Commit graph

163 commits

Author SHA1 Message Date
dependabot[bot]
cd5de7bec5
chore(deps): bump aws-actions/configure-aws-credentials (#185)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Bumps the minor-and-patch group with 1 update in the / directory: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials).


Updates `aws-actions/configure-aws-credentials` from 6.2.2 to 6.2.3
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](517a711dbc...e6de054238)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 22:19:28 +00:00
Adam Moussa
f4712e0bcf
ci(deps): pin org reusable workflows to v1.0.2 (#190)
* ci(deps): pin org reusable workflows to v1.0.2

* style(ci): normalize workflow block spacing
2026-07-28 18:15:29 -04:00
Adam Moussa
f996f9600b
fix: resolve code-scanning alerts 11-15 (workflow permissions + log taint) (#184)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* ci(dependency-review): set explicit read-only GITHUB_TOKEN permissions

Resolves code-scanning alert 11 (actions/missing-workflow-permissions).
The callable workflow only needs contents: read.

* fix(logging): remove taint-flagged values from 3CX and roster-sync logs

Resolves code-scanning alerts 12-15 (py/clear-text-logging-sensitive-data).
CodeQL taints the 3CX response dicts via the Secrets Manager-sourced
domain in the request URL, so entity IDs subscripted from those
responses (ivr_id, resource_id, queue_id) and the roster result dict
trip the query. None of the flagged values are secrets, but the log
lines are rewritten so the pattern cannot trip: entity IDs are dropped
in favor of the untainted destination DNs, and the roster summary logs
counts instead of the member-derived dict (which also keeps employee
names out of the logs).

* fix: update ci workflow SHA to latest version

* fix(logging): drop employee-derived DNs from forwarding log

Resolves new code-scanning alerts 16/17. The closed/holiday DNs added
in the previous commit derive from roster employee lookups in the
Slack bot, so CodeQL classifies them as private data. Log only the
resource type; ring_scheduler already logs the queue number.
2026-07-27 13:48:14 -04:00
dependabot[bot]
fafefae500
Bump actions/setup-python from 6 to 7 (#175)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 19:31:01 -04:00
Adam Moussa
e769260598
chore: batch Dependabot boto3 bumps (#176, #177, #178, #179, #180, #181, #182) (#183)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Update boto3 requirement in /src/holiday-router

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement in /src/release-notifier

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement in /src/ring-scheduler

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/roster-sync

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/shared

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/slack-bot

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.48 to >=1.43.53 in /src/weekly-post

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.48...1.43.53)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.53
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: gitignore .idea/

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 13:08:01 -04:00
dependabot[bot]
e3031c879b
Update boto3 requirement from >=1.43.43 to >=1.43.48 in /src/shared (#172)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.48)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.48
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 17:02:10 +00:00
dependabot[bot]
526c421455
Update boto3 requirement from >=1.43.43 to >=1.43.48 in /src/roster-sync (#171)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.48)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.48
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 16:57:25 +00:00
dependabot[bot]
2eefd46410
Update boto3 requirement in /src/release-notifier (#169)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.48)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.48
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 16:52:52 +00:00
dependabot[bot]
690d5fd73c
Update boto3 requirement from >=1.43.43 to >=1.43.48 in /src/slack-bot (#173)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.48)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.48
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 16:48:45 +00:00
dependabot[bot]
47930e6b74
Update boto3 requirement in /src/ring-scheduler (#170)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.48)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.48
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 16:43:58 +00:00
dependabot[bot]
08cf28933f
Update boto3 requirement from >=1.43.43 to >=1.43.48 in /src/weekly-post (#174)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.48)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.48
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 23:51:45 +00:00
dependabot[bot]
fce0fb2bf7
Update boto3 requirement in /src/holiday-router (#168)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.48)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.48
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 19:47:51 -04:00
seahaven-openswe[bot]
2202cde9ed
fix: delete+repost schedule on weekly rollover for bottom placement (#167)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* fix: delete+repost schedule on weekly rollover for bottom placement

The Monday rollover was chat_update-ing in place, which only refreshes
content without moving the message to the bottom. Now it chat_deletes
the old post and chat_postMessages a fresh one so the schedule lands
at the bottom every Monday, independent of in-week activity.

Also added info-level logging to the bump handler silent return paths
so skipped bumps are observable at runtime.

