65c6d4c178
* fix(enable-banking): keep bank account mappings across reconnects and surface dead sessions A PSD2 reconnect silently moved the user's ledger mapping. Account identity came from the provider's account uid, which does not survive a re-authorization at every ASPSP, and a fresh connect to an already-connected bank mints a new bank_connections row regardless. Both paths looked like "an account we have never seen", so the allocator handed out the next free 19xx slot and a 1930/1940/1941 mapping came back as 1942-1946 on every consent renewal, roughly quarterly per connection. Match on the IBAN instead. resolvePsd2LedgerAccount() finds the existing cash_accounts row by normalized IBAN before allocating, and upsertFromPsd2 promotes that row in place rather than inserting a second one, so it keeps its id and its linked transactions and is re-pointed at the connection that just authorized. The previous holder's connection status is deliberately ignored: one IBAN is one physical account, and the old row often still reads 'active' because the bank killed the session without telling us. The allocator also stopped treating a 19xx number as free just because no cash_accounts row holds it. A chart imported from SIE carries the company's real bank accounts by name with no PSD2 row behind them, which is how a SEK company account got proposed as an unrelated brokerage account. Overflow now skips chart-occupied numbers, falling back only when nothing unnamed is left. Dead connections kept rendering as "Aktiv": status only ever changed when a transaction fetch failed, so a session killed bank-side stayed healthy-looking with a stale last_synced_at while the user read old balances as current. Add probeSessionHealth() and run it in the daily cron over every connection that run did not prove alive, including the ones the loop skips silently (capability gate, all accounts deselected) and the ones parked in pending_selection that the cron never looked at. It acts only on a definite dead answer; anything ambiguous leaves the row alone, since a wrong flip costs a full BankID re-authorization. The all-accounts-deselected branch is reclassified 'synced' to 'skipped' for the same reason: it never contacts the bank, so it must not count as proof of life. The settings row warns when an active connection has not synced in three days or has never synced. Which company a connection belongs to was invisible. Everything was already scoped to ctx.companyId, so there was no cross-tenant leak, but a bank authorized while the wrong company was active looked identical to the right one. Name the company on the connect surface and in the account picker, and say where the connection went when the callback lands under a different active company. Warn (bypassably) before authorizing a bank where the same user already holds live connections in other companies: several ASPSPs allow one active AIS session per login, so the new authorization can kill the others. The history start date already defaulted to the fiscal-year start; the card above it recommended a mid-year date and contradicted the selected option. It now states the fact and offers the shortcut without presenting it as advice. Not addressed: sharing one PSD2 session across companies. company_id is the tenancy anchor on bank_connections and cash_accounts hangs off (company_id, bank_connection_id), so that needs the session to become its own entity. See DECISIONS.md. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(supplier-invoices): show the posted line description in the voucher preview The "Verifikation som bokförs" preview built its expense debit lines with description set to the raw account number, so the BESKRIVNING column showed "5615" or "6990" where the posted verifikat actually says "Leverantörsfaktura 123, ACME AB". A hardcoded 11-entry ACCOUNT_LABELS map masked this for 2440/2641/26xx, which is why the column read as a mix of friendly labels and bare account numbers, neither of which was the posted text. The preview now renders exactly the line_description the engine writes: the shared invoice-level text on expense lines and 2440, "Ingående moms {rate}% {desc}" on 2641, and the reverse-charge pair taken straight from generateReverseChargeLines instead of being re-derived locally. buildSupplierDescription moves into its own dependency-free module so the client-side preview can call it without pulling the journal engine (and its Supabase server client) into the browser bundle. The account name stays reachable on the AccountNumber hover card. Picked option A from the issue, keeping the fixed invoice-level description rather than propagating each item's own text: the customer-invoice side already writes invoice-level descriptions, so per-item text would create an inconsistency between the two invoice sides rather than remove one, and it would need an aggregation-collision policy in the journal engine. Rationale recorded in DECISIONS.md. Refs #1258 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(bookkeeping): restore the copy icon on verifikat rows The row-language rewrite in #1123 reused the copy icon's slot for the new expand toggle, removing the zero-click copy affordance from the bookkeeping list without mentioning it. The leftover orphaned copy_voucher_tooltip key in both message files is what identifies it as collateral rather than a product decision. Restore a copy icon in the row's right-edge action cell, reusing that key for aria-label and title. stopPropagation keeps the click off the row's expand toggle. The icon is hover-revealed on md+ and always visible below it: #1123 collapsed the desktop table and the mobile card into one responsive table, so hover-only would leave touch users with nothing. Copy is no longer gated on posted. The copy_from handler and the GET journal-entries route never looked at status, so copying a draft already worked end-to-end and only the detail-page button hid it; the two list surfaces were already ungated. Both list affordances now respect canWrite, which previously dropped read-only users into a dialog they could not submit. The repo does not render components in tests, which is why #1123 removed this silently. Pin the source shape instead, the same way the copy-invoice query is pinned. Closes #1266 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(transactions): revalidate stale invoice match pointers before offering a match potential_invoice_id / potential_supplier_invoice_id are written once, at bank import, and never revisited. When one of several identical recurring invoices was settled by a different transaction, every other transaction kept pointing at the now fully paid invoice. The match dialog then measured the bank amount against a 0 kr remaining balance and reported a "Beloppen skiljer sig ... fakturan blir delbetald" partial payment, and the worklist offered the same dead suggestion as a one-click confirm row. Worse, the manual escape hatch was hidden exactly when it was needed: TransactionInboxCard only shows "Matcha mot leverantörsfaktura" when no suggestion exists, so a stale pointer left the user with no way at all to reach the correct invoice. Fixed by revalidating at read time rather than by clearing sibling pointers on settle. Invoices are settled through many paths (both match routes, mark-paid, MCP, bank reconciliation, SIE import), so write-time cleanup leaks the moment one is missed, while the candidate lookup covers every route into the list. The shared accept-lists in lib/invoices/matchable-statuses.ts mirror the CAS guards the match routes already enforce. - listSuggestedMatches and the transactions page candidate fetch filter on status + remaining_amount, so a settled candidate yields no suggestion and the manual picker reappears on its own. - InvoiceMatchDialog blocks a settled target with a distinct message and a disabled confirm. Not advisory: both routes reject it outright with MATCH_INVOICE_ALREADY_PAID / MATCH_SI_ALREADY_PAID, so no override could succeed. - The supplier detail card now shows remaining_amount like the customer branch, instead of total. On a partially paid invoice it used to print "1 250 kr" directly beside "Differens: 1 250 kr". - match-supplier-invoice clears potential_supplier_invoice_id on the transaction it just matched, mirroring the customer route. No bookkeeping was ever at risk: both routes already refused a settled target before creating a voucher. The damage was confined to a misleading dialog and a dead end. createQueuedMockSupabase gains passive call recording (calls / findCall / findCalls) because the proxy swallowed filter and update arguments, which made the new assertions inexpressible. Refs #1259, #1260 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(webhooks): dispatch on emit instead of waiting for the next cron tick (#1256) * feat(webhooks): dispatch on emit instead of waiting for the next cron tick The webhook dispatcher ran only on a per-minute cron, so the floor on delivery latency was up to 60 seconds plus the request. An external consumer that wanted to react as a transaction landed had only one alternative: polling /api/events, which the 100 rpm per-key limit makes expensive and which still cannot beat the tick interval. Schedules one dispatch cycle as soon as deliveries are enqueued. The cron is unchanged and remains the retry and sweep path; this only moves the first attempt forward. Wired into the event-bus fanout plus the two routes that enqueue a delivery directly: the :test verb, whose entire purpose is telling someone whether their receiver works, and the manual delivery retry. Three properties are load-bearing and covered by tests. The kick is never awaited, because eventBus.emit is awaited at ~99 call sites including journal_entry.committed and each delivery can burn a 10 s receiver timeout. It coalesces per function instance, so a bulk booking that emits once per row does not schedule one claim round trip per row. It claims 5 rows rather than the cron's 50, because it runs on the tail of a user-facing request. Double