phase-1: packages/rules complete, 100% covered

Every algorithm in docs/RULES.md, implemented exactly as written: the RUC
check digit, the calendario perpetuo with weekend and holiday roll forward,
CDC and KUDE QR parsing, keyword classification, computeF120, computeF515 and
the dashboard projections, plus the two form definitions.

Both worked examples reproduce verbatim on the first implementation: F120 at
Gs. 277.273 to pay with the Gs. 350.000 flip case, F515 at Gs. 11.290.000 on a
5,65% effective rate. 162 tests over the package, coverage enforced at 100%
statements, branches, functions and lines; the only exclusions are three
bounded-loop guards marked v8 ignore with a comment saying why.

No tax rule was invented. All six TODO-TAX-VERIFY items from RULES.md have a
test pinning today's behaviour and a row in the DECISIONS.md register, so
verification later is a red/green diff. Where RULES.md was silent the choice is
marked SPEC-GAP in the code and listed too, the notable one being that
taxpayer.hasIrp gates the deduction amount.

No floats anywhere in a money path: money is a branded Pyg of whole guaranies
and percentages go through integer arithmetic rounded half up.

Also: contracts now takes IRP_CATEGORIES from rules rather than declaring the
eight strings twice; classification returns reason codes with catalog strings
in both locales, so the detail sheet localizes; apps/api/.env.example now names
the same web port as apps/web/.env.example, without which a fresh checkout
fails sign in on the origin check.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Michilis
2026-09-03 22:15:28 +00:00
co-authored by Claude Opus 5
parent ae2ea20b7e
commit 80b10c958e
45 changed files with 3317 additions and 48 deletions
+5 -2
View File
@@ -6,7 +6,9 @@ NODE_ENV=development
# Port the Hono server listens on. The web app proxies /api here.
PORT=4000
# User facing origin. Used for links in emails, push payloads and Telegram messages.
APP_PUBLIC_URL=http://localhost:3000
# Must name the same port as apps/web/.env PORT, or better-auth rejects the sign in
# request as a foreign origin.
APP_PUBLIC_URL=http://localhost:3005
# server = serves HTTP. worker = runs the job poller and sweeps, serves only /healthz.
ROLE=server
@@ -24,7 +26,8 @@ DATABASE_URL=sqlite:./data/app.db
# Signing key for sessions. At least 32 characters. Generate: openssl rand -base64 32
BETTER_AUTH_SECRET=change-me-to-at-least-32-characters-long
# Public origin cookies are issued for. Auth routes are proxied, so this is the web origin.
BETTER_AUTH_URL=http://localhost:3000
# Keep in step with APP_PUBLIC_URL and apps/web/.env PORT.
BETTER_AUTH_URL=http://localhost:3005
# local | s3. local needs one shared volume across replicas; s3 is required to scale out.
STORAGE_DRIVER=local