Org assignment history, mobile support, and a correctness pass

Data model
- employee_assignments records org placement over time (valid_from/valid_to),
  written by a trigger on `employees` rather than inside each RPC: ~70
  `update employees` statements spread over fifteen migrations mean per-call
  bookkeeping would miss paths today and again with every future RPC. A
  partial unique index enforces the one-open-interval invariant the trigger
  relies on when closing the current row.
- The Organigramm gains a Stichtag (default today). Membership comes from
  entry/exit/karenz, past placement from the new history, future placement
  projected from pending_org_changes. Placements predating the migration are
  backfilled with today's values and flagged as such in the UI, since
  employee_history only ever stored free text and cannot be reconstructed.

Correctness
- Reports and exports silently truncated at PostgREST's 1000-row cap
  (db.max_rows); employee_history is already past it at ~800 staff. Every
  whole-table read now pages explicitly.
- XLSX date cells were a day early: ExcelJS converts a Date to an Excel
  serial straight off getTime(), so a Date built at local midnight lands on
  the previous day's serial in any positive-offset zone.
- Date handling is pinned to Europe/Vienna throughout, and date-only strings
  are formatted without a Date round-trip. The dashboard's YTD window was
  built by round-tripping a local Date through toISOString(), which shifted
  it a day early and dropped 31 December entirely.
- Export routes parsed measure/group/split/eventType with unchecked `as`
  casts, so an unknown value reached column headers as `undefined` and the
  Content-Disposition filename. Parsed against the label maps now, with the
  filename slugged as a backstop.
- toXlsx keyed columns by header text, silently dropping the second of any
  two columns sharing a name — split columns take their header from data.
- The org chart tree walks had no cycle guard; nothing in the schema forbids
  a manager_id cycle, and one would hang the tab rather than misreport.
- The login page reflected ?error= verbatim, letting anyone put arbitrary
  text on the real sign-in screen; messages are looked up by code now.
- React Flow needs elementsSelectable on, or it sets pointer-events:none on
  the whole node and the expand control stops responding.

UI
- Mobile: the shell was unusable below lg — a fixed 236px margin pushed
  content off-screen with no mobile navigation at all. The sidebar is now a
  drawer, dvh replaces vh, safe-area insets are honoured, inputs are 16px so
  iOS stops zooming on focus, and form grids stack.
- Org chart nodes redesigned: per-kind accent stripes and icons, vacant
  roles called out, expand control moved to the bottom edge carrying the
  child count.
- Pagination is windowed; it previously rendered one link per page (54 for
  the employee list, unbounded for the audit log).
- Positions page reduced to open positions with a single "Besetzen" action.
- The employee Organisation tab links into the org chart focused on that
  person, reusing the chart's existing search-match highlighting.

Also included, uncommitted until now
- Dependants, HR notes, academic titles, split address fields, position
  validity and role/employment fields, with their migrations and UI.
- Docker/compose deployment setup, data-model and security-review docs.
This commit is contained in:
2026-07-24 23:38:10 +02:00
parent f96773da0f
commit 79f0e19bf8
101 changed files with 6120 additions and 700 deletions