* fix: roll back weekly repost when its ts can't be persisted

The Monday rollover deletes the old post then reposts a fresh one, but only
saved the new ts as its last step. If the save failed (or the Lambda died)
after the post landed, the async retry would read the stale, already-deleted
ts, no-op its delete, and post a second schedule — orphaning the first at the
bottom of the channel.

Wrap the save so a failure after a successful repost best-effort deletes the
fresh message before re-raising, letting the retry start clean. Mirrors the
orphan-avoidance the activity bump already has.

---------

Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-10 16:36:47 -04:00
seahaven-openswe[bot]
7a8133fea3
fix: prepend "Boo, " to shift-drop Slack channel notification (#166)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
2026-07-10 18:09:56 +00:00
dependabot[bot]
97c9cf1173
Update boto3 requirement from >=1.43.42 to >=1.43.43 in /src/shared (#165)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.42...1.43.43)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.43
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 21:55:36 +00:00
dependabot[bot]
51eb2ae0a8
Update boto3 requirement from >=1.43.42 to >=1.43.43 in /src/roster-sync (#164)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.42...1.43.43)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.43
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 21:53:05 +00:00
dependabot[bot]
0ca4ffeec2
Update slack-sdk requirement in /src/release-notifier (#163)
Updates the requirements on [slack-sdk](https://github.com/slackapi/python-slack-sdk) to permit the latest version.
- [Release notes](https://github.com/slackapi/python-slack-sdk/releases)
- [Commits](https://github.com/slackapi/python-slack-sdk/compare/v3.42.0...v3.43.0)

---
updated-dependencies:
- dependency-name: slack-sdk
  dependency-version: 3.43.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 17:50:48 -04:00
dependabot[bot]
f6c6bd8f5e
Update boto3 requirement in /src/release-notifier (#162)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.27...1.43.43)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.43
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 21:16:42 +00:00
dependabot[bot]
adc1436f8c
Update boto3 requirement in /src/holiday-router (#161)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.27...1.43.43)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.43
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 17:12:49 -04:00
Adam Moussa
3f6ac9654a
ci: expand dependabot coverage (INFRA-130) (#160)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
2026-07-08 16:53:42 -04:00
dependabot[bot]
3741a0c107
Update boto3 requirement from >=1.43.38 to >=1.43.42 in /src/roster-sync (#155)
* Update boto3 requirement from >=1.43.38 to >=1.43.42 in /src/roster-sync

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.38...1.43.42)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.42
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update boto3 requirement from >=1.43.38 to >=1.43.42 in /src/shared (#156)

* Update boto3 requirement from >=1.43.39 to >=1.43.43 in /src/slack-bot (#157)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
2026-07-08 20:30:32 +00:00
dependabot[bot]
c6b5b0c76b
Update boto3 requirement in /src/ring-scheduler (#154) 2026-07-08 16:23:16 -04:00
dependabot[bot]
e396530227
Bump aws-actions/configure-aws-credentials in the minor-and-patch group (#153)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
2026-07-08 02:31:42 -04:00
Adam Moussa
e19a70b5df
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#152)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
2026-07-06 18:26:46 -04:00
Adam Moussa
48a61cad66
chore(ci): SHA-pin mutable-tag third-party actions (INFRA-118) (#151) 2026-07-06 18:26:18 -04:00
Adam Moussa
14f2bc2cd5
docs: link Confluence AWS Architecture Map (INFRA-53) (#150)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
2026-07-06 17:43:58 -04:00
seahaven-openswe[bot]
73b295e5eb
[#136] Add Slack admin modals + App Home admin section (#141)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* Add Slack admin modals + App Home admin section

Replace the two most error-prone positional admin commands with Block Kit
modals (override and holiday-add) opened from a new App Home admin section,
while keeping the typed subcommands as a fallback. Validation and side
effects are factored into shared helpers so the modal and command paths
can't drift, and every action/view handler re-checks is_admin against
get_admin_users() so a modal opened from Home can't bypass authorization.
Adds Schedule.list_overrides for the upcoming-overrides overview.

