* fix(reports): paginate 8 more report/ledger queries (1000-row truncation) Raw .select() without fetchAllRows() silently caps at PostgREST's 1000-row limit, producing wrong statutory output for high-volume companies. Following #806 (trial-balance/VAT), wrap the remaining offenders in fetchAllRows + a stable .order('id') + dedupeBy: - ink2-engine / ne-engine: INK2 & NE-bilaga tax declarations under-counted - ar-reconciliation (1510/1513), supplier-reconciliation (2440): phantom "Ej avstämd" gaps - full-archive-export: 7-year DR archive (added a unique total order so rows are not silently skipped/duplicated across pages) - avgifter-basis, currency-revaluation, vat-declaration Adds a regression guard test asserting >1000 ledger lines are summed, not truncated at 1000. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(api): close extension-dispatcher MFA gap, scope /api/events to API key, sweep dead code Security/correctness: - ext/[...path] dispatcher now uses requireAuth() instead of inline supabase.auth.getUser(), enforcing MFA (AAL2) on hosted across the whole enabled-extension surface (banking sync, document upload/booking, supplier invoices, migration). Ratchets antipatterns-baseline raw-route-auth 168->165. - /api/events now filters by the API key's bound company_id instead of the user's active company (was a cross-company read with a scoped key). - enable-banking OAuth callback calls ensureInitialized() at module load so the PSD2 consent audit event (ASVS V16 / GDPR Art.30) isn't dropped on a cold-start instance. Dead-code sweep (all confirmed zero importers): - delete lib/tax/calculator.ts, lib/salary/engangsskatt.ts (+test), lib/email/resend.ts, lib/salary/salary-transaction-matcher.ts, lib/webhooks/diff.ts, lib/salary/effective-values.ts, lib/bookkeeping/template-prompt.ts - trim unused lib/vat/eu-countries.ts helpers (keep EU_COUNTRIES) - remove dead getAutomaticStatus() and the abandoned Activepieces CSP entry Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(invoices): fail closed when a payment journal entry doesn't post Three mark-paid paths (legacy route, v1 API, agent commit) diverged on the "mark paid but the JE failed" case — two would flip the invoice to paid (or leave an orphaned posted voucher) with no booking, silently diverging the GL from the AR/AP sub-ledger. Unify on fail-closed: - legacy + v1 + agent commitMarkInvoicePaid: never mark paid without a posted voucher; on a null/failed JE return INVOICE_PAID_BOOK_FAILED before any state mutation (v1 mirrors the match-invoice strict mode). - agent path: add the .in('status',[...]).select('id') CAS guard and cancel the orphaned voucher (cancelOrphanedPaymentEntry) on a lost race or update error, matching the web route. - legacy route: cancel the orphan on a non-race update error too (was only handled on the race branch). - supplier mark-paid: stop swallowing a failed supplier_invoice_payments insert — that row drives the reversal amount in payment-sync; roll back the status flip and cancel the voucher instead. - pending-ops orchestrator: error-check the terminal 'committed' write so an op stranded in 'committing' (the expire sweep only targets 'pending') is at least logged loudly. Adds a guard test for the legacy fail-closed path. Full unit suite green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(ci): unblock core build + address compliance-review findings - avgifter-basis.ts: fix the core-build TypeScript error — PostgREST's type-level select parser models the salary_run embed as an array, which wasn't assignable to the object-typed generic. Type it `unknown` (rows are read via an explicit cast), making it robust across postgrest-js versions. - /api/events: