Commit Graph
17 Commits
Author SHA1 Message Date
nikolaandClaude Opus 5.5 5847245638 Bundle a static pdftotext into the binary
The PDF parsers shell out to pdftotext, so every machine running money needed
poppler-utils installed. scripts/build-bundled.sh now builds a deployable
binary that carries its own: pdftotext is compiled in a container from a
checksum-pinned poppler release as a fully static musl executable, then
embedded with `go build -tags bundled`. The result is one file that runs on
any Linux of that architecture with nothing installed alongside it.

It is still the real pdftotext, run as a subprocess. Linking poppler through
cgo would have cost the pure-Go build, and its C++ text API is not guaranteed
to space columns the way pdftotext -layout does, which is what the parsers
were tuned on. Only what text extraction needs is compiled in -- no
fontconfig, cairo or image codecs -- and its output is byte-identical to a
full distro build on the same PDF.

At runtime the embedded copy is written to the user cache directory, not
/tmp, which servers often mount noexec. It is named by content hash, so a
newer build never runs an older copy, and verified before reuse, so a write cut
short by a killed process is replaced rather than trusted. `money config` says
which pdftotext is in use.

The tag is opt-in: plain go build and go test never need the 5 MB executable,
which is gitignored rather than committed. Building with the tag for anything
but linux/amd64 or linux/arm64 fails with a message saying so.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-02 18:02:46 +02:00
nikolaandClaude Opus 5.5 6faf99719a Serve the TUI's screens as a web app
money serve puts the seven screens in a browser: accounts, transactions, the
report with its period axis and sort, the rule builder with its live preview
and edit-in-place, the rules list, the transfer builder with its tolerance
preview, and the transfers list. Import and retag are buttons in the header.
It is one binary: the page is plain HTML, CSS and JavaScript embedded with
go:embed, with no framework and no build step.

It is a second frontend, not a second implementation. Amounts are formatted on
the server, the rule preview is matched by glob.Match there, and the transfer
preview runs transfers.Analyze, so the browser only lays out answers and
cannot drift from the TUI on what a rule catches or what a pair costs.

The server outlives hand edits to rules.toml in a way the TUI does not, so
retag and import re-read it first, as a fresh `money retag` or `money import`
would, and the overview says when the file on disk no longer matches what the
index was derived from. Edits and deletes still go by position, but carry the
rule they showed and are refused unless rules.toml still holds exactly that
there; a position from a stale tab could otherwise name a different rule. An
edit takes the type pattern from the rule on disk, never from the request.

There is no authentication, by request. It listens on loopback unless --addr
says otherwise, and writes must be sent as JSON so a cross-site form cannot
post to it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-02 09:48:56 +02:00
nikolaandClaude Opus 5 7d4c3eba17 Open the report on last month
The report answered for the whole index, which is the one window a spending
report is least often asked for: last January's groceries sat in the same total
as last week's, and nothing on screen said which was which. It now opens on the
month that has just ended -- the last one a statement can be complete for --
and left/right step along an axis beside the totals, from all time down through
the named windows to the oldest month the index holds.

The period narrows the report and nothing else. reloadReport runs its own query
rather than reusing the rows the transaction list is showing: the two share the
account, the search and the untagged toggle, and differ only in the date
bounds, so opening on last month must not hide the rest of the index from the
list beside it. Nothing may put the period into m.filter, which is exactly what
would make it leak.

The windows are relative to today, never to the newest statement. "Last month"
with nothing in it reports nothing and says so, because silently answering for
a month nobody asked for is worse than an empty screen; an empty period and an
empty index therefore give different messages, one asking for another period
and the other for an import. The rolling windows run to the end of this month
rather than to the last complete one -- "last 3 months" is asked in order to
see what is happening now, and leaving out the days since the 1st answers a
question nobody put. The axis is built over the whole index rather than the
rows in view, or it would grow and shrink as the account or search filter
changed and move under the cursor; a reload rebuilds it, since an import can
reach further back, but keeps the window the user was on.

s cycles how those rows are arranged: largest out first as before, then in, net
lowest first so the biggest losses lead, count, and the tag A to Z. A letter
rather than a chord because the report is not a form. The marked heading says
which column the rows are read from and the help names what the key does next,
as the rule builder's preview already does. The sort rearranges rows and never
changes which rows there are, so the order stays out of the filter for the same
reason the period does. Currency remains the outer key under every order --
there are no rates here, so two currencies interleaved by amount would invite a
comparison that cannot be made -- and every order falls back to the tag, so
ties keep a fixed position instead of reshuffling between reloads.

money report takes the same choice as --sort out|in|net|count|tag, and a
misspelt one is refused rather than silently reporting in the default order. It
keeps --month and has no equivalent of the wider windows.

