| Age | Commit message (Collapse) | Author |
|
New image bokf-web (Dockerfile target "web", compose service "web" on
127.0.0.1:8790): Caddy routing with forward_auth, the bokfweb login gate
(C, authenticates with bokfd's session.open, per-address limit, cookie +
terminal handle, one login handed to the TUI via /redeem) and ttyd running
bokftui in web mode in an isolated throwaway HOME. TLS stays with the
host's reverse proxy. BOKF_WEB=1 blocks every local file and viewer path in
the TUI. bokfd's login limiter is now per user name instead of one global
counter (5 wrong guesses from anyone locked out everybody), and a full
counter table no longer disables it. The cross build and deploy.sh build
and ship both images.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
Needs the current password (wrong ones rate limited like logins) and a
password session, requires at least 10 characters, closes the user's
other sessions and is audited without secrets. The TUI main menu gets
"Byt lösenord" with masked prompts; ^R keeps working with the new
password. Masked prompt buffers are wiped before they are freed.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
Stäng skip
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
|
|
checks
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
When db_open finds an older schema version, write a consistent
VACUUM INTO copy to <backup_dir>/pre-migration-v<old>-<UTC>.db
before the first migration statement. A taken name gets a numeric
suffix; if the snapshot fails, the open and the migration abort.
|
|
|
|
|
|
|
|
|
|
|
|
sru.export now returns the emitted fields as ink2/ink2r/ink2s arrays
plus from/to, so Rapporter -> Inkomstdeklaration (INK2/SRU) renders the
declaration as a table with the official fältnamn before saving; unmapped
accounts are listed in the view.
The voucher list puts the verifikat id before the date, widens the column
gaps and adds an inner margin.
|
|
- bokslut.post: year-end bookings (manual entries, periodiseringsfond,
skatt at a given rate, resultatdisposition) with a dry-run plan through
the normal ledger path; the resultatrapport separates
bokslutsdispositioner and skatt per K2.
- sru.export: INFO.SRU + BLANKETTER.SRU (INK2/INK2R/INK2S) from the
official 2025P4 field tables and the BAS mapping, with manual INK2S
adjustments, submitter defaults and unmapped-account detection; the TUI
writes both files from Rapporter -> Inkomstdeklaration.
- voucher.list carries attachment_count and the voucher list marks
vouchers with underlag with an x column.
- date_prompt restores the cursor state so it stops blinking at the bottom
after the report date prompts.
|
|
The voucher detail can attach a file to an existing voucher (^F) and
the underlag picker (f) can remove a link (d, confirmed). The Underlag
inbox links a highlighted item to a voucher picked from a list (k).
attachment.link and attachment.unlink are new write commands (dry-run,
audited); unlinked files return to the inbox. The same content may now
link to several vouchers — only the same voucher/attachment pair is a
CONFLICT, matching the table's primary key.
|
|
report.vat_eskd builds the ISO-8859-1 XML from report.vat: whole
kronor with öre truncated like the blankett, box 48 positive as filed,
MomsBetala computed from the whole-krona boxes, and an optional
upplysning converted from UTF-8, XML-escaped and capped at 300
characters. The TUI momsrapport gains "s = spara eSKD", prompting for a
path and writing the bytes verbatim.
Verified against the FY2027 Kapitas report: 05=703200, 10=175800,
20=1453, 30=851, 48=1030, 49=175621.
|
|
report.general_ledger lists every account with activity or IB, its
postings in date order with a running saldo, and Omslutning/Utgående
saldo; accounts?/from?/to? narrow it. report.voucher_list lists the
year's vouchers with rows and totals, with an optional series filter.
fiscal_year.reopen undoes a close (owner-only, confirm:true, audited) so
the Räkenskapsår screen can toggle the status.
|
|
The report views dumped JSON; they now render Saldobalans,
Resultatrapport (previous-year column, 89xx bokfört/ej bokfört),
Balansrapport (Ing balans/Ing saldo/Period/Utg balans, Beräknat
resultat) and Momsrapport ruta för ruta, with Swedish amount
formatting (1 234,56).
The moms starter rules missed 33xx sales, sent reverse-charge VAT
2614 to box 10 instead of 30 and had box 48 positive. Rules may now
share a box and report.vat sums them; box 49 is the sum of the moms
boxes only. Schema v3 replaces the rules for existing orgs. Verified
on a copy of the live DB: 05=703 200, 10=175 800, 20=1 453, 30=851,
48=-1 030, 49=175 621, matching the Kapitas 2027 export.
Ctrl+R reload passes --socket and auto-login no longer rewrites
tui.conf; pty tests now run through scripts/tui-sandbox.sh so they
cannot touch the real config, cache or bw session.
|
|
- owner-editable company details form (read-only for other roles)
- org.update honors dry_run; covered in tests
|
|
- tokenizer treats CR as whitespace; closing brace matches with CRLF
- only #RAR with year indicator 0 selects the fiscal year
- zero-amount #TRANS rows are dropped instead of violating the schema
- #IB becomes an IB voucher only when the year has no earlier history
|
|
|
|
- bokfctl: --token / BOKFD_TOKEN via client_token_login
- tokens must carry the admin scope for admin commands (was bypassed)
- docs: token-based snapshot for restic backups
|
|
- bokfd: optional TLS listener (OpenSSL), certificate reload on change
- clients: tls:host:port targets with chain and host verification
- compose: port 8788 and an INWX/lego renewal sidecar
- Makefile: header dependency tracking (-MMD -MP)
|
|
|