add a non-null companyId guard before the event_log query (defense-in-depth for the API-key-bound scope) — addresses ASVS V8.2.1 / ISO A.5.15. - supplier mark-paid: add a CAS guard (.eq('status', newStatus)) to the payment-insert-failure rollback so a concurrent settlement can't be clobbered — addresses ASVS V2.3. - dispatcher: add an AAL2 regression test asserting a non-MFA session is rejected (403) and the extension handler never runs — addresses the GDPR Art.32 review ask for the single extension chokepoint. Verified deletions are safe: effective-values.ts was a dead duplicate — the live AGI/payslip path inlines the same `?? override` coalescing (generate-declaration.ts), so AGI correctness is unaffected. next build: exit 0. Full unit suite: 6147 passing. ESLint clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
301 lines
9.7 KiB
TypeScript
301 lines
9.7 KiB
TypeScript
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
|
|
|
// ============================================================
|
|
// Mock — sequential result queue
|
|
// ============================================================
|
|
|
|
let resultIdx: number
|
|
let results: Array<{ data?: unknown; error?: unknown }>
|
|
let calls: Array<{ method: string; args: unknown[] }>
|
|
|
|
function makeBuilder() {
|
|
const b: Record<string, unknown> = {}
|
|
for (const m of ['select', 'eq', 'in', 'order', 'range']) {
|
|
b[m] = vi.fn().mockImplementation((...args: unknown[]) => {
|
|
calls.push({ method: m, args })
|
|
return b
|
|
})
|
|
}
|
|
b.single = vi.fn().mockImplementation(async () => results[resultIdx++] ?? { data: null, error: null })
|
|
b.then = (resolve: (v: unknown) => void) => resolve(results[resultIdx++] ?? { data: null, error: null })
|
|
return b
|
|
}
|
|
|
|
function makeClient() {
|
|
return {
|
|
from: vi.fn().mockImplementation(() => makeBuilder()),
|
|
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
|
} as any
|
|
}
|
|
|
|
import { generateARReconciliation } from '../ar-reconciliation'
|
|
|
|
let supabase: ReturnType<typeof makeClient>
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
resultIdx = 0
|
|
results = []
|
|
calls = []
|
|
supabase = makeClient()
|
|
})
|
|
|
|
describe('generateARReconciliation', () => {
|
|
it('returns reconciled when AR ledger matches account 1510', async () => {
|
|
results = [
|
|
// 0: invoices
|
|
{
|
|
data: [
|
|
{ total: 5000, paid_amount: 2000 },
|
|
{ total: 3000, paid_amount: 0 },
|
|
],
|
|
error: null,
|
|
},
|
|
// 1: journal_entry_lines for account 1510
|
|
{
|
|
data: [
|
|
{ debit_amount: 8000, credit_amount: 0, journal_entry_id: 'e1' },
|
|
{ debit_amount: 0, credit_amount: 2000, journal_entry_id: 'e2' },
|
|
],
|
|
error: null,
|
|
},
|
|
]
|
|
|
|
const result = await generateARReconciliation(supabase, 'company-1', 'period-1')
|
|
|
|
// AR: (5000-2000) + (3000-0) = 6000
|
|
expect(result.ar_ledger_total).toBe(6000)
|
|
// 1510: 8000 - 2000 = 6000
|
|
expect(result.account_1510_balance).toBe(6000)
|
|
expect(result.difference).toBe(0)
|
|
expect(result.is_reconciled).toBe(true)
|
|
})
|
|
|
|
it('detects difference when AR ledger does not match account 1510', async () => {
|
|
results = [
|
|
// 0: invoices
|
|
{
|
|
data: [
|
|
{ total: 5000, paid_amount: 0 },
|
|
],
|
|
error: null,
|
|
},
|
|
// 1: journal_entry_lines — manual debit on 1510 creates mismatch
|
|
{
|
|
data: [
|
|
{ debit_amount: 5000, credit_amount: 0, journal_entry_id: 'e1' },
|
|
{ debit_amount: 1000, credit_amount: 0, journal_entry_id: 'e2' }, // manual entry
|
|
],
|
|
error: null,
|
|
},
|
|
]
|
|
|
|
const result = await generateARReconciliation(supabase, 'company-1', 'period-1')
|
|
|
|
