Commit graph

45 commits

Author SHA1 Message Date
Adam Moussa
470e00affb
feat(schedule): align the work week with Sunday-Saturday payroll (DEV-300) (#282)
Some checks are pending
Deploy API / Deploy API to dev (push) Waiting to run
Deploy API / Deploy API to prod (push) Waiting to run
* feat(schedule): align the work week with Sunday-Saturday payroll

Saturday night stays in the week that ends Saturday, and the first Flex close skips dates already sent.

* fix(slack-bot): show the last pay close on Sunday

The Monday 7am row for the week that just ended is not written yet, so /oncall pay now falls back to the prior close.
2026-09-25 17:56:46 +00:00
renovate[bot]
b3fa705d8c
chore(deps): update dependency boto3 to >=1.43.99 (#278)
Some checks are pending
Deploy API / Deploy API to dev (push) Waiting to run
Deploy API / Deploy API to prod (push) Waiting to run
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-24 23:29:34 +00:00
renovate[bot]
682f272c5a
chore(deps): update dependency boto3 to >=1.43.98 (#270)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-22 14:24:13 +00:00
Adam Moussa
26adb8e6c0
feat(api): collapse Slack, portal, and jobs onto Fargate (PLAT-216) (#259)
* feat(api): collapse Slack, portal, and jobs onto Fargate (PLAT-216)

Move HTTP and scheduled work onto one always-on Flask task so after-hours
loses Lambda cold start without changing the Cognito or roster contracts.

* fix(portal-api): keep CORS headers on unexpected 500s

Portal SPA error handling needs Access-Control-Allow-Origin even when
DynamoDB or other internals fail, otherwise the browser hides the 500.

* fix(api): retarget holidays per account and ship App Home changelog (PLAT-216)

* fix(iam): list ECS tasks and fail closed on non-prod Paychex (PLAT-216)

* fix(portal-api): serve portal JSON with an explicit JSON content type
2026-09-21 19:13:30 +00:00
Adam Moussa
969ebf90de
feat(portal-api): add Cognito shift API for the employee portal (DEV-287) (#255)
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* feat(portal-api): add Cognito shift API for the employee portal (DEV-287)

Employees and admins can pick, drop, swap, and manage coverage through
GET/POST/DELETE /api/shifts. Roster PUT accepts optional email for portal
identity. Slack slash commands and App Home admin modals stay in place.

Co-authored-by: adam <adam@seahavenind.com>

* fix(portal-api): preserve shift and deployment invariants (DEV-287)

Co-authored-by: adam <adam@seahavenind.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-09-21 17:50:57 +00:00
renovate[bot]
f1695cadfa
chore(deps): update pip minor and patch (#256)
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 15:42:56 +00:00
renovate[bot]
b53d856a75
chore(deps): update pip minor and patch (#251)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 16:38:24 +00:00
Adam Moussa
9544dd696a
fix(slack-bot): return 400 on malformed request bodies (#254)
Bolt parse_body raises JSONDecodeError for empty or non-JSON form
payload fields, which turned probe POSTs into unhandled Lambda 500s.

Fixes AFTERHOURS-SHIFT-MANAGER-2
2026-09-16 16:37:54 +00:00
renovate[bot]
37f12421fd
chore(deps): update pip minor and patch (#246)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-09 18:40:59 +00:00
Adam Moussa
4ffa09bd3e
feat(pay): send after-hours lines to paychex checkcomponents (PLAT-154) (#244)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* feat(pay): send after-hours lines to paychex checkcomponents (PLAT-154)

* style(pay): drop trailing blank line in weekly post tests

* fix(pay): skip duplicate checkcomponents send on weekly-post retry
2026-09-03 22:12:55 +00:00
renovate[bot]
42921aa2ba
chore(deps): update pip minor and patch (#243)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-31 16:06:56 +00:00
Adam Moussa
6eb2e52a74
feat(observability): add Sentry error reporting to Lambdas (#241)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
Unhandled errors and timeout warnings go to Sentry when SENTRY_DSN is set; Slack and 3CX secrets are stripped before send.
2026-08-29 20:52:28 +00:00
renovate[bot]
b30828b701
chore(deps): update dependency boto3 to >=1.43.78 (#238)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
2026-08-24 21:54:44 +00:00
dependabot[bot]
dc96388fa6
chore(deps): update boto3 requirement in /src/slack-bot (#231)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
2026-08-19 03:56:51 +00:00
dependabot[bot]
7f5b85c774
chore(deps): update boto3 requirement in /src/slack-bot (#223)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.62...1.43.67)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.67
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-11 23:56:50 +00:00
Adam Moussa
c28c63f06e
chore(deps): batch bumps for slack-bolt and test deps (DEV-27) (#216)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* chore(deps): update slack-bolt requirement in /src/slack-bot