View File

@@ -1,11 +1,25 @@
import { describe, expect, it } from "vitest";
import { daysBetween, fmtAge, fmtDate, initials, tenure } from "@/lib/format";
import { addDaysIso, daysBetweenIso, fmtAge, fmtDate, initials, tenure, toIsoDate, yearsBetweenIso } from "@/lib/format";
describe("fmtDate", () => {
it("formats an ISO date string in de-AT order", () => {
expect(fmtDate("2026-03-05")).toBe("05.03.2026");
});
// A date-only column has no time and no zone. Routing it through a Date
// would anchor it to UTC midnight and render the previous day wherever the
// renderer sits west of UTC — including a server/browser hydration split.
it("never shifts a date-only string across a day boundary", () => {
expect(fmtDate("2026-01-01")).toBe("01.01.2026");
expect(fmtDate("2026-12-31")).toBe("31.12.2026");
});
it("renders a timestamp in Vienna time regardless of the runtime zone", () => {
// 23:30 UTC on 5 March is already 6 March in Vienna (UTC+1 before the
// DST switch); the same instant is still 5 March in UTC.
expect(fmtDate("2026-03-05T23:30:00Z")).toBe("06.03.2026");
});
it("returns an em dash for null/undefined/empty input", () => {
expect(fmtDate(null)).toBe("");
expect(fmtDate(undefined)).toBe("");
@@ -67,12 +81,47 @@ describe("tenure", () => {
});
});
describe("daysBetween", () => {
describe("daysBetweenIso", () => {
it("computes whole days between two dates", () => {
expect(daysBetween("2026-01-01", "2026-01-11")).toBe(10);
expect(daysBetweenIso("2026-01-01", "2026-01-11")).toBe(10);
});
it("returns a negative number when the second date precedes the first", () => {
expect(daysBetween("2026-01-11", "2026-01-01")).toBe(-10);
expect(daysBetweenIso("2026-01-11", "2026-01-01")).toBe(-10);
});
// Both ends are anchored at UTC midnight, so the DST switch in between
// cannot turn 30 calendar days into 29.96 and round down.
it("is exact across a DST transition", () => {
expect(daysBetweenIso("2026-03-15", "2026-04-15")).toBe(31);
expect(daysBetweenIso("2026-10-15", "2026-11-15")).toBe(31);
});
});
describe("addDaysIso", () => {
it("rolls over month and year boundaries", () => {
expect(addDaysIso("2026-12-31", 1)).toBe("2027-01-01");
expect(addDaysIso("2026-01-31", 1)).toBe("2026-02-01");
});
it("handles a leap day", () => {
expect(addDaysIso("2028-02-28", 1)).toBe("2028-02-29");
});
});
describe("yearsBetweenIso", () => {
it("counts only completed years", () => {
expect(yearsBetweenIso("1990-05-15", "2026-05-15")).toBe(36);
expect(yearsBetweenIso("1990-05-15", "2026-05-14")).toBe(35);
});
});
describe("toIsoDate", () => {
it("passes a date-only string through untouched", () => {
expect(toIsoDate("2026-01-01")).toBe("2026-01-01");
});
it("resolves a timestamp to the Vienna calendar day", () => {
expect(toIsoDate("2026-03-05T23:30:00Z")).toBe("2026-03-06");
});
});

