* docs: add AGPL extension exception for third-party plugins
Extensions that interact solely through the documented Extension API
(Extension interface, ExtensionContext, event bus) are not considered
derivative works and may be licensed under any terms, including
proprietary. Core modifications remain fully AGPL-3.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* docs: address review — explicit route path, precise irrevocability, revert security email
- Name the catch-all route file explicitly in the extension exception
- Clarify that irrevocability binds the copyright holder, not downstream
redistributors (per AGPL section 7 removal rights)
- Revert SECURITY.md to role-based security@arcim.io alias
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
- Replace magic-link-only login with email+password (primary) and magic link (toggle)
- Add registration page with strong password validation
- Add MFA enrollment (/mfa/enroll) with QR code and manual secret
- Add MFA verification (/mfa/verify) with 6-digit TOTP input
- Add password reset flow (/reset-password)
- Add middleware MFA enforcement gated by NEXT_PUBLIC_REQUIRE_MFA env var
- Self-hosted deployments (NEXT_PUBLIC_SELF_HOSTED=true) skip MFA entirely
- Add Security tab in Settings for password change and MFA management
- Add requireAuth() API route helper with MFA check
- Update CLAUDE.md with Authentication section and env var docs
- Update Dockerfile and docker-entrypoint.sh for new env var placeholders
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add setup.sh interactive script for guided .env configuration
- Add env var validation and placeholder detection to docker-entrypoint.sh
- Fix migration count (52 → 63) in SELF-HOSTING.md
- Align Docker image name to ghcr.io/erp-mafia/gnubok in docker-compose.yml
- Update README and SELF-HOSTING.md to reference setup.sh
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Rename migration files (039-052) from sequential to real deployed
timestamps, add 11 missing migration files that were applied directly
to production, apply invoice_delivery_note_sequences migration, and
rename placeholder files for clarity.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Replace hardcoded personal email in clear-user-data.sql with placeholder
- Change SECURITY.md contact to role-based security@arcim.io
- Add supabase/.temp/ and .claude/settings.local.json to .gitignore
- Untrack .claude/settings.local.json (keeps file on disk)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Broad update across dashboard pages, components, extensions, and lib code. Includes ESLint config additions, onboarding flow redesign, settings page refactor, help page content expansion, dead code removal, and test mock fixes. Adds dev docs and public assets.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Remove FSkattWarningCard component, related tax warning functions,
types, and thresholds. Feature was not providing enough value.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add LICENSE (AGPL-3.0-or-later), CONTRIBUTING.md, SECURITY.md, DCO, and NOTICE files.
Rewrite README for open-source audience with self-hosting instructions.
Redesign color palette to grayscale chrome theme across all components.
Add transaction uncategorize API route with tests.
Fix VAT account name mismatches in migration 052.
Improve import page with SIE file support and loading skeleton.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Fix VAT declaration ruta mappings to match SKV 4700 form correctly
(ruta 05 = total taxable sales, ruta 10/11/12 = output VAT per rate)
- Add INK2 declaration report for aktiebolag with SRU export
- Add full archive ZIP export for 7-year retention compliance
- Add AI consent gate requiring user approval before AI extension API calls
- Add DPA and privacy policy public pages
- Add audit trail API routes
- Update VAT registration threshold from 80k to 120k kr in onboarding
- Update CLAUDE.md documentation
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Remove ai-chat from extensions.config.json and docker/extensions.hosted.json
(kept in self-hosted config). Remove ChatWidget imports from dashboard layout
and root page. Reposition chat widget FAB and panel to bottom-right corner.
Regenerate extension registry.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Integrate Recapt session tracking with user identity in dashboard layout
- Remove push-notifications extension from settings, panel registry, and toggle list
- Fix journal entry preview overflow on narrow viewports
- Update transaction manual booking button label
- Clarify invoice email error message to reference env vars
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Read _PRODUCTION env var variants for APP_ID, private key, and API URL
- Handle raw base64 DER key format (production) in addition to
base64-encoded PEM (sandbox) by auto-wrapping in PEM headers
- Make API URL configurable (sandbox: api.tilisy.com, prod: api.enablebanking.com)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The previous rewrite replaced the working client-side widget with server-side
API calls that fail due to JWT auth issues, showing only 4 fallback banks
without logos. Restore the widget (handles logos, search, full bank list
natively) and add popular Swedish banks grid above for one-click connect.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Replace the external Enable Banking widget with a custom component that
fetches banks from our API, shows popular Swedish banks in a grid, provides
search filtering, and connects on click without an intermediate selection step.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
BankSelector defaulted to sandbox=true. Now reads
NEXT_PUBLIC_ENABLE_BANKING_SANDBOX env var, defaulting to false
(production mode) when not set.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Remove the Day dropdown since fiscal year always starts on the 1st.