Updates the requirements on [slack-bolt](https://github.com/slackapi/bolt-python) to permit the latest version.
- [Release notes](https://github.com/slackapi/bolt-python/releases)
- [Commits](https://github.com/slackapi/bolt-python/compare/v1.29.0...v1.30.0)

---
updated-dependencies:
- dependency-name: slack-bolt
  dependency-version: 1.30.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update pytest requirement from >=8.0 to >=9.1.1 in /tests

Updates the requirements on [pytest](https://github.com/pytest-dev/pytest) to permit the latest version.
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/8.0.0...9.1.1)

---
updated-dependencies:
- dependency-name: pytest
  dependency-version: 9.1.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update freezegun requirement in /tests

Updates the requirements on [freezegun](https://github.com/spulec/freezegun) to permit the latest version.
- [Release notes](https://github.com/spulec/freezegun/releases)
- [Changelog](https://github.com/spulec/freezegun/blob/master/CHANGELOG)
- [Commits](https://github.com/spulec/freezegun/compare/1.5.0...1.5.5)

---
updated-dependencies:
- dependency-name: freezegun
  dependency-version: 1.5.5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update responses requirement in /tests

Updates the requirements on [responses](https://github.com/getsentry/responses) to permit the latest version.
- [Release notes](https://github.com/getsentry/responses/releases)
- [Changelog](https://github.com/getsentry/responses/blob/master/CHANGES)
- [Commits](https://github.com/getsentry/responses/compare/0.25.0...0.26.2)

---
updated-dependencies:
- dependency-name: responses
  dependency-version: 0.26.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update moto requirement from >=5.0 to >=5.2.2 in /tests

Updates the requirements on [moto](https://github.com/getmoto/moto) to permit the latest version.
- [Release notes](https://github.com/getmoto/moto/releases)
- [Changelog](https://github.com/getmoto/moto/blob/master/CHANGELOG.md)
- [Commits](https://github.com/getmoto/moto/compare/5.0.0...5.2.2)

---
updated-dependencies:
- dependency-name: moto
  dependency-version: 5.2.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 20:26:37 -04:00
Adam Moussa
4b6c15644f
chore(deps): batch boto3 bumps to >=1.43.62 (DEV-25) (#210)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* chore(deps): update boto3 requirement in /src/holiday-router

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.62
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update boto3 requirement in /src/release-notifier

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.62
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update boto3 requirement in /src/ring-scheduler

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.62
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update boto3 requirement in /src/roster-sync

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.62
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update boto3 requirement in /src/shared

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.62
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update boto3 requirement in /src/slack-bot

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.62
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update boto3 requirement in /src/weekly-post

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.58...1.43.62)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.62
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 14:24:23 -04:00
dependabot[bot]
091d667d9c
chore(deps): update boto3 requirement in /src/slack-bot (#197)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.53...1.43.58)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.58
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
2026-07-28 23:43:20 +00:00
Adam Moussa
e769260598
chore: batch Dependabot boto3 bumps (#176, #177, #178, #179, #180, #181, #182) (#183)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Update boto3 requirement in /src/holiday-router

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement in /src/release-notifier

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement in /src/ring-scheduler

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/roster-sync

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/shared

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/slack-bot

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/weekly-post

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: gitignore .idea/

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 13:08:01 -04:00
dependabot[bot]
690d5fd73c
Update boto3 requirement from >=1.43.43 to >=1.43.48 in /src/slack-bot (#173)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.48)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.48
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 16:48:45 +00:00
seahaven-openswe[bot]
2202cde9ed
fix: delete+repost schedule on weekly rollover for bottom placement (#167)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* fix: delete+repost schedule on weekly rollover for bottom placement

The Monday rollover was chat_update-ing in place, which only refreshes
content without moving the message to the bottom. Now it chat_deletes
the old post and chat_postMessages a fresh one so the schedule lands
at the bottom every Monday, independent of in-week activity.

Also added info-level logging to the bump handler silent return paths
so skipped bumps are observable at runtime.