delivery is not a risk: claim_due_webhook_deliveries already claims FOR UPDATE SKIP LOCKED and flips rows to in_flight in the same statement, so a kick racing the cron sees disjoint rows. Does not close #1201, which asks for a realtime stream for API consumers. This is the cheap half. Refs #1201 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs(webhooks): stop claiming the kick makes double delivery impossible Adversarial review of the previous commit caught an overstatement in its own comments. SKIP LOCKED keeps a kick and the cron from claiming the same row at the same moment, but claim_due_webhook_deliveries autocommits before any POST is issued, so from then on ownership is only status='in_flight' and a later cycle's recoverStuckInFlight sweep can re-arm a row still queued behind an earlier cycle's serial loop. Delivery is at-least-once, which is what the public docs already tell receivers ("the same delivery id may arrive more than once ... idempotency is on you"). The comments contradicted that. No behaviour change. The kick does not create this window: the cron claims 50 rows serially against the same 20 s stuck threshold, which is wider than what a batch of 5 can open. Refs #1201 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(bokslut): add bokslut-flow depreciation (78xx) back to the bolagsskatt base (#1253) * fix(bokslut): add bokslut-flow depreciation (78xx) back to the bolagsskatt base sumPostedYearEndDispositions reconstructs resultat fore skatt for the tax calculation, because generateIncomeStatement excludes every source_type='year_end' entry. It summed class 88 and 7533 but not 78xx, so planenlig avskrivning posted by the bokslut flow (lib/bokslut/assets/depreciation-engine.ts) was dropped from the income statement and never added back. The bolagsskatt base and the periodiseringsfond 25 % cap were therefore computed on an overstated result: tax too high by roughly 20.6 % of the depreciation. Also exclude the period's final bokslutsverifikation from the fetch. It carries source_type='year_end' as well and reverses every P&L account, 78xx/88xx/7533 included (verified against production closing entries), so once the year is closed it would cancel the add-back this function exists to produce. That hazard already applied to 88xx and 7533; the fix closes it for all three rather than widening it. Scope is deliberately the tax base only. Making the standalone resultatrakning show bokslut entries is a separate, larger change: the same exclusion is duplicated in the kpi_report_aggregates RPC, it moves displayed profit for every company that ran the bokslut flow, and it means removing the add-back at four call sites. Refs #1051 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(bokslut): scope the closing-entry lookup to the company and fail loudly Review (CodeRabbit + the compliance swarm, ASVS V8.2.1) flagged the new fiscal_periods read in sumPostedYearEndDispositions on two counts, both fair. It filtered only on the period id while every sibling query in the same function carries the tenant scope. Primary key or not, service-role paths have no RLS to fall back on and the repo's rule is to filter company_id explicitly, so it now does. It also discarded the query error. That mattered more than it looks: a failed read fell through to closingEntryId = null, which silently re-admits the closing verifikat's 78xx/88xx reversals and understates the tax base, i.e. exactly the failure this lookup was added to prevent. It now throws, and the surrounding catch turns it into the existing 'Failed to read posted dispositions' error. A wrong bolagsskatt is worse than a loud failure. Two regression tests: the lookup carries both eq filters, and a lookup failure propagates instead of degrading to a wrong number. Refs #1051 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(storage): drop the client-side DELETE policy on the documents bucket (#1254) * fix(storage): drop the client-side DELETE policy on the documents bucket 20240101000024 documents this bucket as WORM: "No UPDATE or DELETE policies". That described the repo, not production. Production carries a users_delete_own_documents policy that exists in no migration file: FOR DELETE TO authenticated USING (bucket_id = 'documents' AND (storage.foldername(name))[2] = auth.uid()::text) Under it, the uploading user can delete the storage bytes of any document they uploaded under the legacy documents/{userId}/... layout, using nothing but their normal browser token. That includes documents linked to a posted verifikat, which are rakenskapsinformation under the BFL 7 kap 2 § seven-year retention duty. deleteDocument()'s linked-check and the block_document_deletion() trigger both guard the document_attachments ROW, not the object: the row survives, still pointing at a file that is gone. Reproduced against a local replay of the full migration stream: with the policy present the uploader's own DELETE removes the object; with it dropped the same statement matches zero rows. Company-scoped keys were never exposed (their second path segment is the company id, not auth.uid()), so this only ever reached the legacy layout, which is where most documents still live. Safe because every in-app remove() on this bucket already runs on the service role, covered by service_role_all_documents. Deliberately narrow: users_read_own_documents and users_upload_own_documents stay. The Phase B backfill from 20260726092000 has not run, so dropping the legacy SELECT policy now would make existing documents unreadable. That is Phase C. The pg-real test asserts no DELETE and no UPDATE policy over the bucket under ANY name: the hole arrived under a name this repo never used, so pinning a name would not have caught it. Refs #1208 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(storage): make the WORM ratchet see FOR ALL and WITH CHECK policies Review caught two blind spots in the ratchet, both fair. It matched only polcmd 'd' and 'w', but polcmd '*' (FOR ALL) grants DELETE and UPDATE just as effectively, and FOR ALL is the shape the one legitimate policy on this table already uses, so a hostile one would look unremarkable in the catalogue. It also read only polqual, so an UPDATE policy carrying its bucket restriction in WITH CHECK was invisible. Both assertions now run through one helper that covers d/w/*, concatenates USING and WITH CHECK, and filters by grantee so service_role_all_documents (how the application does its authorized deletes) is excluded while every client-reachable role is not. A policy granted to PUBLIC has an empty polroles, which is the most permissive case there is, so it is treated as client-reachable rather than as "no roles". Matching on the substring rather than the exact `bucket_id = 'documents'` shape pg_get_expr emits today: a policy written as bucket_id::text or with the comparison reversed would slip past a stricter match, and for a WORM ratchet a false alarm is cheap while a silent hole is not. Adds a probe case that creates a FOR ALL policy and asserts the helper sees it, so the main assertion cannot pass vacuously. That case earned its keep immediately: it caught that node-postgres hands back a raw string for a name[] column, so the role filter needed rolname::text to work at all. Verified against a local replay of the full migration stream: red with the original prod FOR DELETE policy present, red with a FOR ALL probe, green without either. Full pg-real suite 933 passed. Refs #1208 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(storage): catch a destructive policy that names no bucket at all Adversarial review of the previous commit found the ratchet still failed open, and reproduced it: a policy with no bucket_id predicate covers EVERY bucket, documents included, so gating on the bucket name discarded exactly the widest hole. The concrete shape is Supabase's own stock "Enable delete for users based on user_id" template, USING (auth.uid() = owner), which is the single most likely form of a future dashboard edit. A destructive policy is now in scope unless it provably cannot reach this bucket, i.e. only a bucket_id predicate naming some other bucket exempts it. The behavioural assertions had the matching blind spot: fixtures were seeded without an owner, so an owner-based policy matched NULL and the DELETE reported 0 rows for the wrong reason. Objects now carry an owner the way storage-api stamps them in production, so those tests fail loudly instead of passing by accident. Two probes pin both directions: a bucketless policy must be reported (and is shown to really permit the delete), and a policy scoped to another bucket must not be, so the ratchet cannot start crying wolf on receipts or sie-files and get switched off. Verified against a local replay of the full migration stream: red with the stock bucketless template installed, green without it. Full pg-real suite 935 passed. Refs #1208 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(kontoplan): make a deactivated account reachable again (#1262) is_active=false read as "does not exist" on every read path but as "exists" on the (company_id, account_number) unique constraint, so a deactivated account vanished from the kontoplan with no way back and re-creating it answered "Kontonummer X finns redan i din kontoplan." The write side was already correct: POST /accounts/activate has a toReactivate branch and PUT /accounts/[number] accepts is_active:true. Both were simply unreachable, so this opens routes to them rather than relaxing the read filters, which are load-bearing for AccountsNotInChartError. - Kontoplan gets a "Visa inaktiva" filter; inactive rows carry an "Inaktiv" chip and the existing per-row switch reactivates them in one click. - Deactivating an account that has posted lines now warns first, using the usage count already loaded for the Verifikat column. - POST /accounts distinguishes the two collisions and returns the new ACCOUNT_EXISTS_INACTIVE code; AddAccountDialog offers "Aktivera kontot istallet" rather than a dead-end 409. The stored account is left exactly as it was; values typed into the failed create form are not applied. - bas-lookup consults the company's own chart before the static BAS reference, so a deactivated custom account reads as known and "Aktivera och bokfor" is no longer disabled for it. New in_chart / is_active fields let callers tell "will be added" from "will be revived". - BAS-katalog stops showing "Aktiverat" for an account the company holds but has deactivated; it falls through to a relabelled Aktivera button, and the per-class counts follow. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(supplier-invoices): flag foreign 0 % lines with reverse charge switched off (#1255) * fix(supplier-invoices): flag foreign 0 % lines with reverse charge switched off A foreign supplier charging no Swedish VAT is normally omvand skattskyldighet. With the reverse-charge switch off, createSupplierInvoiceRegistrationEntry emits neither the 26x4 output leg nor the 44xx/45xx basis lines, so ruta 20-24, 30-32 and 48 all stay empty and the momsdeklaration takes a shape Skatteverket rejects. For a fully deductible purchase the net moms att betala is unchanged, which is exactly why this goes unnoticed. The form already auto-ticks reverse charge for eu_business but not for non_eu_business, so that path slips through silently. Adds a pure helper plus a non-blocking banner cloned from the existing rc_account_warning block. Deliberately silent for swedish_business, where 0 % is a genuine exemption that belongs in no ruta at all, and phrased as a question rather than an assertion: a non-EU goods purchase cleared at customs is legitimately 0 % without reverse charge, and pushing that user into ticking the switch would manufacture a new wrong verifikat. Does not add the exempt/import/other picker the issue proposes: supplier_invoices.vat_treatment is metadata that no booking or ruta mapping reads, and the codebase cannot book import VAT at all, so an import option would imply ruta 50/60 were handled when they are not. Refs #1042 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(supplier-invoices): name the local-VAT case in the foreign 0 % hint Review flagged that the most common foreign document a Swedish small company sees is an invoice carrying the supplier's OWN local VAT, booked at 0 % Swedish VAT with reverse charge correctly off. The banner fires there, and the previous copy only offered "momsfri av annat skal, till exempel en varuimport" as the way out, which does not describe that invoice at all: it is not VAT-free, it carries foreign VAT. Names both legitimate cases explicitly and says 0 % is correct in them, so the hint cannot read as an instruction to tick reverse charge on a purchase where that would produce a wrong verifikat. Title also narrowed to "utan svensk moms" for the same reason. Refs #1042 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(sandbox): call the sandbox assistant Assistenten, not Anna (#1244) A named persona earns its name once someone has been through onboarding and chosen it: it is their assistant and they named it. Nobody in the sandbox chose anything, so a first name reads as a character the product invented and implies a relationship the visitor never opted into. Both halves move together, which is the point. profile_summary is the agent's own self-description inside the system prompt, so leaving it as "Du är Anna" would have the header say one thing while the assistant introduces itself as another in its first sentence. Nothing else in the stack checks that pairing, so a test now does. Scope: this changes the seed, so new sandbox companies get the new name. The 483 sandbox profiles already seeded keep 'Anna' (the seeder returns early once a profile exists, and its caller only runs while verified_at is null). Backfilling those is a production write on demo data and is being raised separately rather than smuggled into a code change. Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * feat(reports): show the last posted voucher per series in report headers Adds a "Senaste bokforda verifikat: A 214, B 37" line to the balans- and resultatrapport, so a printed or exported report answers which vouchers are actually in it rather than only which dates it spans (#1267). Reads MAX(voucher_number) over posted entries, never voucher_sequences.last_number. The sequence counter is an allocation high-water mark that drifts from the books in both directions: next_voucher_number burns a number when the follow-up insert fails, delete_last_voucher decrements by one instead of resetting to the new MAX, and pre-RPC SIE imports left it behind. Since the point of the line is avstamning, an allocated number would send a reconciler chasing a gap that does not exist, so the label says plainly that the number is the posted one. Scoped to the report own date range, so a Q1 report printed in November says something true about Q1. The balansrapport keeps the fiscal-year start as its lower bound because it accumulates. Skipped on a dimension-filtered resultatrapport: that report already discloses it is partial, and an unfiltered voucher range beside a filtered result invites the wrong conclusion. Populated in both engines, so the JSON, PDF and XLSX routes all inherit it without signature changes. Best-effort: a header nicety never breaks a report. The pure formatter lives in its own module so the client view does not pull the Supabase query path into the browser bundle. No new i18n keys; both report views and the PDF template are hard-coded Swedish per the "stays Swedish" report surfaces in .claude/rules/i18n.md. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(customers): stop rendering personnummer ciphertext, make unreadable rows editable, add a reveal path (#1263) customers.personal_number holds AES-256-GCM ciphertext (20260726110000). Three defects compounded into one broken surface for private customers. The list queried Supabase from the browser with select('*') and rendered the raw value, 76-82 chars of hex, into the nowrap identifier cell. It now reads GET /api/customers, which already masks every row, so the ciphertext never leaves the server. Searching by personnummer works again: the client filter had been matching against ciphertext and could never hit. A row whose value cannot be decrypted renders as the placeholder '********-????'. None of the three mask checks recognised it, each having its own '-1234'-only copy, so such a customer could not be edited in ANY field: name and address edits 400'd on a personnummer the user had no way to correct. All three now share one pattern from the new crypto-free lib/customers/mask-personal-number.ts, which the client form can import. Typing a fresh personnummer overwrites the unreadable value, which is the only repair possible: the rejected writes failed whole INSERTs, so there is nothing to backfill. The value was write-only by construction. GET /api/customers/{id}/personal-number is the deliberate drill-in, mirroring the employee convention, gated on the write role because .compliance/ropa.yaml listed no_full_value_read_endpoint as a safeguard for this column; that entry is rewritten rather than left stale, and reveals log actor and customer id but never the value. Also: arcim-migration wrote the identity number as plaintext, which aborts any import containing a Privatperson with 23514 since the constraint flip; and the customer embeds on /api/invoices shipped ciphertext to the browser on every invoice read. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat: enhance ruta 05 handling for dynamic revenue accounts - Introduced `fetchDynamicRuta05Accounts` to fetch company-specific revenue accounts marked with a VAT rate, addressing issue #1261. - Updated VAT declaration logic to include these dynamic accounts in ruta 05 calculations, ensuring accurate reporting for user-added accounts. - Modified `ACCOUNT_RUTA` to include account 3000 for completeness in ruta 05. - Enhanced tests to validate the inclusion of user-added revenue accounts in ruta 05 and ensure correct VAT calculations. - Seeded default VAT rates for BAS revenue accounts to ensure proper classification in the VAT declaration. * fix: enhance data handling and masking in customer and invoice APIs * fix(vat): resolve the 3000 gruppkonto's rate for the ruta 05 base split 3000 "Forsaljning inom Sverige" is mapped to ruta05 by ACCOUNT_RUTA, so a balance on it is filed in the right box already. What was missing is the rate split: unlike 3001/3002/3003 the account number carries no sats, and fetchDynamicRuta05Accounts skipped it because it is in ACCOUNT_TO_BOX. A company posting to the gruppkonto therefore got a ruta 05 total that breakdown.invoices.base25/12/6 did not add up to. Surface those rates separately as staticRateByAccount: rate-only on purpose, because the static map already sums the account and adding it to the dynamic account list would double the filed figure. A test pins that single-count property. Also add 3000 to the MCP server's RUTA_05_ACCOUNTS, which is the display list behind report.rutor.ruta05: without it a 3000 balance appeared in the filed projection but not in the report the agent reads back. The comment claiming SALES_OUTPUT_VAT_SHORTFALL reads base25/12/6 was wrong and is corrected. That check derives its expected base from the output-VAT rutor (ruta10/0.25 + ruta11/0.12 + ruta12/0.06); nothing reads the per-rate bases, which are reporting metadata. So the incomplete split never affected a filed return or a warning, only the breakdown. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Jakob Wennberg <149234542+jakobwennberg@users.noreply.github.com>
677 lines
28 KiB
TypeScript
677 lines
28 KiB
TypeScript
import type { SupabaseClient } from '@supabase/supabase-js'
|
|
import type {
|
|
VatDeclaration,
|
|
VatDeclarationRutor,
|
|
VatPeriodType,
|
|
} from '@/types'
|
|
import type { VatCheckAccountTotals } from './vat-declaration-checks'
|
|
import { fetchDynamicRuta05Accounts } from './vat-revenue-accounts'
|
|
|
|
/**
|
|
* Calculate VAT declaration (Momsdeklaration) for a given period.
