Files
accounted/lib/reports/vat-eskd-file.ts
T
Mattsson abe9ac9d8c Fix/attributes config (#926)
* fix(git): pin LF on generated extension registry and vitest snapshots

setup:extensions and vitest write these files with LF; with
core.autocrlf=true git expects CRLF and flags them as phantom
modifications on every dev/build run.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(security): enforce MFA on mcp-oauth consent and gate viewer storno route

mcp-oauth/authorize renders an HTML consent page and issues 303 redirects that withRouteContext cannot express, so it kept raw getUser() and thereby skipped the AAL2 gate: a password-only (AAL1) session could approve consent that mints a long-lived, MFA-bypassing API key. Add a route-local requireAal2() step-up on GET and POST; AAL1 sessions redirect to /mfa/verify, BankID users are exempt.

Separately, POST /api/reports/vat-declaration/rc-basis-gaps/fix calls correctEntry() (storno of a posted entry) but lacked requireWrite, so viewer-role members could trigger it. Add { requireWrite: true }.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(api): route transactions endpoints through withRouteContext

Migrate the transactions routes off hand-rolled supabase.auth.getUser() onto the MFA-enforcing withRouteContext wrapper; add requireWrite on mutating handlers (book, uncategorize, attach-document, ignore, batch-match, create-from-document). Behavior and response shapes preserved; tests updated to the wrapper mock pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(api): route SIE import and bank reconciliation through withRouteContext

Migrate import/sie and reconciliation/bank routes onto the MFA-enforcing wrapper; requireWrite on mutations (import execute, create-accounts, mappings write verbs, link/unlink/run/mark-opening-balance). Reads (status, unmatched-entries) stay ungated. Response shapes preserved; tests added/updated to the wrapper mock pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(api): route salary endpoints through withRouteContext

Migrate salary employees and runs routes (plus ku, payroll-config, tax-tables) onto the MFA-enforcing wrapper; requireWrite on mutations. Personnummer masking/encryption untouched; file downloads (AGI XML, payslip PDF, payment files) keep their headers. Two payment-file GETs retain requireWrite because they stamp *_file_generated_at and previously gated viewers. Tests added/updated to the wrapper mock pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(api): route report endpoints through withRouteContext

Migrate the read-only report routes (trial balance, balansrapport, resultatrapport, income statement, ledgers, KPI, VAT declaration, salary journal, monthly breakdown, journal register, continuity check, full archive, etc.) onto the MFA-enforcing wrapper. All read-only, no requireWrite. JSON/XLSX/PDF/ZIP response bodies and headers preserved byte-for-byte; tests updated to the wrapper mock pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(api): route invoices, skatteverket, agent and extension endpoints through withRouteContext

Migrate invoices, supplier-invoices, skatteverket tax-payments, and dynamic extension routes onto the MFA-enforcing wrapper with requireWrite on mutations. The two NDJSON streaming agent routes (invoke, onboarding/stream) use requireAuth() directly (the wrapper can't wrap a streaming response) so MFA is still enforced. skatteverket payment-file GET keeps requireWrite (stamps a generated-at field). Response shapes and file headers preserved; tests added/updated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(api): route documents, events, team and account endpoints through withRouteContext

Migrate documents, events, kpi/preferences, vat/validate, support/contact onto the MFA-enforcing wrapper with requireWrite on mutations. account/password, team/accept and team/members use requireAuth() directly (user-level or pre-membership flows with no active company context) so MFA is still enforced. events keeps its dual API-key-or-session auth. Document retention guard untouched; tests added/updated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(api): route settings and pending-operations endpoints through withRouteContext

Migrate settings (api-keys, oauth-clients, booking-templates, counterparty-templates, logo, company settings) and pending-operations (commit, bulk-commit, reject, edit-before-approve) onto the MFA-enforcing wrapper with requireWrite on mutations. Credential-guarding routes keep their per-user ownership filters. Response shapes preserved; tests added/updated to the wrapper mock pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore(guards): ratchet raw-route-auth baseline 119->1 after A1 migration