expect(result.ar_ledger_total).toBe(5000)
|
|
expect(result.account_1510_balance).toBe(6000)
|
|
expect(result.difference).toBe(-1000)
|
|
expect(result.is_reconciled).toBe(false)
|
|
})
|
|
|
|
it('returns zero balances when no data exists', async () => {
|
|
results = [
|
|
{ data: [], error: null },
|
|
{ data: [], error: null },
|
|
]
|
|
|
|
const result = await generateARReconciliation(supabase, 'company-1', 'period-1')
|
|
|
|
expect(result.ar_ledger_total).toBe(0)
|
|
expect(result.account_1510_balance).toBe(0)
|
|
expect(result.difference).toBe(0)
|
|
expect(result.is_reconciled).toBe(true)
|
|
})
|
|
|
|
it('handles null invoice data gracefully', async () => {
|
|
results = [
|
|
{ data: null, error: null },
|
|
{
|
|
data: [
|
|
{ debit_amount: 3000, credit_amount: 0, journal_entry_id: 'e1' },
|
|
],
|
|
error: null,
|
|
},
|
|
]
|
|
|
|
const result = await generateARReconciliation(supabase, 'company-1', 'period-1')
|
|
|
|
expect(result.ar_ledger_total).toBe(0)
|
|
expect(result.account_1510_balance).toBe(3000)
|
|
expect(result.difference).toBe(-3000)
|
|
expect(result.is_reconciled).toBe(false)
|
|
})
|
|
|
|
it('uses correct debit-normal balance for account 1510 (asset)', async () => {
|
|
results = [
|
|
{ data: [], error: null },
|
|
{
|
|
data: [
|
|
{ debit_amount: 10000, credit_amount: 0, journal_entry_id: 'e1' },
|
|
{ debit_amount: 0, credit_amount: 4000, journal_entry_id: 'e2' },
|
|
{ debit_amount: 0, credit_amount: 3000, journal_entry_id: 'e3' },
|
|
],
|
|
error: null,
|
|
},
|
|
]
|
|
|
|
const result = await generateARReconciliation(supabase, 'company-1', 'period-1')
|
|
|
|
// Balance = debits - credits = 10000 - 4000 - 3000 = 3000
|
|
expect(result.account_1510_balance).toBe(3000)
|
|
})
|
|
|
|
it('converts foreign-currency outstanding to SEK before reconciliation', async () => {
|
|
results = [
|
|
// 0: invoices — 225 EUR at 11 (with 25 EUR paid) → 200 EUR → 2 200 SEK,
|
|
// plus 1 000 SEK invoice (no payment)
|
|
{
|
|
data: [
|
|
{ total: 225, paid_amount: 25, currency: 'EUR', exchange_rate: 11 },
|
|
{ total: 1000, paid_amount: 0, currency: 'SEK', exchange_rate: null },
|
|
],
|
|
error: null,
|
|
},
|
|
// 1: 1510 balance = 3 200 SEK
|
|
{
|
|
data: [
|
|
{ debit_amount: 3200, credit_amount: 0, journal_entry_id: 'e1' },
|
|
],
|
|
error: null,
|
|
},
|
|
]
|
|
|
|
const result = await generateARReconciliation(supabase, 'company-1', 'period-1')
|
|
|
|
expect(result.ar_ledger_total).toBe(3200)
|
|
expect(result.account_1510_balance).toBe(3200)
|
|
expect(result.difference).toBe(0)
|
|
expect(result.is_reconciled).toBe(true)
|
|
expect(result.unconverted_fx_count).toBe(0)
|
|
})
|
|
|
|
it('excludes FX invoices without exchange_rate from the SEK total and counts them', async () => {
|
|
results = [
|
|
// 0: invoices — 100 EUR without rate (excluded), 500 SEK control
|
|
{
|
|
data: [
|
|
{ total: 100, paid_amount: 0, currency: 'EUR', exchange_rate: null },
|
|
{ total: 500, paid_amount: 0, currency: 'SEK', exchange_rate: null },
|
|
],
|
|
error: null,
|
|
},
|
|
// 1: 1510 balance reflects only the SEK invoice
|
|
{
|
|
data: [
|
|
{ debit_amount: 500, credit_amount: 0, journal_entry_id: 'e1' },
|
|
],
|
|
error: null,
|
|
},
|
|
]
|
|
|
|
const result = await generateARReconciliation(supabase, 'company-1', 'period-1')
|
|
|
|
expect(result.unconverted_fx_count).toBe(1)
|
|
// EUR row excluded → ledger total is just the SEK 500
|
|
expect(result.ar_ledger_total).toBe(500)
|
|
expect(result.account_1510_balance).toBe(500)
|
|
// Numbers match, but the calculation is incomplete (a row was excluded);
|
|
// BFL 5 kap requires the period not be stamped Avstämd until the missing
|
|
// exchange rate is filled in.
