Files
alpenwerk-hr/lib/supabase/types.ts
Maximilian Stubhan 8d978981b0 SVNR validation, CI, and a dependency/security pass
Positions
- Removed the "Besetzen" action, the StaffInternallyModal behind it and the
  now-unreachable staffPositionInternally server action: a position is filled
  through the hire process, not from the positions list. Note that
  transfer_employee has no position_id at all and never touched `positions`,
  so with staff_position_internally out of the UI, hire_employee is the only
  thing that closes a position — a transfer into an open one leaves it open.
  The RPC itself is still in the database and still covered by its tests.

SVNR
- Austrian social security numbers are now validated: ten digits, weighted
  check digit mod 11, and the TTMMJJ tail cross-checked against birth_date,
  which is what catches a transposed date that a valid check digit would let
  through. A serial whose weighted sum lands on 11 is rejected rather than
  wrapped — those are never issued.
- Applies to Austrian locations only; the German/Czech/Slovenian equivalents
  have their own formats and stay free-form.
- Enforced by a trigger, not inside hire_employee/change_employee_data, for
  the same reason as the assignment history: both have been redefined by
  half a dozen migrations. Only a *newly written* value is checked, so a
  legacy number never blocks an unrelated transfer or address change.
- The seed drew a random four-digit prefix, so its check digit was right
  only by chance and every seeded Austrian row would now be rejected;
  it computes the check digit properly now.

Tech stack
- next 16.2.11 closes nine advisories against 16.2.10, including a
  middleware/proxy bypass in App Router apps on Turbopack — proxy.ts is this
  app's entry gate. RLS remains the real boundary, so the blast radius was a
  blank page rather than data, but it is a patch-level fix. Also react
  19.2.8, tailwind 4.3.3, lucide-react 1.26, supabase-js/ssr, postcss.
- CI runs lint, typecheck, schema/type drift, tests and build; a second job
  replays every migration onto an empty database and runs the integration
  suite against it, so a migration that cannot be replayed from scratch
  fails here instead of during a restore.
- scripts/check-schema-types.mjs diffs the hand-written lib/supabase/types.ts
  against the migrations. Reading the SQL rather than a live database keeps
  Postgres out of the fast CI job. Verified in both directions.
- vitest now runs two projects: node for logic, jsdom for components. The
  first component test covers the org chart expand control, which broke
  earlier this session when elementsSelectable={false} made React Flow
  compute pointer-events:none for the whole node; re-introducing that prop
  fails three of these tests.
- Content-Security-Policy is emitted report-only. Enforcing a policy derived
  from inspection rather than from violation reports risks blanking the app;
  'unsafe-inline' on script-src is required until a nonce is threaded through
  proxy.ts, which is a separate change.
- Fixed supabase/seed.ts, which this session's SVNR change had broken: the
  extensionless "../lib/svnr" import does not resolve under Node's ESM
  loader, so the seed failed at startup.
- engines pinned to node >=22 <25, tsconfig target ES2022, and the dead
  test:e2e script removed (no Playwright is installed).
2026-07-25 11:13:10 +02:00

439 lines
16 KiB
TypeScript

// Hand-written to match supabase/schema.sql + supabase/migrations/*.sql (no DB
// connection string available to run `supabase gen types typescript` in this
// environment — regenerate from the live project once you have the Supabase
// CLI linked).
export type EmploymentStatus = "Aktiv" | "Karenz" | "Geplant" | "Ausgetreten";
export type EmploymentType = "Vollzeit" | "Teilzeit";
export type ContractType = "unbefristet" | "befristet";
export type PaygradeType = "A" | "B" | "C" | "D" | "E" | "F";
export type SourceType = "Intern" | "Extern";
export type GenderType = "m" | "w";
export type WorkerType = "Angestellte:r" | "Arbeiter:in";
export type CollectiveAgreement = "Handel" | "Süßwaren";
export type Weekday = "Mo" | "Di" | "Mi" | "Do" | "Fr" | "Sa" | "So";
export type RelationshipType = "Ehepartner:in" | "Lebenspartner:in" | "Kind" | "Sonstige";
export type NoteCategory = "Allgemein" | "Vertraulich" | "Personalgespräch" | "Wiedervorlage" | "Lob / Anerkennung";
// Single HR-only role (see docs/decisions/0001-hr-only-access.md). Kept as a
// union (not a string literal) so a future hr_admin/hr_user split, if ever
// technically required, is a type-level addition, not a rewrite.
