Commit graph

116 commits

Author SHA1 Message Date
Adam Moussa
0c255c4bf4
Merge branch 'main' into dependabot/pip/src/weekly-post/boto3-gte-1.43.31 2026-06-16 21:04:36 -04:00
dependabot[bot]
36232f4ae4
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/slack-bot (#119) 2026-06-17 01:04:12 +00:00
dependabot[bot]
b1c9e50e05
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/weekly-post
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.27...1.43.31)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.31
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-17 01:03:53 +00:00
dependabot[bot]
7362d89a0d
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/shared (#118) 2026-06-17 01:01:45 +00:00
dependabot[bot]
d836f8fbf0
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/roster-sync (#117) 2026-06-17 00:59:53 +00:00
dependabot[bot]
4815e4032b
Update boto3 requirement in /src/ring-scheduler (#116) 2026-06-16 20:56:31 -04:00
dependabot[bot]
3099046527
Bump actions/setup-python from 5 to 6 (#115) 2026-06-16 20:52:56 -04:00
Adam Moussa
1e1e5176a3
Fix payroll summary email (SES config-set permission) + isolate failures (#114)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* Fix payroll email: grant SES config-set permission + isolate failures

The weekly pay-summary email to payroll has been failing with SES
AccessDenied since 2026-06-08. The sending identity (seahaven.com) gained
a default configuration set (seahaven-email-events), and SES authorizes
SendEmail against the config-set ARN as well as the identity — but the
WeeklyPostFunction role only granted ses:SendEmail on identity/*.

- template.yaml: add the configuration-set ARN (scoped to the known set
  name) to the SES policy so sends are authorized again.
- weekly-post/app.py: wrap _send_pay_email in try/except so a delivery
  failure can never abort the handler before the Slack schedule post.
  Previously the SES error also blocked the two-week schedule post.
- Add a regression test covering the isolation.

Cross-family GPT-4.1 IAM review: APPROVE.

* Bump to v1.10.1 in CHANGELOG and sync App Home copy
2026-06-15 13:24:32 -04:00
Adam Moussa
8e90d41b6c
Point release-notify invoke role trust at deploy.yaml (#113)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
The release job moved from release.yaml into deploy.yaml to clear
CodeQL's workflow_run findings, but the OIDC invoke role's trust still
pinned job_workflow_ref to release.yaml. That denied the AssumeRole at
the release job's Configure-AWS step, so the v1.10.0 announcement never
fired. Point the condition at deploy.yaml (the inline release job's
top-level workflow) so the token's job_workflow_ref matches.
2026-06-12 11:42:55 -04:00
Adam Moussa
53c85f7eed
Add changelog-driven releases and App Home tab (#112)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Add changelog-driven releases and App Home tab

Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:

- A new afterhours-release-notifier Lambda posts a "What's New" message
  to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
  command list, and the current version's notes.

release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.

* Harden release workflow and regex against CodeQL findings

Address three code-scanning alerts on the PR:

- Critical (actions/untrusted-checkout): split release.yaml into a
  read-only `prepare` job that checks out and runs repo code, and a
  privileged `publish` job (contents:write + OIDC) that never checks out
  repo code — it tags, releases, and invokes purely through the GitHub
  and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
  markdown_to_mrkdwn with possessive quantifiers and exclusive character
  classes so they run in linear time on adversarial input. Adds a
  regression test.

* Move release/announce into Deploy workflow to clear CodeQL

The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.

Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00
dependabot[bot]
1c9ddaeadf
Update boto3 requirement from >=1.43.26 to >=1.43.27 in /src/weekly-post (#111)
Some checks are pending
Deploy / deploy (push) Waiting to run
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:13 -04:00
dependabot[bot]
ef4fafb943
Update boto3 requirement from >=1.43.26 to >=1.43.27 in /src/slack-bot (#110)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:09 -04:00
dependabot[bot]
c1d76390b0
Update boto3 requirement from >=1.43.26 to >=1.43.27 in /src/shared (#109)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:05 -04:00
dependabot[bot]
0c8eb14f55
Update boto3 requirement from >=1.43.26 to >=1.43.27 in /src/roster-sync (#108)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:00 -04:00
dependabot[bot]
1a5faa53f8
Update boto3 requirement in /src/ring-scheduler (#107)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:30:56 -04:00
Adam Moussa
2995f6b3ea
Repo hygiene: PR labeler + README badges + dependabot (INFRA-56/57/66) (#106) 2026-06-11 14:13:35 -04:00
dependabot[bot]
b4798c12fe
Update boto3 requirement from >=1.43.22 to >=1.43.26 in /src/weekly-post (#104)
Some checks are pending
Deploy / deploy (push) Waiting to run
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:12:07 -04:00
dependabot[bot]
e007b10e81
Update boto3 requirement from >=1.43.22 to >=1.43.26 in /src/slack-bot (#103)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:12:02 -04:00
dependabot[bot]
43680b7f8f
Update boto3 requirement from >=1.43.22 to >=1.43.26 in /src/shared (#102)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:11:58 -04:00
dependabot[bot]
4b5006da9a
Update boto3 requirement from >=1.43.22 to >=1.43.26 in /src/roster-sync (#101)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:11:54 -04:00
dependabot[bot]
27dfe4bf8e
Update boto3 requirement in /src/ring-scheduler (#100)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:11:49 -04:00
Adam Moussa
424be7c2da
Attach permissions boundary to all Lambda execution roles (#105)
Some checks are pending
Deploy / deploy (push) Waiting to run
Applies seahaven-lambda-execution-boundary to all SAM auto-generated
function execution roles via Globals.Function.PermissionsBoundary.
Required so the github-cfn-execution-role scope-down (INFRA-97) can
safely constrain role creation without blocking Lambda deploys.

No explicit AWS::IAM::Role resources exist in this template.

Refs: INFRA-103
2026-06-10 14:14:46 -04:00
Adam Moussa
efa4bc569d
INFRA-28: add HTTP API access logging and throttling (audit M-18) (#98)
Some checks failed
Deploy / deploy (push) Has been cancelled
Add AccessLogSettings on the implicit HTTP API stage pointing at a new
/aws/apigateway/afterhours-shift-manager log group with 90-day retention,
plus DefaultRouteSettings throttling (100 rps / 50 burst). Mirrors the
M-18 pattern landed on payments-dashboard.
2026-06-05 17:47:41 -04:00
Adam Moussa
9bea3ed4c7
Add dependency-review caller workflow (#97)
Some checks are pending
Deploy / deploy (push) Waiting to run
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:26:41 -04:00
dependabot[bot]
abf9a5cded
Update boto3 requirement from >=1.43.19 to >=1.43.22 in /src/weekly-post (#96)
Some checks failed
Deploy / deploy (push) Has been cancelled
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.19...1.43.22)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.22
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 01:00:31 +00:00
dependabot[bot]
fedecbf30c
Update boto3 requirement from >=1.43.19 to >=1.43.22 in /src/slack-bot (#95)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.19...1.43.22)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.22
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 01:00:12 +00:00
dependabot[bot]
0aef0c98a3
Update boto3 requirement from >=1.43.19 to >=1.43.22 in /src/shared (#94)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.19...1.43.22)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.22
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 00:59:59 +00:00
dependabot[bot]
668045ba7c
Update boto3 requirement from >=1.43.19 to >=1.43.22 in /src/roster-sync (#93)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.19...1.43.22)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.22
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 00:59:39 +00:00
dependabot[bot]
c879dc3fbf
Update boto3 requirement in /src/ring-scheduler (#92)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.19...1.43.22)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.22
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 00:59:25 +00:00
Adam Moussa
dbbaaccce8
Add a plain-language changelog from inception (#91)
Some checks failed
Deploy / deploy (push) Has been cancelled
Human-readable history of the bot from launch (Apr 3) through v1.9.2, written
for a non-technical reader. Recent entries map to the new semantic version tags
(v1.7.19-v1.9.2); earlier work is grouped by dated milestone since those
releases were daily auto-versioned.
2026-06-01 20:02:17 -04:00
Adam Moussa
b2967946cc
Make version bump manual-only and remove Slack notification (#90)
We now apply semantic version tags deliberately (see v1.7.19–v1.9.2), so the
daily auto-bump is no longer wanted.