Lock in the withRouteContext migration so the count cannot regress. The single remaining entry, mcp-oauth/authorize, is a documented exception (HTML consent + redirects, MFA enforced via route-local step-up). Record the campaign and requireWrite decisions in DECISIONS.md.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(vat): add eSKD momsdeklaration file export for "Deklarera via fil"

Generate the Skatteverket eSKDUpload v6.0 XML file so users can file VAT by
upload instead of typing every ruta into the form. Extract buildFiledAmounts()
as the shared whole-krona source of truth (öre truncated per SFL 22 kap 1 §) so
the XML file and the manual-filing PDF can never disagree. Adds the /eskd API
route, an XML option in the report export menu, and the upload button on the
manual-filing card. Strings in sv + en.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(vat): add 'vat_settlement' source type and update related components

* fix(booking): adjust search input layout and enable autofocus

* fix(vat): support 12-digit org numbers and adjust emission order for eSKD file

* fix(migration): add 'vat_settlement' to journal_entries.source_type CHECK

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-08 09:54:46 +02:00

144 lines
5.7 KiB
TypeScript

import { VAT_RUTA_LABELS, type VatDeclarationRutor } from '@/types'
import { buildFiledAmounts } from '@/lib/reports/vat-manual-filing'
/**
* Maps each momsdeklaration ruta to its eSKDUpload XML tag, per Skatteverket's
* "Skapa en fil" specification (dev_docs/skatteverket/moms). The tag order in
* the emitted file follows the ruta order defined below, which matches the SKV
* form/file layout. ruta49 (MomsBetala) is the mandatory summering and is always
* emitted last.
*/
const RUTA_TO_ESKD_TAG: Record<keyof VatDeclarationRutor, string> = {
ruta05: 'ForsMomsEjAnnan',
ruta06: 'UttagMoms',
ruta07: 'UlagMargbesk',
ruta08: 'HyrinkomstFriv',
ruta10: 'MomsUtgHog',
ruta11: 'MomsUtgMedel',
ruta12: 'MomsUtgLag',
ruta20: 'InkopVaruAnnatEg',
ruta21: 'InkopTjanstAnnatEg',
ruta22: 'InkopTjanstUtomEg',
ruta23: 'InkopVaruSverige',
ruta24: 'InkopTjanstSverige',
ruta30: 'MomsInkopUtgHog',
ruta31: 'MomsInkopUtgMedel',
ruta32: 'MomsInkopUtgLag',
ruta35: 'ForsVaruAnnatEg',
ruta36: 'ForsVaruUtomEg',
ruta37: 'InkopVaruMellan3p',
ruta38: 'ForsVaruMellan3p',
ruta39: 'ForsTjSkskAnnatEg',
ruta40: 'ForsTjOvrUtomEg',
ruta41: 'ForsKopareSkskSverige',
ruta42: 'ForsOvrigt',
// Import block: beskattningsunderlag (50) then output VAT (60/61/62).
ruta50: 'MomsUlagImport',
ruta60: 'MomsImportUtgHog',
ruta61: 'MomsImportUtgMedel',
ruta62: 'MomsImportUtgLag',
ruta48: 'MomsIngAvdr',
ruta49: 'MomsBetala',
}
// Emission order: the RUTA_TO_ESKD_TAG key order, which encodes the SKV file
// spec's radnummer sequence. Notably the import block (ruta 50/60/61/62,
// rad 29-32) comes BEFORE MomsIngAvdr (ruta 48, rad 33); a numeric ruta sort
// would invert that and produce a file SKV rejects (avvisande fel). ruta49
// (MomsBetala) is the mandatory summering and is emitted last by the builder.
const EMIT_ORDER: (keyof VatDeclarationRutor)[] = (
Object.keys(RUTA_TO_ESKD_TAG) as (keyof VatDeclarationRutor)[]
).filter((key) => key !== 'ruta49')
export interface ESkdFileInput {
/** Company org/person number, any format; digits are extracted and re-formatted. */
orgNumber: string
/**
* The declaration period's END date (YYYY-MM-DD). The eSKD <Period> is the