|
|
*
|
|
* Reads directly from the general ledger: sums posted journal entry lines
|
|
* on 26xx (VAT) and 3xxx (revenue) accounts for the period. This makes the
|
|
* momsdeklaration a pure projection from the double-entry bookkeeping ledger.
|
|
*
|
|
* The accounting method (accrual vs cash) is already reflected in when
|
|
* journal entries were created by the entry generators, so no separate
|
|
* filtering logic is needed here.
|
|
*/
|
|
|
|
/**
|
|
* Account-to-ruta mapping for the Swedish momsdeklaration (SKV 4700).
|
|
*
|
|
* Pure ledger projection: every Ruta on the SKV 4700 form maps to one or more
|
|
* BAS account balances aggregated over the period. The mapping below follows
|
|
* the BAS 2026 chart and Skatteverket's published BAS-to-Ruta spec
|
|
* (`.claude/skills/swedish-vat/references/vat-compliance-reference.md` §7).
|
|
*
|
|
* Output VAT (261x/262x/263x) → ruta 10/11/12 per rate (credit balance)
|
|
* Includes parent/summary accounts (2610/2620/2630) for users who post
|
|
* directly to the group account, and vilande accounts (2618/2628/2638)
|
|
* used by cash-method bookkeepers for invoices not yet paid.
|
|
* Reverse charge output (2614/2624/2634) → ruta 30/31/32 (credit)
|
|
* Import VAT (2615/2625/2635) → ruta 60/61/62 (credit)
|
|
* Input VAT (2640-2649) → ruta 48 (debit), incl. parent 2640
|
|
* Domestic taxable sales (3000-3003) → ruta 05 (credit)
|
|
* The company's OWN class 3 accounts marked with a moms-sats join ruta 05 on
|
|
* top of this fixed list: see fetchDynamicRuta05Accounts (#1261). This map
|
|
* only covers the accounts Accounted itself seeds.
|
|
* Uttag (3401-3403) → ruta 06 (credit)
|
|
* EU goods (3108) → ruta 35; EU services (3308) → ruta 39 (credit)
|
|
* Export (3105/3305) → ruta 36/40; Exempt (3004/3100/3404/3994/3980) → ruta 42 (credit)
|
|
* Reverse-charge purchase bases: read from the cost account the journal
|
|
* entry posted to (debit balance), not from supplier classification:
|
|
* 4515/4516/4517 (EU goods 25/12/6%) → ruta 20
|
|
* 4535/4536/4537 (EU services 25/12/6%) → ruta 21
|
|
* 4531/4532/4533 (non-EU services 25/12/6%) → ruta 22
|
|
* 4415/4416/4417 (domestic goods reverse charge) → ruta 23
|
|
* 4425/4426/4427 (domestic services reverse charge) → ruta 24
|
|
* 4545/4546/4547 (import) → ruta 50
|
|
*/
|
|
export const ACCOUNT_RUTA: Record<string, { box: keyof VatDeclarationRutor; side: 'credit' | 'debit' }> = {
|
|
// Output VAT 25% → ruta 10
|
|
'2610': { box: 'ruta10', side: 'credit' }, // Utgående moms 25% (summary/parent)
|
|
'2611': { box: 'ruta10', side: 'credit' }, // Försäljning inom Sverige
|
|
'2612': { box: 'ruta10', side: 'credit' }, // Egna uttag
|
|
'2613': { box: 'ruta10', side: 'credit' }, // Uthyrning (frivillig skattskyldighet)
|
|
'2616': { box: 'ruta10', side: 'credit' }, // Vinstmarginalbeskattning
|
|
'2618': { box: 'ruta10', side: 'credit' }, // Vilande utgående moms 25%
|
|
// Output VAT 12% → ruta 11
|
|
'2620': { box: 'ruta11', side: 'credit' }, // Utgående moms 12% (summary/parent)
|
|
'2621': { box: 'ruta11', side: 'credit' },
|
|
'2622': { box: 'ruta11', side: 'credit' }, // Egna uttag
|
|
'2623': { box: 'ruta11', side: 'credit' }, // Uthyrning
|
|
'2626': { box: 'ruta11', side: 'credit' }, // VMB
|
|
'2628': { box: 'ruta11', side: 'credit' }, // Vilande utgående moms 12%
|
|
// Output VAT 6% → ruta 12
|
|
'2630': { box: 'ruta12', side: 'credit' }, // Utgående moms 6% (summary/parent)
|
|
'2631': { box: 'ruta12', side: 'credit' },
|
|
'2632': { box: 'ruta12', side: 'credit' }, // Egna uttag
|
|
'2633': { box: 'ruta12', side: 'credit' }, // Uthyrning
|
|
'2636': { box: 'ruta12', side: 'credit' }, // VMB
|
|
'2638': { box: 'ruta12', side: 'credit' }, // Vilande utgående moms 6%
|
|
// Reverse charge output VAT → ruta 30/31/32
|
|
'2614': { box: 'ruta30', side: 'credit' },
|
|
'2624': { box: 'ruta31', side: 'credit' },
|
|
'2634': { box: 'ruta32', side: 'credit' },
|
|
// Input VAT → ruta 48
|
|
'2640': { box: 'ruta48', side: 'debit' }, // Ingående moms (summary/parent)
|
|
'2641': { box: 'ruta48', side: 'debit' }, // Debiterad ingående moms
|
|
'2642': { box: 'ruta48', side: 'debit' }, // Frivillig skattskyldighet
|
|
'2645': { box: 'ruta48', side: 'debit' }, // Förvärv utlandet (EU/non-EU RC)
|
|
'2646': { box: 'ruta48', side: 'debit' }, // Uthyrning
|
|
'2647': { box: 'ruta48', side: 'debit' }, // Omvänd skattskyldighet i Sverige
|
|
'2649': { box: 'ruta48', side: 'debit' }, // Blandad verksamhet
|
|
// Import VAT (since 2015, via momsdeklaration) → ruta 60/61/62
|
|
'2615': { box: 'ruta60', side: 'credit' }, // Import 25%
|
|
'2625': { box: 'ruta61', side: 'credit' }, // Import 12%
|
|
'2635': { box: 'ruta62', side: 'credit' }, // Import 6%
|
|
// Revenue: domestic taxable sales → ruta 05
|
|
'3000': { box: 'ruta05', side: 'credit' }, // Försäljning inom Sverige (summary/parent)
|
|
'3001': { box: 'ruta05', side: 'credit' },
|
|
'3002': { box: 'ruta05', side: 'credit' },
|
|
'3003': { box: 'ruta05', side: 'credit' },
|
|
// Revenue: momspliktiga uttag → ruta 06
|
|
'3401': { box: 'ruta06', side: 'credit' },
|
|
'3402': { box: 'ruta06', side: 'credit' },
|
|
'3403': { box: 'ruta06', side: 'credit' },
|
|
// Revenue: EU goods/services → ruta 35/39
|
|
'3108': { box: 'ruta35', side: 'credit' }, // Varuförsäljning till EU
|
|
'3308': { box: 'ruta39', side: 'credit' }, // Tjänsteförsäljning till EU
|
|
// Revenue: export/other → ruta 36/40/42
|
|
'3105': { box: 'ruta36', side: 'credit' }, // Varuförsäljning export
|
|
'3305': { box: 'ruta40', side: 'credit' }, // Tjänsteförsäljning export
|
|
'3004': { box: 'ruta42', side: 'credit' }, // Momsfri försäljning (AB)
|
|
'3100': { box: 'ruta42', side: 'credit' }, // Momsfria intäkter (EF)
|
|
'3404': { box: 'ruta42', side: 'credit' }, // Momsfria uttag
|
|
'3980': { box: 'ruta42', side: 'credit' }, // Erhållna offentliga stöd m.m.
