* feat(invariants): centralise shared format contracts, reconcile the org-number paths
The same format rules were written out independently across the codebase, and
where they disagreed the disagreement was invisible until a filing failed.
Worst case, now fixed: four Skatteverket- and Bolagsverket-bound export paths
each had their own idea of a valid organisationsnummer.
lib/skatteverket/format.ts strip '-' only threw on any input with a space
lib/salary/ku/ku10-generator.ts replace('-', '') first hyphen only, spaces survived
lib/salary/agi/xml-generator.ts strip non-digits stray letters passed the length check
lib/bokslut/ixbrl/validate /^\d{6}-?\d{4}$/ rejected the 12-digit form, no Luhn
A company stored with a space or in 12-digit form could file AGI all year and
then fail at the arsredovisning deadline with a message that did not say why.
lib/invariants/ now owns account number, ISO date, four-digit fiscal year and
org number, each with the rationale recorded next to the rule. normalizeOrgNumber
moves here from lib/company-lookup/ and isSaneDateString from lib/utils.ts; both
old paths re-export, so no caller changes. lib/api/schemas.ts builds its
primitives on the module, so ~100 schemas inherit any correction.
The arsredovisning check-digit verdict is a warn, not an error: a wrong Luhn
digit is almost certainly a typo worth surfacing, but whether every org number
Bolagsverket accepts satisfies Luhn is a Swedish domain question we have not
verified against a primary source, and an error there blocks Skicka in. We do
not block a statutory filing on an unverified assumption.
KU10 still passes a 12-digit stored org number through unfolded. That is
pre-existing, and whether the KU10 schema wants 10 or 12 digits is not covered
by the swedish-payroll skill, so it is pinned by a test rather than changed
silently.
Guard 8 (hand-rolled-invariant) tracks the remaining 114 inline copies as a
ratchet that may only go down, same mechanism as the roundOre guard.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* test(ci): add an upgrade-path job that applies new migrations against real data
The pg-real job applies all 548 migrations to an EMPTY database. Empty means
zero rows, so a migration that adds a NOT NULL, adds a CHECK, creates a unique
index or backfills passes trivially in CI and can still fail on production,
where the rows exist. CI proved that a fresh install works; nothing proved that
an existing install upgrades.
The new pg-upgrade job: apply the schema as it stands at the merge base, seed a
small real company (three posted verifikat, balanced lines, one ore-level
amount), then apply ONLY the migrations this PR adds, then assert the data
survived (entries still posted, lines intact, ledger still balances, ore
unchanged, voucher numbers sequential). A PR with no migration no-ops.
Verified locally against supabase/postgres:15.8.1.060 rather than assumed, with
three deliberately bad migrations:
rescale money on posted lines empty: would pass seeded: ERROR (immutability trigger)
CHECK violating the ore row empty: exit 0 seeded: exit 3
NOT NULL on a populated column empty: exit 0 seeded: exit 3
Base migrations are read out of the merge-base git tree, not the working tree,
so a PR that edits an already-shipped migration still gets the original applied
and the edit surfaces as a failure here.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* docs: record the invariants and upgrade-CI decisions
Two entries covering what this PR changes and, more importantly, the calls that
are not obvious from the diff: why the arsredovisning check-digit verdict is a
warning rather than an error, why KU10's 12-digit passthrough is pinned instead
of fixed, and why the ROT/RUT brf org-number schemas stay on their own rule.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* docs(test): mark the upgrade fixture as CI-only, never a production template
The fixture writes posted journal_entries and their lines directly, bypassing
the engine and the atomic commit RPC. That is the only way to hand a migration
pre-existing posted rows to break, and it is safe against a throwaway CI
database, but it reads like a sanctioned pattern to anyone who finds it later.
Says so explicitly, with the reason it is confined here (no voucher sequence to
keep gapless, no retention obligation on a database destroyed with the job) and
a pointer back to Hard Rule 2 for anything touching a real database.