store.Filter gains From and To, compared as strings because dates are stored
ISO-8601 and a string comparison is therefore a date comparison. store.Months
replaces report.Months, which nothing had ever called: the axis needs the
months of the whole index, not of a slice already in hand.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 15:45:23 +02:00
nikolaandClaude Opus 5 656e7e1de4 Sort the rule builder's preview by count
Alphabetical order finds a payee you are already looking at, which is what the
list is for once a glob is typed. With the glob empty it answers a different
question -- what to write a rule for next -- and there the name is the least
useful thing about a row: one pattern claiming forty rows is worth more than
the first of forty claiming one, and nothing on screen said which was which
until you read the whole list.

ctrl+s switches between the two. A chord rather than a letter because the
builder is a form and every printable key belongs to the field being typed in;
the invariant that keeps q from quitting there cuts this way too. Ties fall
back to the alphabetical order so the list does not reshuffle when it is
rebuilt, and the cursor returns to the top, since the row under it is not the
row that was there a moment ago.

The header marks the column the order is read from, and the help names what the
key does next rather than where the list already is. The choice is the user's,
so it outlives the builder being left and reopened.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 20:33:46 +02:00
nikolaandClaude Opus 5 6477147988 Edit a rule from the rules screen
A rule could be written and deleted but never changed, so fixing a glob meant
deleting the rule and typing it again -- losing its note, the comments around
it, and its position, which still breaks ties between equally specific rules.
e now opens the selected rule in the builder and enter rewrites it where it
sits. config.ReplaceRule edits rules.toml textually, as deleting does, and
keeps the comments above the rule: they say why it is there, which editing its
glob rarely changes.

The round trip must not lose what the form does not show. The builder has four
fields and a Rule has five, so an edit carries the type pattern through
untouched and says so under the glob; a type-only rule saves without one. The
preview needed the same care in reverse: a working rule's transactions are
tagged, so an untagged-only preview would be empty for it. Its own rows are
added back, and the ones a narrowed glob stops catching stay on screen marked
-- giving one up is the decision being made, and it must not happen silently.

The builder and its list shared one return view, so opening the builder from
the list left esc pointing back into the form. Each screen now remembers its
own way out; transfers had the same trap and the same fix.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 19:40:55 +02:00
nikolaandClaude Opus 5 442684be60 Try the most specific rule first, not the topmost
File order decided precedence, so a narrow rule had to be written above the
broad one it carves an exception out of -- an ordering constraint the file
cannot show and the user has to remember. *NIKOLA* below *NIK* silently matched
nothing, and a catch-all * could only ever be the last line.

Engine.New now sorts once and MatchIndex walks that order: most literal
characters first, then fewest *, then account-scoped over unscoped. Literals
are what a rule commits to and a * is what it gives up, so a bare * is tried
last wherever it sits. The sort is stable, so equally specific rules keep file
order and the earlier one wins -- which is all position decides now, and why
AppendRule can keep appending without displacing a rule written by hand.

The two orders must not be confused: Rules(), Usage and MatchIndex still speak
in file positions, because that is what the rules screen numbers and what
DeleteRules deletes by. A shadowed rule still reports zero usage, but a zero no
longer says anything about where the rule sits.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 19:30:04 +02:00
nikolaandClaude Opus 5 ebf7770569 Pair transfers from rules.toml
The boolean transfer flag went two commits ago because a one-sided verdict let
half a movement vanish and left the report unbalanced. This is what replaces
it: a [[transfer]] block names both legs, and only a matched pair is dropped
from the report -- both legs together, never one.

Legs pair within five days, nearest date first, and a transaction belongs to at
most one transfer, so the first definition to claim a leg keeps it, exactly as
the first matching rule keeps a tag. The pairing is derived state like the tags:
Engine.Link rewrites the whole transfers table from rules.toml, which is why
retag re-derives both halves of what that file decides, and why it runs over
the whole index rather than a filtered view -- pairing inside one would let a
movement count as a transfer in one report and not in another. An unmatched leg
is not a transfer and keeps counting, surfaced as a warning instead.

Within one currency the amount is the evidence and must be the exact opposite.
Across currencies it is not checked at all: there are no rates here, so the two
numbers are unrelated and the dates carry the pairing alone.

tolerance_pct is the one exception, per definition, for a route where the bank
takes a fee and the two statements genuinely disagree. It defaults to zero and
belongs on the one definition that charges; a global or default tolerance would
loosen every route that does not. The difference it admits is not forgiven --
the pair leaves the report entirely, so a fee hidden inside one would be
spending that appears nowhere. Pair.Fee is what left less what arrived, and
report.Excluded carries it out per currency alongside the legs. It counts only
pairs whose legs are both in view, for the same reason it counts legs and not
transfers: half a pair cannot say what the other half received.

