Files
accounted/lib/core/bookkeeping/fiscal-year-reset.ts
T
MattssonandClaude Fable 5 79013cf092 feat(bookkeeping): guarded fiscal-year reset + findable Angra import (#1883) (#1897)
* feat(bookkeeping): guarded fiscal-year reset + findable Angra import (#1883)

Two deliverables from the community report where a bad SIE test import
left no way out short of deleting the company:

A) Discoverability: the voucher list shows one attn line linking to
   /import?history=sie whenever the page contains import-sourced
   vouchers, and /import?history=sie deep-links straight into the
   fold-open SIE import history where per-import Angra already lives.

B) Reset of an UNLOCKED fiscal year regardless of how the entries
   arrived: new reset_fiscal_year RPC (same gnubok.allow_delete escape
   hatch as undo_sie_import; no enforcement trigger touched) behind
   GET/POST /api/bookkeeping/fiscal-periods/[id]/reset and a typed
   type-the-year-name confirmation dialog on the fiscal years settings
   list. Refuses on: locked/closed year, company lock date over any part
   of the year, executed year-end, arsredovisning state, later year
   depending on this year's UB, VAT-declared evidence (vat_settlement
   verifikat, SKV lock/submit audit rows, extension workflow keys, fail
   closed) and AGI-declared months. Entries referenced by RESTRICT/NO
   ACTION FKs abort the whole reset (all-or-nothing). Documents are
   detached, never deleted (BFL 7 kap); every delete is audit-logged
   plus one behandlingshistorik summary row.

Fixes #1883

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(bookkeeping): harden fiscal-year reset after skeptic review (#1883)

Blocking skeptic findings on PR #1897, one consolidated pass:

- New snapshot blocker cross_year_reference: an entry outside the year whose
  correction_of_id / reverses_id / reversed_by_id points into the year made
  the delete crash with an uncaught P0001 (immutability trigger refusing the
  ON DELETE SET NULL referential UPDATE) after an eligible:true preview, and
  silently severed draft chains. 12 such chains exist in prod today.
- New snapshot blocker rot_rut_state: a begaran om utbetalning that reached
  Skatteverket (submitted/paid/partially_paid/rejected) was silently
  unlinked via SET NULL, erasing the bokforing behind a filed and possibly
  decided myndighetsarende.
- Rakenskapsinformation preservation (BFL 7 kap): line-level trigger audit
  rows carry no company_id and header rows no amounts, so a reset destroyed
  konton/belopp with no company-readable trace. The RPC now archives the
  full content of every verifikat in company-scoped RESET_SNAPSHOT audit
  rows before deleting (action added to audit_log_action_check, NOT VALID),
  and behandlingshistorik renders them.
- Dimension registry lockstep on reset (mirrors undo_sie_import): flipped
  imports can never be undone again, so their dimensions/values would have
  been orphaned forever.
- EXCEPTION WHEN raise_exception now returns a typed
  FISCAL_YEAR_RESET_LINKED_ENTRIES envelope instead of a bare 500;
  gnubok.allow_delete is cleared before leaving the guarded block.
- Voucher-list attn line fires only for source_type 'import':
  opening_balance is also written by year-end closing and the manual IB
  flows, which mislabelled every year-2+ company as SIE-imported.
- /import?history=sie now scrolls the SIE history into view.
- Reset dialog copy (sv+en) discloses that linked invoices, payments and
  bank transactions become unbooked; new blocker strings in both locales.
- pg fixture fix: document_attachments seeded without company_id (23502);
  new pg tests for both blockers, RESET_SNAPSHOT rows and the lockstep.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-25 14:36:18 +02:00

106 lines
3.6 KiB
TypeScript

import type { SupabaseClient } from '@supabase/supabase-js'
import { rpcClientForBulkDelete } from '@/lib/import/sie-import'
import type { FiscalYearResetEligibility, FiscalYearResetRpcResult } from '@/types'
/**
* Fiscal-year reset (issue #1883): guarded hard-delete of ALL vouchers in one
* OPEN fiscal year, regardless of how they arrived (SIE import, manual,
* agent). The heavy lifting and every guard live in the `reset_fiscal_year`
* RPC (migration 20260825150000), which reuses the same
* `gnubok.allow_delete` escape hatch as `undo_sie_import`: this module is a
* thin typed wrapper.
*
* The RPC refuses whenever any reliance state exists: locked/closed year,
* company lock date over the year, year-end/arsredovisning state, a later
* year depending on this year's UB, VAT/AGI declared evidence, or entries
* referenced by other records (assets, accruals, salary runs). Documents are
* detached, never deleted (BFL 7 kap).
*/
export type FiscalYearResetOutcome =
| { ok: true; deleted: number; detachedDocuments: number; periodName: string }
| { ok: false; code: string; blockers?: FiscalYearResetEligibility['blockers'] }
export type FiscalYearResetEligibilityOutcome =
| { ok: true; eligibility: FiscalYearResetEligibility }
| { ok: false; code: string }
/**
* Owner/admin-only eligibility preview. Runs on the caller's session client
* (auth.uid() present), so no explicit user id is needed. The execution RPC
* rechecks every condition; this response is informational only.
*/
export async function getFiscalYearResetEligibility(
supabase: SupabaseClient,
companyId: string,
periodId: string,
): Promise<FiscalYearResetEligibilityOutcome> {
const { data, error } = await supabase.rpc('get_fiscal_year_reset_eligibility', {
p_company_id: companyId,
p_period_id: periodId,
})
if (error) {
return { ok: false, code: 'FISCAL_YEAR_RESET_FAILED' }
}
const result = data as FiscalYearResetRpcResult | null
if (!result?.ok) {
return { ok: false, code: result?.code ?? 'FISCAL_YEAR_RESET_FAILED' }
}
return {
ok: true,
eligibility: {
eligible: result.eligible === true,
blockers: result.blockers ?? [],
period: result.period!,
counts: result.counts ?? { vouchers: 0, documents_to_detach: 0 },
},
}
}
/**
* Execute the reset. Runs on the service client when available (the
* authenticated role's 8s statement_timeout cannot fit a year-sized delete;
* see rpcClientForBulkDelete), passing the authorising user explicitly: on
* the service client auth.uid() is NULL and the RPC resolves its owner/admin
* gate from p_user_id instead. `confirmedName` must restate the year's label
* exactly (typed confirmation, verified again inside the RPC).
*/
export async function resetFiscalYear(
supabase: SupabaseClient,
companyId: string,
periodId: string,
userId: string,
confirmedName: string,
): Promise<FiscalYearResetOutcome> {
const rpcClient = await rpcClientForBulkDelete(supabase)
const { data, error } = await rpcClient.rpc('reset_fiscal_year', {
p_company_id: companyId,
p_period_id: periodId,
p_confirmed_name: confirmedName,
p_user_id: userId,
})
if (error) {
return { ok: false, code: 'FISCAL_YEAR_RESET_FAILED' }
}
const result = data as FiscalYearResetRpcResult | null
if (!result?.ok) {
return {
ok: false,
code: result?.code ?? 'FISCAL_YEAR_RESET_FAILED',
blockers: result?.blockers,
}
}
return {
ok: true,
deleted: result.deleted ?? 0,
detachedDocuments: result.detached_documents ?? 0,
periodName: result.period_name ?? '',
}
}