Files
accounted/lib/parties/scb/__tests__/scb.test.ts
T
MattssonandClaude Fable 5.1 fc2d78a7c4 feat(onboarding): the orgnr step suggests companies as you type (SCB search, TIC on the pick) (#2452)
* feat(onboarding): the orgnr step suggests companies as you type, SCB search, TIC on the pick

Most people do not know their organisationsnummer. They left the
onboarding for allabolag, searched their company name there, copied the
number and pasted it back. #2421 let the field take a name, but only on
Enter and behind a screen that still said "organisationsnummer", so the
detour stayed. Now the field suggests companies while a name is typed
(name, orgnr or "Enskild firma", city; arrow keys or click to pick), the
pick fills the company like a typed orgnr, and the screen says "Vilket
företag är det?" with "Företagsnamn eller organisationsnummer" as the
placeholder.

Why the problem occurred: the one identifier the step asked for is the one
the user is least likely to remember, and the free-text path added in
#2421 was invisible (copy unchanged) and had to be guessed (Enter only),
because the only search index behind it was TIC, whose Lens budget cannot
take a call per keystroke.

What was removed or simplified: nothing is stored and no new state model:
a picked suggestion is an ORG_SUBMITTED with prefill, so the existing
LOOKUP_RESULT transitions (found, not found, disabled, error) decide the
step exactly as for a typed number. SCB's name search already existed for
the parties picker; it gained one option (sole traders) instead of a
second client. No rate limiting anywhere, per the founder.

Why this shape: SCB's företagsregister is free and already configured for
the parties picker, so search-as-you-type costs nothing while typing; TIC
runs once, on the pick, as it always did on Enter. TIC per keystroke was
rejected (3000/month). SCB alone was rejected for the pick because it
knows no F-skatt, VAT registration or fiscal year. The Enter path and the
chip row from #2421 stay as the fallback when no row is picked. Sole
traders are offered (they are half the users) but their row names the
form and never prints the personnummer, and the field shows the company
name after a pick for the same reason.

Changes:
- app/api/company/search: GET ?q= over the SCB client with sole traders
  included, top 6 rows plus a truncated flag; requireAuth() (no company
  yet), 400 for short or numeric q, 503 without SCB credentials, 502 when
  SCB does not answer.
- lib/parties/scb/client.ts: searchByName(query, { includeSoleTraders }),
  legalFormCode on every candidate; the parties picker is unchanged.
- lib/company-lookup: CompanySuggestion, COMPANY_SUGGEST_MAX,
  fetchCompanySuggestions (503 is disabled, everything else error, never
  throws), toCompanySuggestion (SCB legal form 49/10/61 into the TIC
  vocabulary mapSetupEntityType reads).
- lib/onboarding-journey/reducer.ts: SUGGESTION_PICKED (orgnr, name and
  form as prefill, lookupPending; lookupRan stays false until TIC answers).
- components/onboarding/journey: 300 ms debounced SCB search with abort of
  the superseded request, listbox under the field (combobox ARIA, arrow
  keys, Escape, Enter picks the highlighted row, otherwise the Enter path),
  copy switches with companySearchEnabled or ticEnabled; both journey
  pages pass isScbConfigured().
- messages sv+en: five strings.

Tests: route (401, 400 short, 400 missing, 400 numeric, 503, happy with a
sole trader, cap at 6, flood, 502); fetchCompanySuggestions (every
outcome); toCompanySuggestion; reducer (pick equals typed orgnr after TIC,
TIC overrides prefill, TIC off keeps the AB past form and name, unmapped
form falls to the picker, sole trader confirms the name, replaces a
previous orgnr, ignored off-step); SCB client sole-trader option.

Fixes #2448

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YNDuYBHVu172tesKfJmcmi

* fix(onboarding): the suggestion list stays visible and stands alone (skeptic on e56eb242c)

Three independent refuters on the frozen commit; every refutation that
stood is fixed here.

