Files
accounted/lib/salary/__tests__/derive-absence-line-items.test.ts
T
MattssonandClaude Fable 5 b6332e9ff4 Fix/skv connection flow (#1015)
* feat(salary): one-click AGI submission with filing state machine and success feedback

The AGI panel required users to know that "Ladda ner AGI-fil" was the
generate step, then click submit, signing link, and kvittens manually.
A nollkorning filing stalled on "AGI-XML saknas" pointing at a UI path
that does not exist.

- New primary button "Lamna in till Skatteverket" chains the existing
  endpoints client-side: generate XML if missing, POST underlag, poll
  kontrollresultat, create signing link, open Mina Sidor in a tab opened
  synchronously at click (popup-blocker safe). Inline stepper shows each
  step; the four old buttons become collapsed advanced/recovery actions,
  auto-expanded in stale-draft and rejected states. XML download stays
  visible and free for manual filing.
- deriveAgiFilingState() + useAgiSubmission() lift the per-period
  submission record to the run page: the progress rail and salary hero
  now render the real state machine (generated, underlag inskickat,
  vantar pa BankID-signatur, inlamnad med kvittensnummer) instead of
  telling users to "lamna in" an already-submitted declaration.
- Success card with kvittensnummer and signature metadata once signed,
  plus a toast when a poll flips the state while the page is open.
- AGI kvittens cron every 15 min instead of every 2 h so filings signed
  on another device get stamped and emailed promptly.
- Advanced submit also auto-generates, and the stale "Lon -> AGI ->
  Generera" error text now points at the real buttons.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(enable-banking): instant OAuth callback feedback and dead-attempt cleanup

The bank redirect landed on a blank page for the several seconds the
callback spent exchanging the PSD2 session and mirroring accounts, and
every failed connect attempt left a status='error' row that rendered
forever as an "Atgard kravs" card next to a successful retry, showing
duplicate connections to the same bank.

- Stream a branded "Slutfor bankanslutningen" progress page from the
  callback: the shell flushes before the session exchange starts and a
  script/meta redirect follows when the work completes, with a 30s
  slow-work escape hatch. Fast outcomes (denial, bad params, unknown
  state) keep their plain redirects.
- Delete never-activated connection rows (no session_id, no
  accounts_data) on denial or exchange failure, and sweep leftovers for
  the same bank on the next connect. Established connections keep their
  "Atgard krävs" card via the accounts_data guard; FKs are ON DELETE
  SET NULL so deletion has no dependents.
- Show "Banken ar ansluten: hamtar dina konton" while the settings
  panel loads after the callback instead of an anonymous spinner.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(invoices): reject re-send of issued invoices and gate bookkeeping on the sent flip

A direct POST to /api/invoices/[id]/send against an already-issued
invoice re-emailed the customer and posted a second revenue verifikat
(createInvoiceJournalEntry has no dedup), overwriting journal_entry_id
and orphaning the first entry. Only the UI hid the button; the v1 route
and the MCP commit executor already rejected non-drafts.

- Non-draft invoices now return 409 INVOICE_ALREADY_SENT.
- The draft to sent status flip is an optimistic lock (status guard plus
  row-count check); journal entry, accrual schedules, PDF archival and
  the invoice.sent event only run for the request that won the flip.
- On a flip failure the journal entry is deferred: the row stays draft
  and a retry re-runs the pipeline, ending with exactly one verifikat.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(invoices): payment links, failure visibility and sandbox guard for recurring auto-send

- sendInvoiceFromSchedule now auto-creates an online payment link via
  applyPaymentLinkToInvoice before rendering and passes the payment
  link QR to the PDF: parity with the dashboard and v1 send routes,
  which recurring invoices silently lacked.
- The recurring cron persists last_run_warning both when a claimed run
  throws (hourly retries stay visible on the schedule) and when a stale
  schedule is rolled forward, so a deterministic failure can no longer
  skip a month silently.
- Auto-send is blocked for sandbox companies at the email chokepoint
  (freeze-and-retain: the invoice is still generated as a draft),
  covering both the cron and the run-now route with one guard.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(salary): close the Fortnox payroll API gaps (phases 1-4)

Payroll now runs end-to-end through the open API, including onboarding a
client from another payroll system, with every write staged for approval.

