fix(customers): make country ISO-2 everywhere and check it against the customer type (#2241)
* fix(customers): make country ISO-2 everywhere and check it against the customer type (#2025, #2028) customers.country and suppliers.country were read as ISO codes by the periodisk sammanstallning (SKV 5740), Peppol and the provider importers but written as English names by the customer form and the v1 API, so a correct German customer produced GERMANY811234567 in the SKV file plus two false warnings, and an EU customer saved with land Sverige got reverse charge with nothing objecting until after the invoice was sent. - lib/vat/country-codes.ts: one helper that normalises codes and the Swedish/English names the writers used to store, the country-vs-type rule (swedish_business = SE, eu_business = EU member other than SE that matches the VAT prefix, non_eu_business = outside the EU), and the reverse-charge country gate. - Writers: customer form and supplier form get a country select; internal REST, v1 REST, bulk-create, MCP create/update, CSV/Excel import and the provider migration mapper normalise to a code and refuse unknown text; the consistency rule is a form error and an API 400 (CUSTOMER_COUNTRY_MISMATCH on update). An omitted country is SE for Swedish types, derived from the VAT prefix for eu_business, required for non_eu_business. - vat-rules.ts: getVatRules and friends take the country as a third argument and grant reverse charge only for an EU country other than SE; every invoice/sales-order/MCP call site passes customer.country. - periodisk sammanstallning reads legacy names through the same helper. - Migration 20260903170000: normalize_country_code() SQL twin, country_raw rollback column on both tables, backfill of every non-code row; unknown text is left as-is. pg-real test for the function. Closes #2025, closes #2028 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D5EmmndLyDCmY5NHYAvYkE * fix(customers): keep reverse charge for defaulted-SE EU rows, gate the country rule on the fields it reads, fix build Skeptic and CI findings on #2241, one pass: - Migration step 4: eu_business rows whose country was null or only the old writer default (SE) while the VAT number names another EU member take the country from the prefix. The pre-2026-09 rules granted reverse charge on type + VIES validation alone, so these rows invoiced at 0% and would have flipped to 25% on the next invoice. country_raw = '' marks a null origin; rollback uses nullif(country_raw, ''). - countryPermitsReverseCharge refuses SE only: a VIES-validated number outweighs a non-EU address (Swiss company registered in DE, Monaco with a FR number, Northern Ireland XI). - checkCountryConsistency: an eu_business outside the EU VAT area is accepted when the VAT prefix is an EU-trade registration (incl. XI); Monaco maps to the FR prefix. - Internal PATCH, MCP update and the commit executor judge the country rule only when customer_type, country or vat_number is part of the update, so a contradictory legacy row can still change its email (v1 already did). - Webshop-order customers get the order's billing country; spreadsheet import derives a missing country from the type and flags contradictions (parser row error + execute schema refine). - Build: v1 [id] route typed the existing row through a narrowed alias (never) and passed messageSv/messageEn the v1 error context lacks; the self-billed customer projection lacked country. - Checks: regenerated skills/accounted-api (customer example country SE). - New parity test holds the migration's SQL name table to the TS table. - DECISIONS.md: correct migration version and the revised rule. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D5EmmndLyDCmY5NHYAvYkE --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5.1
parent
80b87c55fc
commit
3918ff6620
+84
-6
@@ -24,6 +24,12 @@ import {
|
||||
} from '@/lib/invoices/rot-rut-rules'
|
||||
import { NON_IBAN_CURRENCIES } from '@/lib/invoices/payment-accounts'
|
||||
import { PERSONAL_NUMBER_INPUT_RE } from '@/lib/customers/mask-personal-number'
|
||||
import {
|
||||
COUNTRY_CONSISTENCY_MESSAGES,
|
||||
checkCountryConsistency,
|
||||
defaultCountryForParty,
|
||||
normalizeCountryCode,
|
||||
} from '@/lib/vat/country-codes'
|
||||
import {
|
||||
looksLikeSwedishPersonalNumber,
|
||||
normalizeReroutedPersonalNumber,
|
||||
@@ -945,6 +951,29 @@ export const SendInvoiceSchema = MarkInvoiceSentSchema.extend({
|
||||
// Customer schemas
|
||||
// ============================================================
|
||||
|
||||
/**
|
||||
* ISO 3166-1 alpha-2 country on customers and suppliers. A code in any case
|
||||
* ("de", "DE"), Skatteverket's EL for Greece, or a Swedish/English country
|
||||
* name ("Tyskland", "Germany") is normalised to the uppercase code; anything
|
||||
* else is a 400. The column used to take free text, which put
|
||||
* GERMANY811234567 in the SKV 5740 file (#2028). Empty string reads as
|
||||
* "not supplied".
|
||||
*/
|
||||
const countryCode = z.string().transform((value, ctx) => {
|
||||
const code = normalizeCountryCode(value)
|
||||
if (!code) {
|
||||
ctx.addIssue({
|
||||
code: 'custom',
|
||||
message:
|
||||
`country "${value}" is not an ISO 3166-1 alpha-2 code or a known country name. `
|
||||
+ 'Use a code such as SE, DE or NO.',
|
||||
})
|
||||
return z.NEVER
|
||||
}
|
||||
return code
|
||||
})
|
||||
export const CountryCodeSchema = emptyStringAsUndefined(countryCode)
|
||||
|
||||
export const CreateCustomerSchema = z.object({
|
||||
name: z.string().min(1, 'Customer name is required'),
|
||||
customer_type: CustomerTypeSchema,
|
||||
@@ -965,7 +994,7 @@ export const CreateCustomerSchema = z.object({
|
||||
address_line2: z.string().optional(),
|
||||
postal_code: z.string().optional(),
|
||||
city: z.string().optional(),
|
||||
country: z.string().optional(),
|
||||
country: CountryCodeSchema,
|
||||
org_number: z.string().optional(),
|
||||
vat_number: z.string().optional(),
|
||||
personal_number: z
|
||||
@@ -984,6 +1013,37 @@ export const CreateCustomerSchema = z.object({
|
||||
message: 'Personal number is only allowed for individual customers',
|
||||
})
|
||||
}
|
||||
// Country vs customer type vs VAT prefix (#2025): an EU business with
|
||||
// country SE got reverse charge and nothing objected until the periodisk
|
||||
// sammanställning, after the invoice was sent. An omitted country is SE
|
||||
// for Swedish types, derived from the VAT prefix for eu_business, and
|
||||
// required for non_eu_business (see defaultCountryForParty); the
|
||||
// transform below stores the resolved value.
