Files
accounted/lib/bookkeeping/no-doc-required.ts
T
Jakob Wennberg 4dfd790de5 feat(bookkeeping): Ny verifikat modal, ledger-style list, SIE no-underlag exemptions (#698)
* feat(bookkeeping): Ny verifikat modal, ledger-style list, SIE no-underlag exemptions

Verifikat UX
- "Ny verifikat" opens in a modal (NewJournalEntryDialog) instead of an inline tab;
  the review step renders inline in the dialog rather than stacking a second dialog.
- JournalEntryForm: konteringsrader are the focus, with a compact pre-filled metadata
  bar (datum/serie/text/valuta/period) on top; verifikationstext auto-fills from the
  first row's account.
- JournalEntryList: belopp shown on collapsed rows; expanded view is an aligned
  Konto/Benämning/Debet/Kredit table.

SIE imports no longer flood "Att hantera: saknade underlag"
- Import gains an opt-in (off by default) toggle to mark imported verifikat as "Inget
  underlag krävs"; a "Rekommenderas vid migrering" badge nudges it for historical years.
- Multi-select batch-mark in the list for selective cleanup.
- Filter-scoped bulk mark (POST /api/bookkeeping/no-doc-required/bulk-missing): marks
  every missing-doc verifikat matching the active filters across all pages, with a
  dry_run count to confirm scope — the scalable remedy for a post-import flood.
- Shared helper markEntriesNoDocRequired + per-entry batch route.

Tests: no-doc helper, batch route, bulk-missing route.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(bookkeeping): address PR #698 review findings

- JournalEntryForm: restore the explicit "no underlag" acknowledgement in the
  modal's inline review. When no document is attached, the confirm button reads
  "Bokför utan underlag" (BFL 5 kap 6-7 §§), equivalent to the blocking dialog the
  non-bare flow shows — the bare path no longer posts behind only a passive banner.
- batch no-doc route: guard the ownership query with source_type IN
  NEEDS_DOC_SOURCE_TYPES so a crafted request can't exempt non-document-requiring
  entries (defense in depth on top of company + posted scoping).
- bulk-missing route: resolve doc/exemption status by querying only the candidate
  ids (chunked) instead of loading the company's full document_attachments and
  journal_entry_no_doc_required tables into memory — data minimisation + bounded
  memory for large migrations (the most-repeated reviewer finding).

Triaged as non-issues (left as-is): partial-import exemption (gated on
result.success == zero errors), reason write-back (sidecar row is FK-linked and
carries the reason), and "bulk-exempting manual entries" (consistent with the
existing per-entry NoDocRequiredToggle). No DB migration — reuses the existing
journal_entry_no_doc_required table.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(bookkeeping): centralize bulk-missing date/series validation in Zod

Move the ISO-date and verifikationsserie format checks into the Zod schema so
malformed input is rejected with a clean 400 instead of being silently nulled
(or, for a shaped-but-invalid date, throwing a 500 via fetchAllRows). The date
refinement rejects values like 9999-99-99 / 2026-02-30 that a bare
/^\d{4}-\d{2}-\d{2}$/ regex lets through. Addresses the PR #698 reviewer nit on
split schema-vs-runtime validation. +2 route tests.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 20:41:30 +02:00

51 lines
1.7 KiB
TypeScript

import type { SupabaseClient } from '@supabase/supabase-js'
const CHUNK_SIZE = 500
/**
* Bulk-mark posted journal entries as "Inget underlag krävs" (no supporting
* document required) by inserting rows into journal_entry_no_doc_required.
*
* The flag lives in a sidecar table so the verifikation itself stays immutable
* per BFL — same write the single-entry route performs, just batched. Inserts
* are chunked (Postgres/PostgREST payload safety) and idempotent: rows that
* already exist are left untouched (`ignoreDuplicates`).
*
* The caller is responsible for passing only entry IDs that belong to
* `companyId` and are eligible (posted, document-requiring source type); RLS on
* the table is the security backstop. Used by the SIE-import opt-in auto-exempt
* flow and the batch-mark endpoint.
*
* @returns the number of entry IDs processed (deduped), not the number of new rows.
*/
export async function markEntriesNoDocRequired(
supabase: SupabaseClient,
companyId: string,
userId: string,
entryIds: string[],
reason: string | null,
): Promise<number> {
if (entryIds.length === 0) return 0
// De-dupe so a chunk can never carry the same id twice (ON CONFLICT target).
const uniqueIds = Array.from(new Set(entryIds))
for (let i = 0; i < uniqueIds.length; i += CHUNK_SIZE) {
const chunk = uniqueIds.slice(i, i + CHUNK_SIZE)
const rows = chunk.map((journal_entry_id) => ({
journal_entry_id,
company_id: companyId,
user_id: userId,
reason: reason ?? null,
}))
const { error } = await supabase
.from('journal_entry_no_doc_required')
.upsert(rows, { onConflict: 'journal_entry_id', ignoreDuplicates: true })
if (error) throw new Error(error.message)
}
return uniqueIds.length
}