* fix: roll back weekly repost when its ts can't be persisted

The Monday rollover deletes the old post then reposts a fresh one, but only
saved the new ts as its last step. If the save failed (or the Lambda died)
after the post landed, the async retry would read the stale, already-deleted
ts, no-op its delete, and post a second schedule — orphaning the first at the
bottom of the channel.

Wrap the save so a failure after a successful repost best-effort deletes the
fresh message before re-raising, letting the retry start clean. Mirrors the
orphan-avoidance the activity bump already has.

---------

Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-10 16:36:47 -04:00
dependabot[bot]
3741a0c107
Update boto3 requirement from >=1.43.38 to >=1.43.42 in /src/roster-sync (#155)
* Update boto3 requirement from >=1.43.38 to >=1.43.42 in /src/roster-sync

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.38...1.43.42)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.42
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.38 to >=1.43.42 in /src/shared (#156)

* Update boto3 requirement from >=1.43.39 to >=1.43.43 in /src/slack-bot (#157)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
2026-07-08 20:30:32 +00:00
seahaven-openswe[bot]
73b295e5eb
[#136] Add Slack admin modals + App Home admin section (#141)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* Add Slack admin modals + App Home admin section

Replace the two most error-prone positional admin commands with Block Kit
modals (override and holiday-add) opened from a new App Home admin section,
while keeping the typed subcommands as a fallback. Validation and side
effects are factored into shared helpers so the modal and command paths
can't drift, and every action/view handler re-checks is_admin against
get_admin_users() so a modal opened from Home can't bypass authorization.
Adds Schedule.list_overrides for the upcoming-overrides overview.

Refs: #136

* Update changelog date to July 02, 2026

* Add point-and-click admin actions in Slack for easier overrides and holidays

* [#136] Add admin UI evaluation spike doc (#140)

Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-07-02 16:29:42 -04:00
dependabot[bot]
11afaf1f1f
Update boto3 requirement from >=1.43.36 to >=1.43.39 in /src/slack-bot (#148)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.39)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-02 15:29:18 -04:00
dependabot[bot]
e57560b87c
Update slack-bolt requirement in /src/slack-bot (#147)
Updates the requirements on [slack-bolt](https://github.com/slackapi/bolt-python) to permit the latest version.
- [Release notes](https://github.com/slackapi/bolt-python/releases)
- [Commits](https://github.com/slackapi/bolt-python/compare/v1.28.0...v1.29.0)

---
updated-dependencies:
- dependency-name: slack-bolt
  dependency-version: 1.29.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 23:49:32 +00:00
Adam Moussa
f7c44778b5
[#142] Fix payroll email: SES domain identity + send-as pin + failure alarm (#143)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
The weekly-post pay-summary email to payroll failed with SES AccessDenied
every Monday since v1.10.1: the role granted ses:SendEmail on
identity/noreply@seahaven.com, but that address is not a verified SES
identity — it is covered by the verified domain identity seahaven.com,
which is what SES authorizes against. Grant the domain ARN instead.

Pin the grant with a ses:FromAddress condition (= noreply@seahaven.com,
the existing SES_SENDER) so the domain-wide identity can't be used to
send-as any other @seahaven.com mailbox (BEC blast radius). Surfaced by
/sh-security-review; matches the existing single-sender intent.

Add a CloudWatch metric-filter alarm on the swallowed "Failed to send
pay summary" log line -> site-alerts. The email send is wrapped in
try/except so a delivery failure never increments the Lambda Errors
metric; this is the only signal that surfaces a silent payroll failure.

Closes #142
2026-06-29 15:10:02 -04:00
seahaven-openswe[bot]
254f6b989f
[#135] Stick weekly schedule post to bottom of channel (#139)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
2026-06-27 15:45:01 -04:00
seahaven-openswe[bot]
b8ab4d6b77
[#134] Clarify dropping a shift and differentiate night rows (#138)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Expand /oncall date parser to accept more formats

Users entering everyday forms like 7/3/26 hit a generic parse
failure because the parser only accepted four-digit years and a
bare m/d. Add two-digit-year and month-name (with optional
ordinal/year) formats, treating explicit-year inputs as fixed and
keeping the year-less roll-forward for bare m/d. Update the help
text and per-command parse hints to match.