Raised by the Swedish compliance review bot on #1364.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
154 lines
5.8 KiB
TypeScript
154 lines
5.8 KiB
TypeScript
import { decryptPersonnummer } from '../personnummer'
|
|
import { getBranding } from '@/lib/branding/service'
|
|
import { stripOrgNumberFormatting } from '@/lib/invariants/org-number'
|
|
|
|
/**
|
|
* KU10 (Kontrolluppgift): Annual employee income statement.
|
|
*
|
|
* Per Skatteförfarandelagen 15 kap: Every employer must file KU10 for each
|
|
* employee by January 31 of the following year. Reports total income, tax
|
|
* withheld, and benefit values for the calendar year.
|
|
*
|
|
* The KU10 is filed electronically via Skatteverket's Filöverföring or API.
|
|
* XML format follows Skatteverket Teknisk beskrivning for KU.
|
|
*
|
|
* Penalties: Late filing = 500 SEK per KU per commenced 5-day period
|
|
* (max 5,000 SEK per KU or 500,000 SEK total per filing deadline).
|
|
*/
|
|
|
|
export interface KU10EmployeeData {
|
|
personnummer: string // Encrypted, will be decrypted
|
|
specificationNumber: number // FK570
|
|
totalGross: number // Ruta 011: Total kontant bruttolön for year
|
|
totalTax: number // Ruta 001: Total avdragen skatt for year
|
|
totalAvgifterBasis: number // Ruta 020: Total avgiftsunderlag
|
|
benefitCar?: number // Ruta 012: Total bilförmån
|
|
benefitHousing?: number // Ruta 014: Total bostadsförmån
|
|
benefitMeals?: number // Ruta 015: Total kostförmån
|
|
benefitOther?: number // Ruta 019: Total övrigt
|
|
sickDays?: number // Total sjukdagar
|
|
employmentStart?: string // YYYY-MM-DD
|
|
employmentEnd?: string // YYYY-MM-DD (if terminated during year)
|
|
}
|
|
|
|
export interface KU10CompanyData {
|
|
orgNumber: string
|
|
companyName: string
|
|
year: number
|
|
contactName: string
|
|
contactPhone: string
|
|
contactEmail: string
|
|
}
|
|
|
|
/**
|
|
* Generate KU10 XML for all employees for a calendar year.
|
|
*
|
|
* Per BFL 7 kap: The KU10 file is räkenskapsinformation, retained 7 years.
|
|
*/
|
|
export function generateKU10Xml(
|
|
company: KU10CompanyData,
|
|
employees: KU10EmployeeData[]
|
|
): string {
|
|
const lines: string[] = []
|
|
// Shared rule (lib/invariants/org-number.ts). The previous
|
|
// `replace('-', '')` removed only the FIRST hyphen and left spaces intact, so
|
|
// an org number entered as "556012 5790" reached Skatteverket with a space in it.
|
|
const orgNr = stripOrgNumberFormatting(company.orgNumber)
|
|
|
|
lines.push('<?xml version="1.0" encoding="UTF-8"?>')
|
|
lines.push('<Skatteverket xmlns="http://xmls.skatteverket.se/se/skatteverket/ai/instans/infoForBeskworksgivku/1.0"')
|
|
lines.push(' xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">')
|
|
|
|
// Avsändare
|
|
lines.push(' <Avsandare>')
|
|
lines.push(` <Programnamn>${escapeXml(getBranding().appName.toLowerCase())}</Programnamn>`)
|
|
lines.push(` <Organisationsnummer>${orgNr}</Organisationsnummer>`)
|
|
lines.push(' <TekniskKontaktperson>')
|
|
lines.push(` <Namn>${escapeXml(company.contactName)}</Namn>`)
