0b86901a2b
* feat(lib): add canonical money + format + fetch primitives (audit Tier 0) Foundation for post-audit cleanup: shared primitives so subsequent refactors import one helper instead of reinventing (the duplication the audit found). - lib/money.ts: canonical roundOre/ORE_TOLERANCE (+ equalOre/isZeroOre/sumOre); lib/bokslut/rounding.ts re-exports for back-compat - lib/utils.ts: formatAmount, formatWholeKr, formatDateTime - lib/hooks/use-fetch.ts: generic client fetch hook (abort, bilingual errors, refetch) - components/common/DataState.tsx: loading/error/empty wrapper over Skeleton/EmptyState - messages: common.retry / common.load_error (sv+en) - tests: 16 tests incl. the 1.005 half-ore case and locale-robust format assertions Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ci(guards): ratchet against new MFA-bypassing routes and naive ore-rounding Adds scripts/checks/no-new-antipatterns.mjs + committed baseline. Fails CI only when a PR ADDS a route hand-rolling supabase.auth.getUser() (which skips MFA AAL2 enforcement) or a new Math.round(x*100)/100. Baseline: 178 raw-auth routes, 668 naive rounds — ratchets down as the A1 (route-auth) and D1 (rounding) migrations land. Wired into core-build.yml; green at baseline. Note: scripts/ is gitignored (.gitignore:70 '/scripts') yet tracks 39 files via force-add; these two were force-added to match that existing pattern. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(api,errors): enforce MFA on journal-entry mutation routes via withRouteContext (A1) Migrates the 4 journal-entry mutation routes (commit, correct, reverse, recordate) off hand-rolled supabase.auth.getUser() onto withRouteContext, which enforces MFA AAL2 (requireAuth) + non-viewer role (requireWrite) and routes thrown errors through the canonical errorResponse envelope. Fixes audit finding A1 for the most compliance-critical mutations and folds in C8 for these routes (drops bookkeepingErrorResponse; they now emit message_en). Also fixes a latent bug: errorResponse()/extractBookkeepingDetails only handled 11 of 15 typed bookkeeping errors, so MeaninglessCorrection / NoOpenPeriodForDate / TargetPeriodClosed / TargetPeriodLocked silently degraded to a generic 500 (affecting existing v1 callers too). Adds the 4 missing registry codes + extract cases -> correct 400/409. Behavior change: untyped engine throws now return the canonical 500 envelope instead of 400+raw-string; typed errors keep their status (verified against the registry). Tests updated to the realistic typed-error contract + a 403 write-gate test on commit. Updates .claude/rules/api-routes.md to prescribe withRouteContext. Ratchets the antipattern guard 178 -> 174. Full unit suite green (5023); tsc: no new errors. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(api): enforce MFA on salary run authorization routes via withRouteContext (A1) Migrates the salary-run lifecycle write routes (approve, paid, revert) — the highest-PII A1 surface — off hand-rolled supabase.auth.getUser() onto withRouteContext (enforces MFA AAL2 + non-viewer role). Explicit { error } returns are preserved unchanged (passed through the wrapper); only auth changes, so no error-shape regression. Salary unit suite green (8). Ratchets the antipattern guard 174 -> 171. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * review: address PR #646 bot findings - guard: match withRouteContext/requireAuth at the CALL site (withRouteContext[<(]), not a bare import — closes the false-negative greptile flagged. It surfaced app/api/sandbox/seed (hand-rolled getUser; the loose regex had matched a code comment). Switched that route to requireAuth() — the documented stopgap for routes that can't use withRouteContext (it runs before a company exists; anonymous users, so MFA is a no-op but the auth path is now consistent). Guard stays at 171. - money.test: add the negative half-ore case roundOre(-1.005) === -1 to lock the rounding direction against regressions. - use-fetch: document keep-previous-data + deferred-loading (effect-tick) semantics. - structured-errors: drop the BFL 5 kap. 5 § citation from MEANINGLESS_CORRECTION per the swedish-compliance bot (5 § governs correction procedure, not the no-op precondition). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * review: enrich wrapper error logging + document sandbox GDPR controls (PR #646) - with-route-context: log unhandled errors and route errorResponse through the resolved { userId, companyId } logger, not just { requestId, operation } — closes the OWASP V16 audit-trail finding for all 82+ routes using the wrapper. Documented in the JSDoc. - sandbox/seed: document the GDPR Art.32 compensating controls for the anonymous write path (anonymous-only, /24 rate limit, synthetic demo data, own-company RLS scope). No functional change — the flagged behaviour is pre-existing by design; this records the reasoning inline. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
70 lines
2.3 KiB
TypeScript
70 lines
2.3 KiB
TypeScript
import { describe, it, expect } from 'vitest'
|
|
import { roundOre, ORE_TOLERANCE, equalOre, isZeroOre, sumOre } from '@/lib/money'
|
|
|
|
describe('roundOre', () => {
|
|
it('rounds exact-half öre values up where naive Math.round fails', () => {
|
|
// The whole reason this helper exists: 1.005 stored as 1.00499999… makes
|
|
// naive Math.round(x*100)/100 yield 1.00. roundOre must give 1.01.