|
|
'3994': { box: 'ruta42', side: 'credit' }, // Övriga rörelseintäkter momsfria
|
|
// Reverse-charge purchase bases (debit on cost accounts) → ruta 20-24, 50
|
|
'4515': { box: 'ruta20', side: 'debit' }, // Inköp varor EU 25%
|
|
'4516': { box: 'ruta20', side: 'debit' }, // Inköp varor EU 12%
|
|
'4517': { box: 'ruta20', side: 'debit' }, // Inköp varor EU 6%
|
|
'4535': { box: 'ruta21', side: 'debit' }, // Inköp tjänster EU 25%
|
|
'4536': { box: 'ruta21', side: 'debit' }, // Inköp tjänster EU 12%
|
|
'4537': { box: 'ruta21', side: 'debit' }, // Inköp tjänster EU 6%
|
|
'4531': { box: 'ruta22', side: 'debit' }, // Inköp tjänster utanför EU 25%
|
|
'4532': { box: 'ruta22', side: 'debit' }, // Inköp tjänster utanför EU 12%
|
|
'4533': { box: 'ruta22', side: 'debit' }, // Inköp tjänster utanför EU 6%
|
|
'4415': { box: 'ruta23', side: 'debit' }, // Inköp varor SE reverse charge 25%
|
|
'4416': { box: 'ruta23', side: 'debit' }, // Inköp varor SE reverse charge 12%
|
|
'4417': { box: 'ruta23', side: 'debit' }, // Inköp varor SE reverse charge 6%
|
|
'4425': { box: 'ruta24', side: 'debit' }, // Inköp tjänster SE reverse charge 25%
|
|
'4426': { box: 'ruta24', side: 'debit' }, // Inköp tjänster SE reverse charge 12%
|
|
'4427': { box: 'ruta24', side: 'debit' }, // Inköp tjänster SE reverse charge 6%
|
|
'4545': { box: 'ruta50', side: 'debit' }, // Beskattningsunderlag import 25%
|
|
'4546': { box: 'ruta50', side: 'debit' }, // Beskattningsunderlag import 12%
|
|
'4547': { box: 'ruta50', side: 'debit' }, // Beskattningsunderlag import 6%
|
|
}
|
|
|
|
const VAT_ACCOUNTS = Object.keys(ACCOUNT_RUTA)
|
|
|
|
/**
|
|
* 26xx output VAT accounts feeding rutor 10/11/12, 30/31/32 and 60/61/62.
|
|
* Derived from ACCOUNT_RUTA so the KPI vatLiability widget can never drift
|
|
* from the momsdeklaration (ruta 49) calculation.
|
|
*/
|
|
export const VAT_OUTPUT_ACCOUNTS = Object.entries(ACCOUNT_RUTA)
|
|
.filter(([account, mapping]) => account.startsWith('26') && mapping.side === 'credit')
|
|
.map(([account]) => account)
|
|
|
|
/** Input VAT accounts feeding ruta 48 (2640-2649 series). */
|
|
export const VAT_INPUT_ACCOUNTS = Object.entries(ACCOUNT_RUTA)
|
|
.filter(([, mapping]) => mapping.box === 'ruta48')
|
|
.map(([account]) => account)
|
|
|
|
/**
|
|
* The reverse-charge INPUT VAT accounts the momsdeklaration completeness check
|
|
* compares rutor 30-32 against: 2645 (beräknad ingående moms på förvärv från
|
|
* utlandet, EU and non-EU) and 2647 (ingående moms, omvänd betalningsskyldighet
|
|
* i Sverige). The other five ruta 48 accounts are not reverse charge and stay
|
|
* out, 2649 (blandad verksamhet) above all: counting it would reintroduce the
|
|
* aggregation the sharpened check exists to remove.
|
|
*
|
|
* Mirrors RC_INPUT_ACCOUNTS in ./vat-declaration-checks, which keeps its copy
|
|
* private. The two lists are pinned together behaviourally in
|
|
* __tests__/vat-declaration.test.ts: it feeds the projected pair and a full
|
|
* totals map carrying a balance on every OTHER ruta 48 account to
|
|
* runVatDeclarationChecks and asserts identical findings, so widening the list
|
|
* on one side without the other fails there.
|
|
*/
|
|
export const RC_INPUT_VAT_ACCOUNTS = ['2645', '2647'] as const
|
|
|
|
/**
|
|
* Calculate period start and end dates
|
|
*/
|
|
export function calculatePeriodDates(
|
|
periodType: VatPeriodType,
|
|
year: number,
|
|
period: number
|
|
): { start: string; end: string } {
|
|
let startMonth: number
|
|
let endMonth: number
|
|
|
|
switch (periodType) {
|
|
case 'monthly':
|
|
// period is 1-12
|
|
startMonth = period
|
|
endMonth = period
|
|
break
|
|
case 'quarterly':
|
|
// period is 1-4
|
|
startMonth = (period - 1) * 3 + 1
|
|
endMonth = period * 3
|
|
break
|
|
case 'yearly':
|
|
// period is 1
|
|
startMonth = 1
|
|
endMonth = 12
|
|
break
|
|
default:
|
|
startMonth = 1
|
|
endMonth = 12
|
|
}
|
|
|
|
const startDate = new Date(year, startMonth - 1, 1)
|
|
const endDate = new Date(year, endMonth, 0) // Last day of end month
|
|
|
|
return {
|
|
start: formatDate(startDate),
|
|
end: formatDate(endDate),
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Format date as YYYY-MM-DD
|
|
*/
|
|
function formatDate(date: Date): string {
|
|
const y = date.getFullYear()
|
|
const m = String(date.getMonth() + 1).padStart(2, '0')
|
|
const d = String(date.getDate()).padStart(2, '0')
|
|
return `${y}-${m}-${d}`
|
|
}
|
|
|
|
/**
|
|
* Round to 2 decimal places
|
|
*/
|
|
function round(value: number): number {
|
|
return Math.round(value * 100) / 100
|
|
}
|
|
|
|
/**
|
|
* Resolve the start/end dates for a VAT period.
