Whole-krona Bankgiro/Swish payments of öre-bearing invoices were stranded
as partially_paid forever (e.g. 11 231 paid on an 11 231,25 invoice left
0,25 kr open). Book the sub-krona residual to BAS 3740 (Öres- och
kronutjämning) and settle the invoice in full, on both the supplier- and
customer-invoice match flows.
New shared pure helpers buildSupplierPaymentClearingLines +
planSupplierPayment mirror the customer-side primitives; routing preview
and commit through the same builder also fixes two pre-existing
preview↔commit drifts (payment account + line descriptions). Öre
absorption is accrual-only — cash entries book the full invoice, so
absorbing there would hide a 1930 discrepancy.
Also improves supplier-invoice ↔ bank matching:
- Pass-3 date window now spans [invoice_date-5, due_date+5] instead of
due_date ±5, so early payments auto-match; an ambiguity guard demotes
non-unique amount matches to suggestions.
- New retroactive matcher (on supplier_invoice.registered/.approved)
surfaces the settling bank payment when the invoice is registered after
the payment was imported. Matches are written as suggestions for
one-click confirm-to-book, never silently auto-booked.
Tests: new unit tests for both pure helpers; extended matching, handler,
customer öre, and route suites. Full suite green (407 files / 5364 tests).
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* test: add real-Postgres smoke gate (pg-real)
Mocked Supabase tests cannot exercise triggers, RPCs, or RLS policies —
a migration that drops enforce_period_lock, mangles user_company_ids(),
or weakens an RLS policy ships green today. Closes that gap with a
small Vitest project `pg-real` running 5 smoke tests against a real
supabase/postgres:15 container in CI.
Covers: closed-period INSERT rejection, commit_journal_entry voucher
atomicity under concurrency, posted-entry immutability, RLS tenant
isolation on journal_entries, and audit_log UPDATE/DELETE rejection.
Also lands the bankid anonymization migration that was sitting
untracked from a prior task.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* test(pg-real): fix storage schema bootstrap + de-scope + PR review fixes
- Drop bankid anonymization migration from this PR. That change is
separate scope (and has open compliance questions flagged by the
Swedish review bot on #357); it will land in its own PR.
- Add tests/pg/bootstrap.sql to align storage.buckets/objects/foldername
with what migrations expect before the replay loop. The supabase/postgres
image ships only a partial storage schema; the rest comes from the
storage-api service at runtime, which CI does not run. First pg-real run
failed at migration 24 on "column public of relation buckets does not exist".
- Add concurrency group to the workflow so stacked PR commits cancel
in-progress runs instead of queueing.
- Gate the pg-real vitest project on DATABASE_URL so a bare `vitest run`
with no DB configured runs only the unit project. npm run test:pg is
the opt-in entry point.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* test(pg-real): widen JWT claim setup so auth.uid() resolves under RLS
The rls.pg test came back with 0 rows instead of 1 — user_company_ids()
returned empty because auth.uid() didn't resolve to the seeded user.
Two fixes:
- Set both request.jwt.claims (whole object) and request.jwt.claim.sub
(individual claim). Different Supabase auth.uid() versions read one or
the other.
- Assert auth.uid() = expected userId immediately after the context
switch, so the next failure points at the right layer instead of an
unrelated empty-result assertion.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>