Files
accounted/lib/reports/continuity-check.ts
T
Mattsson 32d9978f1b Fix/chrome pdf preview csp (#572)
* feat: add option to exclude year-end closing entries in SIE export and related reports

* delete docs

* fix: allow Chrome's PDF viewer in verifikat document preview

The /api/documents/:id/inline route shipped with
`object-src 'none'` in its CSP, which blocked Chrome's built-in PDF
viewer (it renders inline PDFs via an internal <embed>). Users on
Chrome saw "Det här innehållet har blockerats" when expanding a PDF
attachment in the bookkeeping view; Firefox (PDF.js) and Edge (own
viewer) were unaffected, and JPGs worked because <img> isn't subject
to object-src.

Drops the CSP for this route to the minimum needed for embeddability:
`frame-ancestors 'self'`. X-Content-Type-Options: nosniff plus the
fixed Content-Type from the handler already block MIME confusion;
X-Frame-Options: SAMEORIGIN + frame-ancestors still block clickjacking.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(auth): add webmail deep link to email confirmation screens

Mirrors Stripe's signup UX: after asking the user to verify their email,
detect their webmail provider from the domain and show a button that
opens the inbox in a new tab. Gmail gets a from:<sender> search
pre-populated; Outlook/Yahoo/iCloud/Proton open the inbox directly.
Unknown / custom domains fall back to the existing copy.

Sender address is configurable via NEXT_PUBLIC_BRANDING_AUTH_EMAIL_FROM
(default noreply@gnubok.se) so white-label installs can match their
Supabase Auth SMTP config.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(auth): unblock first-time password set for BankID users with MFA

Supabase rejects updateUser({password}) and mfa.unenroll with "AAL2 session
is required" whenever a TOTP factor is enrolled. BankID magic-link logins
produce AAL1, and middleware skips MFA enforcement for bankid_linked users,
so they had no path to AAL2 — leaving them unable to set a backup password
or disable MFA without going through the email-recovery escape hatch.

- /api/account/password: branch on app_metadata.has_password. First-time set
  writes via service.auth.admin.updateUserById (no existing credential to
  protect, AAL2 guard does not apply). Change-password keeps the user-session
  updateUser so AAL2 still fires for credential rotation.
- /mfa/verify: accept a safeReturnTo query param and route there after
  successful verify, so step-up flows can land back where they came from.
- SecuritySettings: detect the AAL2 error from both change-password and
  mfa.unenroll and redirect through /mfa/verify?returnTo=/settings/account
  instead of toasting a dead-end error.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add tests and rounding utility for öre precision in bokslut calculations

- Implemented `roundOre` function for rounding SEK amounts to two decimal places, ensuring consistent monetary calculations.
- Introduced `ORE_TOLERANCE` constant for comparing rounded amounts, facilitating invariant checks in financial entries.
- Created comprehensive tests for `roundOre`, covering typical cases, edge cases, and idempotency.
- Added year-end invariants tests to verify database-level guarantees for closing entries, ensuring they balance to the öre and reject discrepancies.
- Developed end-to-end tests for the dispositions chain, validating the correctness of calculations across various scenarios.

* fix: update PDF rendering to remove Swish QR code generation and set default to disable Swish visibility

* fix: enhance security by rejecting data URIs in safeReturnTo function tests

* fix: improve rounding logic in roundOre function and add customer_type migration

* fix: add customer_type column to customers and enforce CHECK constraint

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 22:29:41 +02:00

129 lines
4.1 KiB
TypeScript

import type { SupabaseClient } from '@supabase/supabase-js'
import type { ContinuityCheckResult, ContinuityDiscrepancy } from '@/types'
import { generateTrialBalance } from './trial-balance'
import { getOpeningBalances } from './opening-balances'
import { roundOre, ORE_TOLERANCE } from '@/lib/bokslut/rounding'
/**
* Validate that a fiscal period's opening balances (IB) match the previous
* period's closing balances (UB) for all balance sheet accounts (class 1-2).
*
* Uses the same data paths as the actual reports: generateTrialBalance() for
* UB and getOpeningBalances() for IB, so a passing check proves the reports
* are consistent.
*
* Tolerance: ORE_TOLERANCE (0.005 SEK) per account. All monetary values
* funnel through roundOre() first, so a half-öre threshold is sufficient
* to absorb float drift and any larger difference is a real discrepancy.
* (Swedish öresavrundning was abolished 2010 — this is purely IEEE 754
* hygiene, not a regulatory rounding.)
*/
export async function validateBalanceContinuity(
supabase: SupabaseClient,
companyId: string,
fiscalPeriodId: string
): Promise<ContinuityCheckResult> {
// Fetch target period
const { data: period, error: periodError } = await supabase
.from('fiscal_periods')
.select('id, name, period_start, previous_period_id, opening_balance_entry_id')
.eq('id', fiscalPeriodId)
.eq('company_id', companyId)
.single()
if (periodError || !period) {
throw new Error('Fiscal period not found')
}
// First period — nothing to compare against
if (!period.previous_period_id) {
return {
valid: true,
period_name: period.name,
previous_period_name: null,
discrepancies: [],
checked_accounts: 0,
}
}
// Fetch previous period name
const { data: prevPeriod } = await supabase
.from('fiscal_periods')
.select('id, name')
.eq('id', period.previous_period_id)
.eq('company_id', companyId)
.single()
if (!prevPeriod) {
throw new Error('Previous fiscal period not found')
}
// Previous period UB: trial balance filtered to class 1-2
const { rows: trialRows } = await generateTrialBalance(
supabase,
companyId,
prevPeriod.id
)
const previousUB = new Map<string, { net: number; name: string }>()
for (const row of trialRows) {
if (row.account_class >= 1 && row.account_class <= 2) {
const net = roundOre(row.closing_debit - row.closing_credit)
if (Math.abs(net) >= ORE_TOLERANCE) {
previousUB.set(row.account_number, { net, name: row.account_name })
}
}
}
// Current period IB
const { balances: ibBalances } = await getOpeningBalances(supabase, companyId, period)
const currentIB = new Map<string, number>()
for (const [accountNumber, bal] of ibBalances) {
// Only check balance sheet accounts
const accountClass = parseInt(accountNumber[0]) || 0
if (accountClass >= 1 && accountClass <= 2) {
const net = roundOre(bal.debit - bal.credit)
if (Math.abs(net) >= ORE_TOLERANCE) {
currentIB.set(accountNumber, net)
}
}
}
// Compare all accounts from both sides
const allAccounts = new Set([...previousUB.keys(), ...currentIB.keys()])
const discrepancies: ContinuityDiscrepancy[] = []
// Get account names for IB-only accounts
const accountNames = new Map<string, string>()
for (const [num, data] of previousUB) {
accountNames.set(num, data.name)
}
for (const accountNumber of allAccounts) {
const ubNet = previousUB.get(accountNumber)?.net ?? 0
const ibNet = currentIB.get(accountNumber) ?? 0
const difference = roundOre(ubNet - ibNet)
if (Math.abs(difference) > ORE_TOLERANCE) {
discrepancies.push({
account_number: accountNumber,
account_name: accountNames.get(accountNumber) ?? `Konto ${accountNumber}`,
previous_ub_net: ubNet,
current_ib_net: ibNet,
difference,
})
}
}
discrepancies.sort((a, b) => a.account_number.localeCompare(b.account_number))
return {
valid: discrepancies.length === 0,
period_name: period.name,
previous_period_name: prevPeriod.name,
discrepancies,
checked_accounts: allAccounts.size,
}
}