* feat(salary): allow recalling approval on a salary run (approved → review)
An approved run was a dead end: the only forward path was paid → booked,
so a wrong salary snapshot (e.g. stale employee monthly pay) could not be
fixed without paying and then storno-correcting. Approval is an internal
control point — nothing legally binding happens until payment, booking,
or AGI filing — so recalling it is allowed until the AGI reaches
Skatteverket.
- POST /api/salary/runs/[id]/unapprove: approved → review; clears
approved_by/at and payment-file tracking; deletes generated-but-unfiled
AGI declarations (stale XML must not stay exportable); 409 once the
AGI is pending_signature/submitted/accepted — correction AGI (same
specifikationsnummer) is the lawful path then.
- New salary_run.approval_reverted event for the audit trail.
- "Ångra godkännande" secondary action on the run page with a
consequence-aware confirm (payment file possibly at the bank, sent
payslips, generated AGI), sv + en.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(salary): delete stale AGI after the unapprove transition, not before
Bot-review triage on #894: the declaration delete ran before the
optimistic status update, so a failed transition (concurrent flip,
transient error) would have destroyed the generated AGI while the run
stayed approved. Flip the run first; a delete failure afterwards is
harmless (agi_generated_at is already null, regeneration upserts over
the orphan). Also record the deleted declaration id in the
approval_reverted event payload, and warn in the confirm dialog that a
manually filed AGI requires a correction declaration instead.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(salary): close the unapprove TOCTOU on concurrent AGI filing
Superagent P2 + compliance-bot round 2 on #894: AGI submission is
allowed from approved (also out-of-band via MCP/public API), so a
filing could land between the route's read and its update, and the
route would flip the run and delete a submitted declaration.
- Re-assert agi_submitted_at IS NULL inside the optimistic update
filter, not just on the stale read.
- Guard the declaration delete with the same status filter so it
no-ops if the declaration advanced since the read; log a miss.
- Zero-row update (PGRST116) now returns 409 "status har ändrats"
instead of a generic 500.
- The approval_reverted event only reports deletedAgiDeclarationId
when a row was actually deleted.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>