export type ProfileRole = "hr";
export type HistoryEventType =
| "Eintritt"
| "Beförderung"
| "Versetzung"
| "Karenz"
| "Vertragsänderung"
| "Stammdatenänderung"
| "Austritt"
| "Wiedereintritt"
| "Reorganisation"
| "Gehaltsanpassung"
| "Rückkehr";
export type PositionStatus = "open" | "filled";
export type ReorgMoveKind = "emp" | "team" | "abt" | "dept";
export type PendingChangeType =
| "transfer"
| "promotion"
| "karenz_start"
| "karenz_return"
| "contract_change"
| "reorg";
export type PendingChangeStatus = "pending" | "applied" | "cancelled";
// @supabase/postgrest-js requires every table/view to carry a Relationships
// array (used for typed embedded selects) — left empty since no code in this
// app relies on nested/embedded resource selects.
type NoRelationships = { Relationships: [] };
export type Database = {
public: {
Tables: {
divisions: NoRelationships & {
Row: { id: string; org_number: string; name: string };
Insert: { id?: string; org_number: string; name: string };
Update: Partial<{ id: string; org_number: string; name: string }>;
};
departments: NoRelationships & {
Row: { id: string; org_number: string; name: string; division_id: string };
Insert: { id?: string; org_number: string; name: string; division_id: string };
Update: Partial<{ id: string; org_number: string; name: string; division_id: string }>;
};
teams: NoRelationships & {
Row: { id: string; org_number: string; name: string; department_id: string };
Insert: { id?: string; org_number: string; name: string; department_id: string };
Update: Partial<{ id: string; org_number: string; name: string; department_id: string }>;
};
locations: NoRelationships & {
Row: { id: string; name: string; country: string };
Insert: { id?: string; name: string; country: string };
Update: Partial<{ id: string; name: string; country: string }>;
};
profiles: NoRelationships & {
Row: {
id: string;
email: string;
full_name: string | null;
role: ProfileRole;
is_active: boolean;
created_by: string | null;
created_at: string;
updated_at: string;
};
Insert: {
id: string;
email: string;
full_name?: string | null;
role?: ProfileRole;
is_active?: boolean;
created_by?: string | null;
created_at?: string;
updated_at?: string;
};
Update: Partial<{
id: string;
email: string;
full_name: string | null;
role: ProfileRole;
is_active: boolean;
created_by: string | null;
created_at: string;
updated_at: string;
}>;
};
employees: NoRelationships & {
Row: {
id: string;
personnel_number: number;
first_name: string;
last_name: string;
gender: GenderType;
birth_date: string;
sv_nummer: string | null;
nationality: string;
address: string | null;
postal_code: string | null;
city: string | null;
address_country: string | null;
email: string;
phone: string | null;
team_id: string | null;
division_id: string;
job_title: string;
location_id: string;
manager_id: string | null;
org_level: number;
is_lead: boolean;
employment_type: EmploymentType;
weekly_hours: number;
/** @deprecated Salary is out of MVP scope; column kept only for pre-existing data. */
monthly_salary_gross: number | null;
contract_type: ContractType;
contract_end_date: string | null;
paygrade: PaygradeType;
source: SourceType;
status: EmploymentStatus;
entry_date: string;
exit_date: string | null;
exit_reason: string | null;
karenz_start_date: string | null;
karenz_return_date: string | null;
avatar_color: string | null;
worker_type: WorkerType;
collective_agreement: CollectiveAgreement;
work_days: Weekday[];
is_betriebsrat: boolean;
has_dienstwagen: boolean;
is_laterale_fuehrung: boolean;
is_c_level: boolean;
title_prefix: string[];
title_suffix: string[];
created_at: string;
updated_at: string;
};
Insert: {
id?: string;
first_name: string;
last_name: string;
gender: GenderType;
birth_date: string;
sv_nummer?: string | null;
nationality?: string;
address?: string | null;
postal_code?: string | null;
city?: string | null;
address_country?: string | null;
email: string;
phone?: string | null;
team_id?: string | null;