- The listbox was position: absolute inside the field, but the step
  scrolls (.jny-qstep is overflow-y: auto), so the list was clipped to
  the first row and mouse picks were unreachable (measured in headless
  Chrome). It now renders in flow under the field, where the chip row
  from #2421 already lives.
- After Enter on a name (the #2421 path), SEARCH_RESULT flipped
  lookupPending back and the debounced effect refetched SCB, laying the
  listbox over the chip row or next to the nomatch note. The effect is
  now quiet while searchHits is non-empty and for text the user already
  confirmed (Enter or a pick), until the text changes.
- The "many matches, type more" hint only rendered inside the list, so
  the flood case (SCB counts over 100 rows and sends none) showed
  nothing. The hint now renders on its own for that case.
- app/companies/new-client (byrå adds a client) renders the same journey
  and now passes companySearchEnabled like the other two pages.
- A stale mouse highlight could commit a row from the previous text on
  Enter: typing resets the highlight.
- Any 503 switched the picker off for the session; only the route's own
  SCB_NOT_CONFIGURED does now.
- NOTFOUND_EDIT / CEASED_EDIT dropped only the number and kept the
  abandoned pick's name and form, which a later TIC error path would
  have written into the company. Both now drop name and form too, unless
  they came from BankID's CompanyRoles prefill, which is not about the
  number.

Not changed, recorded: a sole trader picked from SCB whom TIC does not
know lands on the "no company on that number" step with the name in the
field; the flow continues with the SCB name prefilled. The search JSON
carries the personnummer of sole-trader rows to the authenticated
browser (the row prints "Enskild firma"), same class as #2421's Enter
search; flagged to the founder.

