32d9978f1b
* feat: add option to exclude year-end closing entries in SIE export and related reports * delete docs * fix: allow Chrome's PDF viewer in verifikat document preview The /api/documents/:id/inline route shipped with `object-src 'none'` in its CSP, which blocked Chrome's built-in PDF viewer (it renders inline PDFs via an internal <embed>). Users on Chrome saw "Det här innehållet har blockerats" when expanding a PDF attachment in the bookkeeping view; Firefox (PDF.js) and Edge (own viewer) were unaffected, and JPGs worked because <img> isn't subject to object-src. Drops the CSP for this route to the minimum needed for embeddability: `frame-ancestors 'self'`. X-Content-Type-Options: nosniff plus the fixed Content-Type from the handler already block MIME confusion; X-Frame-Options: SAMEORIGIN + frame-ancestors still block clickjacking. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * feat(auth): add webmail deep link to email confirmation screens Mirrors Stripe's signup UX: after asking the user to verify their email, detect their webmail provider from the domain and show a button that opens the inbox in a new tab. Gmail gets a from:<sender> search pre-populated; Outlook/Yahoo/iCloud/Proton open the inbox directly. Unknown / custom domains fall back to the existing copy. Sender address is configurable via NEXT_PUBLIC_BRANDING_AUTH_EMAIL_FROM (default noreply@gnubok.se) so white-label installs can match their Supabase Auth SMTP config. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(auth): unblock first-time password set for BankID users with MFA Supabase rejects updateUser({password}) and mfa.unenroll with "AAL2 session is required" whenever a TOTP factor is enrolled. BankID magic-link logins produce AAL1, and middleware skips MFA enforcement for bankid_linked users, so they had no path to AAL2 — leaving them unable to set a backup password or disable MFA without going through the email-recovery escape hatch. - /api/account/password: branch on app_metadata.has_password. First-time set writes via service.auth.admin.updateUserById (no existing credential to protect, AAL2 guard does not apply). Change-password keeps the user-session updateUser so AAL2 still fires for credential rotation. - /mfa/verify: accept a safeReturnTo query param and route there after successful verify, so step-up flows can land back where they came from. - SecuritySettings: detect the AAL2 error from both change-password and mfa.unenroll and redirect through /mfa/verify?returnTo=/settings/account instead of toasting a dead-end error. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * Add tests and rounding utility for öre precision in bokslut calculations - Implemented `roundOre` function for rounding SEK amounts to two decimal places, ensuring consistent monetary calculations. - Introduced `ORE_TOLERANCE` constant for comparing rounded amounts, facilitating invariant checks in financial entries. - Created comprehensive tests for `roundOre`, covering typical cases, edge cases, and idempotency. - Added year-end invariants tests to verify database-level guarantees for closing entries, ensuring they balance to the öre and reject discrepancies. - Developed end-to-end tests for the dispositions chain, validating the correctness of calculations across various scenarios. * fix: update PDF rendering to remove Swish QR code generation and set default to disable Swish visibility * fix: enhance security by rejecting data URIs in safeReturnTo function tests * fix: improve rounding logic in roundOre function and add customer_type migration * fix: add customer_type column to customers and enforce CHECK constraint --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
129 lines
4.1 KiB
TypeScript
129 lines
4.1 KiB
TypeScript
import type { SupabaseClient } from '@supabase/supabase-js'
|
|
import type { ContinuityCheckResult, ContinuityDiscrepancy } from '@/types'
|
|
import { generateTrialBalance } from './trial-balance'
|
|
import { getOpeningBalances } from './opening-balances'
|
|
import { roundOre, ORE_TOLERANCE } from '@/lib/bokslut/rounding'
|
|
|
|
/**
|
|
* Validate that a fiscal period's opening balances (IB) match the previous
|
|
* period's closing balances (UB) for all balance sheet accounts (class 1-2).
|
|
*
|
|
* Uses the same data paths as the actual reports: generateTrialBalance() for
|
|
* UB and getOpeningBalances() for IB, so a passing check proves the reports
|
|
* are consistent.
|
|
*
|
|
* Tolerance: ORE_TOLERANCE (0.005 SEK) per account. All monetary values
|
|
* funnel through roundOre() first, so a half-öre threshold is sufficient
|
|
* to absorb float drift and any larger difference is a real discrepancy.
