Files
accounted/app/api/mileage/export/route.ts
T
Mattsson 7411a0171b feat(mileage): körjournal with milersättning booking, MCP tools and CSV export (#1448)
* feat(mileage): körjournal with milersättning booking, MCP tools and CSV export

New mileage_trips table (RLS, booked-delete trigger per BFL retention),
lib/mileage service reusing the payroll schablon rates, /api/mileage routes
(trips CRUD, period booking to 7331, salary-run push, körjournal CSV),
Körjournal dashboard page + nav, and three staged MCP tools (search-only
catalog). Trips book as one verifikat per period via the engine; salary
path inserts mileage_taxfree line items. mileage_trips classified in the
full-archive export.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(mileage): use shared roundOre helper per tightened ratchet baseline

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(mileage): pending_operations op-type migration + Swedish review findings

- New migration pair adds log_mileage_trip/book_mileage_period to the
  pending_operations operation_type CHECK (pg-real audit).
- bookMileagePeriod refuses a period spanning several employees and names
  the employee in the verifikationstext when scoped (BFL motpart).
- vehicle_registration required for förmånsbil trips (schema, service,
  MCP staging, UI surfaces the field).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(mileage): claim-first booking, CSV injection guard and driver column

- bookMileagePeriod claims trips (draft to booked CAS) before creating the
  verifikat, so a concurrent second booking loses the race instead of
  double-booking; claim reverts if verifikat creation fails.
- Körjournal CSV neutralizes formula-injection triggers (OWASP) and adds a
  Förare column naming the employee per trip.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(mileage): resolve CodeRabbit + Swedish review round: race, drift and hardening

- Copying a round trip no longer re-doubles the stored distance.
- pushMileageToSalaryRun claims trips before inserting line items (retry can
  no longer double-pay); CLAIM_LOST replaces misleading NO_TRIPS on lost races.
- Booked trips are DB-immutable via a BEFORE UPDATE trigger (new migration
  20260807113215): only claim/link/revert transitions and notes edits pass.
- Cross-year periods rejected (schablon rates are per calendar year); payroll
  config year read from the date string, not TZ-dependent getFullYear().
- MCP staged bookings freeze the previewed trip set (trip_ids in params) and
  the commit fails on drift; validation errors return 400, not 500.
- PATCH enforces the förmånsbil regnr rule on the effective row; export
  validates dates before they reach the Content-Disposition header; employee_id
  is verified company-scoped on trip creation; stale orphaned claims released.
- UI: fetch flags reset in finally; ICU plural for draft summary; distance
  stored at the column's 1-decimal precision.
- Tests: [id] route suite, pushMileageToSalaryRun suite, claim-race, drift,
  cross-year and update-trigger pg cases.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(mileage): revert-to-draft must clear salary_run_id at the trigger level

New migration 20260807114924 replaces the booked-immutability function: a
booked -> draft revert now rejects rows keeping salary_run_id, closing the
DB-level double-pay path CodeRabbit flagged. pg test pins both directions;
the CLAIM_LOST unit test now asserts the revert.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(mileage): company-scope employee_id on PATCH (Superagent P2)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(mileage): valid v4 uuid in cross-company employee PATCH test

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-07 14:17:21 +02:00

64 lines
2.6 KiB
TypeScript

import { NextResponse } from 'next/server'
import { ensureInitialized } from '@/lib/init'
import { withRouteContext } from '@/lib/api/with-route-context'
import { ISO_DATE_RE } from '@/lib/invariants'
import { listTrips } from '@/lib/mileage/mileage-service'
import { mileageTripsToCsv } from '@/lib/mileage/csv-export'
ensureInitialized()
/** Körjournal CSV export (Skatteverket audit underlag). */
export const GET = withRouteContext('mileage.export', async (request, { supabase, companyId }) => {
const { searchParams } = new URL(request.url)
const from = searchParams.get('from') || undefined
const to = searchParams.get('to') || undefined
// Validated dates are also what the Content-Disposition filename is built
// from, so nothing user-controlled reaches the header unchecked.
for (const value of [from, to]) {
if (value !== undefined && !ISO_DATE_RE.test(value)) {
return NextResponse.json({ error: 'Ogiltigt datum (ÅÅÅÅ-MM-DD)' }, { status: 400 })
}
}
const trips = await listTrips(supabase, companyId, { from, to })
// Oldest first in the export: a körjournal reads chronologically.
trips.reverse()
const entryIds = [...new Set(trips.map((t) => t.journal_entry_id).filter(Boolean))] as string[]
const voucherLabels = new Map<string, string>()
if (entryIds.length > 0) {
const { data: entries } = await supabase
.from('journal_entries')
.select('id, voucher_series, voucher_number')
.eq('company_id', companyId)
.in('id', entryIds)
for (const entry of entries || []) {
voucherLabels.set(entry.id, `${entry.voucher_series}${entry.voucher_number}`)
}
}
// Driver attribution (BFL 5 kap 6-7 §): name the employee per trip so a
// multi-employee körjournal stays attributable in the exported underlag.
const employeeIds = [...new Set(trips.map((t) => t.employee_id).filter(Boolean))] as string[]
const driverLabels = new Map<string, string>()
if (employeeIds.length > 0) {
const { data: employees } = await supabase
.from('employees')
.select('id, first_name, last_name')
.eq('company_id', companyId)
.in('id', employeeIds)
for (const employee of employees || []) {
driverLabels.set(employee.id, `${employee.first_name} ${employee.last_name}`)
}
}
const csv = mileageTripsToCsv(trips, voucherLabels, driverLabels)
const suffix = [from, to].filter(Boolean).join('_')
return new NextResponse(csv, {
headers: {
'Content-Type': 'text/csv; charset=utf-8',
'Content-Disposition': `attachment; filename="korjournal${suffix ? `_${suffix}` : ''}.csv"`,
},
})
})