|
|
*
|
|
* Monthly and quarterly VAT periods are always calendar months/quarters
|
|
* (kalendermånad / kalenderkvartal per SFL 26 kap), so they use the plain
|
|
* calendar calculation.
|
|
*
|
|
* Annual VAT (helårsmoms), however, is reported per *räkenskapsår* (the
|
|
* beskattningsår), not per calendar year (SFL 26 kap 10-11 §§). A räkenskapsår
|
|
* can be extended or shortened (up to 18 months for a first/changed year per
|
|
* BFL 3 kap 3 §), so a calendar Jan-Dec span would silently drop part of an
|
|
* extended year (e.g. a first year 2025-07-03 → 2026-12-31). When the caller
|
|
* supplies the fiscal period we therefore use its actual bounds. If the period
|
|
* can't be resolved we fall back to the calendar span so behaviour degrades
|
|
* gracefully instead of erroring.
|
|
*/
|
|
export async function resolvePeriodDates(
|
|
supabase: SupabaseClient,
|
|
companyId: string,
|
|
periodType: VatPeriodType,
|
|
year: number,
|
|
period: number,
|
|
fiscalPeriodId?: string
|
|
): Promise<{ start: string; end: string }> {
|
|
if (periodType === 'yearly') {
|
|
if (fiscalPeriodId) {
|
|
const { data: fp } = await supabase
|
|
.from('fiscal_periods')
|
|
.select('period_start, period_end')
|
|
.eq('id', fiscalPeriodId)
|
|
.eq('company_id', companyId)
|
|
.maybeSingle()
|
|
if (fp?.period_start && fp?.period_end) {
|
|
return { start: fp.period_start, end: fp.period_end }
|
|
}
|
|
} else {
|
|
// No explicit fiscal period: resolve the räkenskapsår ending in `year`
|
|
// instead of assuming a calendar FY. Helårsmoms is filed per
|
|
// räkenskapsår (SFL 26 kap 10-11 §§), so for a broken fiscal year the
|
|
// calendar-year assumption would put both the redovisningsperiod and
|
|
// the figures on the wrong period. For calendar-FY companies this
|
|
// resolves to Jan-Dec of `year`, identical to the arithmetic fallback.
|
|
const { data: fp } = await supabase
|
|
.from('fiscal_periods')
|
|
.select('period_start, period_end')
|
|
.eq('company_id', companyId)
|
|
.gte('period_end', `${year}-01-01`)
|
|
.lte('period_end', `${year}-12-31`)
|
|
.order('period_end', { ascending: false })
|
|
.limit(1)
|
|
.maybeSingle()
|
|
if (fp?.period_start && fp?.period_end) {
|
|
return { start: fp.period_start, end: fp.period_end }
|
|
}
|
|
}
|
|
}
|
|
return calculatePeriodDates(periodType, year, period)
|
|
}
|
|
|
|
/**
|
|
* Accounts a momsredovisning settles the period's net against: 2650
|
|
* (Redovisningskonto för moms, att betala) and 1650 (Momsfordran, att återfå).
|
|
* Mirrors VAT_SETTLEMENT_ACCOUNT/VAT_REFUND_ACCOUNT in vat-settlement.ts,
|
|
* which imports from this module and therefore cannot be imported here.
|
|
*/
|
|
export const VAT_SETTLEMENT_NET_ACCOUNTS = ['2650', '1650']
|
|
|
|
/** A momsredovisning entry detected by shape rather than source_type. */
|
|
export interface VatSettlementShapedEntry {
|
|
id: string
|
|
status: string
|
|
entry_date: string
|
|
source_type: string | null
|
|
voucher_series: string | null
|
|
voucher_number: number | null
|
|
}
|
|
|
|
export interface VatAccountTotals {
|
|
totals: Map<string, { debit: number; credit: number }>
|
|
/**
|
|
* Untagged momsredovisning entries found in the period (manual vouchers,
|
|
* SIE-imported settlements, stornos of a settlement). Already excluded
|
|
* from `totals`; surfaced so the settlement proposal can warn and gate.
|
|
*/
|
|
settlementShapedEntries: VatSettlementShapedEntry[]
|
|
/**
|
|
* Posted/reversed entry counts per source_type for the whole period,
|
|
* INCLUDING tagged vat_settlement entries (they never match the
|
|
* invoice/transaction buckets, and the metadata scan always counted them).
|
|
* Comes back in the same RPC round trip so the declaration metadata no
|
|
* longer needs its own paginated entry scan.
|
|
*/
|
|
sourceTypeCounts: Record<string, number>
|
|
}
|
|
|
|
/** Wire shape of the get_vat_declaration_totals RPC jsonb payload. */
|
|
interface VatTotalsRpcPayload {
|
|
totals: Array<{ account_number: string; debit: number; credit: number }>
|
|
settlement_shaped_entries: VatSettlementShapedEntry[]
|
|
source_type_counts: Record<string, number>
|
|
}
|
|
|
|
/**
|
|
* Fetch and aggregate debit/credit totals per VAT-relevant account
|
|
* (ACCOUNT_RUTA) for a period. Shared by the declaration calculation and the
|
|
* settlement proposal (lib/reports/vat-settlement.ts) so the two can never
|
|
* disagree on which ledger lines count.
|
|
*
|
|
* Momsredovisning entries are excluded. They are bookkeeping about the
|
|
* declaration, not VAT-bearing business activity; including them would zero
|
|
* out the rutor the moment the settlement is booked, turning the report, its
|
|
* exports, and a later Skatteverket submission into an empty declaration
|
|
* (#984). Two detection paths:
|
|
*
|
|
* - tagged: source_type 'vat_settlement' (the app's own settlement flow),
|
|
* filtered in the query;
|
|
* - shaped: an entry with at least one line on a declaration account
|
|
* (ACCOUNT_RUTA) and at least one on 2650/1650. This catches settlements
|
|
* booked before the tagged flow existed, manual vouchers, SIE-imported
|
|
* settlements, and storno reversals of a settlement (source_type
|
|
* 'storno', which would otherwise re-inflate the rutor after annullera).
|
|
*
|
|
* Opening-balance entries are exempt from the shape rule: 26xx balances
|
|
* carried in by a migrating company are unsettled VAT that belongs in the
|
|
* next declaration, even when the same entry carries a 2650/1650 balance.
|
|
*/
|
|
export async function fetchVatAccountTotals(
|
|
supabase: SupabaseClient,
|
|
companyId: string,
|
|
start: string,
|
|
end: string,
|
|
dynamicRuta05Accounts: string[] = []
|
|
): Promise<VatAccountTotals> {
|
|
// Aggregation, settlement-shape detection, and source_type counts all
|
|
// happen in one SQL pass (get_vat_declaration_totals). The previous
|
|
// implementation paged every entry + line for the period through PostgREST
|
|
// and reduced in JS: dozens of round trips for a busy quarter. The account
|
|
// lists are parameters so ACCOUNT_RUTA stays the single source of truth.