* year plus the last month of the period (YYYYMM): for monthly that is the
* month itself, for quarterly the last month of the quarter, for a full
* beskattningsår the last month of the fiscal year. Deriving it from the end
* date handles all three uniformly.
*/
periodEnd: string
}
/**
* Formats a Swedish org/person number as `xxxxxx-xxxx` (10 digits with hyphen),
* as required by the eSKD header. Accepts 12-digit century-prefixed values
* (16xxxxxxxxxx org numbers, 19/20-prefixed personnummer) by stripping the
* prefix, mirroring formatRedovisare/formatOrgNumber12; settings rows predating
* org-number normalization legitimately hold 12 digits. Throws otherwise, since
* an out-of-format OrgNr is an "avvisande fel" that Skatteverket rejects outright.
*/
function formatESkdOrgNumber(orgNumber: string): string {
let digits = orgNumber.replace(/\D/g, '')
if (digits.length === 12) digits = digits.slice(2)
if (digits.length !== 10) {
throw new Error(
`Ogiltigt organisationsnummer för momsdeklaration (kräver 10 siffror): ${orgNumber}`,
)
}
return `${digits.slice(0, 6)}-${digits.slice(6)}`
}
/** Derives the eSKD <Period> value (YYYYMM) from the period end date. */
function toESkdPeriod(periodEnd: string): string {
const match = /^(\d{4})-(\d{2})-\d{2}$/.exec(periodEnd)
if (!match) {
throw new Error(`Ogiltigt periodslutdatum för momsdeklaration: ${periodEnd}`)
}
return `${match[1]}${match[2]}`
}
/**
* Builds the Skatteverket eSKDUpload (v6.0) momsdeklaration file from the
* calculated rutor. This is the file a user uploads under "Deklarera via fil";
* unlike the PDF (a read/record copy) this is a real submission artifact.
*
* Format rules (dev_docs/skatteverket/moms/momsdeklaration_via_etjänst.txt):
* - Whole kronor only, no decimals; öre are truncated (shared with the PDF via
* buildFiledAmounts so the two documents always tie out).
* - Only rutor with a value are emitted, except <MomsBetala> (ruta49) which is
* the mandatory summering and is always present.
* - A refund is written with a leading minus directly before the amount; no
* leading plus is ever emitted.
* - Declared encoding is ISO-8859-1. The content is effectively ASCII (tags,
* digits, hyphen), so no non-ASCII bytes appear; the caller still encodes as
* latin1 to honour the declared charset.
* - CRLF line endings.
*
* @returns the XML string. Encode with Buffer.from(xml, 'latin1') before serving.
*/
export function buildESkdFile(rutor: VatDeclarationRutor, input: ESkdFileInput): string {
const orgNr = formatESkdOrgNumber(input.orgNumber)
const period = toESkdPeriod(input.periodEnd)
const { amounts } = buildFiledAmounts(rutor)
const lines: string[] = [
'<?xml version="1.0" encoding="ISO-8859-1"?>',
'<eSKDUpload Version="6.0">',
`<OrgNr>${orgNr}</OrgNr>`,
'<Moms>',
`<Period>${period}</Period>`,
]
for (const key of EMIT_ORDER) {
const amount = amounts[key]
if (amount === 0) continue // omit empty rutor; MomsBetala is emitted below
lines.push(`<${RUTA_TO_ESKD_TAG[key]}>${amount}</${RUTA_TO_ESKD_TAG[key]}>`)
}
// ruta49 (MomsBetala) is always emitted, even when 0 (Exempel 3: inget att
// deklarera). A refund keeps its leading minus from the signed net.
lines.push(`<MomsBetala>${amounts.ruta49}</MomsBetala>`)
lines.push('</Moms>')
lines.push('</eSKDUpload>')
return lines.join('\r\n') + '\r\n'
}
// Re-exported for tests and any caller that needs the tag mapping directly.
export { RUTA_TO_ESKD_TAG, VAT_RUTA_LABELS }