division_id?: string;
job_title: string;
location_id: string;
manager_id?: string | null;
org_level?: number;
is_lead?: boolean;
employment_type?: EmploymentType;
weekly_hours?: number;
contract_type?: ContractType;
contract_end_date?: string | null;
paygrade?: PaygradeType;
source?: SourceType;
status?: EmploymentStatus;
entry_date: string;
exit_date?: string | null;
exit_reason?: string | null;
karenz_start_date?: string | null;
karenz_return_date?: string | null;
avatar_color?: string | null;
worker_type?: WorkerType;
collective_agreement?: CollectiveAgreement;
work_days?: Weekday[];
is_betriebsrat?: boolean;
has_dienstwagen?: boolean;
is_laterale_fuehrung?: boolean;
is_c_level?: boolean;
title_prefix?: string[];
title_suffix?: string[];
created_at?: string;
updated_at?: string;
};
Update: Partial<Database["public"]["Tables"]["employees"]["Insert"]>;
};
employee_history: NoRelationships & {
Row: {
id: string;
employee_id: string;
event_date: string;
event_type: HistoryEventType;
description: string;
reorg_scenario_id: string | null;
created_at: string;
};
Insert: {
id?: string;
employee_id: string;
event_date: string;
event_type: HistoryEventType;
description: string;
reorg_scenario_id?: string | null;
created_at?: string;
};
Update: Partial<Database["public"]["Tables"]["employee_history"]["Insert"]>;
};
employee_dependents: NoRelationships & {
Row: {
id: string;
employee_id: string;
first_name: string;
last_name: string;
relationship: RelationshipType;
sv_nummer: string | null;
birth_date: string;
created_at: string;
};
Insert: {
id?: string;
employee_id: string;
first_name: string;
last_name: string;
relationship: RelationshipType;
sv_nummer?: string | null;
birth_date: string;
created_at?: string;
};
Update: Partial<Database["public"]["Tables"]["employee_dependents"]["Insert"]>;
};
employee_notes: NoRelationships & {
Row: {
id: string;
employee_id: string;
author_user_id: string | null;
author_name: string;
category: NoteCategory;
note_text: string;
due_date: string | null;
done: boolean;
done_at: string | null;
done_by: string | null;
created_at: string;
};
Insert: {
id?: string;
employee_id: string;
author_user_id?: string | null;
author_name: string;
category?: NoteCategory;
note_text: string;
due_date?: string | null;
done?: boolean;
done_at?: string | null;
done_by?: string | null;
created_at?: string;
};
Update: Partial<Database["public"]["Tables"]["employee_notes"]["Insert"]>;
};
positions: NoRelationships & {
Row: {
id: string;
position_number: string;
title: string;
team_id: string;
division_id: string;
is_lead: boolean;
reports_to_employee_id: string | null;
status: PositionStatus;
valid_from: string;
created_at: string;
filled_at: string | null;
filled_by_employee_id: string | null;
};
Insert: {
id?: string;
position_number?: string;
title: string;
team_id: string;
division_id?: string;
is_lead?: boolean;
reports_to_employee_id?: string | null;
status?: PositionStatus;
valid_from?: string;
created_at?: string;
filled_at?: string | null;
filled_by_employee_id?: string | null;
};
Update: Partial<Database["public"]["Tables"]["positions"]["Insert"]>;
};
hire_drafts: NoRelationships & {
Row: { id: string; created_by: string | null; step: number; payload: Record<string, unknown>; updated_at: string };
Insert: { id?: string; created_by?: string | null; step?: number; payload: Record<string, unknown>; updated_at?: string };
Update: Partial<Database["public"]["Tables"]["hire_drafts"]["Insert"]>;
};
saved_reports: NoRelationships & {
Row: { id: string; created_by: string | null; name: string; config: Record<string, unknown>; created_at: string };
Insert: { id?: string; created_by?: string | null; name: string; config: Record<string, unknown>; created_at?: string };
Update: Partial<Database["public"]["Tables"]["saved_reports"]["Insert"]>;
};
audit_log: NoRelationships & {
Row: {
id: string;
occurred_at: string;
actor_user_id: string | null;
actor_name: string;
action: string;
target_label: string;