|
|
//
|
|
// The company's own ruta 05 accounts join p_accounts (they must be summed)
|
|
// but deliberately NOT p_ruta_accounts. That second list is the settlement
|
|
// SHAPE detector: an entry with a line on it plus a line on 2650/1650 is
|
|
// classified a momsredovisning and dropped from the totals entirely. A plain
|
|
// sale booked 1930 / 3013 / 2650 (a company clearing moms straight off the
|
|
// revenue voucher) would then vanish from its own declaration. The fixed
|
|
// ACCOUNT_RUTA list is what defines settlement shape; user accounts widen
|
|
// what is measured, never what counts as a momsredovisning.
|
|
const { data, error } = await supabase.rpc('get_vat_declaration_totals', {
|
|
p_company_id: companyId,
|
|
p_start: start,
|
|
p_end: end,
|
|
p_accounts: [...VAT_ACCOUNTS, ...VAT_SETTLEMENT_NET_ACCOUNTS, ...dynamicRuta05Accounts],
|
|
p_ruta_accounts: VAT_ACCOUNTS,
|
|
p_net_accounts: VAT_SETTLEMENT_NET_ACCOUNTS,
|
|
})
|
|
if (error) {
|
|
throw new Error(`get_vat_declaration_totals failed: ${error.message}`)
|
|
}
|
|
|
|
const payload = (data ?? {}) as Partial<VatTotalsRpcPayload>
|
|
const totals = new Map<string, { debit: number; credit: number }>()
|
|
for (const row of payload.totals ?? []) {
|
|
totals.set(row.account_number, {
|
|
debit: Number(row.debit) || 0,
|
|
credit: Number(row.credit) || 0,
|
|
})
|
|
}
|
|
|
|
return {
|
|
totals,
|
|
settlementShapedEntries: payload.settlement_shaped_entries ?? [],
|
|
sourceTypeCounts: payload.source_type_counts ?? {},
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Map aggregated per-account totals to the momsdeklaration boxes, including
|
|
* the recomputed ruta 49 net (FK009). Pure projection over ACCOUNT_RUTA plus
|
|
* the company's own ruta 05 accounts (fetchDynamicRuta05Accounts).
|
|
*
|
|
* `dynamicRuta05Accounts` is optional so callers that only need the 26xx boxes
|
|
* keep working untouched: ruta 05 is a beskattningsunderlag, not moms, so it
|
|
* never reaches ruta 49 and the settlement proposal nets the same either way.
|
|
*/
|
|
export function rutorFromTotals(
|
|
totals: Map<string, { debit: number; credit: number }>,
|
|
dynamicRuta05Accounts: string[] = []
|
|
): VatDeclarationRutor {
|
|
const rutor: VatDeclarationRutor = {
|
|
ruta05: 0, ruta06: 0, ruta07: 0, ruta08: 0,
|
|
ruta10: 0, ruta11: 0, ruta12: 0,
|
|
ruta20: 0, ruta21: 0, ruta22: 0, ruta23: 0, ruta24: 0,
|
|
ruta30: 0, ruta31: 0, ruta32: 0,
|
|
ruta35: 0, ruta36: 0, ruta37: 0, ruta38: 0,
|
|
ruta39: 0, ruta40: 0, ruta41: 0, ruta42: 0,
|
|
ruta48: 0, ruta49: 0,
|
|
ruta50: 0, ruta60: 0, ruta61: 0, ruta62: 0,
|
|
}
|
|
|
|
for (const [account, mapping] of Object.entries(ACCOUNT_RUTA)) {
|
|
const t = totals.get(account)
|
|
if (!t) continue
|
|
const balance = mapping.side === 'credit'
|
|
? t.credit - t.debit
|
|
: t.debit - t.credit
|
|
rutor[mapping.box] = round(rutor[mapping.box] + balance)
|
|
}
|
|
|
|
// The company's own momspliktiga intäktskonton. Always credit-side: these are
|
|
// revenue accounts by construction (account_class 3).
|
|
for (const account of dynamicRuta05Accounts) {
|
|
const t = totals.get(account)
|
|
if (!t) continue
|
|
rutor.ruta05 = round(rutor.ruta05 + (t.credit - t.debit))
|
|
}
|
|
|
|
// FK009: summaMoms = (10 + 11 + 12 + 30 + 31 + 32 + 60 + 61 + 62) - 48
|
|
rutor.ruta49 = round(
|
|
rutor.ruta10 + rutor.ruta11 + rutor.ruta12 +
|
|
rutor.ruta30 + rutor.ruta31 + rutor.ruta32 +
|
|
rutor.ruta60 + rutor.ruta61 + rutor.ruta62 -
|
|
rutor.ruta48
|
|
)
|
|
|
|
return rutor
|
|
}
|
|
|
|
/**
|
|
* Project the reverse-charge input pair (2645/2647) out of a full totals map,
|
|
* for `VatDeclaration.rcInputAccountTotals`.
|
|
*
|
|
* Both keys are always present, zeros included, so the wire shape is stable and
|
|
* an absent field keeps meaning "this producer does not carry the pair" rather
|
|
* than "no reverse charge in the period".
|
|
*/
|
|
function rcInputTotals(
|
|
totals: Map<string, { debit: number; credit: number }>
|
|
): Record<string, { debit: number; credit: number }> {
|
|
const pair: Record<string, { debit: number; credit: number }> = {}
|
|
for (const account of RC_INPUT_VAT_ACCOUNTS) {
|
|
const t = totals.get(account)
|
|
pair[account] = { debit: round(t?.debit ?? 0), credit: round(t?.credit ?? 0) }
|
|
}
|
|
return pair
|
|
}
|
|
|
|
/**
|
|
* Rebuild the per-account totals map `runVatDeclarationChecks` takes as its
|
|
* optional second argument, from a declaration that may have arrived as JSON
|
|
* over HTTP.
|
|
*
|
|
* Returns undefined when the pair is absent, which makes the check fall back to
|
|
* its weaker ruta 48 comparison. That is deliberate: an empty map would read as
|
|
* "0 kr beräknad ingående moms" and turn a correct declaration into a warning.
|
|
*/
|
|
export function rcInputTotalsFromDeclaration(
|
|
declaration: Pick<VatDeclaration, 'rcInputAccountTotals'>
|
|
): VatCheckAccountTotals | undefined {
|
|
const pair = declaration.rcInputAccountTotals
|
|
return pair ? new Map(Object.entries(pair)) : undefined
|
|
}
|
|
|
|
/**
|
|
* Calculate VAT declaration from the general ledger.
|
|
*
|
|
* Sums posted journal entry lines on the BAS accounts in ACCOUNT_RUTA per the
|
|
* SKV 4700 form mapping. Pure ledger projection: no supplier classification
|
|
* or other side-channel signals.
|
|
*
|
|
* - ruta 49 = (10 + 11 + 12 + 30 + 31 + 32 + 60 + 61 + 62) - 48
|
|
*
|
|
* INVARIANT: the company's accounting method (faktureringsmetoden vs
|
|
* kontantmetoden) needs no parameter here and must not become one. The method
|
|
* is already baked into journal entry TIMING: kontantmetod companies post
|
|
* VAT-bearing entries at payment date, faktureringsmetod companies at invoice
|
|
* date, so summing posted lines per period is correct for both. A method
|
|
* parameter existed until 2026-07-23 and was silently ignored; it was removed
|
|
* so no future code path can branch on a value that callers hard-code.
|
|
*/
|
|
export async function calculateVatDeclaration(
|
|
supabase: SupabaseClient,
|
|
companyId: string,
|
|
periodType: VatPeriodType,
|
|
year: number,
|
|
period: number,
|
|
options: { fiscalPeriodId?: string } = {}
|
|
): Promise<VatDeclaration> {
|
|
// For yearly VAT this resolves to the räkenskapsår bounds (when a fiscal
|
|
// period is supplied), not the calendar year: see resolvePeriodDates.
