- Replace magic-link-only login with email+password (primary) and magic link (toggle)
- Add registration page with strong password validation
- Add MFA enrollment (/mfa/enroll) with QR code and manual secret
- Add MFA verification (/mfa/verify) with 6-digit TOTP input
- Add password reset flow (/reset-password)
- Add middleware MFA enforcement gated by NEXT_PUBLIC_REQUIRE_MFA env var
- Self-hosted deployments (NEXT_PUBLIC_SELF_HOSTED=true) skip MFA entirely
- Add Security tab in Settings for password change and MFA management
- Add requireAuth() API route helper with MFA check
- Update CLAUDE.md with Authentication section and env var docs
- Update Dockerfile and docker-entrypoint.sh for new env var placeholders
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Broad update across dashboard pages, components, extensions, and lib code. Includes ESLint config additions, onboarding flow redesign, settings page refactor, help page content expansion, dead code removal, and test mock fixes. Adds dev docs and public assets.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Remove FSkattWarningCard component, related tax warning functions,
types, and thresholds. Feature was not providing enough value.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add LICENSE (AGPL-3.0-or-later), CONTRIBUTING.md, SECURITY.md, DCO, and NOTICE files.
Rewrite README for open-source audience with self-hosting instructions.
Redesign color palette to grayscale chrome theme across all components.
Add transaction uncategorize API route with tests.
Fix VAT account name mismatches in migration 052.
Improve import page with SIE file support and loading skeleton.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Fix VAT declaration ruta mappings to match SKV 4700 form correctly
(ruta 05 = total taxable sales, ruta 10/11/12 = output VAT per rate)
- Add INK2 declaration report for aktiebolag with SRU export
- Add full archive ZIP export for 7-year retention compliance
- Add AI consent gate requiring user approval before AI extension API calls
- Add DPA and privacy policy public pages
- Add audit trail API routes
- Update VAT registration threshold from 80k to 120k kr in onboarding
- Update CLAUDE.md documentation
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Remove ai-chat from extensions.config.json and docker/extensions.hosted.json
(kept in self-hosted config). Remove ChatWidget imports from dashboard layout
and root page. Reposition chat widget FAB and panel to bottom-right corner.
Regenerate extension registry.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Integrate Recapt session tracking with user identity in dashboard layout
- Remove push-notifications extension from settings, panel registry, and toggle list
- Fix journal entry preview overflow on narrow viewports
- Update transaction manual booking button label
- Clarify invoice email error message to reference env vars
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Update BAS account catalog with comprehensive SRU codes and K2 flags
- Add currency revaluation service with tests and API route
- Add expenses page and account deletion API
- Enhance booking templates with new patterns and improved tests
- Improve transaction categorization with template picker and description matching
- Polish dashboard, onboarding, import, and transaction UIs
- Refactor year-end service for multi-step closing
- Move SRU generator to ne-bilaga, remove standalone SRU export
- Remove unused dev docs, mock data, and extension hooks
- Add invoice delivery note sequences migration
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Expand supplier invoice module with overdue cron job, credit note journal
entries, and event emissions on approve/mark-paid/create flows. Add entity
type (EF/AB) awareness to transaction categorization UI and category
mapping logic. Add comprehensive tests for supplier-invoice-entries,
transaction-entries, and expanded API route coverage.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The ensureInitialized() env check threw on missing SUPABASE_SERVICE_ROLE_KEY
and CRON_SECRET during Next.js page collection at Docker build time. These
server-only vars are injected at runtime, not build time.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Docker builds use __NEXT_PUBLIC_*__ sentinel values that get replaced at
runtime by docker-entrypoint.sh. These placeholders caused build failures:
- Supabase client constructor rejected invalid URL during page prerendering
- web-push VAPID init rejected invalid key format
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- #43: Improve AI categorization to use account 2350 for loan repayments
instead of incorrectly suggesting 2440 (supplier payables). Add explicit
prompt guidance distinguishing loans from supplier debts.