target_employee_id: string | null;
details: string | null;
};
Insert: {
id?: string;
occurred_at?: string;
actor_user_id?: string | null;
actor_name: string;
action: string;
target_label: string;
target_employee_id?: string | null;
details?: string | null;
};
Update: Partial<Database["public"]["Tables"]["audit_log"]["Insert"]>;
};
reorg_scenarios: NoRelationships & {
Row: {
id: string;
name: string;
effective_date: string;
created_by: string | null;
applied: boolean;
applied_at: string | null;
undo_snapshot: Record<string, unknown> | null;
created_at: string;
};
Insert: {
id?: string;
name: string;
effective_date: string;
created_by?: string | null;
applied?: boolean;
applied_at?: string | null;
undo_snapshot?: Record<string, unknown> | null;
created_at?: string;
};
Update: Partial<Database["public"]["Tables"]["reorg_scenarios"]["Insert"]>;
};
reorg_moves: NoRelationships & {
Row: { id: string; scenario_id: string; kind: ReorgMoveKind; payload: Record<string, unknown> };
Insert: { id?: string; scenario_id: string; kind: ReorgMoveKind; payload: Record<string, unknown> };
Update: Partial<Database["public"]["Tables"]["reorg_moves"]["Insert"]>;
};
pending_org_changes: NoRelationships & {
Row: {
id: string;
employee_id: string;
change_type: PendingChangeType;
effective_date: string;
payload: Record<string, unknown>;
reorg_scenario_id: string | null;
status: PendingChangeStatus;
created_by: string | null;
created_at: string;
applied_at: string | null;
};
Insert: {
id?: string;
employee_id: string;
change_type: PendingChangeType;
effective_date: string;
payload: Record<string, unknown>;
reorg_scenario_id?: string | null;
status?: PendingChangeStatus;
created_by?: string | null;
created_at?: string;
applied_at?: string | null;
};
Update: Partial<Database["public"]["Tables"]["pending_org_changes"]["Insert"]>;
};
// Written exclusively by trg_track_employee_assignment; RLS grants HR
// read access only, hence no Insert/Update shapes worth modelling.
employee_assignments: NoRelationships & {
Row: {
id: string;
employee_id: string;
manager_id: string | null;
team_id: string | null;
division_id: string;
job_title: string;
is_lead: boolean;
org_level: number;
valid_from: string;
valid_to: string | null;
created_at: string;
};
Insert: never;
Update: never;
};
};
Views: Record<string, never>;
Functions: {
hire_employee: { Args: { payload: Record<string, unknown> }; Returns: string };
terminate_employee: { Args: { payload: Record<string, unknown> }; Returns: void };
transfer_employee: { Args: { payload: Record<string, unknown> }; Returns: void };
promote_employee: { Args: { payload: Record<string, unknown> }; Returns: void };
start_karenz: { Args: { payload: Record<string, unknown> }; Returns: void };
adjust_karenz_return: { Args: { payload: Record<string, unknown> }; Returns: void };
record_karenz_return: { Args: { payload: Record<string, unknown> }; Returns: void };
change_employee_data: { Args: { payload: Record<string, unknown> }; Returns: void };
rehire_employee: { Args: { payload: Record<string, unknown> }; Returns: void };
add_employee_dependent: { Args: { payload: Record<string, unknown> }; Returns: void };
delete_employee_dependent: { Args: { payload: Record<string, unknown> }; Returns: void };
add_employee_note: { Args: { payload: Record<string, unknown> }; Returns: string };
complete_employee_note: { Args: { payload: Record<string, unknown> }; Returns: void };
create_position: { Args: { payload: Record<string, unknown> }; Returns: string };
delete_position: { Args: { payload: Record<string, unknown> }; Returns: void };
staff_position_internally: { Args: { payload: Record<string, unknown> }; Returns: void };
is_valid_svnr: { Args: { p_svnr: string; p_birth_date?: string | null }; Returns: boolean };
apply_reorg: { Args: { payload: Record<string, unknown> }; Returns: string };
undo_reorg: { Args: { payload: Record<string, unknown> }; Returns: void };
apply_due_pending_changes: { Args: Record<string, never>; Returns: number };
};
};
};