Refs: #136

* Update changelog date to July 02, 2026

* Add point-and-click admin actions in Slack for easier overrides and holidays

* [#136] Add admin UI evaluation spike doc (#140)

Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-07-02 16:29:42 -04:00
dependabot[bot]
11afaf1f1f
Update boto3 requirement from >=1.43.36 to >=1.43.39 in /src/slack-bot (#148)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.39)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-02 15:29:18 -04:00
dependabot[bot]
bc7fba40dd
Update boto3 requirement from >=1.43.36 to >=1.43.38 in /src/shared (#146)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.38)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-01 01:06:00 +00:00
dependabot[bot]
61a7ba8ca4
Update boto3 requirement from >=1.43.36 to >=1.43.38 in /src/roster-sync (#145)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.38)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-01 01:01:52 +00:00
dependabot[bot]
9a9c776da3
Update boto3 requirement from >=1.43.36 to >=1.43.38 in /src/weekly-post (#149)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.38)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 23:53:36 +00:00
dependabot[bot]
e57560b87c
Update slack-bolt requirement in /src/slack-bot (#147)
Updates the requirements on [slack-bolt](https://github.com/slackapi/bolt-python) to permit the latest version.
- [Release notes](https://github.com/slackapi/bolt-python/releases)
- [Commits](https://github.com/slackapi/bolt-python/compare/v1.28.0...v1.29.0)

---
updated-dependencies:
- dependency-name: slack-bolt
  dependency-version: 1.29.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 23:49:32 +00:00
dependabot[bot]
c0b2a41e34
Update boto3 requirement in /src/ring-scheduler (#144)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.36...1.43.38)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.38
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 19:45:36 -04:00
Adam Moussa
f7c44778b5
[#142] Fix payroll email: SES domain identity + send-as pin + failure alarm (#143)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
The weekly-post pay-summary email to payroll failed with SES AccessDenied
every Monday since v1.10.1: the role granted ses:SendEmail on
identity/noreply@seahaven.com, but that address is not a verified SES
identity — it is covered by the verified domain identity seahaven.com,
which is what SES authorizes against. Grant the domain ARN instead.

Pin the grant with a ses:FromAddress condition (= noreply@seahaven.com,
the existing SES_SENDER) so the domain-wide identity can't be used to
send-as any other @seahaven.com mailbox (BEC blast radius). Surfaced by
/sh-security-review; matches the existing single-sender intent.

Add a CloudWatch metric-filter alarm on the swallowed "Failed to send
pay summary" log line -> site-alerts. The email send is wrapped in
try/except so a delivery failure never increments the Lambda Errors
metric; this is the only signal that surfaces a silent payroll failure.

Closes #142
2026-06-29 15:10:02 -04:00
seahaven-openswe[bot]
254f6b989f
[#135] Stick weekly schedule post to bottom of channel (#139)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
2026-06-27 15:45:01 -04:00
seahaven-openswe[bot]
b8ab4d6b77
[#134] Clarify dropping a shift and differentiate night rows (#138)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Expand /oncall date parser to accept more formats

Users entering everyday forms like 7/3/26 hit a generic parse
failure because the parser only accepted four-digit years and a
bare m/d. Add two-digit-year and month-name (with optional
ordinal/year) formats, treating explicit-year inputs as fixed and
keeping the year-less roll-forward for bare m/d. Update the help
text and per-command parse hints to match.

Refs: #133

* Let drop pick a shift and flag night rows

Drop now accepts an optional [day|night|holiday] qualifier and, when a
date carries more than one shift the user holds, asks which to drop
instead of silently releasing the holiday or weekend day shift. The
static post also tags day/night rows with distinct glyphs and labels on
weekdays, so the after-hours row is unmistakable.

Refs: #134

* Refine night-row labeling and drop notifications

Weekday rows are night-only, so the moon glyph alone marks the
after-hours shift; the verbose time-range label is kept only on
weekend rows where day and night shifts coexist. Channel shift-change
notifications now label the shift on every day for parity. Thread the
caller's user_id through the regular-drop path instead of re-reading it
off the employee record, and document the user-facing changes.

Refs: #134

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-06-26 15:19:22 -04:00
seahaven-openswe[bot]
eb78a98de0
[#133] Expand /oncall date parser to accept more formats (#137)
* Expand /oncall date parser to accept more formats

Users entering everyday forms like 7/3/26 hit a generic parse
failure because the parser only accepted four-digit years and a
bare m/d. Add two-digit-year and month-name (with optional
ordinal/year) formats, treating explicit-year inputs as fixed and
keeping the year-less roll-forward for bare m/d. Update the help
text and per-command parse hints to match.