- v1: per-employee payslips (list/detail/PDF), payslip line writes,
  run roster attach/remove, absence ranges (per-day storage), jamkning
  fields, cutover opening balances (single + atomic bulk PUT), vacation
  balance + vacation-year-close. PUT added to the wrapper's idempotency/
  test-key set (test keys could otherwise write through PUT).
- MCP: 10 new tools (get_employee/get_payslip/list_absence/
  get_vacation_balance reads + staged update_payslip_line,
  register_absence, create_employee, update_employee,
  set_employee_opening_balances, close_vacation_year), executors, risk
  tiers, op-type CHECK expansions. create_employee encrypts personnummer
  at staging: pending_operations never holds plaintext.
- Scope-map audit retrofit: 11 formerly unmapped tools now scoped;
  BREAKING for keys that relied on the 4 default-allow writes.
- Cutover: employee_opening_balances (derived lock trigger, self-unlocks
  on run correction), engine YTD/karens/liability integration,
  Ingaende saldon section in the employee editor.
- Arbetsschema-lite: employees.hours_per_week/workdays_per_week drive the
  hourly/daily divisors; legacy 173/21 preserved exactly at defaults so
  existing pay math is byte-identical.
- Vacation ledger + semesterberedning/arsavslut: recomputed per-year day
  balances (synced on book/correct, non-fatal), year-close with the
  min-20 floor, 5-year sparade-dagar expiry to forced payout, and a
  2920/2940 drift adjustment via the bookkeeping engine; Semester
  dashboard card with preview-then-confirm dialog.
- Fix: Zod 4 defaults leak through .partial(), which made every sparse
  employee PATCH fail validation and reset defaulted columns.

Migrations 20260713100000/101000/110000/121000/122000 (applied to
staging with version rows; prod via merge). vacation_ledger renamed from
20260713120000 to avoid colliding with vat_declaration_totals_rpc.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* perf: cut dashboard page-load latency (region, round trips, caching, VAT RPC)

The dominant cost was infrastructure: Vercel functions ran in iad1
(Washington D.C.) while Supabase (DB + auth) lives in eu-north-1
(Stockholm), so every request paid 4-5 transatlantic round trips of
auth + company resolution before doing any real work (measured
530-1900ms for single-query GETs in prod logs). Pin functions to arn1
and cut the redundant work on top:

- vercel.json: functions to arn1, same city as the database
- getActiveCompanyId: preference + first-membership queries run in
  parallel; the fallback result doubles as validation in the common
  single-company case (one round trip instead of two sequential)
- withRouteContext: Server-Timing header and authMs/companyMs/handlerMs
  in the op-completed log, so latency is attributable per phase
- dashboard layout: nav badge counts off the critical path; DashboardNav
  loads them client-side via the new use-worklist-badges SWR hook with
  debounced realtime revalidation
- swr (new dependency, approved): global provider; useCompanySettings
  shares one cache entry across consumers and renders from cache on
  back-navigation instead of re-showing skeletons
- /pending: realtime refetch debounced; bulk operations previously
  fired 4 requests per row-change event
- VAT declaration: new get_vat_declaration_totals RPC returns
  per-account totals, settlement-shape detection (#984) and
  source_type counts in ONE round trip instead of paging every
  entry+line through PostgREST. Account lists stay TS-side parameters
  so ACCOUNT_RUTA remains the single source of truth. Shape-exclusion
  coverage moved to tests/pg/vat-declaration-totals-rpc.pg.test.ts;
  DDL already applied to staging.
- bundle: CommandPalette lazy-mounts on first Ctrl/Cmd+K, AgentChat
  dynamic-imports the markdown parser, @vercel/speed-insights (new
  dependency, approved) added for real-user timings

The /salary fetch-waterfall fix from the same effort already landed
inside 2084a756.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(invoices): settle öre-rounded payments from the mark-paid flow

An invoice with öresavrundning shows a rounded "Att betala" on the PDF;
the customer pays that amount (up to 50 öre off the stored öre total) and
the invoice-page mark-paid flow rejected it with
MATCH_AMOUNT_EXCEEDS_REMAINING: a dead end, while the bank-transaction
match flow already absorbed the residual to 3740.