Refs #2448

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YNDuYBHVu172tesKfJmcmi

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-09 11:43:14 +02:00

235 lines
12 KiB
TypeScript

import { readFileSync } from 'node:fs'
import { join } from 'node:path'
import { describe, expect, it } from 'vitest'
import { createScbClient, identityLookupBody, nameQuery, nameSearchBody, SCB_SEARCH_CAP } from '../client'
import { isScbConfigured, scbConfigFromEnv } from '../config'
import { factsFromScbCompany, BOLAGSVERKET_WARNING_CODES } from '../map'
import { isLegalPersonOrgNumber, toPeOrgNr } from '../org-number'
import { ScbApiError, scbJson } from '../transport'
/** One Je row exactly as the live API returned it on 2026-09-03 (AB Volvo, public registry data). */
const volvo = JSON.parse(readFileSync(join(__dirname, 'fixtures', 'volvo-je.json'), 'utf8')) as Record<string, string>
describe('org numbers we send to SCB', () => {
it('accepts legal persons (month slot 20 or more) and refuses personnummer-shaped numbers', () => {
expect(isLegalPersonOrgNumber('556012-5790')).toBe(true)
expect(isLegalPersonOrgNumber('5564300142')).toBe(true)
expect(isLegalPersonOrgNumber('9696789012')).toBe(true)
expect(isLegalPersonOrgNumber('19800101-1234')).toBe(false)
expect(isLegalPersonOrgNumber('8001011234')).toBe(false)
expect(isLegalPersonOrgNumber('')).toBe(false)
expect(isLegalPersonOrgNumber(null)).toBe(false)
})
it('builds PeOrgNr with the 16 prefix', () => {
expect(toPeOrgNr('556012-5790')).toBe('165560125790')
})
})
describe('config', () => {
it('is configured only when both the certificate and its password are set', () => {
const env = (v: Record<string, string>) => v as unknown as NodeJS.ProcessEnv
expect(isScbConfigured(env({}))).toBe(false)
expect(isScbConfigured(env({ SCB_API_CERT_PFX_BASE64: 'AAAA' }))).toBe(false)
expect(isScbConfigured(env({ SCB_API_CERT_PFX_BASE64: 'AAAA', SCB_API_CERT_PASSWORD: 'x' }))).toBe(true)
const cfg = scbConfigFromEnv(env({ SCB_API_CERT_PFX_BASE64: Buffer.from('pfx').toString('base64'), SCB_API_CERT_PASSWORD: 'x', SCB_API_BASE_URL: 'https://example.test/base/' }))
expect(cfg.baseUrl).toBe('https://example.test/base')
expect(cfg.pfx.toString()).toBe('pfx')
expect(() => scbConfigFromEnv(env({}))).toThrow(/SCB_API_CERT_PFX_BASE64/)
})
})
describe('factsFromScbCompany on a live row', () => {
it('maps the Volvo row with SCB codes and SCB text', () => {
const facts = factsFromScbCompany(volvo)
const by = Object.fromEntries(facts.map((f) => [f.field, f.value]))
expect(by.legal_name).toBe('AKTIEBOLAGET VOLVO')
expect(by.trade_name).toBeUndefined()
expect(by.f_tax).toEqual({ code: '1', label: 'Är registrerad för F-skatt' })
expect(by.vat_registration).toEqual({ code: '1', label: 'Är registrerad för moms' })
expect(by.employer_registration).toEqual({ code: '1', label: 'Är registrerad som vanlig arbetsgivare' })
expect(by.company_status).toEqual({ code: '1', label: 'Är verksam' })
expect(by.legal_form).toEqual({ code: '49', label: 'Övriga aktiebolag' })
expect(by.bolagsverket_status).toEqual({ code: '0', label: 'Normalläge', warning: false })
expect(by.employees_band).toEqual({ code: '8', label: '200-499 anställda' })
expect(by.registered_skv).toBeUndefined()
expect(by.vat_number).toBe('SE556012579001')
expect(by.industry).toEqual({ code: '70100', label: 'Verksamheter som utövas av huvudkontor' })
expect(by.postal_address).toEqual({ street: null, co: null, postal_code: '405 08', city: 'GÖTEBORG' })
expect(by.seat).toEqual({ municipality_code: '1480', county_code: '14', municipality: 'Göteborg', county: 'Västra Götaland' })
expect(by.turnover_band).toEqual({ code: '10', label: '1 000 000 - 4 999 999 tkr', year: '2025' })
expect(by.registered_at).toBe('1972-01-01')
expect(by.active_since).toBe('1972-01-01')
expect(by.active_until).toBeUndefined()
expect(by.phone).toBe('031660000')