|
|
const { start, end } = await resolvePeriodDates(
|
|
supabase, companyId, periodType, year, period, options.fiscalPeriodId
|
|
)
|
|
|
|
// Which of the company's OWN class 3 accounts count as momspliktig
|
|
// försäljning. Resolved from their "Standard moms" rather than a fixed BAS
|
|
// list, because Accounted seeds no varugrupp accounts: every 3011/3013-style
|
|
// konto is user-added and would otherwise never be fetched at all (#1261).
|
|
const dynamicRuta05 = await fetchDynamicRuta05Accounts(supabase, companyId)
|
|
|
|
// Fetch and aggregate posted VAT-account activity for the period. The same
|
|
// RPC round trip carries the per-source_type entry counts for the metadata.
|
|
const { totals, sourceTypeCounts } = await fetchVatAccountTotals(
|
|
supabase, companyId, start, end, dynamicRuta05.accounts
|
|
)
|
|
|
|
// Map account balances to momsdeklaration boxes
|
|
const rutor = rutorFromTotals(totals, dynamicRuta05.accounts)
|
|
|
|
// Compute per-rate base amounts from individual revenue accounts. The
|
|
// company's own accounts carry their rate on the konto itself, so they land
|
|
// in the same three buckets: without that, a 3013 company would show a
|
|
// ruta 05 base that none of base25/12/6 accounts for.
|
|
//
|
|
// These three are REPORTING metadata (breakdown.invoices), not check inputs:
|
|
// vat-declaration-checks.ts derives its expected base from the output-VAT
|
|
// rutor (ruta10/0.25 + ruta11/0.12 + ruta12/0.06) and never reads base25/12/6.
|
|
// So an incomplete split understates nothing that gets filed; it only makes
|
|
// the breakdown fail to add up to ruta 05.
|
|
const revenueByRate = {
|
|
base25: 0, // 3001
|
|
base12: 0, // 3002
|
|
base6: 0, // 3003
|
|
}
|
|
const RATE_BUCKET = { 0.25: 'base25', 0.12: 'base12', 0.06: 'base6' } as const
|
|
for (const [account, rate] of [['3001', 'base25'], ['3002', 'base12'], ['3003', 'base6']] as const) {
|
|
const t = totals.get(account)
|
|
if (t) revenueByRate[rate] = round(t.credit - t.debit)
|
|
}
|
|
for (const [account, rate] of dynamicRuta05.rateByAccount) {
|
|
const t = totals.get(account)
|
|
if (!t) continue
|
|
const bucket = RATE_BUCKET[rate as keyof typeof RATE_BUCKET]
|
|
if (!bucket) continue
|
|
revenueByRate[bucket] = round(revenueByRate[bucket] + (t.credit - t.debit))
|
|
}
|
|
// Accounts the static map ALREADY sums into ruta 05 (3000, the 30xx
|
|
// gruppkonto) but whose rate only exists as the konto's "Standard moms".
|
|
// Rate-only on purpose: their balance is in ruta 05 either way, so adding
|
|
// them to dynamicRuta05.accounts would double the filed figure.
|
|
for (const [account, rate] of dynamicRuta05.staticRateByAccount) {
|
|
const t = totals.get(account)
|
|
if (!t) continue
|
|
const bucket = RATE_BUCKET[rate as keyof typeof RATE_BUCKET]
|
|
if (!bucket) continue
|
|
revenueByRate[bucket] = round(revenueByRate[bucket] + (t.credit - t.debit))
|
|
}
|
|
|
|
// Entry counts by source type for metadata: aggregated by the RPC in the
|
|
// same round trip as the totals (SQL GROUP BY, so a busy VAT period can
|
|
// never truncate the counts).
|
|
const invoiceSources = new Set([
|
|
'invoice_created', 'invoice_paid', 'invoice_cash_payment', 'credit_note',
|
|
])
|
|
let invoiceCount = 0
|
|
let transactionCount = 0
|
|
for (const [sourceType, n] of Object.entries(sourceTypeCounts)) {
|
|
if (invoiceSources.has(sourceType)) invoiceCount += n
|
|
else if (sourceType === 'bank_transaction') transactionCount += n
|
|
}
|
|
|
|
return {
|
|
period: { type: periodType, year, period, start, end },
|
|
rutor,
|
|
// The 2645/2647 pair travels with the declaration so an HTTP caller can run
|
|
// the sharp RC_INPUT_VAT_MISMATCH comparison instead of the ruta 48
|
|
// fallback: see VatDeclaration.rcInputAccountTotals.
|
|
rcInputAccountTotals: rcInputTotals(totals),
|
|
invoiceCount,
|
|
transactionCount,
|
|
breakdown: {
|
|
invoices: {
|
|
ruta05: rutor.ruta05,
|
|
ruta06: rutor.ruta06,
|
|
ruta07: rutor.ruta07,
|
|
ruta10: rutor.ruta10,
|
|
ruta11: rutor.ruta11,
|
|
ruta12: rutor.ruta12,
|
|
ruta39: rutor.ruta39,
|
|
ruta40: rutor.ruta40,
|
|
base25: revenueByRate.base25,
|
|
base12: revenueByRate.base12,
|
|
base6: revenueByRate.base6,
|
|
},
|
|
transactions: { ruta48: rutor.ruta48 },
|
|
receipts: { ruta48: 0 },
|
|
reverseCharge: {
|
|
ruta20: rutor.ruta20,
|
|
ruta21: rutor.ruta21,
|
|
ruta22: rutor.ruta22,
|
|
ruta23: rutor.ruta23,
|
|
ruta24: rutor.ruta24,
|
|
ruta30: rutor.ruta30,
|
|
ruta31: rutor.ruta31,
|
|
ruta32: rutor.ruta32,
|
|
},
|
|
},
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Get a summary of the VAT declaration for display
|
|
*/
|
|
export function getVatDeclarationSummary(declaration: VatDeclaration): {
|
|
totalOutputVat: number
|
|
totalInputVat: number
|
|
vatToPay: number
|
|
isRefund: boolean
|
|
} {
|
|
const totalOutputVat = round(
|
|
declaration.rutor.ruta10 +
|
|
declaration.rutor.ruta11 +
|
|
declaration.rutor.ruta12 +
|
|
declaration.rutor.ruta30 +
|
|
declaration.rutor.ruta31 +
|
|
declaration.rutor.ruta32 +
|
|
declaration.rutor.ruta60 +
|
|
declaration.rutor.ruta61 +
|
|
declaration.rutor.ruta62
|
|
)
|
|
|
|
const totalInputVat = declaration.rutor.ruta48
|
|
const vatToPay = declaration.rutor.ruta49
|
|
|
|
return {
|
|
totalOutputVat,
|
|
totalInputVat,
|
|
vatToPay,
|
|
isRefund: vatToPay < 0,
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Format period label for display
|
|
*/
|
|
export function formatPeriodLabel(
|
|
periodType: VatPeriodType,
|
|
year: number,
|
|
period: number
|
|
): string {
|
|
switch (periodType) {
|
|
case 'monthly':
|
|
const monthNames = [
|
|
'Januari', 'Februari', 'Mars', 'April', 'Maj', 'Juni',
|
|
'Juli', 'Augusti', 'September', 'Oktober', 'November', 'December'
|
|
]
|
|
return `${monthNames[period - 1]} ${year}`
|
|
case 'quarterly':
|
|
return `Kvartal ${period} ${year}`
|
|
case 'yearly':
|
|
return `Helår ${year}`
|
|
default:
|
|
return `${year}`
|
|
}
|
|
}
|