Refs: #133

* Let drop pick a shift and flag night rows

Drop now accepts an optional [day|night|holiday] qualifier and, when a
date carries more than one shift the user holds, asks which to drop
instead of silently releasing the holiday or weekend day shift. The
static post also tags day/night rows with distinct glyphs and labels on
weekdays, so the after-hours row is unmistakable.

Refs: #134

* Refine night-row labeling and drop notifications

Weekday rows are night-only, so the moon glyph alone marks the
after-hours shift; the verbose time-range label is kept only on
weekend rows where day and night shifts coexist. Channel shift-change
notifications now label the shift on every day for parity. Thread the
caller's user_id through the regular-drop path instead of re-reading it
off the employee record, and document the user-facing changes.

Refs: #134

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-06-26 15:19:22 -04:00
seahaven-openswe[bot]
eb78a98de0
[#133] Expand /oncall date parser to accept more formats (#137)
* Expand /oncall date parser to accept more formats

Users entering everyday forms like 7/3/26 hit a generic parse
failure because the parser only accepted four-digit years and a
bare m/d. Add two-digit-year and month-name (with optional
ordinal/year) formats, treating explicit-year inputs as fixed and
keeping the year-less roll-forward for bare m/d. Update the help
text and per-command parse hints to match.

Refs: #133

* Add dash 4-digit year format and pin year boundary

Dash inputs like 7-3-2026 previously returned None because only the
slash variant had a 4-digit-year format. Add %m-%d-%Y so dash and slash
behave alike, and pin the two-digit-year century boundary with a test.

Refs: #133

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-06-26 15:07:02 -04:00
dependabot[bot]
8c2418b675
Update boto3 requirement from >=1.43.31 to >=1.43.36 in /src/slack-bot (#131)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 00:49:22 +00:00
Adam Moussa
bdff6bee30
INFRA-106: nightly-sweep security remediation (auth/race/IAM) (#125)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* Fix auth and race-condition flaws in shift commands

Four confirmed findings from the 2026-06-17 security sweep:

- register_user let any Slack user overwrite an extension already
  bound to a different user (account takeover). Add a DynamoDB
  ConditionExpression so a write only succeeds when the extension is
  unclaimed or already this user's; raise ExtensionAlreadyRegistered
  otherwise and surface a clear Slack message.
- The `rate` subcommand was routed without the is_admin flag, so any
  user could set $0 pay rates. Gate _handle_rate on is_admin, matching
  the admin-command guard.
- `/oncall pick` used a plain put_item (TOCTOU): two concurrent picks
  both won. Use the atomic claim_open_shift conditional claim so the
  loser gets an "already picked up" message.
- swap-accept overwrote a shift independently claimed after the swap
  was initiated. Add reassign_if_held_by, a conditional write that only
  applies the swap while the override is still the requester's (or on
  the weekly fallback), and notify the accepter otherwise.

Add tests for the register-ownership guard and the rate admin guard.

Refs: INFRA

* Scope shift-manager Lambda IAM to least privilege

The nightly sweep flagged four over-broad permissions. Scope each to
only what the function actually reads (verified against source):

- WeeklyPost: secrets to slack-bot-token-* only (was the whole
  afterhours-shift-manager/* namespace); SES SendEmail to the single
  noreply@seahaven.com identity (was identity/*).
- RosterSync and RingScheduler: secrets to 3cx-* only (was the whole
  namespace); both read only the 3cx domain/client-id/client-secret.

SlackBotFunction and HolidayRouter wildcards are left unchanged — out
of scope for this sweep.

Refs: INFRA

* fix: re-validate shift holder on swap-accept (sh-security-review RIHB-1)

reassign_if_held_by trusted 'no override row' as 'still the requester's',
but a weekly-held shift also has no override row. An admin clear or weekly
edit between swap-init and accept could move the shift to a third party
with no override, letting the accept steal it (CWE-367, confirmed HIGH).
Re-resolve the current holder at accept and abort if it is no longer the
requester. Adds regression test + seeds the holder in existing accept tests.