View File

@@ -0,0 +1,168 @@
import { describe, expect, it } from "vitest";
import { resolveOrgSnapshot } from "@/lib/orgchart-data";
const DIV = "div-1";
const TEAM_A = "team-a";
const TEAM_B = "team-b";
type EmployeeInput = Parameters<typeof resolveOrgSnapshot>[0]["employees"][number];
type AssignmentInput = Parameters<typeof resolveOrgSnapshot>[0]["assignments"][number];
function emp(id: string, overrides: Partial<EmployeeInput> = {}): EmployeeInput {
return {
id,
personnel_number: 1000,
first_name: "Test",
last_name: id,
job_title: "Mitarbeiter:in",
manager_id: null,
team_id: TEAM_A,
division_id: DIV,
is_lead: false,
org_level: 3,
entry_date: "2020-01-01",
exit_date: null,
karenz_start_date: null,
karenz_return_date: null,
...overrides,
};
}
function assignment(employeeId: string, overrides: Partial<AssignmentInput> = {}): AssignmentInput {
return {
employee_id: employeeId,
manager_id: null,
team_id: TEAM_A,
division_id: DIV,
job_title: "Mitarbeiter:in",
is_lead: false,
org_level: 3,
valid_from: "2020-01-01",
...overrides,
};
}
const TEAMS = [
{ id: TEAM_A, department_id: "dept-1" },
{ id: TEAM_B, department_id: "dept-2" },
];
const DEPARTMENTS = [
{ id: "dept-1", division_id: DIV },
{ id: "dept-2", division_id: "div-2" },
];
function snapshot(args: Partial<Parameters<typeof resolveOrgSnapshot>[0]> & { asOf: string }) {
return resolveOrgSnapshot({ employees: [], assignments: [], teams: TEAMS, departments: DEPARTMENTS, pending: [], ...args });
}
describe("membership as of a date", () => {
it("excludes someone who had not started yet and includes them once they have", () => {
const employees = [emp("a", { entry_date: "2026-06-01" })];
expect(snapshot({ asOf: "2026-05-31", employees }).employees).toHaveLength(0);
expect(snapshot({ asOf: "2026-06-01", employees }).employees).toHaveLength(1);
});
it("excludes someone from their exit date onwards", () => {
const employees = [emp("a", { exit_date: "2026-06-30" })];
expect(snapshot({ asOf: "2026-06-29", employees }).employees).toHaveLength(1);
expect(snapshot({ asOf: "2026-06-30", employees }).employees).toHaveLength(0);
});
it("keeps someone on Karenz in the chart", () => {
const employees = [emp("a", { karenz_start_date: "2026-01-01", karenz_return_date: "2026-12-01" })];
expect(snapshot({ asOf: "2026-06-01", employees }).employees).toHaveLength(1);
});
});
describe("placement as of a date", () => {
it("uses the assignment interval covering the date, not today's row on employees", () => {
const employees = [emp("a", { team_id: TEAM_B, job_title: "Heutiger Titel" })];
const assignments = [assignment("a", { team_id: TEAM_A, job_title: "Damaliger Titel" })];
const [result] = snapshot({ asOf: "2024-03-01", employees, assignments }).employees;
expect(result.team_id).toBe(TEAM_A);
expect(result.job_title).toBe("Damaliger Titel");
});
it("falls back to the employee row when no assignment covers the date", () => {
const employees = [emp("a", { team_id: TEAM_B })];
const [result] = snapshot({ asOf: "2024-03-01", employees, assignments: [] }).employees;
expect(result.team_id).toBe(TEAM_B);
});
});
describe("orphan re-rooting", () => {
// Without this the whole reporting line below an absent manager silently
// disappears from the chart instead of moving up a level.
it("drops a manager reference to somebody not employed on that date", () => {
const employees = [
emp("boss", { exit_date: "2026-01-01", org_level: 2, is_lead: true }),
emp("report", { manager_id: "boss" }),
];
const assignments = [assignment("report", { manager_id: "boss" })];
const result = snapshot({ asOf: "2026-06-01", employees, assignments }).employees;
expect(result).toHaveLength(1);
expect(result[0].id).toBe("report");
expect(result[0].manager_id).toBeNull();
});
});
describe("future projection from pending changes", () => {
const leadB = emp("lead-b", { id: "lead-b", team_id: TEAM_B, division_id: "div-2", is_lead: true, org_level: 2 });
it("moves an employee into the target team and under that team's lead", () => {
const employees = [emp("a", { manager_id: "lead-a" }), leadB];
const assignments = [assignment("a", { manager_id: "lead-a" }), assignment("lead-b", { team_id: TEAM_B, division_id: "div-2", is_lead: true, org_level: 2 })];
const pending = [{ employee_id: "a", effective_date: "2026-08-01", payload: { new_team_id: TEAM_B } }];
const result = snapshot({ asOf: "2026-09-01", employees, assignments, pending });
const moved = result.employees.find((e) => e.id === "a")!;
expect(moved.team_id).toBe(TEAM_B);
expect(moved.division_id).toBe("div-2");
expect(moved.manager_id).toBe("lead-b");
expect(result.projectedCount).toBe(1);
});
it("lets a later change win over an earlier one", () => {
const employees = [emp("a")];
const assignments = [assignment("a")];
const pending = [
{ employee_id: "a", effective_date: "2026-08-01", payload: { new_team_id: TEAM_B, new_title: "Zwischenstand" } },
{ employee_id: "a", effective_date: "2026-09-01", payload: { new_team_id: TEAM_A, new_title: "Endstand" } },
];
const [result] = snapshot({ asOf: "2026-10-01", employees, assignments, pending }).employees;
expect(result.team_id).toBe(TEAM_A);
expect(result.job_title).toBe("Endstand");
});
it("leaves an untouched employee's manager exactly as recorded", () => {
// Deliberately deviating from the resolve rule: real data drifts, and a
// snapshot must not silently "repair" reporting lines it was not asked
// to change.
const employees = [emp("a", { manager_id: "someone-else" }), emp("someone-else", { id: "someone-else" }), leadB];
const assignments = [assignment("a", { manager_id: "someone-else" })];
const [result] = snapshot({ asOf: "2026-09-01", employees, assignments }).employees;
expect(result.manager_id).toBe("someone-else");
});
it("ignores pending changes for a date the caller did not ask about", () => {
// loadOrgAsOf only fetches pending rows for a future date, so an empty
// list here must simply mean "no projection", not "drop the employee".
const employees = [emp("a")];
const assignments = [assignment("a")];
const result = snapshot({ asOf: "2026-09-01", employees, assignments, pending: [] });
expect(result.projectedCount).toBe(0);
expect(result.employees).toHaveLength(1);
});
});
describe("historyStartsAt", () => {
it("reports the earliest recorded assignment so the UI can flag older dates", () => {
const employees = [emp("a"), emp("b", { id: "b" })];
const assignments = [assignment("a", { valid_from: "2023-05-01" }), assignment("b", { valid_from: "2021-02-01" })];
expect(snapshot({ asOf: "2026-01-01", employees, assignments }).historyStartsAt).toBe("2021-02-01");
});
it("is null when nothing is recorded yet", () => {
expect(snapshot({ asOf: "2026-01-01", employees: [emp("a")] }).historyStartsAt).toBeNull();
});
});

