e978136210
* fix(transactions): abort supplier-invoice match when payment voucher fails The match route caught a payment-JE creation failure and proceeded anyway: invoice marked paid with payment_journal_entry_id NULL, a payments row with no voucher, and the bank line linked but unbooked. That half-state is unrecoverable from the UI — mark-paid rejects 'paid' invoices and the match route rejects already-linked transactions (the "user can re-book" comment was wrong). The v1 route was already strict; this aligns the cookie route. A failed voucher now fails the whole match before any state mutation, with bookkeeping errors mapped to their structured codes and a new MATCH_SI_JE_FAILED fallback. Incident: Arcim 2026-06-11 — invoice 20250928 marked paid with no payment voucher because account 3740 was missing from the chart. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(transactions): bank-sync supplier-invoice match is a suggestion, not a hard link A high-confidence (>=0.85, unambiguous) supplier-invoice hit at sync time set transactions.supplier_invoice_id directly — without booking a payment or touching the invoice. The half-link then BLOCKED the match route (MATCH_SI_TX_ALREADY_LINKED), stranding the bank line with no path to a payment voucher and the invoice stuck on 'registered'. Sync now always writes potential_supplier_invoice_id; the hard link is reserved for completed matches where the payment voucher is booked. High-confidence hits still drain the matching pool and skip the mapping engine. Incident: Arcim 2026-06-11 — RosholmDell 18299 (29 890 kr) auto-linked at sync, unmatchable afterwards. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(bookkeeping): seed standard BAS accounts on demand in the engine A minimal company chart routinely lacks accounts that legitimate engine flows reach — 3740 (öres- och kronutjämning) the first time a Bankgiro payment lands a sub-krona off the invoice, 6580 on a first legal invoice. createDraftEntry threw AccountsNotInChartError and turned a standard account into a dead end. The engine now backfills missing accounts from BAS_REFERENCE (full metadata incl. SRU code) before failing. Conservative by design: unknown numbers still throw, and deactivated accounts are never resurrected — deactivation is a deliberate user choice. Concurrent seeding (23505) counts as success. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(supplier-invoices): require explicit expense account, drop the 5010 seed Every new line item (and every AI-prefilled line) was silently seeded with account 5010 Lokalhyra. AI extraction deliberately never suggests accounts, so any invoice saved without touching the field was misbooked as premises rent — legally wrong verifikat that need rättelse to fix. Lines now start with an empty account: the supplier's default_expense_account fills empty rows when set, and submit blocks with a clear toast until every row has an account. Incident: Arcim 2026-06-11 — a legal-services invoice (should be 6580) and a SaaS subscription (should be 5420) both posted to 5010. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * refactor(bookkeeping): clarify voucher description suffix to (ankomstnr N) "(ankomst 2)" read as "arrived twice" / a duplicate marker; it is the company-internal sequential arrival counter for supplier invoices. "(ankomstnr 2)" says what the number is. Existing posted vouchers keep their old description (immutable). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(transactions): cancel orphaned payment voucher when match loses the CAS race When the payment JE posts but the invoice CAS update matches 0 rows (a concurrent request settled it first), both match routes returned MATCH_SI_NOT_OPEN and left the voucher orphaned in the ledger. mark-paid has always compensated for exactly this case; the compensation is now a shared helper (cancelOrphanedPaymentEntry: cancel + voucher-gap explanation per BFNAR 2013:2) used by all three routes. Flagged by the compliance swarm and the Swedish compliance review on PR #711 — the one finding both converged on. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(bookkeeping): next_voucher_number user_id fallback for service-role contexts Mirrors 20260421170500 (commit_journal_entry got this fix; its twin did not). Under a service-role client auth.uid() is NULL and the voucher_sequences upsert fails its user_id NOT NULL check before ON CONFLICT can arbitrate — even when the sequence row exists. Every non-interactive caller of the storno/correction path (getNextVoucherNumber → correctEntry) was broken. Fallback: companies.created_by (same source seed_chart_of_accounts uses). Interactive flows still record auth.uid(); DO UPDATE never touches user_id on existing rows. Also restores SET search_path = public, lost when 20260330 recreated the function after the 20260304 hardening. pg-real: new test exercises the RPC on the superuser connection (auth.uid() IS NULL) and asserts sequential numbers + owner attribution. Found live: the Arcim repair script booked payment vouchers fine (commit_journal_entry) but failed on corrections (next_voucher_number). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(bookkeeping): harden cancelOrphanedPaymentEntry — never throw, breadcrumb before mutating Two hardenings from the PR #711 review round: - Whole body wrapped in try/catch: the caller is returning the correct CAS-conflict response, so an unexpected client rejection must not replace it with a 500 (best-effort is now a hard guarantee). - The gap-recovery data (series, number, period, explanation) is logged BEFORE the cancel: the cancel and gap insert are separate statements, and a crash between them would otherwise leave a cancelled voucher with no BFNAR 2013:2 gap explanation and no way to reconstruct it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
98 lines
3.3 KiB
TypeScript
98 lines
3.3 KiB
TypeScript
import type { SupabaseClient } from '@supabase/supabase-js'
|
|
import { createLogger } from '@/lib/logger'
|
|
|
|
const log = createLogger('cancel-orphaned-entry')
|
|
|
|
/**
|
|
* Compensation for the payment-flow CAS guard: a payment voucher was posted,
|
|
* but the invoice row was settled by a concurrent request between our read
|
|
* and write, so the voucher belongs to no payment. Cancel it and document
|
|
* the voucher-number gap (BFNAR 2013:2 requires gaps to be explained).