- PaymentBookingDialog now proposes the rounded bank leg plus the 3740
  residual line (credit when rounded up, debit when rounded down),
  resolved via getDisplayTotal from the per-invoice override and
  company_settings.ore_rounding.
- settleInvoicePayment and the v1 mark-paid route absorb the sub-krona
  residual, gated by planInvoicePaymentForLines: absorption applies ONLY
  when the caller lines carry the exact residual on 3740; otherwise the
  strict plan applies (sub-krona partials stay partial, no-3740
  overshoots keep the 400), so the GL can never diverge from the AR
  sub-ledger.
- planInvoicePayment absorb-band boundary tightened to >= 1 kr: an
  exactly-1-kr overshoot used to slip past both the guard and the absorb
  branch and silently over-record paid_amount (pre-existing on the
  bank-match path).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(security): resolve all 7 PR compliance findings

- ASVS V3.3: per-request CSP nonce on the enable-banking finalize page
  (mirrors the mcp-oauth consent page); inline scripts are nonce-bound
- ASVS V16: decouple callback finalize work from the response stream
  (eager promise + next/server after()) so a client disconnect cannot
  drop session persistence or the consent_granted audit emit
- ISO 27001 A.8.15: failed audit-event emits log through the structured
  logger with a stable message for log-based alerting
- ASVS V2.3: recurring-invoice cron and run-now routes resolve
  isSandboxCompany themselves and pass an explicit suppressAutoSend flag
  (defence in depth around the email chokepoint, freeze-and-retain kept)
- ISO 27001 A.8.11: stagePendingOperation rejects plaintext
  personnummer-bearing keys in params/preview_data (key-based guard;
  EF org numbers make value-matching unsafe)
- ASVS V4.5: employee PATCH body is truly sparse; cleared number fields
  are omitted instead of resetting DB values to hardcoded fallbacks
- ASVS V8.2.1: route-level tests pin the v1 cross-company deny (404 by
  convention, not 403) on the payslip PDF endpoint

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat: implement vacation-year basis change validation and error handling

- Added tests to block vacation-year basis changes when open balances exist.
- Implemented error handling for open-balances guard query failures in the settings route.
- Enhanced absence route to reject reversed date ranges with a validation error.
- Updated absence handling to use atomic upserts instead of delete+insert for better performance and reliability.
- Refactored salary calculation logic to correctly handle age-based avgifter rates according to Skatteverket's rules.
- Improved error messaging for vacation year closure adjustments.
- Adjusted employee opening balances handling to preserve audit information during upserts.

* feat(settings): add validation to block vacation-year basis change with open balances

feat(absence): reject reversed date ranges in absence queries

fix(absence): update absence handling to use atomic upserts instead of delete+insert

fix(employee): improve validation for jamkning dates in employee updates

fix(opening-balances): ensure created_by field is preserved during upserts

test(absence): enhance tests for absence range and date validations

test(calculation): add tests for age-based avgifter rates and edge cases

test(semesterberedning): validate vacation year closure adjustments and error handling

test(employee-opening-balances): update tests to reflect changes in salary_run_employees schema

* fix(migrations): implement NOT VALID constraints for pending_operations and add validation migration