Fix selection bug where picking month first showed nothing because the
compose function required all three values before updating the form.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add migration 051 to SET search_path = public on all 24 custom
functions, preventing search_path injection attacks
- Remove dashboard subtitle (status summary line)
- Update CLAUDE.md with new migration reference
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Update BAS account catalog with comprehensive SRU codes and K2 flags
- Add currency revaluation service with tests and API route
- Add expenses page and account deletion API
- Enhance booking templates with new patterns and improved tests
- Improve transaction categorization with template picker and description matching
- Polish dashboard, onboarding, import, and transaction UIs
- Refactor year-end service for multi-step closing
- Move SRU generator to ne-bilaga, remove standalone SRU export
- Remove unused dev docs, mock data, and extension hooks
- Add invoice delivery note sequences migration
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Expand supplier invoice module with overdue cron job, credit note journal
entries, and event emissions on approve/mark-paid/create flows. Add entity
type (EF/AB) awareness to transaction categorization UI and category
mapping logic. Add comprehensive tests for supplier-invoice-entries,
transaction-entries, and expanded API route coverage.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Repo moved from gnubok/gnubok to erp-mafia/erp-base. Updated GHCR image
reference in CI workflow and docker-compose.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The ensureInitialized() env check threw on missing SUPABASE_SERVICE_ROLE_KEY
and CRON_SECRET during Next.js page collection at Docker build time. These
server-only vars are injected at runtime, not build time.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Docker builds use __NEXT_PUBLIC_*__ sentinel values that get replaced at
runtime by docker-entrypoint.sh. These placeholders caused build failures:
- Supabase client constructor rejected invalid URL during page prerendering
- web-push VAPID init rejected invalid key format
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Multi-stage Dockerfile (Node 22 Alpine), docker-compose for self-hosted
and hosted deployments, CI workflow for GHCR publishing, runtime env var
substitution, and cron sidecar with supercronic.
Aligns hosted extension preset with dev config (enable-banking,
ai-categorization, ai-chat, email).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- #43: Improve AI categorization to use account 2350 for loan repayments
instead of incorrectly suggesting 2440 (supplier payables). Add explicit
prompt guidance distinguishing loans from supplier debts.
- #45: Change unclear invoice unit "mån" to "månad"
- #46: Enable email extension in extensions.config.json so it appears in
the marketplace and can be activated by users
- #47: Change "Makulera" to "Ta bort utkast" for draft invoices — reserve
"Makulera" terminology for proforma invoices only
- #48: Show field-level validation errors when supplier creation fails
instead of generic "Validation failed" message
- #49: Temporarily hide Leverantörer and Leverantörsfakturor from sidebar
pending module rework
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add 'unsafe-inline' to script-src so Next.js hydration scripts run
- Whitelist *.enablebanking.com in CSP (script, style, connect, img)
- Allow HTTPS images broadly for third-party bank logos
- Clear stale refresh tokens in middleware (skip on /auth callback)
- Fix login button disabled on browser autofill by reading email from form DOM
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Vercel outage resolved — re-enable Sentry build-time integration for
source map uploads when SENTRY_AUTH_TOKEN is configured.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sentry runtime capture still works via instrumentation.ts. The build-time
wrapper can be re-added once SENTRY_ORG/PROJECT/AUTH_TOKEN are set on Vercel.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Change missing extension env vars from throw to log.warn (graceful degradation)
- Move initialized flag after all init steps complete
- Add error.tsx and loading.tsx for dashboard error boundaries
- Fix cron route auth header checks
- Add ensureInitialized() to journal entry reverse and invoice mark-paid/sent routes
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Consolidate the standalone user-description-match extension into ai-categorization,
adding an AI description analyzer that provides account/VAT suggestions alongside
template matching. The describe transaction dialog now shows AI suggestions with
confidence scores and supports both template-based and AI-based booking.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Reorganize reports page from flat 11-tab bar into 4-column categorized
grid (Bokslut, Skatt & moms, Huvudböcker, Avstämning)
- Move Import from Övrigt to Finans nav group for better discoverability
- Merge standalone Marketplace link into Tillägg section as "Utforska fler..."
