* perf(bundle): drop the BAS chart and the Node crypto polyfill from the shared client baseline
Two chunks rode along in the first-load JS of almost every dashboard route:
the full BAS 2026 chart (315 KB uncompressed, in 81 route manifests) and
the browser polyfill for Node's crypto/vm/Buffer (327 KB, in 26 routes
incl. login and register). Neither was needed on first paint; both got
there through static imports of helpers that happen to live next to code
that needs the data or the builtin.
Node polyfill (4 pure splits, behaviour unchanged, re-exported from the
original modules for server callers):
- lib/auth/bankid-flags.ts: isBankIdEnabled (login, register, security
settings imported it from bankid.ts, which imports crypto).
- lib/import/bank-file/formats.ts: the format registry + detection (the
import history imported getFormat from parser.ts, which hashes).
- lib/salary/personnummer-format.ts: parsing/validation/formatting (the
employee forms reached the encrypting personnummer.ts via tax-column).
- lib/auth/api-key-scopes.ts: scope catalogue, groups, tool map, helpers
(the API key panel imported STAGING_SCOPES from the key generator).
BAS chart:
- lib/bookkeeping/bas-lazy.ts + use-bas-reference.ts: the chart becomes a
dynamic import, fetched once per session after first paint; components
that show BAS names/descriptions call useBasReference() and re-render
when it lands. Until then (and on the server) only the hardcoded
account-descriptions answer, so SSR and hydration agree.
- lib/bookkeeping/bas-labels.ts: class/group labels out of bas-reference.ts
(account-descriptions needed a label and paid for the whole chart).
- lib/bookkeeping/bas-account-numbers.ts (generated, ~11 KB) +
scripts/generate-bas-account-numbers.ts (--check) + parity test:
isStandardBASAccountNumber for AddAccountDialog/ChartOfAccountsManager.
- lib/bookkeeping/account-classifier-{heuristic,client}.ts: the BAS-aligned
heuristic shared by the server classifier and a client variant that uses
the lazy chart.
- lib/bookkeeping/invoice-accounts.ts: INVOICE_FX_RATE_MISSING,
InvoiceFxRateMissingError, getRevenueAccount, getOutputVatAccount out of
invoice-entries.ts, whose engine import pulled account-backfill and the
chart into SendInvoiceDialog/PaymentBookingDialog.
- CorrectOpeningBalanceDialog re-seeds names when the chart lands;
OpeningBalanceRowEditor builds its Fuse indexes lazily; the
ChartOfAccountsManager BAS-katalog tab awaits the chunk.
Tooling:
- scripts/perf/client-import-closure.mjs: static import closure of every
'use client' module with the shortest chain to a target (file or bare
specifier); found every path above without a build.
- scripts/checks/client-node-builtin.mjs wired into check:guards: a client
module reaching a Node builtin is a hard failure (0 today).
Left as is: invoices/[id], its credit page and SendInvoiceDialog still
reach the chart through lib/invoices/issue-credit-note -> invoice-entries
-> engine -> account-backfill; splitting the engine is out of scope here.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(perf): unambiguous import-edge regex in the closure walker (CodeQL js/redos)
One quantifier per span: a greedy [^'"]* up to the specifier quote, which it
cannot cross, so a run of whitespace has a single parse. Same edges as
before (multi-line named imports, re-exports, side-effect imports; type-only
imports still skipped).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
120 lines
4.5 KiB
TypeScript
120 lines
4.5 KiB
TypeScript
import { createCipheriv, createDecipheriv, randomBytes, scryptSync } from 'crypto'
|
|
import { createLogger } from '@/lib/logger'
|
|
|
|
const ALGORITHM = 'aes-256-gcm'
|
|
const IV_LENGTH = 12
|
|
const TAG_LENGTH = 16
|
|
|
|
const logger = createLogger('salary/personnummer')
|
|
|
|
/**
|
|
* Get the encryption key from environment.
|
|
* Falls back to a dev-only key for local development.
|
|
*/
|
|
function getEncryptionKey(): Buffer {
|
|
const envKey = process.env.PERSONNUMMER_ENCRYPTION_KEY
|
|
if (!envKey) {
|
|
if (process.env.NODE_ENV === 'production') {
|
|
throw new Error('PERSONNUMMER_ENCRYPTION_KEY is required in production')
|
|
}
|
|
// Dev-only deterministic key (NOT safe for production)
|
|
return scryptSync('dev-only-key', 'gnubok-dev-salt', 32)
|
|
}
|
|
// Use scrypt to derive a 32-byte key from the env var
|
|
return scryptSync(envKey, 'gnubok-pnr-salt', 32)
|
|
}
|
|
|
|
/**
|
|
* Encrypt a personnummer for storage.