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 22:54:33 +02:00

327 lines
12 KiB
TypeScript

import { describe, it, expect } from 'vitest'
import {
deriveAbsenceLineItems,
buildSjukloneperioder,
type AbsenceDay,
type DeriveInput,
} from '../derive-absence-line-items'
import type { PayrollConfig } from '../payroll-config'
const config: PayrollConfig = {
configYear: 2026,
avgifterTotal: 0.3142,
avgifterAlderspension: 0.1021,
avgifterSjukforsakring: 0.0355,
avgifterForaldraforsakring: 0.02,
avgifterEfterlevandepension: 0.003,
avgifterArbetsmarknad: 0.0264,
avgifterArbetsskada: 0.001,
avgifterAllmanLoneavgift: 0.1262,
avgifterReduced65plus: 0.1021,
avgifterYouthRate: 0.2081,
avgifterYouthSalaryCap: 25000,
avgifterVaxaStodRate: 0.1021,
avgifterVaxaStodCap: 35000,
avgifterMinimumAnnual: 1000,
egenavgifterTotal: 0.2897,
slpRate: 0.2426,
prisbasbelopp: 59200,
inkomstbasbelopp: 83400,
maxPgi: 625500,
sgiCeiling: 592000,
statligSkattBrytpunkt: 660400,
traktamenteHeldag: 300,
traktamenteHalvdag: 150,
traktamenteNatt: 150,
milersattningEgenBil: 25,
milersattningFormansbilFossil: 12,
milersattningFormansbilEl: 9.5,
kostformanHeldag: 310,
kostformanLunch: 124,
kostformanFrukost: 62,
friskvardCap: 5000,
bilformanSlr: 0.0255,
sjuklonRate: 0.8,
karensavdragFactor: 0.2,
maxKarensavdragPerYear: 10,
reducedAvgiftAge: 67,
}
const days = (entries: Array<[string, AbsenceDay['absence_type']]>): AbsenceDay[] =>
entries.map(([d, t]) => ({ absence_date: d, absence_type: t, hours: 8 }))
const baseInput = (over: Partial<DeriveInput> = {}): DeriveInput => ({
monthlySalary: 30000,
payrollConfig: config,
periodDays: [],
lookbackSickDates: [],
vabDaysYtd: 0,
parentalDaysPregnancyYtd: 0,
...over,
})
describe('buildSjukloneperioder', () => {
it('treats consecutive days as one period', () => {
const segs = buildSjukloneperioder(['2026-04-06', '2026-04-07', '2026-04-08'])
expect(segs).toHaveLength(1)
expect(segs[0].sickDayCount).toBe(3)
expect(segs[0].startDate).toBe('2026-04-06')
expect(segs[0].endDate).toBe('2026-04-08')
})
it('merges segments within 5-day återinsjuknande window', () => {
// Sick Mon-Wed, gap Thu-Fri-Sat-Sun-Mon (5 days), sick Tue
// Gap from last sick (Wed Apr 8) to next (Tue Apr 14) = 6 calendar days → new period
const segs1 = buildSjukloneperioder(['2026-04-06', '2026-04-07', '2026-04-08', '2026-04-14'])
expect(segs1).toHaveLength(2)
// Gap of exactly 5 days → same period
// Wed Apr 8 → Mon Apr 13 = 5 days
const segs2 = buildSjukloneperioder(['2026-04-06', '2026-04-07', '2026-04-08', '2026-04-13'])
expect(segs2).toHaveLength(1)
expect(segs2[0].sickDayCount).toBe(4)
})
it('starts a new period when gap is >5 days', () => {
const segs = buildSjukloneperioder(['2026-04-06', '2026-04-13'])
// gap = 7 → new period
expect(segs).toHaveLength(2)
})
it('returns empty for empty input', () => {
expect(buildSjukloneperioder([])).toEqual([])
})
it('deduplicates duplicate dates', () => {
const segs = buildSjukloneperioder(['2026-04-06', '2026-04-06', '2026-04-07'])
expect(segs).toHaveLength(1)
expect(segs[0].sickDayCount).toBe(2)
})
})
describe('deriveAbsenceLineItems: sick', () => {
it('emits karensavdrag for a single sick day', () => {
const result = deriveAbsenceLineItems(
baseInput({ periodDays: days([['2026-04-06', 'sick']]) }),
)
const karens = result.lineItems.find(li => li.item_type === 'sick_karens')
expect(karens).toBeDefined()
expect(karens!.quantity).toBe(1)
expect(karens!.amount).toBeLessThan(0)
expect(result.lineItems.find(li => li.item_type === 'sick_day2_14')).toBeUndefined()