- Rename abbreviated "Lev.fakturor" to full "Leverantörsfakturor"
- Add uncategorized transaction count badge to nav (desktop pill + mobile dot)
- Strengthen credit note confirmation with destructive styling and
type-to-confirm pattern requiring exact invoice number
- Clarify invoice send vs mark-sent with "Skickad manuellt" label,
visual hierarchy, and explanatory helper text
- Show Banking and Notifications settings tabs always, with placeholder
message and link to extensions when not enabled
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add currency-utils module for SEK conversion with exchange rates
- Refactor createJournalEntry to use draft+commit flow preventing voucher number gaps (BFL 5 kap. 7§)
- Add foreign currency support to invoice entries with per-line SEK conversion
- Centralize category-to-account mapping into single source of truth
- Refactor invoice inbox to use shared document analyzer with document type classification (receipt, supplier invoice, government letter)
- Update mapping engine, supplier invoice entries, and transaction entries
- Fix report component rendering issues
- Add new validation schemas and tests
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add inline new supplier form in InboxDetailDialog with pre-populated
fields from AI extraction
- Support new_supplier payload in confirm endpoint to create suppliers
with user-editable fields (type, org number, bankgiro, etc.)
- Improve line item amount calculation using cross-checked extraction totals
- Remove unused estimateProductValue function and LangChain imports
from receipt-analyzer
- Add debug logging to invoice inbox confirm flow
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Enable receipt-ocr, ai-categorization, ai-chat, push-notifications,
invoice-inbox, calendar, enable-banking, email, and
user-description-match in extensions.config.json.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The test expected empty BAS reference to leave 1510 unmapped, but the
bas_range fallback correctly self-maps valid 4-digit BAS accounts with
confidence 0.9.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Remove all sector-specific extensions (construction, ecommerce, export,
hotel, restaurant, tech) — only general-purpose extensions remain
- Move NE-bilaga and SRU export from extensions to core reports (lib/reports/)
- Move moms-box-mapping from extensions/export/shared to lib/vat/
- Replace per-extension API routes with catch-all dispatcher
(app/api/extensions/ext/[...path]/route.ts)
- Add manifest.json for each extension with metadata, env vars, and deps
- Add api-routes.ts pattern for extension-defined API endpoints
- Add code generation scripts (generate-extension-registry, create-extension)
- Add extensions.config.json for opt-in extension loading
- Add extensions.schema.json for config validation
- Add email service interface with noop default (lib/email/service.ts)
- Add CI workflow (core-build.yml) to verify core builds with zero extensions
- Add migration 045: expand account_type CHECK for untaxed_reserves
- Update CLAUDE.md with comprehensive extension system documentation
- Update all report engines and bookkeeping services for new imports
- Clean up extensions.schema.json to only list existing extensions
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Expand BAS reference from ~180 to ~1,276 accounts (full BAS Kontoplan 2026)
with K2 exclusion flags, per-class data files, and computed SRU codes
- Evolve invoice inbox into unified document inbox handling invoices, receipts,
and government letters with AI-powered classification (Claude Haiku Vision)
- Add multi-pass document-to-transaction matching engine with greedy assignment
for both supplier invoices (reference/amount/date/name) and receipts
(weighted amount/merchant/date scoring)
- Add supplier invoice matching in transaction ingest pipeline
- Inject booking template suggestions into AI extraction prompts
- Surface matched documents in swipe categorization UI with one-tap booking
- Auto-activate missing BAS accounts during SIE import against full reference
- Add K2 filter toggle in Chart of Accounts manager
- Add receipt confirmation route with BFNAR representation fields
- Add database migrations for K2 support and document matching columns
- Remove obsolete extension migration scripts
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Reduce booking template library to eliminate duplicate suggestions when
users describe transactions. Templates with identical accounting treatment
(same account + VAT) are merged, keywords consolidated, and the entire
subscriptions group is eliminated. Also includes prior work on reports,
extensions, and transaction improvements.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Uncomment Enable Banking extension in loader (now registered at runtime)
- Add subscriptionNotice field to ExtensionDefinition type
- Show confirmation dialog when enabling extensions with subscription requirements
- Fix Settings banking tab: toggle-aware visibility, URL-addressable tabs,
BankSelector widget, correct API paths (/api/extensions/ext/enable-banking/*)
- Replace inline bank connection cards with BankConnectionStatus component
- Add actionable link to Settings from EnableBankingWorkspace
- Update CLAUDE.md with latest architecture docs
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>