- #45: Change unclear invoice unit "mån" to "månad"
- #46: Enable email extension in extensions.config.json so it appears in
the marketplace and can be activated by users
- #47: Change "Makulera" to "Ta bort utkast" for draft invoices — reserve
"Makulera" terminology for proforma invoices only
- #48: Show field-level validation errors when supplier creation fails
instead of generic "Validation failed" message
- #49: Temporarily hide Leverantörer and Leverantörsfakturor from sidebar
pending module rework
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add 'unsafe-inline' to script-src so Next.js hydration scripts run
- Whitelist *.enablebanking.com in CSP (script, style, connect, img)
- Allow HTTPS images broadly for third-party bank logos
- Clear stale refresh tokens in middleware (skip on /auth callback)
- Fix login button disabled on browser autofill by reading email from form DOM
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Change missing extension env vars from throw to log.warn (graceful degradation)
- Move initialized flag after all init steps complete
- Add error.tsx and loading.tsx for dashboard error boundaries
- Fix cron route auth header checks
- Add ensureInitialized() to journal entry reverse and invoice mark-paid/sent routes
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Consolidate the standalone user-description-match extension into ai-categorization,
adding an AI description analyzer that provides account/VAT suggestions alongside
template matching. The describe transaction dialog now shows AI suggestions with
confidence scores and supports both template-based and AI-based booking.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add currency-utils module for SEK conversion with exchange rates
- Refactor createJournalEntry to use draft+commit flow preventing voucher number gaps (BFL 5 kap. 7§)
- Add foreign currency support to invoice entries with per-line SEK conversion
- Centralize category-to-account mapping into single source of truth
- Refactor invoice inbox to use shared document analyzer with document type classification (receipt, supplier invoice, government letter)
- Update mapping engine, supplier invoice entries, and transaction entries
- Fix report component rendering issues
- Add new validation schemas and tests
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Enable receipt-ocr, ai-categorization, ai-chat, push-notifications,
invoice-inbox, calendar, enable-banking, email, and
user-description-match in extensions.config.json.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The test expected empty BAS reference to leave 1510 unmapped, but the
bas_range fallback correctly self-maps valid 4-digit BAS accounts with
confidence 0.9.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Remove all sector-specific extensions (construction, ecommerce, export,
hotel, restaurant, tech) — only general-purpose extensions remain
- Move NE-bilaga and SRU export from extensions to core reports (lib/reports/)
- Move moms-box-mapping from extensions/export/shared to lib/vat/
- Replace per-extension API routes with catch-all dispatcher
(app/api/extensions/ext/[...path]/route.ts)
- Add manifest.json for each extension with metadata, env vars, and deps
- Add api-routes.ts pattern for extension-defined API endpoints
- Add code generation scripts (generate-extension-registry, create-extension)
- Add extensions.config.json for opt-in extension loading
- Add extensions.schema.json for config validation
- Add email service interface with noop default (lib/email/service.ts)
- Add CI workflow (core-build.yml) to verify core builds with zero extensions
- Add migration 045: expand account_type CHECK for untaxed_reserves
- Update CLAUDE.md with comprehensive extension system documentation
- Update all report engines and bookkeeping services for new imports
- Clean up extensions.schema.json to only list existing extensions
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Expand BAS reference from ~180 to ~1,276 accounts (full BAS Kontoplan 2026)
with K2 exclusion flags, per-class data files, and computed SRU codes
- Evolve invoice inbox into unified document inbox handling invoices, receipts,
and government letters with AI-powered classification (Claude Haiku Vision)
- Add multi-pass document-to-transaction matching engine with greedy assignment
for both supplier invoices (reference/amount/date/name) and receipts
(weighted amount/merchant/date scoring)
- Add supplier invoice matching in transaction ingest pipeline
- Inject booking template suggestions into AI extraction prompts
- Surface matched documents in swipe categorization UI with one-tap booking
- Auto-activate missing BAS accounts during SIE import against full reference
- Add K2 filter toggle in Chart of Accounts manager
- Add receipt confirmation route with BFNAR representation fields
- Add database migrations for K2 support and document matching columns
- Remove obsolete extension migration scripts