expect(result.aggregated.sickDays).toBe(1)
})
it('emits karens + day-2-14 for a 5-day period', () => {
const result = deriveAbsenceLineItems(
baseInput({
periodDays: days([
['2026-04-06', 'sick'],
['2026-04-07', 'sick'],
['2026-04-08', 'sick'],
['2026-04-09', 'sick'],
['2026-04-10', 'sick'],
]),
}),
)
const karens = result.lineItems.find(li => li.item_type === 'sick_karens')
const day2_14 = result.lineItems.find(li => li.item_type === 'sick_day2_14')
expect(karens).toBeDefined()
expect(day2_14).toBeDefined()
expect(day2_14!.quantity).toBe(4) // days 2-5 of segment
expect(result.flagFkReporting).toBe(false)
})
it('flags läkarintyg when day-8 reached (segment day 8+)', () => {
const periodDays = days(
Array.from({ length: 9 }, (_, i): [string, 'sick'] => [`2026-04-${String(6 + i).padStart(2, '0')}`, 'sick']),
)
const result = deriveAbsenceLineItems(baseInput({ periodDays }))
expect(result.flagLakarintyg).toBe(true)
})
it('flags FK reporting when segment passes day 14', () => {
// 16 consecutive sick days
const periodDays = days(
Array.from({ length: 16 }, (_, i): [string, 'sick'] => {
const day = String(6 + i).padStart(2, '0')
return [`2026-04-${day}`, 'sick']
}),
)
const result = deriveAbsenceLineItems(baseInput({ periodDays }))
expect(result.flagFkReporting).toBe(true)
const day15 = result.lineItems.find(li => li.item_type === 'sick_day15_plus')
expect(day15).toBeDefined()
expect(day15!.quantity).toBe(2) // days 15, 16
})
it('suppresses karens via återinsjuknande when segment started in lookback', () => {
// Prior segment: Apr 1-3. Current period sick day: Apr 6 (gap 3 days → merge).
// Segment now spans Apr 1-6. Period day Apr 6 is segment day 6 → day-2-14, no new karens.
const result = deriveAbsenceLineItems(
baseInput({
periodDays: days([['2026-04-06', 'sick']]),
lookbackSickDates: ['2026-04-01', '2026-04-02', '2026-04-03'],
}),
)
expect(result.lineItems.find(li => li.item_type === 'sick_karens')).toBeUndefined()
const day2_14 = result.lineItems.find(li => li.item_type === 'sick_day2_14')
expect(day2_14).toBeDefined()
expect(day2_14!.quantity).toBe(1)
})
it('suppresses karens when högriskskydd cap reached', () => {
// 10 prior single-day karens-eligible periods, each separated by >5 days
const lookback: string[] = []
for (let i = 0; i < 10; i++) {
// periods on the 1st of each prior month
const month = ((4 - 1 + 12 - i - 1) % 12) + 1 // months 3, 2, 1, 12, ...
const year = i < 3 ? 2026 : 2025
lookback.push(`${year}-${String(month).padStart(2, '0')}-01`)
}
const result = deriveAbsenceLineItems(
baseInput({
periodDays: days([['2026-04-15', 'sick']]),
lookbackSickDates: lookback,
}),
)
// 10 prior karens in 12-month window → this 11th is suppressed
expect(result.lineItems.find(li => li.item_type === 'sick_karens')).toBeUndefined()
})
})
describe('deriveAbsenceLineItems: cutover karensPeriodsAdjustment', () => {
it('suppresses karens when the adjustment alone reaches the cap', () => {
// Mid-year switcher with 10 karens periods in the previous system and no
// imported absence rows: the 11th period must be suppressed even though
// the lookback here is empty.
const result = deriveAbsenceLineItems(
baseInput({
periodDays: days([['2026-04-06', 'sick']]),
karensPeriodsAdjustment: 10,
}),
)
expect(result.lineItems.find(li => li.item_type === 'sick_karens')).toBeUndefined()
// Day 1 with suppressed karens is paid normal: no deduction lines at all.
expect(result.aggregated.sickDays).toBe(1)
})
it('combines the adjustment with real lookback segments', () => {