* fix: complete IAM least-privilege sweep (sh-security-review)

HolidayRouter secrets scope afterhours-shift-manager/* -> /3cx-* (reads
only 3cx secrets); RingScheduler DynamoDBCrudPolicy -> DynamoDBReadPolicy
(read-only at runtime). SlackBot wildcard left as-is (reads across all
sub-prefixes; verified defensible).
2026-06-18 12:05:25 -04:00
Adam Moussa
54b585776b
Fix holiday router 3CX IVR calls (Receptionists entity, not IVRs) (#124)
get_ivr/set_ivr_routes/extract_ivr_routes targeted a nonexistent IVRs entity
set with an Options[].Route/TimeoutForward shape. The live 3CX IVR is the
Receptionists entity: the no-input/timeout route is the scalar TimeoutForwardDN,
and the key-0 route is a child of the Forwards collection (matched by Input=='0'),
written via a parent deep-PATCH. Routes are now destination numbers. Caught by the
live prod round-trip (get_ivr returned 405) before any holiday ran; rewritten and
re-verified against the live PBX. v1.11.1.
2026-06-17 12:04:10 -04:00
Adam Moussa
88e782c205
Add holiday shifts with 3CX routing and late-pickup approval (#121)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Holiday day-shifts (08:00-17:00 ET) with N slots and 1.5x pay. A new
afterhours-holiday-router Lambda, fired by per-holiday EventBridge Scheduler
one-offs, repoints IVR 800 (key-0 + no-input/timeout) to holiday queue 802 and
sets 802's membership to the day's assignees (ext 100 fallback when unfilled),
reverting at 17:00. Pickups after a shift starts go through an admin Approve/Deny
flow for both regular and holiday shifts. Pay (weekly post + /oncall pay) shows
holiday rates distinctly.

Adds HOLIDAY and PICKUP_REQUEST DynamoDB record types, scheduler IAM scoped to
holiday-* schedules with conditioned PassRole, and the holiday-router function
with a 60-day log group and error alarm.
2026-06-17 11:14:29 -04:00
dependabot[bot]
36232f4ae4
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/slack-bot (#119) 2026-06-17 01:04:12 +00:00
Adam Moussa
1e1e5176a3
Fix payroll summary email (SES config-set permission) + isolate failures (#114)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* Fix payroll email: grant SES config-set permission + isolate failures

The weekly pay-summary email to payroll has been failing with SES
AccessDenied since 2026-06-08. The sending identity (seahaven.com) gained
a default configuration set (seahaven-email-events), and SES authorizes
SendEmail against the config-set ARN as well as the identity — but the
WeeklyPostFunction role only granted ses:SendEmail on identity/*.

- template.yaml: add the configuration-set ARN (scoped to the known set
  name) to the SES policy so sends are authorized again.
- weekly-post/app.py: wrap _send_pay_email in try/except so a delivery
  failure can never abort the handler before the Slack schedule post.
  Previously the SES error also blocked the two-week schedule post.
- Add a regression test covering the isolation.

Cross-family GPT-4.1 IAM review: APPROVE.

* Bump to v1.10.1 in CHANGELOG and sync App Home copy
2026-06-15 13:24:32 -04:00
Adam Moussa
53c85f7eed
Add changelog-driven releases and App Home tab (#112)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Add changelog-driven releases and App Home tab

Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:

- A new afterhours-release-notifier Lambda posts a "What's New" message
  to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
  command list, and the current version's notes.

release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.

* Harden release workflow and regex against CodeQL findings

Address three code-scanning alerts on the PR:

- Critical (actions/untrusted-checkout): split release.yaml into a
  read-only `prepare` job that checks out and runs repo code, and a
  privileged `publish` job (contents:write + OIDC) that never checks out
  repo code — it tags, releases, and invokes purely through the GitHub
  and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
  markdown_to_mrkdwn with possessive quantifiers and exclusive character
  classes so they run in linear time on adversarial input. Adds a
  regression test.

* Move release/announce into Deploy workflow to clear CodeQL

The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.

Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00
dependabot[bot]
ef4fafb943
Update boto3 requirement from >=1.43.26 to >=1.43.27 in /src/slack-bot (#110)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.26...1.43.27)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.27
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:09 -04:00
dependabot[bot]
e007b10e81
Update boto3 requirement from >=1.43.22 to >=1.43.26 in /src/slack-bot (#103)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.22...1.43.26)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.26
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-10 18:12:02 -04:00
dependabot[bot]
fedecbf30c
Update boto3 requirement from >=1.43.19 to >=1.43.22 in /src/slack-bot (#95)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.19...1.43.22)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.22
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 01:00:12 +00:00
dependabot[bot]
fd17d71dcd
Update boto3 requirement from >=1.43.11 to >=1.43.19 in /src/slack-bot (#81)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.11...1.43.19)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.15
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-01 23:36:50 +00:00
Adam Moussa
7733af6af0
Lock shift drops within 24h of start (#84) (#88)
A user can no longer `/oncall drop` a shift inside the 24h window before it
starts — inside that window coverage must be handed off via a verified swap
(target accepts) or opened by an admin.