The screens:

- 6 builds a definition against the index as you type, showing the pairs it
  would form and the legs it would catch but leave unpaired. Six fields need
  more room than the rule builder's four, so the form sheds its spacing, then
  its hints, then the borders on unfocused fields.
- 7 lists every definition with what it pairs. Two counts, because they mean
  different things: an unpaired leg is a definition doing something and not
  finishing it, no pairs at all is dead weight. Tol names the tolerance, blank
  where amounts must agree.
- 3 grows a (transfers) row under TOTAL, and a fees row beneath it, or the
  report silently disagrees with the account balances.

Two things that are not part of transfers but are the same day's work:

- ls --uniq lists each account and description once, normalised the way a glob
  sees them, which is the shape of "what still needs a rule?" -- fifty visits
  to one shop are one pattern to write, not fifty rows to read.
- The rule builder's preview now filters to what the glob matches instead of
  marking matches in a full list. The count carries the context the rows no
  longer can: 2 of 7, measured against everything still in view.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 19:19:12 +02:00
nikolaandClaude Opus 5 ef6a231d98 Correct the docs against the code
Four removals in a row left both files describing things that are no longer
there, and one claim that was never true:

- The rules screen mock-up still had the transfer column, two commits after
  that column went. The keys table listed 4 twice, once as a view switch and
  once as the tagging row that replaced t; tagging is now a sentence saying
  plainly that no key does it and why 4 is the answer.
- The rule builder mock-up was missing the account field entirely while the
  prose below it described moving between four fields.
- glob was described as linear time with no backtracking. It is the two-pointer
  wildcard match, which backtracks by design -- the branch is right there in
  glob.go -- and is O(n*m) in the worst case. What it actually rules out is
  exponential blowup on patterns like *a*a*a*.
- r on the rules screen was undocumented. It recounts against the index, which
  is what an import makes stale; it does not re-read rules.toml, so an edit
  made elsewhere still needs a restart.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 23:39:17 +02:00
nikolaandClaude Opus 5 93491016cd Drop schema migrations
The index is a cache. Everything in it is re-derived from the statements and
rules.toml, and has been since the last hand-set tags went, so keeping
machinery to nurse an old index through a schema change was paying for a
guarantee nothing needs. The ALTER TABLE lists, the dropped-column list and the
pragma_table_info reader are gone; Open applies the schema and returns.

What replaces it is a line in the release note: delete index.db and import
again. The two directions are not symmetric, which is worth knowing before
assuming something is broken. Removing a column leaves an older index working,
carrying the dead column and its data unread, because every statement here
names its columns -- that is why the drop half was never really load-bearing.
Adding a column the code reads breaks every command against an older index with
`no such column` until the file is deleted.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 23:39:07 +02:00
nikolaandClaude Opus 5 02814d09e5 Remove manual tagging
A tag could come from two places: rules.toml, or the TUI's t key, which wrote
manual_tag with COALESCE(manual_tag, rule_tag) deciding the winner. That split
paid for itself in the first invariant of the codebase, in ClearOverrides and
the c key, in the * marker on the tag column, and in the one exception to a
disposable index -- a tag set by hand was the only thing in index.db that the
statements could not reproduce.

Now rules.toml decides every tag. The index is derived entirely from the
statements plus that file, so deleting it and re-importing gets back exactly
what was there, and retag has nothing to be careful of. Tagging a one-off means
writing a narrow rule on screen 4, which previews what the glob catches before
it is saved.

A manual tag in an existing index is dropped along with the column the first
time this build opens it, and those rows read as whatever the rules say, or as
untagged. TestManualTagSurvivesRetag guarded the invariant that has just been
removed; TestRetagRewritesEveryTag replaces it with the one that took its
place, and keeps Retag itself covered.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 23:19:24 +02:00
nikolaandClaude Opus 5 5ca6cff87b Remove the transfer flag
A transfer was a second verdict carried alongside the tag: a boolean set by
transfer = true in a rule or by x in the TUI, kept in its own pair of rule_
and manual_ columns, whose one real effect was to hold the row out of the
report. The rest of it was display -- a T column in the transaction list, in
the rules screen and in money ls.

Money moved between your own accounts is now tagged like anything else and
counts like anything else. The leg leaving checking is an outflow and the leg
arriving in savings is an inflow, so a report over the whole data root roughly
nets out while one scoped to a single account or month does not. That is the
price of one verdict per transaction instead of two.