// 8 imported periods + adjustment 2 = 10: cap reached, karens suppressed.
const lookback: string[] = []
for (let i = 0; i < 8; i++) {
const month = ((4 - 1 + 12 - i - 1) % 12) + 1
const year = i < 3 ? 2026 : 2025
lookback.push(`${year}-${String(month).padStart(2, '0')}-01`)
}
const capped = deriveAbsenceLineItems(
baseInput({
periodDays: days([['2026-04-15', 'sick']]),
lookbackSickDates: lookback,
karensPeriodsAdjustment: 2,
}),
)
expect(capped.lineItems.find(li => li.item_type === 'sick_karens')).toBeUndefined()
// Adjustment 1 leaves the count at 9: karens still deducted.
const belowCap = deriveAbsenceLineItems(
baseInput({
periodDays: days([['2026-04-15', 'sick']]),
lookbackSickDates: lookback,
karensPeriodsAdjustment: 1,
}),
)
expect(belowCap.lineItems.find(li => li.item_type === 'sick_karens')).toBeDefined()
})
it('zero/absent adjustment changes nothing', () => {
const withZero = deriveAbsenceLineItems(
baseInput({ periodDays: days([['2026-04-06', 'sick']]), karensPeriodsAdjustment: 0 }),
)
const without = deriveAbsenceLineItems(
baseInput({ periodDays: days([['2026-04-06', 'sick']]) }),
)
expect(withZero.lineItems).toEqual(without.lineItems)
})
})
describe('deriveAbsenceLineItems: VAB', () => {
it('emits VAB line item with deduction', () => {
const result = deriveAbsenceLineItems(
baseInput({
periodDays: days([
['2026-04-10', 'vab'],
['2026-04-11', 'vab'],
]),
}),
)
const vab = result.lineItems.find(li => li.item_type === 'vab')
expect(vab).toBeDefined()
expect(vab!.quantity).toBe(2)
expect(vab!.is_vacation_basis).toBe(true) // ≤120 days YTD
expect(result.aggregated.vabDays).toBe(2)
})
it('marks VAB non-vacation-basis when YTD >= 120', () => {
const result = deriveAbsenceLineItems(
baseInput({
periodDays: days([['2026-04-10', 'vab']]),
vabDaysYtd: 120,
}),
)
const vab = result.lineItems.find(li => li.item_type === 'vab')
expect(vab!.is_vacation_basis).toBe(false)
})
})
describe('deriveAbsenceLineItems: parental', () => {
it('emits parental line item with deduction', () => {
const result = deriveAbsenceLineItems(
baseInput({
periodDays: days([
['2026-04-10', 'parental'],
['2026-04-11', 'parental'],
['2026-04-12', 'parental'],
]),
}),
)
const parental = result.lineItems.find(li => li.item_type === 'parental_leave')
expect(parental).toBeDefined()
expect(parental!.quantity).toBe(3)
expect(result.aggregated.parentalDays).toBe(3)
})
})
describe('deriveAbsenceLineItems: unpaid_leave', () => {
it('emits unpaid_leave line item with a per-day daily-rate deduction', () => {
const result = deriveAbsenceLineItems(
baseInput({
monthlySalary: 42000, // dailyRate = 42 000 / 21 = 2 000
periodDays: days([
['2026-04-10', 'unpaid_leave'],
['2026-04-13', 'unpaid_leave'],
]),
}),
)
const unpaid = result.lineItems.find(li => li.item_type === 'unpaid_leave')
expect(unpaid).toBeDefined()
expect(unpaid!.quantity).toBe(2)
expect(unpaid!.amount).toBe(-4000)
// false: engine's Step 3 absence sum already subtracts unpaid_leave;
// setting the flag would double-count in Step 4 totalGrossDeductions.
expect(unpaid!.is_gross_deduction).toBe(false)
expect(unpaid!.is_vacation_basis).toBe(false)
expect(result.aggregated.unpaidLeaveDays).toBe(2)
})
})
describe('deriveAbsenceLineItems: empty', () => {
it('returns empty result for no absence', () => {
const result = deriveAbsenceLineItems(baseInput())
expect(result.lineItems).toEqual([])
expect(result.aggregated).toEqual({ sickDays: 0, vabDays: 0, parentalDays: 0, unpaidLeaveDays: 0 })
expect(result.flagFkReporting).toBe(false)
expect(result.flagLakarintyg).toBe(false)
})
})