* fix(side-effects): keep non-prod off Slack and 3CX
Dev portal actions could still name the production Slack channel and phone queue. Skip those calls unless STAGE is prod, and leave the identifiers empty on non-prod tasks.
* style: apply formatter
---------
Co-authored-by: sea-haven-auto-fix[bot] <332630863+sea-haven-auto-fix[bot]@users.noreply.github.com>
* feat(schedule): align the work week with Sunday-Saturday payroll
Saturday night stays in the week that ends Saturday, and the first Flex close skips dates already sent.
* fix(slack-bot): show the last pay close on Sunday
The Monday 7am row for the week that just ended is not written yet, so /oncall pay now falls back to the prior close.
* fix(3cx): refresh the OAuth token before it expires
The worker kept one 3CX access token for the life of the process, so the 8am queue update failed with 401 after the one-hour token lifetime.
* fix(3cx): ignore a client secret this process already replaced
A slower caller still holding the pre-rotation secret could write it back over the new one. The swap now happens under the auth lock, and a retired secret is dropped.
* fix(3cx): adopt a new client secret only after login succeeds
A candidate secret is tried before it replaces the current one, so a revoked secret cannot stick and a later revert to a working secret still takes effect. A failed re-login after 401 returns the original API response.
* ci(workflows): call org reusable CI and Fargate CD
Local CI and the image deploy duplicated the org workflows and still required ci / ci. Pin the callers to those workflows and trust the reusable deploy ref.
* test(ci): probe ruff with an undefined name
* test(ci): remove the undefined-name ruff probe
* ci: retrigger checks after removing the ruff probe
* test(ci): probe ruff with an unused import
* style: apply formatter
* test(ci): remove the autofix probe
---------
Co-authored-by: sea-haven-auto-fix[bot] <332630863+sea-haven-auto-fix[bot]@users.noreply.github.com>
* feat(infra): export vpc_id and public subnet outputs (DEV-289)
Portal Fargate and meals already attach to this VPC. These outputs are
the HCP existing_vpc_id / existing_public_subnet_ids values.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289)
Same extends: recommended ruleset and @redocly/cli 2.52.1 as
internal-portal. Covers health, roster, and portal /api/shifts.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* fix(api): document 4xx and treat 302 as success in Redocly (DEV-289)
Health and CORS preflight document 400. Recommended only counted 2XX,
so login-style 302s use a shared 2XX-or-3XX rule.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
* fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289)
Promote operation-4xx-response and the 2xx-or-3xx success rule to error.
Drop unused 400s on health and CORS OPTIONS. Health documents 403 like the
portal. CORS stays in Flask and is not part of the employee contract.
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
Prod is already a human GitHub Release. Remove the SAM tagging path so CHANGELOG.md stays App Home copy and leftover notifier IAM is destroyed on the next apply.
Origins already point at the Fargate hostnames. Drop the HTTP API, eight
functions, zip CD, and Lambda/API Gateway alarms while keeping leftover
Lambda IAM so Paychex can still name weekly-post.
PutRolePolicy cannot add a third inline on the prod apply role; CreatePolicy of /tf-managed/afterhours-shift-manager-ecs still needs the bootstrap window.
* feat(api): collapse Slack, portal, and jobs onto Fargate (PLAT-216)
Move HTTP and scheduled work onto one always-on Flask task so after-hours
loses Lambda cold start without changing the Cognito or roster contracts.
* fix(portal-api): keep CORS headers on unexpected 500s
Portal SPA error handling needs Access-Control-Allow-Origin even when
DynamoDB or other internals fail, otherwise the browser hides the 500.
* fix(api): retarget holidays per account and ship App Home changelog (PLAT-216)
* fix(iam): list ECS tasks and fail closed on non-prod Paychex (PLAT-216)
* fix(portal-api): serve portal JSON with an explicit JSON content type
* feat(portal-api): add Cognito shift API for the employee portal (DEV-287)
Employees and admins can pick, drop, swap, and manage coverage through
GET/POST/DELETE /api/shifts. Roster PUT accepts optional email for portal
identity. Slack slash commands and App Home admin modals stay in place.
Co-authored-by: adam <adam@seahavenind.com>
* fix(portal-api): preserve shift and deployment invariants (DEV-287)
Co-authored-by: adam <adam@seahavenind.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Bolt parse_body raises JSONDecodeError for empty or non-JSON form
payload fields, which turned probe POSTs into unhandled Lambda 500s.
Fixes AFTERHOURS-SHIFT-MANAGER-2
* fix(cutover): write Slack secrets into empty Terraform shells
DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset.
* feat(infra): migrate afterhours to HCP Terraform (PLAT-74)
Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main.
* fix(cutover): retry DDB unprocessed items and skip past at() holidays
Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.
PR #248 disabled the SES send by blanking PAYROLL_RECIPIENTS and dropping the
ses:SendEmail grant. This removes the now-dead path: _send_pay_email and
_build_pay_email_html, the SES_SENDER and PAYROLL_RECIPIENTS env, and the
PayrollEmailFailure metric filter and alarm that only fired on that path.
Slack schedule post, pay-summary DM, and checkcomponents enqueue unchanged.
* feat(roster): add Bearer PUT/DELETE roster API
Identity hire needs to write Slack IDs onto roster rows without a stale
daily 3CX sync clearing them, using the existing HTTP client contract.
* fix(roster): strip Secrets Manager token whitespace
A file:// secret commonly includes a trailing newline, so compare_digest
must strip the cached value the same way it strips the Bearer header.
* feat(pay): send after-hours lines to paychex checkcomponents (PLAT-154)
* style(pay): drop trailing blank line in weekly post tests
* fix(pay): skip duplicate checkcomponents send on weekly-post retry