- Drop the `schedule:` cron (and the now-unneeded DST guard) — the workflow
  runs only on `workflow_dispatch`, with patch/minor/major options.
- Remove the Slack notification entirely: the "Update changelog canvas" and
  "Post to Slack" steps (and the PR/bullet collection that fed them) are gone,
  along with their SLACK_* secret usage.
- Keep the core behavior: compute the next version from the latest tag + chosen
  bump and push an annotated tag.

Renames the workflow "Daily Version Bump" -> "Version Bump".
2026-06-01 20:00:02 -04:00
Adam Moussa
11512f9aad
Fix SETUP.md to use Secrets Manager, not SSM (compliance #68) (#89)
SETUP.md step 2 told operators to store the Slack token/signing secret in
SSM Parameter Store, which (a) violates the secrets-and-config handbook
(API tokens/signing values must live in Secrets Manager) and (b) contradicts
the IaC — the stack reads Secrets Manager and the IAM roles only grant
secretsmanager:GetSecretValue on afterhours-shift-manager/*, so following the
old instructions would break the deploy.

- Section 2 now uses `aws secretsmanager create-secret` for all five secrets
  (slack-bot-token, slack-signing-secret, 3cx-domain/client-id/client-secret) —
  the 3CX secrets were also previously undocumented.
- The Slack channel ID is not a secret; documented as the `ShiftChannel` deploy
  parameter (--parameter-overrides) instead of an SSM SecureString.

Addresses violation 2 of #68.
2026-06-01 19:46:47 -04:00
dependabot[bot]
26aec5dade
Update boto3 requirement from >=1.43.11 to >=1.43.19 in /src/roster-sync (#79)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.11...1.43.19)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.15
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-01 23:37:43 +00:00
dependabot[bot]
5772469f1b
Update boto3 requirement in /src/ring-scheduler (#78)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.11...1.43.19)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.15
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-01 23:37:27 +00:00
dependabot[bot]
474c7b04fa
Update boto3 requirement from >=1.43.11 to >=1.43.19 in /src/shared (#80)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.11...1.43.19)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.15
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-01 23:37:19 +00:00
dependabot[bot]
fd17d71dcd
Update boto3 requirement from >=1.43.11 to >=1.43.19 in /src/slack-bot (#81)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.11...1.43.19)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.15
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-01 23:36:50 +00:00
dependabot[bot]
46afc6e651
Update boto3 requirement from >=1.43.11 to >=1.43.19 in /src/weekly-post (#82)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.11...1.43.19)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.15
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-01 23:34:49 +00:00
Adam Moussa
7733af6af0
Lock shift drops within 24h of start (#84) (#88)
A user can no longer `/oncall drop` a shift inside the 24h window before it
starts — inside that window coverage must be handed off via a verified swap
(target accepts) or opened by an admin.

- app.py: _within_drop_lock(date, shift_type) (24h before _shift_start);
  guard in _handle_drop after the ownership check. Admin `open` is a separate
  handler and is unaffected (bypasses the lock).
- Removed the now-unreachable 3CX-repoint-on-drop branch: a same-day shift is
  always inside the lock, so a drop never reaches mark_open for today.
- Help text + README note the 24h rule.
- tests: rewritten test_handle_drop (outside/inside-24h per shift type,
  weekend day, admin bypass, plus the existing guard-precedence cases) and
  direct _shift_start/_shift_started/_within_drop_lock helper tests. 185 passed.

Closes #84
2026-06-01 19:32:40 -04:00
Adam Moussa
060bd0bf3e
Add swap-acceptance (verified-swap) flow (#87)
Some checks are pending
Deploy / deploy (push) Waiting to run
/oncall swap no longer reassigns immediately. It now writes a pending SWAP
record and DMs the target Accept/Decline buttons; the shift only moves once
they accept.