A rule now needs a tag, and one that set only transfer = true is refused by
number on load. A leftover transfer key beside a tag is ignored, as unknown
TOML keys always were, and an index built by an older binary drops both
columns when it is opened.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 23:07:47 +02:00
nikolaandClaude Opus 5 16c2585637 Drop counterparty, the generic parsers and .money/
counterparty was a structured field only nlb could fill honestly. revolut
and traderepublic invented one by running an IBAN-shaped regex over the
description they had just built, and the two spellings disagreed --
SI56 1234 5678 9012 345 against SI56123456789012345 -- so a literal rule
pattern that worked on one account silently matched nothing on another. It
is gone from the model, the index, the rule keys, ls --wide and the rules
screen. nlb now appends its IBAN column to the end of the description,
where the other two already keep theirs, so match = "*SI56*" works
everywhere. That changes those descriptions and with them their
fingerprints, so a statement overlapping an already-imported period will
re-add rather than dedupe those rows until the index is rebuilt. An index
built by an older binary drops the column when it is opened.

The index itself moves from .money/index.db up to index.db beside
rules.toml. Nothing looks in the old location, so an existing one has to be
moved by hand -- otherwise the tool quietly starts a fresh index and the
manual tags in the old file, the only thing statements cannot reproduce,
stay behind in it.

The csv and cmd parsers are gone along with the [csv] and [cmd] config they
carried. cmd shelled out to the Python extractors, which were ported to Go
and deleted, so it bridged to nothing; csv was a generic column-mapped
fallback that no account used, and between them they were the largest
configuration surface in the tool. A bank is now described in Go, where it
can be tested. The importer tests register their own three-column parser
rather than borrow a bank's, so they stay about the directory walk, dedupe
and per-file error reporting.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 22:51:20 +02:00
nikolaandClaude Opus 5 83d842d92e Let rules carry a note
A glob like *4412* says nothing about why it exists or who it catches, and
six months later neither does memory. Rules get an optional note: free text
that never takes part in matching, written as a TOML key rather than a
comment so it survives a round trip and can be shown back.

The rule builder grows a fourth field for it and the rules screen a last
column. Four fields spaced out are taller than a short window has room for,
so the form now drops its blank lines and then the hints on unfocused fields
before anything would run off the bottom.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-09 23:23:29 +02:00
nikolaandClaude Opus 5 73fefea96d Complete account and tag names in the rule builder
Both fields are free text, and a slug or tag that is slightly wrong produces
a rule that silently catches nothing — or a second, near-identical tag. They
now complete against what already exists: accounts from the folders on disk
and the index, tags from every tag in use plus any named in rules.toml, so a
tag is completable from the moment a rule mentions it.

The completion is ghosted after the cursor and never committed until it is
accepted, so inventing a new tag still works. tab takes it and moves focus
only when there is nothing left to complete; ctrl+n/ctrl+p cycle an ambiguous
prefix, and the hint under the box says how many candidates are left.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-09 23:06:31 +02:00
nikolaandClaude Opus 5 c2eba53fd4 Add a rules screen that finds and removes dead rules
Nothing showed whether a rule was still earning its place. The new screen, on
5, lists every rule in file order with the number of transactions it claims,
marking those that claim none.

The count comes from Engine.Usage, which counts by first match, so a rule
shadowed by an earlier one reports zero even though its glob matches. That is
the case worth catching: such a rule looks correct in isolation and can never
fire.

d removes the selected rule and p removes every unused one, each behind a y/n
confirmation since this rewrites a hand-maintained file. config.DeleteRules
edits rules.toml textually rather than re-serialising the parsed rules, so
comments and layout survive; a comment directly above a rule goes with it,
while one separated by a blank line is left as a heading. The result is
re-parsed before it replaces the file.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-09 02:02:01 +02:00
nikolaandClaude Opus 5 aeca203855 Add a rule builder screen with a live glob preview
Writing a glob by hand meant guessing what it would catch, then running retag
to find out. The new screen, on 4, puts the glob, account and tag fields on
the left and every still-untagged description on the right, sorted
alphabetically and grouped by description with an occurrence count.

Matches are marked as the glob is typed, along with a count, so the effect of
a rule is visible before it is written. Enter appends it to rules.toml via
config.AppendRule, reloads the engine from disk and retags, so the rows it
caught leave the list immediately.

Rules are appended rather than prepended, keeping the precedence of anything
already in the file. Since the preview only lists transactions no existing
rule has tagged, it reflects that precedence for free.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-09 01:41:24 +02:00
nikolaandClaude Opus 5 3ba26cadae Document the invariants and testing recipes in CLAUDE.md
Records what the code assumes rather than what it does: why rule verdicts and
manual edits live in separate columns, how the dedupe fingerprint works, why
column positions must not be hardcoded from a sample PDF, and the pty
handshake needed to drive the TUI in a real terminal.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-09 01:20:27 +02:00