Skip to content

v1.6.0

Choose a tag to compare

@PPCM PPCM released this 02 May 16:49
· 30 commits to main since this release

New Features

Admin maintenance: cleanup of duplicate recurring transactions

Detect and clean up duplicate occurrences of recurring transactions (caused by an old hourly-scheduler bug). New section under Administration → System Settings: an Analyze button shows duplicate groups, then a Cleanup button removes them. Reconciled transactions are preferred over the oldest, and account balances are recalculated after the cleanup.

Two-step deactivate-then-permanent-delete for accounts and users

Bank accounts and user accounts now follow an explicit lifecycle:

  • Active → only deactivate / suspend (reversible)
  • Inactive / Suspended → reactivate, or permanent delete behind a typed-name confirmation modal that lists every cascading deletion (transactions, splits, recurring, group memberships)

The Accounts page shows a dedicated "Deactivated accounts" section. The Admin → Users page shows status-aware action buttons (Suspend on active rows, Reactivate + Permanent Delete on suspended rows).

Harmonized confirmation modals

All destructive and lifecycle prompts now use a shared in-app modal (ConfirmModal) with four variants — default, success, warning, danger. Native browser confirm() dialogs are gone from the app entirely. Permanent deletion of an account or a user uses a stronger typed-name modal that requires retyping the resource name/email before the red Confirm button enables.

Bug Fixes

Hourly scheduler no longer creates duplicate recurring occurrences

createOccurrence was recomputing next_occurrence from startDate after each run, which could leave it stuck on today's date — the cron then re-created the same transaction every hour. The new advanceNextOccurrence advances by exactly one frequency period from the current next_occurrence.

Group "Remove member" no longer deletes the user

The trash icon next to a member in Admin → Groups used to silently call User.delete() — destroying the user account, all of their bank accounts, transactions, recurring transactions and other group memberships. It now only severs the group_members link. Permanent user deletion has to go through the Users page (with the typed-email confirmation modal).

Forecast integration tests no longer fail at month boundaries

The forecastTransactions integration suite used hardcoded dates and broke when the calendar month rolled over. Rewritten to use dates relative to today.

Internal

  • Added 18 integration tests for the duplicates admin endpoints (auth, detection, cleanup, balance recalculation, idempotency, user isolation)
  • Added 5 unit tests + 5 integration tests for the new account lifecycle endpoints
  • Added 2 integration tests for the user delete-when-active rejection and cascade
  • Added a UI checklist (tests/ui/modals/confirm-modal.ui.test.js) for ConfirmModal regression testing
  • Patched dependency CVEs across three phases: postcss, nodemailer, axios, follow-redirects, vite (client + root via override), uuid 9 → 14. All Dependabot alerts on main are now closed.