expect(by.email).toBeUndefined()
expect(by.workplaces).toBe(1)
})
it('flags a company in konkurs, falls back to our labels without SCB text, and tolerates an empty row', () => {
const facts = factsFromScbCompany({ Företagsnamn: 'Gone AB', 'Bolagsstatus, kod': '20', 'Fskattstatus, kod': '9 ' })
const by = Object.fromEntries(facts.map((f) => [f.field, f.value]))
expect(by.legal_name).toBe('Gone AB')
expect(by.bolagsverket_status).toEqual({ code: '20', label: 'Konkurs inledd', warning: true })
expect(by.f_tax).toEqual({ code: '9', label: 'Avregistrerad för F-skatt' })
expect(by.vat_number).toBeUndefined()
expect(factsFromScbCompany({ OrgNr: '5560125790', 'Momsstatus, kod': '9' }).find((f) => f.field === 'vat_number')).toBeUndefined()
expect(BOLAGSVERKET_WARNING_CODES.has('0')).toBe(false)
expect(BOLAGSVERKET_WARNING_CODES.has('49')).toBe(false) // fusion pågår
expect(BOLAGSVERKET_WARNING_CODES.has('41')).toBe(true) // upplöst genom fusion
expect(factsFromScbCompany({})).toEqual([])
})
})
describe('createScbClient', () => {
const cfg = { baseUrl: 'https://scb.test', pfx: Buffer.from('x'), passphrase: 'p', timeoutMs: 1 }
it('sends the identity filter the live API accepts', () => {
expect(identityLookupBody('5560125790')).toEqual({
Variabler: [{ Variabel: 'OrgNr (10 siffror)', Operator: 'ArLikaMed', Varde1: '5560125790', Varde2: '' }],
Kategorier: [],
})
})
it('refuses a sole trader before any call is made', async () => {
const json = async () => {
throw new Error('should not be called')
}
const client = createScbClient(cfg, { json: json as never })
await expect(client.lookupByOrgNumber('8001011234')).rejects.toThrow(/juridiska personer/)
})
it('posts HamtaForetag and maps the returned row', async () => {
const calls: Array<{ method: string; path: string; body: unknown }> = []
const json = async (_c: unknown, method: string, path: string, body?: unknown) => {
calls.push({ method, path, body })
return [volvo]
}
const client = createScbClient(cfg, { json: json as never })
const r = await client.lookupByOrgNumber('556012-5790')
expect(calls[0]!.method).toBe('POST')
expect(calls[0]!.path).toBe('/api/Je/HamtaForetag')
expect(calls[0]!.body).toEqual(identityLookupBody('5560125790'))
expect(r.found).toBe(true)
expect(r.peOrgNr).toBe('165560125790')
expect(r.facts.find((f) => f.field === 'legal_name')?.value).toBe('AKTIEBOLAGET VOLVO')
})
it('reports not found when the list is empty', async () => {
const json = async () => []
const client = createScbClient(cfg, { json: json as never })
const r = await client.lookupByOrgNumber('5564300142')
expect(r.found).toBe(false)
expect(r.facts).toEqual([])
})
})
describe('name search', () => {
it('strips AP prefixes, numbers and legal forms from the query', () => {
expect(nameQuery('Levfakt Telia Sverige AB (17)')).toBe('Telia Sverige')
expect(nameQuery('Leverantörsfaktura från 18 Loopia')).toBe('Loopia')
expect(nameQuery('Adobe Systems Software')).toBe('Adobe Systems Software')
expect(nameQuery("O'Learys Sundsvall AB")).toBe('OLearys Sundsvall')
// Foreign legal forms stay: they are part of the registered name and dropping them floods.
expect(nameQuery('Schmidt GmbH')).toBe('Schmidt GmbH')
expect(nameQuery('Google Cloud EMEA Limited')).toBe('Google Cloud EMEA Limited')
expect(nameSearchBody('Telia', 'starts_with').Variabler[0]).toEqual({ Variabel: 'Namn', Operator: 'BorjarPa', Varde1: 'Telia', Varde2: '' })
expect(nameSearchBody('Telia', 'contains').Variabler[0]!.Operator).toBe('Innehaller')
})
const cfg = { baseUrl: 'https://scb.test', pfx: Buffer.from('x'), passphrase: 'p', timeoutMs: 1 }
const row = (org: string, name: string, statusCode = '1', legalForm = '49', city = 'STOCKHOLM') => ({
OrgNr: org,
Företagsnamn: name,
PostOrt: city,
Bransch_1: 'Utgivning av annan programvara',
'Företagsstatus, kod': statusCode,
Företagsstatus: statusCode === '1' ? 'Är verksam' : 'Är ej längre verksam',
