Files
accounted/supabase/migrations/20260709130000_supplier_invoice_start_number.sql
T
MattssonandClaude Opus 4.8 bacc5914af Fix/dependabot cus feedback (#946)
* feat(bookkeeping): per-account default VAT, oresavrundning momsfri

Add a per-account "Standard moms" setting to the chart of accounts and use
it to auto-fill the moms on a leverantorsfaktura-rad when that konto is
picked. Oresavrundning (3740) ships as "Ingen moms", so a rounding line no
longer inherits the 25 % rad-default and skews the moms.

- chart_of_accounts.default_vat_rate (0/0.06/0.12/0.25, CHECK-constrained)
- BEFORE INSERT trigger ships 3740 momsfri on every insert path; backfills
  existing 3740 rows
- kontoplan editor: dead free-text momskod replaced with a Standard moms select
- supplier-invoice rad auto-fills the rate from the konto default

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(supplier-invoices): configurable start number for the ankomstnummer series

Add a company_settings.next_arrival_number start floor so a company can continue its leverantorsfaktura numbering from a previous system (e.g. Fortnox) instead of restarting the ankomstnummer at 1. get_next_arrival_number now floors the series via GREATEST(MAX(arrival_number)+1, next_arrival_number), so the floor can never move the series backwards or collide with the (company_id, arrival_number) unique index.

The RPC is hardened while rewritten: SET search_path to empty, schema-qualified refs, and an auth.uid() membership check matching generate_invoice_number.

Includes the settings UI field, sv/en strings, migration, and pg-real coverage. The CompanySettings type and Zod schema field for this feature landed earlier in 1bf3b641 (swept into the per-account VAT commit).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(dependabot): reduce open pull requests limit and group updates for better management

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-09 12:19:57 +02:00

68 lines
2.7 KiB
PL/PgSQL

-- Configurable starting number for the supplier-invoice series (ankomstnummer).
--
-- Mirrors next_invoice_number for customer invoices: lets a company continue
-- its leverantorsfaktura numbering from a previous system (e.g. Fortnox) when
-- migrating to Accounted, instead of always restarting the ankomstnummer at 1.
--
-- Design: a start FLOOR, not a consumed counter. get_next_arrival_number keeps
-- its self-healing COALESCE(MAX(arrival_number),0)+1 behavior and floors the
-- result at next_arrival_number via GREATEST. Consequences:
-- * Existing companies default to 1, so MAX+1 is unchanged.
-- * Before the first invoice, the series starts at the configured value.
-- * Once real invoices pass the floor, MAX+1 dominates: the floor can never
-- move the series backwards or collide with the
-- (company_id, arrival_number) unique index.
--
-- The function is also hardened while rewritten (it was SECURITY DEFINER with a
-- mutable search_path, flagged by the DB linter): SET search_path = '', all
-- references schema-qualified, plus an inline membership check mirroring
-- generate_invoice_number. NULL auth.uid() (service role / API-key / cron paths
-- that call this RPC) is trusted through.
ALTER TABLE public.company_settings
ADD COLUMN IF NOT EXISTS next_arrival_number integer NOT NULL DEFAULT 1;
ALTER TABLE public.company_settings
DROP CONSTRAINT IF EXISTS company_settings_next_arrival_number_positive;
ALTER TABLE public.company_settings
ADD CONSTRAINT company_settings_next_arrival_number_positive
CHECK (next_arrival_number >= 1);
CREATE OR REPLACE FUNCTION public.get_next_arrival_number(p_company_id uuid)
RETURNS integer
LANGUAGE plpgsql
SECURITY DEFINER
SET search_path = ''
AS $function$
DECLARE
v_floor integer;
v_next integer;
BEGIN
-- Defense-in-depth: refuse to operate on companies the caller is not a
-- member of. NULL auth.uid() (service role / API-key / cron) is trusted
-- through, matching generate_invoice_number.
IF auth.uid() IS NOT NULL AND NOT EXISTS (
SELECT 1 FROM public.company_members
WHERE user_id = auth.uid() AND company_id = p_company_id
) THEN
RAISE EXCEPTION 'unauthorized: caller is not a member of company %', p_company_id
USING ERRCODE = '42501';
END IF;
-- Configured start floor (defaults to 1 for every company; NULL only if the
-- settings row is missing, in which case COALESCE keeps the old behavior).
SELECT COALESCE(next_arrival_number, 1) INTO v_floor
FROM public.company_settings
WHERE company_id = p_company_id;
SELECT GREATEST(COALESCE(MAX(arrival_number), 0) + 1, COALESCE(v_floor, 1))
INTO v_next
FROM public.supplier_invoices
WHERE company_id = p_company_id;
RETURN v_next;
END;
$function$;
NOTIFY pgrst, 'reload schema';