* fix: prevent P&L accumulation when importing multi-year SIE files
The opening-balance fallback summed all prior journal lines without
distinguishing balance sheet (class 1-2) from P&L (class 3-8). When
users imported one SIE file per year without running year-end closing
between them, resultatkonton accumulated across years instead of
resetting at each räkenskapsårsskifte. Reported by a customer.
Skip class 3-8 in the fallback path. P&L accounts must reset to zero
each fiscal year (årets resultat → 2099 → equity).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix: only import unpaid supplier invoices from Fortnox
Fortnox's /supplierinvoices list endpoint doesn't reliably expose
FullyPaid, which caused historic paid invoices to be imported as
unpaid. Switch to the ?filter=unpaid query and surface that scope
in the migration options UI.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* feat: add processing_history table for behandlingshistorik
Append-only event log per BFNAR 2013:2 kap 8. Includes:
- processing_history table with seq, correlation/causation chaining,
aggregate (Document/BankTransaction/MatchProposal/Verifikation/etc.),
open event_type validated against processing_event_types registry.
- Immutability via audit_log_immutable trigger (no UPDATE/DELETE).
- RLS scoped to user_company_ids; writes via service role only.
- appendProcessingHistory() helper with PII guard rejecting payloads
containing personnummer/orgnr patterns.
- Shared TS types in types/index.ts.
No consumers wired yet — this is the persistence layer only.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* chore: add swedish-project-accounting skill
Reference skill covering projektredovisning: dimensional tagging,
WIP accounting, K2/K3 revenue recognition (successiv vinstavräkning,
färdigställandemetoden), entreprenadavtal, BAS patterns (1470,
1620, 2420, 2450, 4970), and SIE4 #DIM 6 encoding.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix: rename processing_history migration to avoid timestamp collision
Main already has 20260418120000_allow_retroactive_first_fiscal_year.sql
from #265. Bumping this migration's timestamp to 20260418130000 to
keep schema_migrations.version unique.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix: address Greptile review on processing_history
- Add BEFORE DELETE immutability trigger so the service role can't
silently remove rows. Mirrors the pattern from migration 014
(audit_log_no_update + audit_log_no_delete) and satisfies the
immutability claim in BFNAR 2013:2 kap 8. Delivered as a follow-up
migration since the original was already applied in some envs.
- Tighten PII patterns with \b word boundaries to avoid false
positives on Bankgiro numbers (123456-7890) and invoice references
like 202312-1234.
- Extend PII validation to actor.label, which previously bypassed
the payload guard despite the docblock explicitly forbidding
names/emails/personnummer there.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>