|
||||
const effectiveCountry =
|
||||
customer.country ?? defaultCountryForParty(customer.customer_type, customer.vat_number)
|
||||
if (!effectiveCountry) {
|
||||
ctx.addIssue({
|
||||
code: 'custom',
|
||||
path: ['country'],
|
||||
message:
|
||||
customer.customer_type === 'eu_business'
|
||||
? 'country is required for an EU business unless vat_number carries an EU country prefix (e.g. DE811234567)'
|
||||
: 'country is required for a non-EU business',
|
||||
})
|
||||
} else {
|
||||
const countryIssue = checkCountryConsistency({
|
||||
partyType: customer.customer_type,
|
||||
country: effectiveCountry,
|
||||
vatNumber: customer.vat_number,
|
||||
})
|
||||
if (countryIssue) {
|
||||
ctx.addIssue({
|
||||
code: 'custom',
|
||||
path: ['country'],
|
||||
message: COUNTRY_CONSISTENCY_MESSAGES[countryIssue].en,
|
||||
})
|
||||
}
|
||||
}
|
||||
// GDPR art. 5.1 c: a personnummer stored as a business org_number is shown
|
||||
// unmasked everywhere (only customer_type='individual' rows are masked), so
|
||||
// refuse to accept one silently.
|
||||
@@ -1029,7 +1089,13 @@ export const CreateCustomerSchema = z.object({
|
||||
message: `At most ${MAX_INVOICE_EMAIL_COPY_RECIPIENTS} customer invoice copy recipients are allowed in total`,
|
||||
})
|
||||
}
|
||||
}).transform((customer) => {
|
||||
}).transform((input) => {
|
||||
// The resolved country (see the superRefine above): always a code here,
|
||||
// the refine has already rejected the cases where none can be derived.
|
||||
const customer = {
|
||||
...input,
|
||||
country: input.country ?? defaultCountryForParty(input.customer_type, input.vat_number) ?? 'SE',
|
||||
}
|
||||
// A personnummer-shaped org_number on customer_type='individual' IS the
|
||||
// personnummer, submitted in the wrong field (the MCP create tool had no
|
||||
// personal_number input until 2026-08-21, and the v1 docs long said
|
||||
@@ -1059,7 +1125,7 @@ export const UpdateCustomerSchema = z.object({
|
||||
address_line2: z.string().optional(),
|
||||
postal_code: z.string().optional(),
|
||||
city: z.string().optional(),
|
||||
country: z.string().optional(),
|
||||
country: CountryCodeSchema,
|
||||
org_number: z.string().optional(),
|
||||
vat_number: z.string().optional(),
|
||||
// Plaintext personnummer (validated here, then encrypted by the route), or
|
||||
@@ -1123,7 +1189,7 @@ export const CreateSupplierSchema = z.object({
|
||||
address_line2: z.string().optional(),
|
||||
postal_code: z.string().optional(),
|
||||
city: z.string().optional(),
|
||||
country: z.string().optional(),
|
||||
country: CountryCodeSchema,
|
||||
org_number: z.string().optional(),
|
||||
vat_number: z.string().optional(),
|
||||
bankgiro: z.string().optional(),
|
||||
@@ -2762,10 +2828,22 @@ const ImportedCustomerRowSchema = z.object({
|
||||
address_line2: z.string().nullable(),
|
||||
postal_code: z.string().nullable(),
|
||||
city: z.string().nullable(),
|
||||
country: z.string(),
|
||||
country: countryCode,
|
||||
vat_number: z.string().nullable(),
|
||||
default_payment_terms: z.number().int().min(0).max(365),
|
||||
notes: z.string().nullable(),
|
||||
}).superRefine((row, ctx) => {
|
||||
// The preview flags these rows and the wizard refuses to continue with
|
||||
// them; repeated here so a hand-built request cannot import an EU
|
||||
// business with country SE (#2025).
|
||||
const countryIssue = checkCountryConsistency({
|
||||
partyType: row.customer_type,
|
||||
country: row.country,
|
||||
vatNumber: row.vat_number,
|
||||
})
|
||||
if (countryIssue) {
|
||||
ctx.addIssue({ code: 'custom', path: ['country'], message: COUNTRY_CONSISTENCY_MESSAGES[countryIssue].en })
|
||||
}
|
||||
})
|
||||
|
||||
export const CustomerImportExecuteSchema = z.object({
|
||||
@@ -2784,7 +2862,7 @@ const ImportedSupplierRowSchema = z.object({
|
||||
address_line2: z.string().nullable(),
|
||||
postal_code: z.string().nullable(),
|
||||
city: z.string().nullable(),
|
||||
country: z.string(),
|
||||
country: countryCode,
|
||||
vat_number: z.string().nullable(),
|
||||
bankgiro: z.string().nullable(),
|
||||
plusgiro: z.string().nullable(),
|
||||
|
||||
Reference in New Issue
Block a user