'Juridisk form, kod': legalForm,
'Juridisk form': 'Övriga aktiebolag',
})
it('counts first, prefers a prefix match, sorts active companies first and drops natural persons', async () => {
const calls: string[] = []
const json = async (_c: unknown, _m: string, path: string, body: { Variabler: Array<{ Operator: string }> }) => {
calls.push(`${path}:${body.Variabler[0]!.Operator}`)
if (path.endsWith('RaknaForetag')) return 3
return [row('5020594593', 'ADOBE SYSTEMS SOFTWARE IRELAND LTD', '9'), row('5564082161', 'Adobe Systems Nordic Aktiebolag'), row('8001011234', 'ADOBE, ANNA', '1', '10')]
}
const client = createScbClient(cfg, { json: json as never })
const r = await client.searchByName('Levfakt Adobe Systems (2)')
expect(calls).toEqual(['/api/Je/RaknaForetag:BorjarPa', '/api/Je/HamtaForetag:BorjarPa'])
expect(r.mode).toBe('starts_with')
expect(r.total).toBe(2)
expect(r.candidates.map((c) => [c.name, c.active])).toEqual([
['Adobe Systems Nordic Aktiebolag', true],
['ADOBE SYSTEMS SOFTWARE IRELAND LTD', false],
])
})
it('falls back to a contains match when the prefix finds nothing, and refuses to pull a flood', async () => {
const calls: string[] = []
const json = async (_c: unknown, _m: string, path: string, body: { Variabler: Array<{ Operator: string; Varde1: string }> }) => {
calls.push(`${path}:${body.Variabler[0]!.Operator}`)
if (path.endsWith('RaknaForetag')) return body.Variabler[0]!.Operator === 'BorjarPa' ? 0 : 593
throw new Error('should not fetch rows for a flood')
}
const client = createScbClient(cfg, { json: json as never })
const r = await client.searchByName('UBER')
expect(calls).toEqual(['/api/Je/RaknaForetag:BorjarPa', '/api/Je/RaknaForetag:Innehaller'])
expect(r).toMatchObject({ mode: 'contains', total: 593, truncated: true, candidates: [] })
expect(SCB_SEARCH_CAP).toBe(25)
})
it('offers sole traders only when asked, and never estates', async () => {
const json = async (_c: unknown, _m: string, path: string) => {
if (path.endsWith('RaknaForetag')) return 3
return [row('5564082161', 'Adobe Systems Nordic Aktiebolag'), row('8001011234', 'ADOBE, ANNA', '1', '10'), row('8001011235', 'ADOBE, ANNA DÖDSBO', '1', '91')]
}
const client = createScbClient(cfg, { json: json as never })
const parties = await client.searchByName('Adobe')
expect(parties.candidates.map((c) => c.orgNumber)).toEqual(['5564082161'])
const onboarding = await client.searchByName('Adobe', { includeSoleTraders: true })
expect(onboarding.candidates.map((c) => [c.orgNumber, c.legalFormCode])).toEqual([
['5564082161', '49'],
['8001011234', '10'],
])
expect(onboarding.total).toBe(2)
})
it('does not call SCB for a query shorter than two characters', async () => {
const json = async () => {
throw new Error('should not be called')
}
const r = await createScbClient(cfg, { json: json as never }).searchByName('Levfakt 17')
expect(r.candidates).toEqual([])
})
})
describe('scbJson', () => {
const cfg = { baseUrl: 'https://scb.test', pfx: Buffer.from('x'), passphrase: 'p', timeoutMs: 1 }
it('retries once on a dropped connection, then succeeds', async () => {
let n = 0
const request = async () => {
n += 1
if (n === 1) throw Object.assign(new Error('read ECONNRESET'), { code: 'ECONNRESET' })
return { status: 200, body: '3' }
}
await expect(scbJson(cfg, 'POST', '/api/Je/RaknaForetag', {}, { request: request as never, delayMs: 0 })).resolves.toBe(3)
expect(n).toBe(2)
})
it('does not retry a non-transient error or a bad status', async () => {
let n = 0
const boom = async () => {
n += 1
throw new Error('certificate unknown')
}
await expect(scbJson(cfg, 'GET', '/x', undefined, { request: boom as never, delayMs: 0 })).rejects.toThrow(/certificate/)
expect(n).toBe(1)
const bad = async () => ({ status: 400, body: '{"Message":"Ogiltigt"}' })
await expect(scbJson(cfg, 'GET', '/x', undefined, { request: bad as never })).rejects.toBeInstanceOf(ScbApiError)
})
})