View File

@@ -4,6 +4,7 @@ import {
aggregateReport,
deriveStatusAsOf,
groupKeyFor,
groupKeysFor,
measureValue,
MEASURE_LABELS,
type OrgLookups,
@@ -30,6 +31,14 @@ function emp(overrides: Partial<ReportEmployee> = {}): ReportEmployee {
paygrade: "B",
birth_date: "1990-01-01",
gender: "w",
worker_type: "Angestellte:r",
collective_agreement: "Handel",
work_days: ["Mo", "Di", "Mi", "Do", "Fr"],
is_betriebsrat: false,
has_dienstwagen: false,
is_laterale_fuehrung: false,
is_c_level: false,
dependents_count: 0,
...overrides,
};
}
@@ -71,6 +80,35 @@ describe("groupKeyFor", () => {
it("derives entry_year from entry_date", () => {
expect(groupKeyFor(emp({ entry_date: "2019-06-01" }), "entry_year", lookups)).toBe("2019");
});
it("resolves the Rolle & Anstellung boolean dimensions as Ja/Nein", () => {
const e = emp({ is_betriebsrat: true, has_dienstwagen: false, is_laterale_fuehrung: true, is_c_level: false });
expect(groupKeyFor(e, "betriebsrat", lookups)).toBe("Ja");
expect(groupKeyFor(e, "dienstwagen", lookups)).toBe("Nein");
expect(groupKeyFor(e, "laterale_fuehrung", lookups)).toBe("Ja");
expect(groupKeyFor(e, "c_level", lookups)).toBe("Nein");
});
it("resolves worker_type/collective_agreement directly", () => {
const e = emp({ worker_type: "Arbeiter:in", collective_agreement: "Süßwaren" });
expect(groupKeyFor(e, "worker_type", lookups)).toBe("Arbeiter:in");
expect(groupKeyFor(e, "collective_agreement", lookups)).toBe("Süßwaren");
});
it("resolves has_dependents from dependents_count", () => {
expect(groupKeyFor(emp({ dependents_count: 0 }), "has_dependents", lookups)).toBe("Nein");
expect(groupKeyFor(emp({ dependents_count: 2 }), "has_dependents", lookups)).toBe("Ja");
});
});
describe("groupKeysFor", () => {
it("returns a single-element array for every ordinary dimension", () => {
expect(groupKeysFor(emp(), "division", lookups)).toEqual(["Produktion"]);
});
it("returns one key per work day for the weekday dimension", () => {
expect(groupKeysFor(emp({ work_days: ["Mo", "Mi"] }), "weekday", lookups)).toEqual(["Mo", "Mi"]);
});
});
describe("measureValue", () => {
@@ -118,6 +156,11 @@ describe("measureValue", () => {
];
expect(measureValue(rows, "avg_tenure")).toBeCloseTo(3, 0);
});
it("computes avg_dependents as the mean dependents_count", () => {
const rows = [emp({ dependents_count: 0 }), emp({ dependents_count: 2 }), emp({ dependents_count: 4 })];
expect(measureValue(rows, "avg_dependents")).toBeCloseTo(2, 5);
});
});
describe("aggregateReport", () => {
@@ -173,6 +216,23 @@ describe("aggregateReport", () => {
expect(measureValue(employees, "avg_age", asOf)).toBe(30);
expect(measureValue(employees, "avg_tenure", asOf)).toBeCloseTo(1.42, 1);
});
it("counts an employee once per work day for the weekday dimension, and sorts Mo→So instead of by value", () => {
const employees = [
emp({ id: "1", work_days: ["Mo", "Di", "Mi", "Do", "Fr"] }),
emp({ id: "2", work_days: ["Mo", "Mi", "Fr"] }),
];
const rows = aggregateReport(employees, "headcount", "weekday", null, lookups);
expect(rows.map((r) => r.key)).toEqual(["Mo", "Di", "Mi", "Do", "Fr"]);
expect(rows.find((r) => r.key === "Mo")).toMatchObject({ value: 2, count: 2 });
expect(rows.find((r) => r.key === "Di")).toMatchObject({ value: 1, count: 1 });
});
it("sorts a weekday split chronologically within each group", () => {
const employees = [emp({ id: "1", division_id: "div-1", work_days: ["Fr", "Mo"] })];
const rows = aggregateReport(employees, "headcount", "division", "weekday", lookups);
expect(rows[0].split?.map((s) => s.key)).toEqual(["Mo", "Fr"]);
});
});
describe("deriveStatusAsOf", () => {