- app.py: _within_drop_lock(date, shift_type) (24h before _shift_start);
  guard in _handle_drop after the ownership check. Admin `open` is a separate
  handler and is unaffected (bypasses the lock).
- Removed the now-unreachable 3CX-repoint-on-drop branch: a same-day shift is
  always inside the lock, so a drop never reaches mark_open for today.
- Help text + README note the 24h rule.
- tests: rewritten test_handle_drop (outside/inside-24h per shift type,
  weekend day, admin bypass, plus the existing guard-precedence cases) and
  direct _shift_start/_shift_started/_within_drop_lock helper tests. 185 passed.

Closes #84
2026-06-01 19:32:40 -04:00
Adam Moussa
060bd0bf3e
Add swap-acceptance (verified-swap) flow (#87)
Some checks are pending
Deploy / deploy (push) Waiting to run
/oncall swap no longer reassigns immediately. It now writes a pending SWAP
record and DMs the target Accept/Decline buttons; the shift only moves once
they accept.

- schedule.py: create_pending_swap / get_swap / mark_swap_verified /
  clear_swap (PK=SWAP, date/shift SK mirroring OVERRIDE, status + timestamps
  + expires_at for TTL). A new request supersedes a prior pending one.
- app.py: _handle_swap creates the pending swap + DMs the target (requires the
  target be Slack-linked; rejects self-swap). New module-level
  handle_swap_accept / handle_swap_decline + two @app.action registrations.
  Accept writes the override, repoints 3CX when it's the active shift, marks
  the swap verified, notifies the channel + requester. Decline clears it and
  DMs the requester. Lazy expiry: accept is rejected once the shift has started
  (_shift_start/_shift_started).
- blocks.py: build_swap_request_blocks (Accept/Decline) + build_swap_resolved_blocks.
- template.yaml: enable DynamoDB TTL on expires_at so abandoned pending swaps
  self-clean.
- tests: swap schedule methods, swap blocks, rewritten test_handle_swap
  (pending + DM, no immediate override), new test_swap_accept_decline. 174 passed.
- README: swap behavior + SWAP item type + TTL.

The verified SWAP status is what #84 (24h drop guard) will query.

Closes #83
2026-06-01 19:22:55 -04:00
Adam Moussa
3a26343cb7
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI

Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.

- Lift slack-bot handlers out of create_app() closures to module level so
  they're unit-testable; create_app is now a thin Bolt-wiring layer. No
  behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
  ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
  admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
  responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
  per-package conftest loads each app.py under a unique name to avoid the
  four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
  the tests dir too.
- README Testing section.

Closes #85

* Add least-privilege permissions block to CI workflow

Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).

* Stop logging extension numbers in 3CX queue updates

Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
dependabot[bot]
c6cebec242
Update boto3 requirement from >=1.43.6 to >=1.43.11 in /src/slack-bot (#75)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.6...1.43.11)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.11
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 05:04:04 +00:00
Adam Moussa
5fc60b6979
Merge ring-scheduler-3cx and resolve all open issues (#62)
* Add arm64, log retention, and compliance fixes

- Set arm64 architecture globally for all Lambda functions
- Add explicit CloudWatch log groups with 60-day retention
- Add missing WeeklyPostFunctionArn to stack outputs
- Add Dependabot assignees for both ecosystems
- Add samconfig.toml.example for onboarding

* Restructure src/ to per-function layout with shared Layer

Move from flat src/ to per-function directories:
- src/slack-bot/ — Slack Bolt Lambda handler
- src/weekly-post/ — Monday schedule + pay post
- src/roster-sync/ — Daily 3CX roster sync
- src/shared/ — Lambda Layer with schedule, blocks, three_cx_client

Each function has its own requirements.txt and CodeUri. Shared
modules are deployed as a SAM Layer (afterhours-shared) importable
as `from shared.X import Y`.