|
|
* Returns a hex string: iv + ciphertext + authTag
|
|
*/
|
|
export function encryptPersonnummer(personnummer: string): string {
|
|
const key = getEncryptionKey()
|
|
const iv = randomBytes(IV_LENGTH)
|
|
const cipher = createCipheriv(ALGORITHM, key, iv)
|
|
|
|
let encrypted = cipher.update(personnummer, 'utf8', 'hex')
|
|
encrypted += cipher.final('hex')
|
|
const authTag = cipher.getAuthTag()
|
|
|
|
return iv.toString('hex') + encrypted + authTag.toString('hex')
|
|
}
|
|
|
|
/**
|
|
* Decrypt a personnummer from storage.
|
|
*/
|
|
export function decryptPersonnummer(encrypted: string): string {
|
|
// Tolerate legacy/unencrypted rows. A raw 12-digit personnummer (written by
|
|
// a path that skipped encryptPersonnummer, e.g. the v1 REST create route
|
|
// before this fix, or a seed) would otherwise be sliced as iv/ciphertext/tag
|
|
// and throw ERR_CRYPTO_INVALID_AUTH_TAG ("Invalid authentication tag length:
|
|
// 6"), 500-ing every decrypt-on-read path (roster, salary runs, payslips,
|
|
// KU, AGI, MCP). Real ciphertext is 80 hex chars, so a 12-digit match is
|
|
// unambiguously plaintext. Return it as-is and warn so the backfill can find
|
|
// and re-encrypt it. Value is never logged. See DECISIONS.md.
|
|
if (/^\d{12}$/.test(encrypted)) {
|
|
logger.warn('decryptPersonnummer received an unencrypted personnummer; returning as-is (row needs backfill)')
|
|
return encrypted
|
|
}
|
|
|
|
const key = getEncryptionKey()
|
|
const ivHex = encrypted.slice(0, IV_LENGTH * 2)
|
|
const authTagHex = encrypted.slice(-TAG_LENGTH * 2)
|
|
const ciphertext = encrypted.slice(IV_LENGTH * 2, -TAG_LENGTH * 2)
|
|
|
|
const iv = Buffer.from(ivHex, 'hex')
|
|
const authTag = Buffer.from(authTagHex, 'hex')
|
|
|
|
const decipher = createDecipheriv(ALGORITHM, key, iv)
|
|
decipher.setAuthTag(authTag)
|
|
|
|
let decrypted = decipher.update(ciphertext, 'hex', 'utf8')
|
|
decrypted += decipher.final('utf8')
|
|
return decrypted
|
|
}
|
|
|
|
// Pure parsing, validation and formatting helpers live in ./personnummer-format
|
|
// (no Node imports) so client components (via lib/salary/tax-column.ts) can
|
|
// use them without pulling this module's `crypto` import into the bundle.
|
|
export {
|
|
calculateAge,
|
|
calculateAgeAtYearStart,
|
|
expandPersonnummerTo12,
|
|
extractBirthDate,
|
|
extractLast4,
|
|
formatPersonnummer,
|
|
maskPersonnummer,
|
|
validatePersonnummer,
|
|
} from './personnummer-format'
|
|
import { maskPersonnummer } from './personnummer-format'
|
|
|
|
/**
|
|
* Shape a raw `employees` row (or an embedded employee object) for a JSON
|
|
* response: drop every personnummer-derived column and expose the display
|
|
* form under `personnummer_masked`.
|
|
*
|
|
* Two columns must go, not one:
|
|
* - `personnummer` (the AES-256-GCM ciphertext), and
|
|
* - `personnummer_last4`: the mask is 'YYYYMMDD-XXXX', so a response that
|
|
* carries the mask AND the last four digits hands the client the full
|
|
* personnummer by simple concatenation, defeating the mask entirely.
|
|
* No UI reads employees.personnummer_last4; it exists for the DB-side
|
|
* uniqueness constraint and Skatteverket-bound documents (payslips, AGI,
|
|
* KU), which render server-side.
|
|
*
|
|
* The mask goes out under `personnummer_masked`, never under the writable
|
|
* `personnummer` key: these payloads feed edit forms, and a mask returned
|
|
* under the write key could be posted straight back into the encrypt path.
|
|
* v1, the MCP tools and lib/salary/employee-commands.ts use the `_masked`
|
|
* suffix for the same reason.
|
|
*/
|
|
export function maskEmployeeForResponse(
|
|
employee: Record<string, unknown>
|
|
): Record<string, unknown> {
|
|
const { personnummer, personnummer_last4: _last4, ...rest } = employee
|
|
return {
|
|
...rest,
|
|
personnummer_masked: maskPersonnummer(decryptPersonnummer(personnummer as string)),
|
|
}
|
|
}
|