|
|
* (Swedish öresavrundning was abolished 2010 — this is purely IEEE 754
|
|
* hygiene, not a regulatory rounding.)
|
|
*/
|
|
export async function validateBalanceContinuity(
|
|
supabase: SupabaseClient,
|
|
companyId: string,
|
|
fiscalPeriodId: string
|
|
): Promise<ContinuityCheckResult> {
|
|
// Fetch target period
|
|
const { data: period, error: periodError } = await supabase
|
|
.from('fiscal_periods')
|
|
.select('id, name, period_start, previous_period_id, opening_balance_entry_id')
|
|
.eq('id', fiscalPeriodId)
|
|
.eq('company_id', companyId)
|
|
.single()
|
|
|
|
if (periodError || !period) {
|
|
throw new Error('Fiscal period not found')
|
|
}
|
|
|
|
// First period — nothing to compare against
|
|
if (!period.previous_period_id) {
|
|
return {
|
|
valid: true,
|
|
period_name: period.name,
|
|
previous_period_name: null,
|
|
discrepancies: [],
|
|
checked_accounts: 0,
|
|
}
|
|
}
|
|
|
|
// Fetch previous period name
|
|
const { data: prevPeriod } = await supabase
|
|
.from('fiscal_periods')
|
|
.select('id, name')
|
|
.eq('id', period.previous_period_id)
|
|
.eq('company_id', companyId)
|
|
.single()
|
|
|
|
if (!prevPeriod) {
|
|
throw new Error('Previous fiscal period not found')
|
|
}
|
|
|
|
// Previous period UB: trial balance filtered to class 1-2
|
|
const { rows: trialRows } = await generateTrialBalance(
|
|
supabase,
|
|
companyId,
|
|
prevPeriod.id
|
|
)
|
|
|
|
const previousUB = new Map<string, { net: number; name: string }>()
|
|
for (const row of trialRows) {
|
|
if (row.account_class >= 1 && row.account_class <= 2) {
|
|
const net = roundOre(row.closing_debit - row.closing_credit)
|
|
if (Math.abs(net) >= ORE_TOLERANCE) {
|
|
previousUB.set(row.account_number, { net, name: row.account_name })
|
|
}
|
|
}
|
|
}
|
|
|
|
// Current period IB
|
|
const { balances: ibBalances } = await getOpeningBalances(supabase, companyId, period)
|
|
|
|
const currentIB = new Map<string, number>()
|
|
for (const [accountNumber, bal] of ibBalances) {
|
|
// Only check balance sheet accounts
|
|
const accountClass = parseInt(accountNumber[0]) || 0
|
|
if (accountClass >= 1 && accountClass <= 2) {
|
|
const net = roundOre(bal.debit - bal.credit)
|
|
if (Math.abs(net) >= ORE_TOLERANCE) {
|
|
currentIB.set(accountNumber, net)
|
|
}
|
|
}
|
|
}
|
|
|
|
// Compare all accounts from both sides
|
|
const allAccounts = new Set([...previousUB.keys(), ...currentIB.keys()])
|
|
const discrepancies: ContinuityDiscrepancy[] = []
|
|
|
|
// Get account names for IB-only accounts
|
|
const accountNames = new Map<string, string>()
|
|
for (const [num, data] of previousUB) {
|
|
accountNames.set(num, data.name)
|
|
}
|
|
|
|
for (const accountNumber of allAccounts) {
|
|
const ubNet = previousUB.get(accountNumber)?.net ?? 0
|
|
const ibNet = currentIB.get(accountNumber) ?? 0
|
|
const difference = roundOre(ubNet - ibNet)
|
|
|
|
if (Math.abs(difference) > ORE_TOLERANCE) {
|
|
discrepancies.push({
|
|
account_number: accountNumber,
|
|
account_name: accountNames.get(accountNumber) ?? `Konto ${accountNumber}`,
|
|
previous_ub_net: ubNet,
|
|
current_ib_net: ibNet,
|
|
difference,
|
|
})
|
|
}
|
|
}
|
|
|
|
discrepancies.sort((a, b) => a.account_number.localeCompare(b.account_number))
|
|
|
|
return {
|
|
valid: discrepancies.length === 0,
|
|
period_name: period.name,
|
|
previous_period_name: prevPeriod.name,
|
|
discrepancies,
|
|
checked_accounts: allAccounts.size,
|
|
}
|
|
}
|