* Migrate secrets from SSM Parameter Store to Secrets Manager

- Slack bot token and signing secret now read from Secrets Manager
- 3CX credentials (domain, client-id, client-secret) moved to
  Secrets Manager under afterhours-shift-manager/3cx-* prefix
- Channel ID is now a non-secret CloudFormation parameter (ShiftChannel)
- Add shared secrets.py helper for Secrets Manager reads
- Remove SSM and KMS IAM policies, add secretsmanager:GetSecretValue

* Merge ring-scheduler-3cx as 4th Lambda function

- Add afterhours-ring-scheduler Lambda with 4 EventBridge rules
  (daily 8am EST/EDT + weekend 5pm EST/EDT) for 3CX ring group
  routing updates
- Extract shared ring_scheduler.py module for direct ring group
  updates from both the scheduled Lambda and the Slack bot
- Replace cross-Lambda invoke with direct update_ring_group() call
  in the Slack bot — eliminates lambda:InvokeFunction dependency
- Use RingGroup API (correct) instead of Queue API (was wrong in
  the original ring-scheduler repo)
- Eliminate YAML config fallback — DynamoDB is the sole schedule
  source
- Add RingGroupNumber CloudFormation parameter

* Add schedule post live-update and old post deletion (#40, #41)

- Store schedule message timestamp in DynamoDB (SCHEDULE_POST record)
- Delete previous week's schedule post before posting the new one
- Live-update the schedule post via chat_update after any
  pick/drop/swap/button-pickup so it always reflects current state

* Disallow past shifts and add day/night labels (#43, #42)

- Reject /oncall pick and /oncall drop for past dates
- Show ephemeral error when stale pickup buttons are clicked
- Hide pickup buttons for dates in the past
- Add explicit "Day (8am-5pm)" and "Night (5pm-8am)" labels to
  schedule lines, pickup buttons, and shift change notifications

* Add admin slash commands for shift and roster management (#39)

- /oncall admin override <date> <ext> — assign a shift
- /oncall admin open <date> — mark shift as open
- /oncall admin clear <date> — remove override, revert to weekly
- /oncall admin roster add/remove/rename — manage roster entries
- Admin access gated by admin_users list in DynamoDB CONFIG
- Help message shows admin commands for admin users

* Update README for merged architecture and new features

* Switch from RingGroup API to Queue API at extension 801

The 3CX routing was changed from ring group 800 to queue 801 in a
previous PR on ring-scheduler-3cx. Updates all callers and the SAM
template parameter default accordingly.

* Pass SAM parameter overrides in deploy workflow

* Fix review findings: IAM, routing guards, past-date check, roster safety

- Ring scheduler: use DynamoDBCrudPolicy (resolve_shift needs Query)
- Button pickup: update 3CX for active shift type, not just night
- Pick/drop/swap commands: only update 3CX when shift type is active
- Swap command: add missing past-date guard
- add_roster_entry: reject if extension already exists
- Apply ruff formatting

* Add error handling to ring scheduler 3CX call

* Fix weekend day shift commands and admin 3CX routing

- Add _find_employee_shift() to check both day/night on weekends
- Drop/swap now correctly find and operate on weekend day shifts
- Pick finds first available shift type on weekends
- Admin override/open/clear update 3CX for same-day active shifts

* Fix dependabot directories and admin weekend shift handling

Dependabot now scans per-function requirement directories instead
of the repo root. Admin override/open/clear commands accept an
optional day/night parameter for weekend day shift management.

* Fix weekend day shift active window to 8am-5pm

Before midnight-8am on weekends incorrectly reported the day shift
as active when the previous night shift is still running.

* Show shift type label for both weekend shifts in notifications

Night shift notifications on weekends were missing the type label,
making them ambiguous. Also fix schedule post text fallback to use
this_monday instead of now for the start date.

* Extract determine_shift_type into shared layer

Eliminates duplicated weekend day/night boundary logic between
the ring scheduler and Slack bot Lambdas.

* Fix weekly schedule fallback start date

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* Include weekend shift type in command confirmations

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* Apply ruff formatting to app.py

* Only show day/night shift labels on weekends in schedule display

Weekday shifts are always night — the label was redundant clutter.

* Deduplicate 3CX forwarding payload and add shift type to pick command

Extract _update_forwarding helper in ThreeCXClient to share the
payload between queue and ring group methods. Add optional day/night
argument to /oncall pick so users can target a specific weekend shift.

* Consolidate WEEKEND_DAYS and fix weekday pickup button labels

Import WEEKEND_DAYS from shared.schedule instead of redefining in
blocks.py and weekly-post/app.py. Gate pickup button day/night
labels on weekends only, matching all other display surfaces.

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-05-12 19:55:39 -04:00