# MR: Fetch-request source types, glass-pane create page, date formatting
**Branch:** `xlsx-statement-support` → `main`
**Commits:** 1af0a6b → 231869d (6 commits)
## Summary
Three related strands of UI work on the fetch-request flow, plus library-level improvements in `react-openapi`:
1. **Source types** — the create form now offers Pdf / Xlsx / Csv / Email sources (spec-driven); legacy generic `file` is no longer offered for new fetch requests, and a per-request `trust_fallback` (`amount` | `balance`) can be set at creation.
2. **Create page redesign** — the flat single-column form is now two equal-height frosted "glass" panes over a subtle brand-indigo gradient backdrop: *Source & Account* (account/bank above the expanding source field) and *Window & Policy* (start/end/pipeline/trusted). Recent fetch-request rows share the same glass recipe.
3. **Date formatting** — all dates/datetimes across lists, details and display-format templates render as `"24 Aug 2026"` / `"24 Aug 2026, 09:07"` instead of raw ISO strings; datetime fields can opt into editing as a plain date picker while storing midnight.
## Changes
### react-openapi (library)
- **`src/utils/datetime.ts` (new)** — zero-dep `formatDate` / `formatDateTime` (en-IN via `Intl`). Only ISO-shaped strings are rewritten; DD-MM-YYYY expense strings and non-dates pass through untouched. Exported from the package index.
- Display wiring: `ListCellRenderer` catch-all + inline-dialog cells, `InlineRefField`, and `applyDisplayFormat` template interpolation (ISO-shaped values auto-format).
- **`x-edit-as` mechanism**: new `FieldConfig.editAs`; `DateField` renders a `date-time` field with `x-edit-as: date` as a plain date input, normalizes inbound values to `YYYY-MM-DD`, and submits `T00:00:00`. Routing sites unchanged.
### App
- `fetch-requests.models.ts`: `SourceType` gains `"csv"`, new `CsvSource`, create-side union drops `FileSource`.
- `FetchRequestCreate.tsx`: two-pane grid layout (explicit field partitioning, grid stretch for equal heights), fixed backdrop layer, local `GlassPanel` helper, list rows restyled; `created_at` pinned right before row actions.
- `ReportList.tsx`: generated date right-aligned before action buttons; outer row no longer wraps.
- `ReportViewer.tsx`: header timestamp formatted via exported `formatDateTime`.
## Verification
- `tsc -b` clean at every commit.
- Formatter behavior spot-checked: `2026-08-24T09:07:25.168000` → `24 Aug 2026, 09:07`; `01-05-2026` unchanged; `Z`-suffixed UTC converts to local wall time.
## Deploy notes
- Pairs with the khata-app MR (same branch name): backend supplies the Source oneOf (pdf/xlsx/csv/email), `trust_fallback`, and `x-edit-as` annotations consumed here.
- No dependency changes; no API changes client-side beyond honoring existing spec extensions.
Reviewed-on: #18
Co-authored-by: Vishesh 'ironeagle' Bangotra <aetoskia@gmail.com>
Co-committed-by: Vishesh 'ironeagle' Bangotra <aetoskia@gmail.com>
# MR: Reports frontend — spec-driven generate form, sliceable viewer, dimension bars
**Branch:** `cached-reporting` → **Target:** `main`
## Summary
Reports UI rebuilt to treat the backend OpenAPI spec as the source of truth: the
generate-report form renders generically from `ReportQuery`, and the viewer displays
API-computed metrics verbatim instead of recomputing them client-side.
## Changes
### react-openapi (library)
- `MultiEnumField` renderer for array-of-enum fields; dispatch branch in
`FormFieldRenderer`
- `useFkFieldOptions` hook + `FKFieldConfig.value` (FK options keyed by a non-PK
field — accounts resolve by `name`)
- `FieldConfig.defaultValue` seeding in `extractFields`; enum lift for
`items.enum` arrays; sanitize-payload bypasses FK resolution when `fk.value` is set
### Reports page
- **GenerateReportPanel**: rewritten (~275 → ~110 lines) — fields extracted from the
served `ReportQuery` schema (labels, order, defaults, multi-enum, account picker);
server-side validation only
- **ReportViewer**:
- Period groups built from cube buckets keyed by canonical `period_id`; buckets
merged per period (disjoint slices), txn ids deduped
- Cards/bars/metric strips read `metrics` verbatim (outflows/inflows/sum/count/
avg/min/max/cadence/frequency); Net = one subtraction at render
- Dimension-switchable bar strip (Period / Payees / Tags): segmented pill control
with sliding indicator; pills disabled when the report has ≤1 distinct value;
top-10 bars in a fixed view paged by chevrons (hidden scrollbar)
- Active dim requests the full distribution via `payee=*` / `tags=*` when its own
filter is unselected; explicit selections always slice normally
- **TransactionList**: shared component with optional `groups` prop (API periods +
metrics) used by the viewer; Expense page keeps the client-side fallback path;
group strip shows Sum · Avg · Min · Max · Cadence (or Frequency /day when
cadence < 1)
### Fixes
- Strict DD-MM-YYYY parsing (`parseOccurredAt`) in period merges and date ordering —
`new Date()` mis-read dates as MM-DD-YYYY and corrupted merged cadence
(Aug Zomato: 12.89 days displayed vs 0.76 actual)
- Bar widths magnitude-based so all-outflow slices render at proper width
Reviewed-on: #16
Co-authored-by: Vishesh 'ironeagle' Bangotra <aetoskia@gmail.com>
Co-committed-by: Vishesh 'ironeagle' Bangotra <aetoskia@gmail.com>
## Summary
Wire spec-driven auth into the frontend. Auth config (server URL, paths) is extracted from the served OpenAPI spec by `AppProvider`. `AuthProvider` receives the config as a prop. 401 responses from both the main API and the auth server dispatch an `auth:unauthorized` event that triggers redirect to `/login`. Fix `ProfileRoutes` URL duplication bug.
## Changes
### Auth config from spec
- **`main.jsx`** — `AppProvider` wraps everything, loads spec, exposes `authConfig`. `AuthProvider` receives `authConfig` from `useAppContext()`. `onUnauthorized` passed to both `AppProvider` and `AuthProvider` wires `navigate("/login")`.
### 401 handling
- **`AppProvider.tsx`** — remove `onUnauthorized` prop (handled by `AuthProvider`'s event listener instead, avoiding double-navigation).
- **`useApi.ts`** — 401 response interceptor dispatches `auth:unauthorized` CustomEvent on `window`.
### Profile routing fix
- **`Admin.tsx:ProfileRoutes`** — replace nested `<Routes>` (which caused `/profile/me/me` URL duplication with React Router v6) with `useLocation()`/`useNavigate()` conditional rendering. Only allows `/profile/me` and `/profile/me/edit`.
- **`Admin.tsx:ProfileComponentWrapper`** — replace `pushState() + reload()` with React Router `navigate()` for both `onEdit` and `handleSubmit`.
### Debug logging
- Temporary console logs at every navigation point for diagnosing remaining issues.
Reviewed-on: #12
Co-authored-by: Vishesh 'ironeagle' Bangotra <aetoskia@gmail.com>
Co-committed-by: Vishesh 'ironeagle' Bangotra <aetoskia@gmail.com>