d012d40b18
Fixes #1168. articles.currency exists in the DB and REST API, but the staged-operation schemas and the two MCP tools had no currency param, so agent-created articles were always SEK and an agent asked to create an EUR-priced article could not. - CreateArticleParamsSchema/UpdateArticleParamsSchema accept an optional ISO 4217 code (normalized to upper case; empty/null = unset). The currencies-table FK stays the allow-list: a 23503 on the currency FK maps to a clear 400 instead of a raw 500. - commitCreateArticle inserts currency ?? 'SEK'; the sparse update executor passes it through only when staged. - gnubok_create_article / gnubok_update_article expose the param. Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
68 lines
2.7 KiB
TypeScript
68 lines
2.7 KiB
TypeScript
import { z } from 'zod'
|
|
import { INVOICE_POSTING_ACCOUNT_REGEX } from '@/lib/invoices/posting-account'
|
|
|
|
// Commit-boundary re-validation for staged article operations. A staged
|
|
// pending_operations row is re-parsed here before it touches the articles table
|
|
// so a tampered row cannot inject unexpected fields or malformed data
|
|
// (defense in depth, ASVS V4.5): mirrors lib/pending-operations/schemas/create-supplier.ts.
|
|
|
|
const invoicePostingAccount = z
|
|
.string()
|
|
.regex(INVOICE_POSTING_ACCOUNT_REGEX, 'Posting account must be a 4-digit BAS class 1-3 account')
|
|
|
|
const vatRatePercent = z.union([z.literal(0), z.literal(6), z.literal(12), z.literal(25)])
|
|
|
|
/** Empty string / null → undefined, then bounded string. */
|
|
const optString = (max: number) =>
|
|
z.preprocess((v) => (v == null || v === '' ? undefined : v), z.string().max(max).optional())
|
|
|
|
const trimmedName = z.preprocess(
|
|
(v) => (typeof v === 'string' ? v.trim() : v),
|
|
z.string().min(1, 'Article name is required').max(200),
|
|
)
|
|
|
|
// ISO 4217 shape, normalized to upper case; the currencies-table FK on
|
|
// articles.currency is the authoritative allow-list (unknown codes fail at
|
|
// commit with a clear message). Empty string / null → undefined.
|
|
const currencyCode = z.preprocess(
|
|
(v) => (v == null || v === '' ? undefined : typeof v === 'string' ? v.trim().toUpperCase() : v),
|
|
z.string().regex(/^[A-Z]{3}$/, 'Currency must be a 3-letter ISO 4217 code (e.g. EUR)').optional(),
|
|
)
|
|
|
|
export const CreateArticleParamsSchema = z.object({
|
|
name: trimmedName,
|
|
type: z.enum(['vara', 'tjanst']).default('tjanst'),
|
|
unit: optString(32),
|
|
price_excl_vat: z.number().nonnegative(),
|
|
currency: currencyCode,
|
|
vat_rate: vatRatePercent.default(25),
|
|
revenue_account: invoicePostingAccount.nullable().optional(),
|
|
cost_price: z.number().nonnegative().nullable().optional(),
|
|
ean: optString(32),
|
|
housework_type: optString(64),
|
|
name_en: optString(200),
|
|
notes: optString(2000),
|
|
article_number: optString(64),
|
|
})
|
|
|
|
export const UpdateArticleParamsSchema = z.object({
|
|
article_id: z.string().uuid(),
|
|
name: trimmedName.optional(),
|
|
type: z.enum(['vara', 'tjanst']).optional(),
|
|
unit: optString(32),
|
|
price_excl_vat: z.number().nonnegative().optional(),
|
|
currency: currencyCode,
|
|
vat_rate: vatRatePercent.optional(),
|
|
revenue_account: invoicePostingAccount.nullable().optional(),
|
|
cost_price: z.number().nonnegative().nullable().optional(),
|
|
ean: optString(32),
|
|
housework_type: optString(64),
|
|
name_en: optString(200),
|
|
notes: optString(2000),
|
|
article_number: optString(64),
|
|
active: z.boolean().optional(),
|
|
})
|
|
|
|
export type CreateArticleParams = z.infer<typeof CreateArticleParamsSchema>
|
|
export type UpdateArticleParams = z.infer<typeof UpdateArticleParamsSchema>
|