Refs: #133

* Add dash 4-digit year format and pin year boundary

Dash inputs like 7-3-2026 previously returned None because only the
slash variant had a 4-digit-year format. Add %m-%d-%Y so dash and slash
behave alike, and pin the two-digit-year century boundary with a test.

Refs: #133

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-06-26 15:07:02 -04:00
dependabot[bot]
b304121cff
Bump actions/checkout from 6 to 7 (#127)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-26 12:32:32 -04:00
dependabot[bot]
c5f17c77dc
Update boto3 requirement from >=1.43.31 to >=1.43.36 in /src/weekly-post (#132)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 00:53:03 +00:00
dependabot[bot]
8c2418b675
Update boto3 requirement from >=1.43.31 to >=1.43.36 in /src/slack-bot (#131)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 00:49:22 +00:00
dependabot[bot]
9be3754b31
Update boto3 requirement from >=1.43.31 to >=1.43.36 in /src/shared (#130)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 00:45:49 +00:00
dependabot[bot]
57c2f3f258
Update boto3 requirement from >=1.43.31 to >=1.43.36 in /src/roster-sync (#129)
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-23 20:42:18 -04:00
dependabot[bot]
b4a7624060
Update boto3 requirement in /src/ring-scheduler (#128)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.31...1.43.36)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.36
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-23 20:24:05 -04:00
Adam Moussa
bdff6bee30
INFRA-106: nightly-sweep security remediation (auth/race/IAM) (#125)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
* Fix auth and race-condition flaws in shift commands

Four confirmed findings from the 2026-06-17 security sweep:

- register_user let any Slack user overwrite an extension already
  bound to a different user (account takeover). Add a DynamoDB
  ConditionExpression so a write only succeeds when the extension is
  unclaimed or already this user's; raise ExtensionAlreadyRegistered
  otherwise and surface a clear Slack message.
- The `rate` subcommand was routed without the is_admin flag, so any
  user could set $0 pay rates. Gate _handle_rate on is_admin, matching
  the admin-command guard.
- `/oncall pick` used a plain put_item (TOCTOU): two concurrent picks
  both won. Use the atomic claim_open_shift conditional claim so the
  loser gets an "already picked up" message.
- swap-accept overwrote a shift independently claimed after the swap
  was initiated. Add reassign_if_held_by, a conditional write that only
  applies the swap while the override is still the requester's (or on
  the weekly fallback), and notify the accepter otherwise.

Add tests for the register-ownership guard and the rate admin guard.

Refs: INFRA

* Scope shift-manager Lambda IAM to least privilege

The nightly sweep flagged four over-broad permissions. Scope each to
only what the function actually reads (verified against source):

- WeeklyPost: secrets to slack-bot-token-* only (was the whole
  afterhours-shift-manager/* namespace); SES SendEmail to the single
  noreply@seahaven.com identity (was identity/*).
- RosterSync and RingScheduler: secrets to 3cx-* only (was the whole
  namespace); both read only the 3cx domain/client-id/client-secret.

SlackBotFunction and HolidayRouter wildcards are left unchanged — out
of scope for this sweep.

Refs: INFRA

* fix: re-validate shift holder on swap-accept (sh-security-review RIHB-1)

reassign_if_held_by trusted 'no override row' as 'still the requester's',
but a weekly-held shift also has no override row. An admin clear or weekly
edit between swap-init and accept could move the shift to a third party
with no override, letting the accept steal it (CWE-367, confirmed HIGH).
Re-resolve the current holder at accept and abort if it is no longer the
requester. Adds regression test + seeds the holder in existing accept tests.

* fix: complete IAM least-privilege sweep (sh-security-review)

HolidayRouter secrets scope afterhours-shift-manager/* -> /3cx-* (reads
only 3cx secrets); RingScheduler DynamoDBCrudPolicy -> DynamoDBReadPolicy
(read-only at runtime). SlackBot wildcard left as-is (reads across all
sub-prefixes; verified defensible).
2026-06-18 12:05:25 -04:00
Adam Moussa
90c10d38d3
Add CloudWatch alarm coverage for all functions, table, and HTTP API (#126)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Add CloudWatch alarm coverage for all functions, table, and HTTP API

Extend the in-template Lambda-<Metric>-<fn> alarm convention to full coverage:

- Errors (Sum, >=1/5min) for roster-sync and release-notifier, plus orphan
  adoption of slack-bot and weekly-post (live alarms of those exact names
  already exist outside the stack and must be deleted before deploy).
- Duration (Maximum, ~80% of timeout, 2-of-3) for all six functions.
- Throttles (Sum, >=1/5min) for all six functions.
- DynamoDB ThrottledRequests (Sum, >=1/5min) on afterhours-shifts. SystemErrors
  omitted: AWS emits it only per-Operation, so a TableName-only alarm would sit
  permanently in INSUFFICIENT_DATA.
- API Gateway v2 4xx (>=5), 5xx (>=1), and p99 Latency (~3000ms, 2-of-3) on the
  implicit ServerlessHttpApi.

All alarms page the shared site-alerts SNS topic, no OKActions,
TreatMissingData notBreaching. README updated with a Monitoring & Alarms section.

Duration and API latency thresholds pending sign-off.

* Fix DynamoDB throttle alarm metric: use Read/WriteThrottleEvents

ThrottledRequests is not emitted at the TableName-only dimension (only
TableName+Operation), so the table-level alarm would sit permanently in
INSUFFICIENT_DATA and never fire. Replace with ReadThrottleEvents and
WriteThrottleEvents, which AWS/DynamoDB emits at the TableName dimension.

* Correct DynamoDB alarm docs and drop sign-off wording

README DynamoDB section now lists the alarms actually shipped
(DDB-ReadThrottle / DDB-WriteThrottle on Read/WriteThrottleEvents) instead
of the stale ThrottledRequests alarm. Thresholds are owner-approved, so
remove PENDING ADAM SIGN-OFF wording from template.yaml comments.
2026-06-17 14:45:47 -04:00
Adam Moussa
06bcb9b1b7
Add CloudWatch error alarm for afterhours-ring-scheduler (#123)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
The live afterhours-ring-scheduler Lambda had no error alarm. Add a
CloudWatch Errors alarm mirroring the existing HolidayRouterErrorAlarm:
AWS/Lambda Errors, Sum over one 5-min period, threshold >=1, missing
data notBreaching, paging the site-alerts SNS topic.

The orphaned Lambda-Errors-3cx-ring-group-scheduler alarm (pointing at
a renamed/absent function) is being removed separately.
2026-06-17 12:08:04 -04:00
Adam Moussa
54b585776b
Fix holiday router 3CX IVR calls (Receptionists entity, not IVRs) (#124)
get_ivr/set_ivr_routes/extract_ivr_routes targeted a nonexistent IVRs entity
set with an Options[].Route/TimeoutForward shape. The live 3CX IVR is the
Receptionists entity: the no-input/timeout route is the scalar TimeoutForwardDN,
and the key-0 route is a child of the Forwards collection (matched by Input=='0'),
written via a parent deep-PATCH. Routes are now destination numbers. Caught by the
live prod round-trip (get_ivr returned 405) before any holiday ran; rewritten and
re-verified against the live PBX. v1.11.1.
2026-06-17 12:04:10 -04:00
Adam Moussa
88e782c205
Add holiday shifts with 3CX routing and late-pickup approval (#121)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Holiday day-shifts (08:00-17:00 ET) with N slots and 1.5x pay. A new
afterhours-holiday-router Lambda, fired by per-holiday EventBridge Scheduler
one-offs, repoints IVR 800 (key-0 + no-input/timeout) to holiday queue 802 and
sets 802's membership to the day's assignees (ext 100 fallback when unfilled),
reverting at 17:00. Pickups after a shift starts go through an admin Approve/Deny
flow for both regular and holiday shifts. Pay (weekly post + /oncall pay) shows
holiday rates distinctly.

Adds HOLIDAY and PICKUP_REQUEST DynamoDB record types, scheduler IAM scoped to
holiday-* schedules with conditioned PassRole, and the holiday-router function
with a 60-day log group and error alarm.
2026-06-17 11:14:29 -04:00
dependabot[bot]
9353b9222b
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/weekly-post (#120)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
2026-06-17 01:06:19 +00:00
dependabot[bot]
36232f4ae4
Update boto3 requirement from >=1.43.27 to >=1.43.31 in /src/slack-bot (#119) 2026-06-17 01:04:12 +00:00