|
|
lines.push(` <Telefon>${escapeXml(company.contactPhone)}</Telefon>`)
|
|
lines.push(` <Epostadress>${escapeXml(company.contactEmail)}</Epostadress>`)
|
|
lines.push(' </TekniskKontaktperson>')
|
|
lines.push(' </Avsandare>')
|
|
|
|
// Blankettgemensamt
|
|
lines.push(' <Blankettgemensamt>')
|
|
lines.push(` <Uppgiftslamnare>`)
|
|
lines.push(` <UppgijftslamnareId>${orgNr}</UppgijftslamnareId>`)
|
|
lines.push(` <NamnUppgiftslamnare>${escapeXml(company.companyName)}</NamnUppgiftslamnare>`)
|
|
lines.push(` </Uppgiftslamnare>`)
|
|
lines.push(' </Blankettgemensamt>')
|
|
|
|
// Per-employee KU10
|
|
for (const emp of employees) {
|
|
let pnr: string
|
|
try {
|
|
pnr = decryptPersonnummer(emp.personnummer)
|
|
} catch {
|
|
pnr = '000000000000'
|
|
}
|
|
|
|
lines.push(' <Blankett>')
|
|
lines.push(' <Arendeinformation>')
|
|
lines.push(` <Arendeagare>${orgNr}</Arendeagare>`)
|
|
lines.push(` <Period>${company.year}</Period>`)
|
|
lines.push(' </Arendeinformation>')
|
|
lines.push(' <Blankettinnehall>')
|
|
lines.push(' <KU10>')
|
|
|
|
// Employee identification
|
|
lines.push(` <Personnummer faltkod="215">${pnr}</Personnummer>`)
|
|
lines.push(` <Specifikationsnummer faltkod="570">${emp.specificationNumber}</Specifikationsnummer>`)
|
|
|
|
// Income and tax
|
|
if (emp.totalGross > 0) {
|
|
lines.push(` <KontantBruttoloen faltkod="011">${Math.round(emp.totalGross)}</KontantBruttoloen>`)
|
|
}
|
|
if (emp.totalTax > 0) {
|
|
lines.push(` <AvdragenSkatt faltkod="001">${Math.round(emp.totalTax)}</AvdragenSkatt>`)
|
|
}
|
|
|
|
// Benefits
|
|
if (emp.benefitCar && emp.benefitCar > 0) {
|
|
lines.push(` <FormanBil faltkod="012">${Math.round(emp.benefitCar)}</FormanBil>`)
|
|
}
|
|
if (emp.benefitHousing && emp.benefitHousing > 0) {
|
|
lines.push(` <FormanBostad faltkod="014">${Math.round(emp.benefitHousing)}</FormanBostad>`)
|
|
}
|
|
if (emp.benefitMeals && emp.benefitMeals > 0) {
|
|
lines.push(` <FormanKost faltkod="015">${Math.round(emp.benefitMeals)}</FormanKost>`)
|
|
}
|
|
if (emp.benefitOther && emp.benefitOther > 0) {
|
|
lines.push(` <FormanOvrigt faltkod="019">${Math.round(emp.benefitOther)}</FormanOvrigt>`)
|
|
}
|
|
|
|
// Avgifter basis
|
|
if (emp.totalAvgifterBasis > 0) {
|
|
lines.push(` <UnderlagArbAvg faltkod="020">${Math.round(emp.totalAvgifterBasis)}</UnderlagArbAvg>`)
|
|
}
|
|
|
|
// Employment period (if not full year)
|
|
if (emp.employmentStart) {
|
|
lines.push(` <Anstallningsdatum faltkod="008">${emp.employmentStart.replace(/-/g, '')}</Anstallningsdatum>`)
|
|
}
|
|
if (emp.employmentEnd) {
|
|
lines.push(` <Avgangsdatum faltkod="009">${emp.employmentEnd.replace(/-/g, '')}</Avgangsdatum>`)
|
|
}
|
|
|
|
lines.push(' </KU10>')
|
|
lines.push(' </Blankettinnehall>')
|
|
lines.push(' </Blankett>')
|
|
}
|
|
|
|
lines.push('</Skatteverket>')
|
|
return lines.join('\n')
|
|
}
|
|
|
|
function escapeXml(str: string): string {
|
|
return str
|
|
.replace(/&/g, '&')
|
|
.replace(/</g, '<')
|
|
.replace(/>/g, '>')
|
|
.replace(/"/g, '"')
|
|
.replace(/'/g, ''')
|
|
}
|