|
|
*
|
|
* Mirrors the inline compensation the mark-paid route has always had; the
|
|
* match routes previously returned MATCH_SI_NOT_OPEN and left the voucher
|
|
* orphaned in the ledger.
|
|
*
|
|
* Best-effort by design: the CAS conflict response is already correct for
|
|
* the caller, so failures here are logged loudly rather than thrown.
|
|
*/
|
|
export async function cancelOrphanedPaymentEntry(
|
|
supabase: SupabaseClient,
|
|
companyId: string,
|
|
userId: string,
|
|
journalEntryId: string,
|
|
explanation: string,
|
|
): Promise<void> {
|
|
try {
|
|
const { data: orphan, error: fetchError } = await supabase
|
|
.from('journal_entries')
|
|
.select('fiscal_period_id, voucher_series, voucher_number')
|
|
.eq('id', journalEntryId)
|
|
.eq('company_id', companyId)
|
|
.single()
|
|
|
|
if (fetchError) {
|
|
log.error('failed to load orphaned payment voucher for cancellation', fetchError, {
|
|
companyId,
|
|
journalEntryId,
|
|
})
|
|
}
|
|
|
|
// Recovery breadcrumb BEFORE mutating: the cancel and the gap insert are
|
|
// separate statements, so a crash between them would leave a cancelled
|
|
// voucher with no gap explanation (BFNAR 2013:2 requires one). This line
|
|
// carries everything an operator needs to write it manually.
|
|
if (orphan) {
|
|
log.info('cancelling orphaned payment voucher', {
|
|
companyId,
|
|
journalEntryId,
|
|
voucherSeries: orphan.voucher_series || 'A',
|
|
voucherNumber: orphan.voucher_number,
|
|
fiscalPeriodId: orphan.fiscal_period_id,
|
|
explanation,
|
|
})
|
|
}
|
|
|
|
const { error: cancelError } = await supabase
|
|
.from('journal_entries')
|
|
.update({ status: 'cancelled' })
|
|
.eq('id', journalEntryId)
|
|
.eq('company_id', companyId)
|
|
|
|
if (cancelError) {
|
|
log.error('failed to cancel orphaned payment voucher (manual cleanup needed)', cancelError, {
|
|
companyId,
|
|
journalEntryId,
|
|
})
|
|
return
|
|
}
|
|
|
|
if (orphan) {
|
|
const { error: gapError } = await supabase.from('voucher_gap_explanations').insert({
|
|
company_id: companyId,
|
|
fiscal_period_id: orphan.fiscal_period_id,
|
|
voucher_series: orphan.voucher_series || 'A',
|
|
gap_number: orphan.voucher_number,
|
|
explanation,
|
|
created_by: userId,
|
|
})
|
|
if (gapError) {
|
|
log.error('failed to record voucher gap explanation for cancelled orphan', gapError, {
|
|
companyId,
|
|
journalEntryId,
|
|
voucherNumber: orphan.voucher_number,
|
|
})
|
|
}
|
|
}
|
|
} catch (err) {
|
|
// Hard never-throw guarantee: the caller is about to return the correct
|
|
// CAS-conflict response, and an unexpected rejection here (network blip,
|
|
// driver error) must not replace it with a 500. The orphan stays posted
|
|
// and visible; the breadcrumb above covers manual recovery.
|
|
log.error('unexpected failure while cancelling orphaned payment voucher', err as Error, {
|
|
companyId,
|
|
journalEntryId,
|
|
})
|
|
}
|
|
}
|