Commit graph

7 commits

Author SHA1 Message Date
Adam Moussa
c611fd5d2b
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#268)
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
* feat(infra): export vpc_id and public subnet outputs (DEV-289)

Portal Fargate and meals already attach to this VPC. These outputs are
the HCP existing_vpc_id / existing_public_subnet_ids values.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289)

Same extends: recommended ruleset and @redocly/cli 2.52.1 as
internal-portal. Covers health, roster, and portal /api/shifts.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(api): document 4xx and treat 302 as success in Redocly (DEV-289)

Health and CORS preflight document 400. Recommended only counted 2XX,
so login-style 302s use a shared 2XX-or-3XX rule.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289)

Promote operation-4xx-response and the 2xx-or-3xx success rule to error.
Drop unused 400s on health and CORS OPTIONS. Health documents 403 like the
portal. CORS stays in Flask and is not part of the employee contract.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:34:15 +00:00
Adam Moussa
13350b72d0
feat(infra): migrate afterhours to HCP Terraform (PLAT-74) (#252)
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* fix(cutover): write Slack secrets into empty Terraform shells

DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset.

* feat(infra): migrate afterhours to HCP Terraform (PLAT-74)

Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main.

* fix(cutover): retry DDB unprocessed items and skip past at() holidays

Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.
2026-09-15 23:31:59 +00:00
Adam Moussa
e769260598
chore: batch Dependabot boto3 bumps (#176, #177, #178, #179, #180, #181, #182) (#183)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Update boto3 requirement in /src/holiday-router

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement in /src/release-notifier

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement in /src/ring-scheduler

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/roster-sync

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/shared

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/slack-bot

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/weekly-post

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: gitignore .idea/

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 13:08:01 -04:00
Adam Moussa
3a26343cb7
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI

Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.

- Lift slack-bot handlers out of create_app() closures to module level so
  they're unit-testable; create_app is now a thin Bolt-wiring layer. No
  behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
  ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
  admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
  responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
  per-package conftest loads each app.py under a unique name to avoid the
  four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
  the tests dir too.
- README Testing section.

Closes #85

* Add least-privilege permissions block to CI workflow

Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).

* Stop logging extension numbers in 3CX queue updates

Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
Adam Moussa
6d6130c1a6
Add CodePipeline CI/CD, remove Git sync config (#36) (#36)
- Added reusable pipeline.yaml (CodePipeline + CodeBuild + CloudFormation deploy)
- Added buildspec.yml for SAM build/package
- Removed deployment-config.yaml and untracked samconfig.toml (Git sync artifacts)
- Restored samconfig.toml to .gitignore
2026-05-01 16:18:56 -04:00
Adam Moussa
0f37558487
Track samconfig.toml for CloudFormation Git sync deployments (#33) 2026-05-01 15:54:30 -04:00
Adam Moussa
4d0cdb5cfb Initial commit: after-hours shift manager Slack bot
Slack Bolt app on Lambda for managing on-call shifts. Employees can
pick up, drop, and swap shifts via /oncall commands. Changes update
3CX ring group 800 routing in real time for same-day shifts.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-03 18:32:32 -04:00