|
|
expect(roundOre(1.005)).toBe(1.01)
|
|
expect(roundOre(2.675)).toBe(2.68)
|
|
expect(roundOre(0.615)).toBe(0.62)
|
|
})
|
|
|
|
it('leaves well-formed decimals untouched', () => {
|
|
expect(roundOre(1.234)).toBe(1.23)
|
|
expect(roundOre(1.235)).toBe(1.24)
|
|
expect(roundOre(100)).toBe(100)
|
|
expect(roundOre(1234.56)).toBe(1234.56)
|
|
})
|
|
|
|
it('preserves the sign of negative zero', () => {
|
|
expect(Object.is(roundOre(-0), -0)).toBe(true)
|
|
expect(roundOre(0)).toBe(0)
|
|
})
|
|
|
|
it('handles negative amounts', () => {
|
|
expect(roundOre(-1.234)).toBe(-1.23)
|
|
expect(roundOre(-99.999)).toBe(-100)
|
|
// The EPSILON nudge moves a stored negative value slightly toward zero, so
|
|
// an exact-half negative rounds toward +∞ (mirrors Math.round on negatives):
|
|
// -1.005 → -1.00, not -1.01. Documented so a refactor can't silently flip it.
|
|
expect(roundOre(-1.005)).toBe(-1)
|
|
})
|
|
})
|
|
|
|
describe('ORE_TOLERANCE / equalOre / isZeroOre', () => {
|
|
it('is half an öre', () => {
|
|
expect(ORE_TOLERANCE).toBe(0.005)
|
|
})
|
|
|
|
it('treats sub-öre float drift as equal', () => {
|
|
expect(equalOre(0.1 + 0.2, 0.3)).toBe(true) // classic 0.30000000000000004
|
|
expect(equalOre(100.001, 100.0)).toBe(true)
|
|
})
|
|
|
|
it('flags a real one-öre discrepancy as not equal', () => {
|
|
expect(equalOre(100.01, 100.0)).toBe(false)
|
|
})
|
|
|
|
it('isZeroOre absorbs drift around zero', () => {
|
|
expect(isZeroOre(0.1 + 0.2 - 0.3)).toBe(true)
|
|
expect(isZeroOre(0.01)).toBe(false)
|
|
})
|
|
})
|
|
|
|
describe('sumOre', () => {
|
|
it('sums then rounds once', () => {
|
|
expect(sumOre([0.1, 0.2])).toBe(0.3)
|
|
expect(sumOre([1.005, 1.005])).toBe(2.01)
|
|
expect(sumOre([])).toBe(0)
|
|
})
|
|
})
|
|
|
|
describe('lib/bokslut/rounding back-compat re-export', () => {
|
|
it('exposes the same roundOre/ORE_TOLERANCE from the legacy path', async () => {
|
|
const legacy = await import('@/lib/bokslut/rounding')
|
|
expect(legacy.roundOre(1.005)).toBe(1.01)
|
|
expect(legacy.ORE_TOLERANCE).toBe(ORE_TOLERANCE)
|
|
})
|
|
})
|