Month management & data separation: - Fix double-count bug: re-uploading a filename updates the existing session_files row in place; identical content (sha256) is skipped — a closing can never parse the same file twice - Guard against duplicate closings per reporting month (409 unless explicitly overridden); dashboard flags duplicates - Default new closings to carry-forward openings; month switcher in the closing header; publish state visible everywhere; Accounts Summary lists unpublished months with the reason instead of dropping them - Completed closings are locked read-only with an explicit reopen Authentication (stdlib only, no new deps): - Per-user login (scrypt + HMAC tokens), AR_AUTH=auto turns on with the first user; manage.py add-user/set-password/deactivate-user - Verified identity feeds reviewed_by/approved_by/confirmed_by Exchange rates: - fx_service with provider abstraction: Frankfurter (free, keyless, ECB) default, exchangerate-api stub; month-end + daily fetch endpoints and UI buttons; rates arrive unconfirmed so Control C5 still gates the close; cache table; certifi CA bundle Deployment & hardening: - Production Docker stack: caddy (auto-HTTPS) + nginx + single-worker backend + mysql:8.4; per-context .dockerignore (images carry no financial data); .env.example with local+production sections - deploy/DEPLOY.md runbook + nightly S3 backup script - Stale-job recovery on startup; export retention (AR_RETENTION_DAYS); deep /api/health; request/job logging; Gitea Actions CI - Repo reorganized: launchers in scripts/, dated lowercase docs, root README, .gitattributes for deterministic line endings Tests: 152 passed (25+ new: dedup, month locking, auth, FX orientation) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| controls_run.py | ||
| fx_service.py | ||
| jobs.py | ||
| retention.py | ||
| store.py | ||