Files
accounted/lib/pending-operations/schemas/article.ts
T
f266c386f3 chore: repo-wide bloat sweep, remove dead code and fold duplicate helpers (#2150)
* chore: repo-wide bloat sweep, remove dead code and fold duplicate helpers

Remove 33 dead files, ~270 unreferenced exports/types, 13 dead i18n
namespaces and 4 unused dependencies; fold byte-identical helper copies
into one canonical home each (lib/utils chunk/sleep/utcDateStamp,
lib/dates/iso, lib/invariants/uuid, lib/xml/escape, lib/reports/sru/format,
lib/pdf/number-text, lib/browser/panel-request, lib/api/v1/body +
v1ValidationError rolled out to ~55 v1 routes, booking-template schemas).

No behaviour change: v1 bodies and status codes, MCP tool schemas, DB
writes and money math are untouched. Naive ore rounding was deliberately
not swapped for roundOre; see DECISIONS.md 2026-09-02 for the full list
of things left alone on purpose.

tsc, lint, 19588 unit tests and check:guards green; antipattern baseline
ratcheted (naive-ore-round 622 -> 620, hand-rolled-invariant 115 -> 113).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* test(transactions): import RawTransaction from @/types after the ingest re-export removal

CI's type ratchet (check:types, full tsconfig) caught the one test file
that still imported the type through lib/transactions/ingest.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 11:51:16 +02:00

92 lines
3.7 KiB
TypeScript

import { z } from 'zod'
import { INVOICE_POSTING_ACCOUNT_REGEX } from '@/lib/invoices/posting-account'
import { HOUSEWORK_TYPE_VALUES, normalizeHouseworkType } from '@/lib/invoices/rot-rut-rules'
// Commit-boundary re-validation for staged article operations. A staged
// pending_operations row is re-parsed here before it touches the articles table
// so a tampered row cannot inject unexpected fields or malformed data
// (defense in depth, ASVS V4.5): mirrors lib/pending-operations/schemas/create-supplier.ts.
const invoicePostingAccount = z
.string()
.regex(INVOICE_POSTING_ACCOUNT_REGEX, 'Posting account must be a 4-digit BAS class 1-3 account')
const vatRatePercent = z.union([z.literal(0), z.literal(6), z.literal(12), z.literal(25)])
/** Empty string / null → undefined, then bounded string. */
const optString = (max: number) =>
z.preprocess((v) => (v == null || v === '' ? undefined : v), z.string().max(max).optional())
// Same vocabulary as HouseworkTypeSchema in lib/api/schemas.ts: work-type code
// or bare ROT/RUT, upper-cased; empty → undefined; anything else rejected.
const houseworkCode = z.string().max(64).transform((v, ctx) => {
const normalized = normalizeHouseworkType(v)
if (!normalized) {
ctx.addIssue({
code: z.ZodIssueCode.custom,
message: `Invalid housework_type. Allowed: ${HOUSEWORK_TYPE_VALUES.join(', ')}`,
})
return z.NEVER
}
return normalized
})
// Create: empty / null / omitted all mean "no flag" (column stays NULL).
const houseworkTypeCreate = z.preprocess(
(v) => (v == null || (typeof v === 'string' && v.trim() === '') ? undefined : v),
houseworkCode.optional(),
)
// Update: commitUpdateArticle drops undefined keys, so a clear must arrive as
// null. Omitted stays undefined (untouched); null / '' / whitespace clear.
const houseworkTypeUpdate = z.preprocess(
(v) => (v == null || (typeof v === 'string' && v.trim() === '') ? (v === undefined ? undefined : null) : v),
houseworkCode.nullable().optional(),
)
const trimmedName = z.preprocess(
(v) => (typeof v === 'string' ? v.trim() : v),
z.string().min(1, 'Article name is required').max(200),
)
// ISO 4217 shape, normalized to upper case; the currencies-table FK on
// articles.currency is the authoritative allow-list (unknown codes fail at
// commit with a clear message). Empty string / null → undefined.
const currencyCode = z.preprocess(
(v) => (v == null || v === '' ? undefined : typeof v === 'string' ? v.trim().toUpperCase() : v),
z.string().regex(/^[A-Z]{3}$/, 'Currency must be a 3-letter ISO 4217 code (e.g. EUR)').optional(),
)
export const CreateArticleParamsSchema = z.object({
name: trimmedName,
type: z.enum(['vara', 'tjanst']).default('tjanst'),
unit: optString(32),
price_excl_vat: z.number().nonnegative(),
currency: currencyCode,
vat_rate: vatRatePercent.default(25),
revenue_account: invoicePostingAccount.nullable().optional(),
cost_price: z.number().nonnegative().nullable().optional(),
ean: optString(32),
housework_type: houseworkTypeCreate,
name_en: optString(200),
notes: optString(2000),
article_number: optString(64),
})
export const UpdateArticleParamsSchema = z.object({
article_id: z.string().uuid(),
name: trimmedName.optional(),
type: z.enum(['vara', 'tjanst']).optional(),
unit: optString(32),
price_excl_vat: z.number().nonnegative().optional(),
currency: currencyCode,
vat_rate: vatRatePercent.optional(),
revenue_account: invoicePostingAccount.nullable().optional(),
cost_price: z.number().nonnegative().nullable().optional(),
ean: optString(32),
housework_type: houseworkTypeUpdate,
name_en: optString(200),
notes: optString(2000),
article_number: optString(64),
active: z.boolean().optional(),
})