Files
accounted/lib/reports/__tests__/source-lines.test.ts
T
Mattsson 32d9978f1b Fix/chrome pdf preview csp (#572)
* feat: add option to exclude year-end closing entries in SIE export and related reports

* delete docs

* fix: allow Chrome's PDF viewer in verifikat document preview

The /api/documents/:id/inline route shipped with
`object-src 'none'` in its CSP, which blocked Chrome's built-in PDF
viewer (it renders inline PDFs via an internal <embed>). Users on
Chrome saw "Det här innehållet har blockerats" when expanding a PDF
attachment in the bookkeeping view; Firefox (PDF.js) and Edge (own
viewer) were unaffected, and JPGs worked because <img> isn't subject
to object-src.

Drops the CSP for this route to the minimum needed for embeddability:
`frame-ancestors 'self'`. X-Content-Type-Options: nosniff plus the
fixed Content-Type from the handler already block MIME confusion;
X-Frame-Options: SAMEORIGIN + frame-ancestors still block clickjacking.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(auth): add webmail deep link to email confirmation screens

Mirrors Stripe's signup UX: after asking the user to verify their email,
detect their webmail provider from the domain and show a button that
opens the inbox in a new tab. Gmail gets a from:<sender> search
pre-populated; Outlook/Yahoo/iCloud/Proton open the inbox directly.
Unknown / custom domains fall back to the existing copy.

Sender address is configurable via NEXT_PUBLIC_BRANDING_AUTH_EMAIL_FROM
(default noreply@gnubok.se) so white-label installs can match their
Supabase Auth SMTP config.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(auth): unblock first-time password set for BankID users with MFA

Supabase rejects updateUser({password}) and mfa.unenroll with "AAL2 session
is required" whenever a TOTP factor is enrolled. BankID magic-link logins
produce AAL1, and middleware skips MFA enforcement for bankid_linked users,
so they had no path to AAL2 — leaving them unable to set a backup password
or disable MFA without going through the email-recovery escape hatch.

- /api/account/password: branch on app_metadata.has_password. First-time set
  writes via service.auth.admin.updateUserById (no existing credential to
  protect, AAL2 guard does not apply). Change-password keeps the user-session
  updateUser so AAL2 still fires for credential rotation.
- /mfa/verify: accept a safeReturnTo query param and route there after
  successful verify, so step-up flows can land back where they came from.
- SecuritySettings: detect the AAL2 error from both change-password and
  mfa.unenroll and redirect through /mfa/verify?returnTo=/settings/account
  instead of toasting a dead-end error.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Add tests and rounding utility for öre precision in bokslut calculations

- Implemented `roundOre` function for rounding SEK amounts to two decimal places, ensuring consistent monetary calculations.
- Introduced `ORE_TOLERANCE` constant for comparing rounded amounts, facilitating invariant checks in financial entries.
- Created comprehensive tests for `roundOre`, covering typical cases, edge cases, and idempotency.
- Added year-end invariants tests to verify database-level guarantees for closing entries, ensuring they balance to the öre and reject discrepancies.
- Developed end-to-end tests for the dispositions chain, validating the correctness of calculations across various scenarios.

* fix: update PDF rendering to remove Swish QR code generation and set default to disable Swish visibility

* fix: enhance security by rejecting data URIs in safeReturnTo function tests

* fix: improve rounding logic in roundOre function and add customer_type migration