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Reduce booking template library to eliminate duplicate suggestions when
users describe transactions. Templates with identical accounting treatment
(same account + VAT) are merged, keywords consolidated, and the entire
subscriptions group is eliminated. Also includes prior work on reports,
extensions, and transaction improvements.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Uncomment Enable Banking extension in loader (now registered at runtime)
- Add subscriptionNotice field to ExtensionDefinition type
- Show confirmation dialog when enabling extensions with subscription requirements
- Fix Settings banking tab: toggle-aware visibility, URL-addressable tabs,
BankSelector widget, correct API paths (/api/extensions/ext/enable-banking/*)
- Replace inline bank connection cards with BankConnectionStatus component
- Add actionable link to Settings from EnableBankingWorkspace
- Update CLAUDE.md with latest architecture docs
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add journal entry preview, human-readable account names, auto-apply VAT,
fallback template suggestions, example prompts, invoice match comparison,
and batch result feedback. Also includes user-description-match extension,
describe/batch-describe API routes, improved AI categorization with multi-
suggestion support, and template embedding search.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add export & utrikeshandel sector to the extension system with BAS
accounts (3105, 3108, 3109, 3521, 3522), sector metadata, icon
imports, workspace registry entries, and design document.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Fix buildLineInserts() using wrong DB column names (cost_center_id → cost_center,
project_id → project) and add missing tax_code field
- Replace transaction-based dashboard income/expense with journal-entry-based
calculation using account classes (3xxx revenue, 4-7xxx expenses)
- Add email/phone fields to CompanySettings type, validate RESEND_FROM_EMAIL
in isResendConfigured(), remove unsafe type casts in invoice send/reminders
- Always auto-fill line description from account name in JournalEntryForm
- Reorder expense lines in TransactionBookingDialog so 1930 is always first row
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add auto-detecting CSV parsers for Länsförsäkringar, ICA Banken, Skandia,
and Lunar. Refine SEB detection to avoid false matches. Update bank file
upload UI with new bank options and export instructions. Include booking
templates, improved AI categorization, and transaction review enhancements.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Auto-create documents storage bucket on first upload. Default legacy general
extensions to enabled when no toggle row exists. Add ChatWidget to dashboard
root page with open-ai-chat event support and AI assistant quick action.
Add ensureInitialized to supplier invoices route for event emission.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add rollback logic to storno-service correctEntry to restore ledger
consistency if step 2 fails after reversal. Add correction API route at
/api/bookkeeping/journal-entries/[id]/correct. Add CorrectionEntryDialog
component and correction button to JournalEntryList.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add validation for non-empty debit/credit accounts before creating journal
entries. Generate fiktiv moms lines (2645/2614) for EU reverse charge expenses.
Change default unmapped expense account from 6900 to 6991. Add tests for
reverse charge handling and exhaustive category mapping coverage.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Fix calculateVat/calculateTotal to use proper monetary rounding. Add
getVatSummaryFromItems helper for deriving VAT labels from mixed-rate items.
Update invoice preview, review, and detail pages to show per-rate VAT
breakdown instead of a single aggregated rate.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Fix monthly-breakdown to use actual column names (debit_amount/credit_amount),
include class 8 financial items, and use year-aware month keys for non-calendar
fiscal years. Add period/status filtering to AR and supplier reconciliation
queries. Exclude reversed entries from general ledger. Fix SIE export rounding.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Enrich ExtensionContext with supabase, emit(), settings, storage, log,
and services so extensions can receive everything through dependency
injection instead of importing core modules directly.
- Add context factory and inject context into event handlers via registry
- Move supplier invoice journal entry creation to core event handler
- Add services.ingestTransactions to ExtensionContext for enable-banking
- Create catch-all API route for extension-declared apiRoutes
- Migrate 5 extensions to accept context with dynamic import fallbacks
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>