View File

@@ -1,6 +1,14 @@
import { NextRequest } from "next/server";
import { afterEach, describe, expect, it, vi } from "vitest";
import { sanitizeForSpreadsheetCell, toCsv } from "@/lib/export";
import { exportFilename, sanitizeForSpreadsheetCell, toCsv } from "@/lib/export";
import {
parseEventDateParam,
parseEventType,
parseGroupDimension,
parseIsoDateParam,
parseMeasure,
parseSplitDimension,
} from "@/lib/reports";
import { sanitizeIlikeTerm } from "@/lib/supabase/query";
// The route under test imports lib/supabase/admin.ts, which is guarded by
@@ -44,6 +52,60 @@ describe("sanitizeIlikeTerm", () => {
});
});
describe("report query-string parsing", () => {
it("falls back to a known dimension instead of passing an unknown one through", () => {
expect(parseMeasure("bogus")).toBe("headcount");
expect(parseGroupDimension("bogus")).toBe("division");
expect(parseMeasure("fte")).toBe("fte");
expect(parseGroupDimension("weekday")).toBe("weekday");
});
it("treats an unknown split or event type as 'none' rather than a value", () => {
expect(parseSplitDimension("bogus")).toBeNull();
expect(parseSplitDimension("")).toBeNull();
expect(parseSplitDimension("location")).toBe("location");
expect(parseEventType("bogus")).toBeNull();
expect(parseEventType("Eintritt")).toBe("Eintritt");
});
// Object.hasOwn, not `in`: a plain `value in LABELS` check would accept
// "constructor" or "toString" off the prototype chain as a valid dimension.
it("does not accept inherited Object properties as dimensions", () => {
expect(parseGroupDimension("constructor")).toBe("division");
expect(parseSplitDimension("toString")).toBeNull();
expect(parseEventType("hasOwnProperty")).toBeNull();
});
it("rejects a Stichtag that is not a real calendar date", () => {
expect(parseIsoDateParam("2026-03-05")).toBe("2026-03-05");
expect(parseIsoDateParam("2026-02-30")).toBeUndefined();
expect(parseIsoDateParam("heute")).toBeUndefined();
expect(parseIsoDateParam('2026-03-05"; rm -rf /')).toBeUndefined();
});
it("keeps the open-interval sentinel but still rejects free text", () => {
expect(parseEventDateParam("open")).toBe("open");
expect(parseEventDateParam("2026-01-01")).toBe("2026-01-01");
expect(parseEventDateParam("whenever")).toBeUndefined();
});
});
describe("exportFilename", () => {
// The base is assembled from query-string values and lands in a
// Content-Disposition header, so a quote in it would otherwise break out
// of the quoted filename.
it("strips characters that would escape the Content-Disposition filename", () => {
const name = exportFilename('bericht"; attachment; filename="evil', "csv");
expect(name).not.toContain('"');
expect(name).not.toContain(";");
expect(name.endsWith(".csv")).toBe(true);
});
it("keeps an ordinary base readable", () => {
expect(exportFilename("bericht-headcount-division", "xlsx")).toMatch(/^bericht-headcount-division-\d{4}-\d{2}-\d{2}\.xlsx$/);
});
});
describe("cron auth guard (/api/cron/apply-pending-changes)", () => {
afterEach(() => {
vi.unstubAllEnvs();