error *codes*, translated by the caller (same pattern as company/actions.ts):
// unauthorized | org_number_invalid | persist_failed | not_found
error?: string
}
/**
* Fetch Bolagsuppgifter on demand from the settings → Företag panel.
*
* The panel normally shows the cached `companies.tic_snapshot`. This action
* lets the user (re)fetch it live by submitting an org number / personnummer —
* the path that recovers a company whose cached snapshot is missing or wrong
* (e.g. an enskild firma whose 10-digit personnummer previously fuzzy-matched
* the wrong entity; `searchCompanyByOrgNumber` now expands it to the 12-digit
* form so Lens resolves it exactly).
*
* We persist the (normalized) number and clear `tic_snapshot_fetched_at` to
* force `ensureTicSnapshot` past its 7-day cache, then let it do the live
* /profile fetch + write. All writes are RLS-scoped to the caller's company.
*/
export async function refreshCompanyProfileAction(
companyId: string,
orgNumberRaw: string,
): Promise<RefreshCompanyProfileResult> {
const supabase = await createClient()
const { data: { user } } = await supabase.auth.getUser()
if (!user) return { error: 'unauthorized' }
// Refuse malformed input at the boundary rather than storing a value that
// would later break SIE/SRU exports (same rule as createCompanyFromOnboarding).
const cleaned = normalizeOrgNumber(orgNumberRaw)
if (!cleaned) return { error: 'org_number_invalid' }
// Persist the (possibly corrected) number and force staleness so
// ensureTicSnapshot re-fetches instead of returning the poisoned cache.
const { error: updateError } = await supabase
.from('companies')
.update({ org_number: cleaned, tic_snapshot_fetched_at: null })
.eq('id', companyId)
if (updateError) return { error: 'persist_failed' }
// Keep the settings form (which reads company_settings.org_number) in sync —
// best-effort; the TIC fetch reads companies.org_number, updated above.
await supabase
.from('company_settings')
.update({ org_number: cleaned })
.eq('company_id', companyId)
// Self-fetch needs the caller's session cookie and the current origin so it
// reaches this same instance (dev / preview / prod) — see ensureTicSnapshot.
const cookieStore = await cookies()
const cookieHeader = cookieStore.getAll().map((c) => `${c.name}=${c.value}`).join('; ')
const hdrs = await headers()
const host = hdrs.get('host')
const proto = hdrs.get('x-forwarded-proto') ?? 'https'
const origin = host ? `${proto}://${host}` : undefined
const { snapshot, source } = await ensureTicSnapshot({
supabase,
companyId,
cookieHeader,
origin,
// The user is watching a spinner; give the ~7-13 call Lens fan-out room to
// finish (the 5s default aborted every fetch during the May quota incident).
timeoutMs: 10_000,
})
// 'fetched' = a fresh live fetch was persisted. 'fallback' = TIC returned
// nothing / errored — surface it and leave the existing snapshot untouched
// rather than blanking a good panel on a transient outage.
if (source !== 'fetched' || !snapshot) {
return { error: 'not_found' }
}
revalidatePath('/settings')
return { ok: true, snapshot, fetchedAt: new Date().toISOString() }
}