|
|
expect(result.is_reconciled).toBe(false)
|
|
})
|
|
|
|
it('sums 1510 + 1513 in the GL balance for ROT/RUT fakturamodellen', async () => {
|
|
// Forward-looking: today no postings hit 1513, but if a fakturamodellen
|
|
// invoice ever splits the AR receivable across 1510 (customer portion)
|
|
// and 1513 (Skatteverket claim), both must be included to reconcile.
|
|
results = [
|
|
// 0: invoices — single 1 500 SEK invoice
|
|
{
|
|
data: [{ total: 1500, paid_amount: 0, currency: 'SEK', exchange_rate: null }],
|
|
error: null,
|
|
},
|
|
// 1: GL — 1 200 on 1510, 300 on 1513 → combined 1 500
|
|
{
|
|
data: [
|
|
{ debit_amount: 1200, credit_amount: 0, journal_entry_id: 'e1' },
|
|
{ debit_amount: 300, credit_amount: 0, journal_entry_id: 'e2' },
|
|
],
|
|
error: null,
|
|
},
|
|
]
|
|
|
|
const result = await generateARReconciliation(supabase, 'company-1', 'period-1')
|
|
|
|
expect(result.ar_ledger_total).toBe(1500)
|
|
expect(result.account_1510_balance).toBe(1500)
|
|
expect(result.is_reconciled).toBe(true)
|
|
})
|
|
|
|
it('counts posted AND reversed 1510 lines (corrected invoice nets correctly)', async () => {
|
|
// Same fix as supplier-reconciliation: a corrected customer invoice flips its
|
|
// original to status='reversed'. The reversed leg must be summed with the
|
|
// posted storno/correction or a corrected, settled invoice shows a phantom
|
|
// gap against the kundreskontra.
|
|
results = [
|
|
// 0: invoices — single 5 000 SEK invoice still open
|
|
{
|
|
data: [{ total: 5000, paid_amount: 0, currency: 'SEK', exchange_rate: null }],
|
|
error: null,
|
|
},
|
|
// 1: 1510 lines as returned by posted+reversed: original (reversed debit
|
|
// 5000), storno (credit 5000), correction (debit 5000). Net = 5000.
|
|
{
|
|
data: [
|
|
{ debit_amount: 5000, credit_amount: 0, journal_entry_id: 'reg-reversed' },
|
|
{ debit_amount: 0, credit_amount: 5000, journal_entry_id: 'storno' },
|
|
{ debit_amount: 5000, credit_amount: 0, journal_entry_id: 'correction' },
|
|
],
|
|
error: null,
|
|
},
|
|
]
|
|
|
|
const result = await generateARReconciliation(supabase, 'company-1', 'period-1')
|
|
|
|
expect(result.ar_ledger_total).toBe(5000)
|
|
expect(result.account_1510_balance).toBe(5000)
|
|
expect(result.difference).toBe(0)
|
|
expect(result.is_reconciled).toBe(true)
|
|
|
|
// Guard the actual fix: the 1510/1513 query must include reversed entries.
|
|
const statusFilter = calls.find(
|
|
(c) => c.method === 'in' && c.args[0] === 'journal_entries.status',
|
|
)
|
|
expect(statusFilter?.args[1]).toEqual(['posted', 'reversed'])
|
|
})
|
|
|
|
it('uses Math.round for monetary precision', async () => {
|
|
results = [
|
|
{
|
|
data: [
|
|
{ total: 100.1, paid_amount: 33.33 },
|
|
],
|
|
error: null,
|
|
},
|
|
{
|
|
data: [
|
|
{ debit_amount: 66.77, credit_amount: 0, journal_entry_id: 'e1' },
|
|
],
|
|
error: null,
|
|
},
|
|
]
|
|
|
|
const result = await generateARReconciliation(supabase, 'company-1', 'period-1')
|
|
|
|
expect(result.ar_ledger_total).toBe(66.77)
|
|
expect(result.account_1510_balance).toBe(66.77)
|
|
expect(result.difference).toBe(0)
|
|
expect(result.is_reconciled).toBe(true)
|
|
})
|
|
})
|