- schedule.py: create_pending_swap / get_swap / mark_swap_verified /
  clear_swap (PK=SWAP, date/shift SK mirroring OVERRIDE, status + timestamps
  + expires_at for TTL). A new request supersedes a prior pending one.
- app.py: _handle_swap creates the pending swap + DMs the target (requires the
  target be Slack-linked; rejects self-swap). New module-level
  handle_swap_accept / handle_swap_decline + two @app.action registrations.
  Accept writes the override, repoints 3CX when it's the active shift, marks
  the swap verified, notifies the channel + requester. Decline clears it and
  DMs the requester. Lazy expiry: accept is rejected once the shift has started
  (_shift_start/_shift_started).
- blocks.py: build_swap_request_blocks (Accept/Decline) + build_swap_resolved_blocks.
- template.yaml: enable DynamoDB TTL on expires_at so abandoned pending swaps
  self-clean.
- tests: swap schedule methods, swap blocks, rewritten test_handle_swap
  (pending + DM, no immediate override), new test_swap_accept_decline. 174 passed.
- README: swap behavior + SWAP item type + TTL.

The verified SWAP status is what #84 (24h drop guard) will query.

Closes #83
2026-06-01 19:22:55 -04:00
Adam Moussa
3a26343cb7
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI

Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.

- Lift slack-bot handlers out of create_app() closures to module level so
  they're unit-testable; create_app is now a thin Bolt-wiring layer. No
  behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
  ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
  admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
  responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
  per-package conftest loads each app.py under a unique name to avoid the
  four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
  the tests dir too.
- README Testing section.

Closes #85

* Add least-privilege permissions block to CI workflow

Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).

* Stop logging extension numbers in 3CX queue updates

Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
dependabot[bot]
9af1a9a161
Update boto3 requirement from >=1.43.6 to >=1.43.11 in /src/weekly-post (#77)
Some checks failed
Deploy / deploy (push) Has been cancelled
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.6...1.43.11)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.11
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 05:06:43 +00:00
dependabot[bot]
510b686cfe
Update boto3 requirement from >=1.43.6 to >=1.43.11 in /src/shared (#73)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.6...1.43.11)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.11
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 05:06:33 +00:00
dependabot[bot]
d702960140
Update boto3 requirement from >=1.43.6 to >=1.43.11 in /src/roster-sync (#72)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.6...1.43.11)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.11
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 05:05:59 +00:00
dependabot[bot]
f8394a2666
Update requests requirement in /src/ring-scheduler (#70)
Updates the requirements on [requests](https://github.com/psf/requests) to permit the latest version.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.34.0...v2.34.2)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.34.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 05:05:50 +00:00
dependabot[bot]
9abf5890fb
Update slack-sdk requirement in /src/weekly-post (#76)
Updates the requirements on [slack-sdk](https://github.com/slackapi/python-slack-sdk) to permit the latest version.
- [Release notes](https://github.com/slackapi/python-slack-sdk/releases)
- [Commits](https://github.com/slackapi/python-slack-sdk/compare/v3.41.0...v3.42.0)

---
updated-dependencies:
- dependency-name: slack-sdk
  dependency-version: 3.42.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 05:04:08 +00:00
dependabot[bot]
c6cebec242
Update boto3 requirement from >=1.43.6 to >=1.43.11 in /src/slack-bot (#75)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.6...1.43.11)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.11
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 05:04:04 +00:00
dependabot[bot]
d70f207341
Update requests requirement from >=2.34.0 to >=2.34.2 in /src/shared (#74)
Updates the requirements on [requests](https://github.com/psf/requests) to permit the latest version.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.34.0...v2.34.2)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.34.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 05:03:44 +00:00
dependabot[bot]
8c8d35ad68
Update requests requirement in /src/roster-sync (#71)
Updates the requirements on [requests](https://github.com/psf/requests) to permit the latest version.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.34.0...v2.34.2)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.34.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 05:03:12 +00:00
dependabot[bot]
e31c31d477
Update boto3 requirement in /src/ring-scheduler (#69)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.6...1.43.11)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.11
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 05:03:02 +00:00
Adam Moussa
fc077e76a4
Fix shared layer packaging that broke all Lambdas (#67)
Some checks failed
Deploy / deploy (push) Has been cancelled
* Fix shared layer packaging — remove python/ wrapper that caused double nesting

SAM BuildMethod: python3.12 wraps layer content in python/ during build.
The source had an extra python/ directory, resulting in the shared package
landing at python/python/shared/ instead of python/shared/. All 4 Lambdas
are failing with ImportModuleError since the PR #62 merge.

* Update CI source-dirs to match new shared layer path
2026-05-13 14:14:21 -04:00