* fix: add customer_type column to customers and enforce CHECK constraint

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 22:29:41 +02:00

147 lines
4.6 KiB
TypeScript

/**
* Compile-time checks for the report drilldown source-line contract plus
* runtime tests for the createSourceLoader helper used by the expansion UI.
*/
import { describe, it, expect, vi } from 'vitest'
import type {
ReportSourceLine,
ReportSourceFetcher,
ReportSourceResponse,
SourceLoaderState,
} from '@/lib/reports/source-lines'
import { createSourceLoader } from '@/lib/reports/source-lines'
describe('source-lines types', () => {
it('ReportSourceLine has the documented fields', () => {
const line: ReportSourceLine = {
journal_entry_id: 'je-1',
voucher_number: 1,
voucher_series: 'A',
date: '2026-01-01',
description: 'desc',
debit: 0,
credit: 100,
}
expect(line.journal_entry_id).toBe('je-1')
expect(line.voucher_series + line.voucher_number).toBe('A1')
})
it('ReportSourceFetcher resolves a lines+cursor envelope', async () => {
const fetcher: ReportSourceFetcher = async () => ({
lines: [],
next_cursor: null,
})
const result = await fetcher()
expect(result.lines).toEqual([])
expect(result.next_cursor).toBeNull()
})
it('ReportSourceResponse accepts every keyed report variant', () => {
const tb: ReportSourceResponse = {
account_number: '1930',
account_name: 'Företagskonto',
lines: [],
next_cursor: null,
}
const vat: ReportSourceResponse = {
ruta: 'ruta10',
lines: [],
next_cursor: null,
}
const ar: ReportSourceResponse = {
customer_id: 'c-1',
lines: [],
next_cursor: null,
}
const sup: ReportSourceResponse = {
supplier_id: 's-1',
lines: [],
next_cursor: null,
}
expect(tb.lines).toEqual(vat.lines)
expect(ar.lines).toEqual(sup.lines)
})
})
describe('createSourceLoader', () => {
const makeLine = (
overrides: Partial<ReportSourceLine> = {}
): ReportSourceLine => ({
journal_entry_id: 'je-1',
voucher_number: 1,
voucher_series: 'A',
date: '2026-01-01',
description: 'desc',
debit: 100,
credit: 0,
...overrides,
})
it('starts in idle state and transitions through loading → success', async () => {
const fetcher: ReportSourceFetcher = vi
.fn()
.mockResolvedValueOnce({ lines: [makeLine()], next_cursor: null })
const states: SourceLoaderState[] = []
const loader = createSourceLoader(fetcher, (s) => states.push({ ...s }))
expect(loader.getState()).toEqual({ lines: null, loading: false, error: null })
await loader.load()
expect(states[0]).toEqual({ lines: null, loading: true, error: null })
const last = states[states.length - 1]
expect(last.loading).toBe(false)
expect(last.error).toBeNull()
expect(last.lines).toHaveLength(1)
expect(last.lines?.[0].voucher_number).toBe(1)
})
it('captures fetcher errors and surfaces them as Swedish messages', async () => {
const fetcher: ReportSourceFetcher = vi
.fn()
.mockRejectedValueOnce(new Error('boom'))
const loader = createSourceLoader(fetcher, () => {})
await loader.load()
const state = loader.getState()
expect(state.loading).toBe(false)
expect(state.error).toBe('boom')
expect(state.lines).toBeNull()
})
it('falls back to a Swedish error when the rejection is not an Error', async () => {
const fetcher: ReportSourceFetcher = vi.fn().mockRejectedValueOnce('nope')
const loader = createSourceLoader(fetcher, () => {})
await loader.load()
expect(loader.getState().error).toBe('Kunde inte hämta verifikat')
})
it('caches results: a second load() is a no-op', async () => {
const fetcher: ReportSourceFetcher = vi
.fn()
.mockResolvedValue({ lines: [makeLine()], next_cursor: null })
const loader = createSourceLoader(fetcher, () => {})
await loader.load()
await loader.load()
await loader.load()
expect(fetcher).toHaveBeenCalledTimes(1)
})
it('does not start a second concurrent load while one is in flight', async () => {
let resolveFetch: (value: { lines: ReportSourceLine[]; next_cursor: null }) => void = () => {}
const pending = new Promise<{ lines: ReportSourceLine[]; next_cursor: null }>(
(r) => { resolveFetch = r }
)
const fetcher: ReportSourceFetcher = vi.fn().mockReturnValueOnce(pending)
const loader = createSourceLoader(fetcher, () => {})
const first = loader.load()
// Second invocation before resolution should be a no-op.
const second = loader.load()
resolveFetch({ lines: [], next_cursor: null })
await Promise.all([first, second])
expect(fetcher).toHaveBeenCalledTimes(1)
})
})