Commit graph

30 commits

Author SHA1 Message Date
Adam Moussa
f164efb383 ci(deps): pin org reusable workflows to v1.0.2 2026-07-28 17:57:34 -04:00
Adam Moussa
f996f9600b
fix: resolve code-scanning alerts 11-15 (workflow permissions + log taint) (#184)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* ci(dependency-review): set explicit read-only GITHUB_TOKEN permissions

Resolves code-scanning alert 11 (actions/missing-workflow-permissions).
The callable workflow only needs contents: read.

* fix(logging): remove taint-flagged values from 3CX and roster-sync logs

Resolves code-scanning alerts 12-15 (py/clear-text-logging-sensitive-data).
CodeQL taints the 3CX response dicts via the Secrets Manager-sourced
domain in the request URL, so entity IDs subscripted from those
responses (ivr_id, resource_id, queue_id) and the roster result dict
trip the query. None of the flagged values are secrets, but the log
lines are rewritten so the pattern cannot trip: entity IDs are dropped
in favor of the untainted destination DNs, and the roster summary logs
counts instead of the member-derived dict (which also keeps employee
names out of the logs).

* fix: update ci workflow SHA to latest version

* fix(logging): drop employee-derived DNs from forwarding log

Resolves new code-scanning alerts 16/17. The closed/holiday DNs added
in the previous commit derive from roster employee lookups in the
Slack bot, so CodeQL classifies them as private data. Log only the
resource type; ring_scheduler already logs the queue number.
2026-07-27 13:48:14 -04:00
dependabot[bot]
fafefae500
Bump actions/setup-python from 6 to 7 (#175)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 19:31:01 -04:00
dependabot[bot]
e396530227
Bump aws-actions/configure-aws-credentials in the minor-and-patch group (#153)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
2026-07-08 02:31:42 -04:00
Adam Moussa
e19a70b5df
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#152)
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
2026-07-06 18:26:46 -04:00
Adam Moussa
48a61cad66
chore(ci): SHA-pin mutable-tag third-party actions (INFRA-118) (#151) 2026-07-06 18:26:18 -04:00
dependabot[bot]
b304121cff
Bump actions/checkout from 6 to 7 (#127)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-26 12:32:32 -04:00
dependabot[bot]
3099046527
Bump actions/setup-python from 5 to 6 (#115) 2026-06-16 20:52:56 -04:00
Adam Moussa
53c85f7eed
Add changelog-driven releases and App Home tab (#112)
Some checks are pending
Deploy / deploy (push) Waiting to run
Deploy / release (push) Blocked by required conditions
* Add changelog-driven releases and App Home tab

Version the bot continuously from CHANGELOG.md (the single source of
truth for both the version and the staff-readable notes) and surface
changes to users in two ways:

- A new afterhours-release-notifier Lambda posts a "What's New" message
  to the shift channel on minor/major releases (patches stay silent).
- The bot gains an App Home "About" tab showing what it does, the
  command list, and the current version's notes.

release.yaml runs on Deploy success (not release:published — GITHUB_TOKEN
events don't start downstream workflows), checks out the deployed commit,
and tags + publishes a GitHub Release + invokes the notifier. It assumes a
dedicated, boundary-carrying OIDC role scoped to InvokeFunction on the
notifier; the account's cfn role gates role creation on that boundary.
The manual Version Bump workflow is retired. A CI guard enforces that a
CHANGELOG edit is a clean SemVer bump and that the in-package copy matches.

* Harden release workflow and regex against CodeQL findings

Address three code-scanning alerts on the PR:

- Critical (actions/untrusted-checkout): split release.yaml into a
  read-only `prepare` job that checks out and runs repo code, and a
  privileged `publish` job (contents:write + OIDC) that never checks out
  repo code — it tags, releases, and invokes purely through the GitHub
  and AWS APIs. Also assert head_branch == main.
- High x2 (py/polynomial-redos): rewrite the italic and link regexes in
  markdown_to_mrkdwn with possessive quantifiers and exclusive character
  classes so they run in linear time on adversarial input. Adds a
  regression test.

* Move release/announce into Deploy workflow to clear CodeQL

The workflow_run-triggered release.yaml kept tripping CodeQL's
privileged-context rules (untrusted-checkout, then cache-poisoning) —
CodeQL distrusts any workflow_run that checks out a ref, regardless of
the main-only guarantee, and there is no autofix.

Fold the release job into deploy.yaml gated on `needs: deploy`. A
push-to-main run is a trusted context, so checking out and running repo
code with write/OIDC is safe there. This still gates on deploy success
and serializes via the deploy concurrency group, and removes the
separate workflow entirely.
2026-06-11 19:41:31 -04:00
Adam Moussa
2995f6b3ea
Repo hygiene: PR labeler + README badges + dependabot (INFRA-56/57/66) (#106) 2026-06-11 14:13:35 -04:00
Adam Moussa
9bea3ed4c7
Add dependency-review caller workflow (#97)
Some checks are pending
Deploy / deploy (push) Waiting to run
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:26:41 -04:00
Adam Moussa
b2967946cc
Make version bump manual-only and remove Slack notification (#90)
We now apply semantic version tags deliberately (see v1.7.19–v1.9.2), so the
daily auto-bump is no longer wanted.

- Drop the `schedule:` cron (and the now-unneeded DST guard) — the workflow
  runs only on `workflow_dispatch`, with patch/minor/major options.
- Remove the Slack notification entirely: the "Update changelog canvas" and
  "Post to Slack" steps (and the PR/bullet collection that fed them) are gone,
  along with their SLACK_* secret usage.
- Keep the core behavior: compute the next version from the latest tag + chosen
  bump and push an annotated tag.

Renames the workflow "Daily Version Bump" -> "Version Bump".
2026-06-01 20:00:02 -04:00
Adam Moussa
3a26343cb7
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI

Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.

- Lift slack-bot handlers out of create_app() closures to module level so
  they're unit-testable; create_app is now a thin Bolt-wiring layer. No
  behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
  ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
  admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
  responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
  per-package conftest loads each app.py under a unique name to avoid the
  four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
  the tests dir too.
- README Testing section.

Closes #85

* Add least-privilege permissions block to CI workflow

Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).

* Stop logging extension numbers in 3CX queue updates

Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
Adam Moussa
fc077e76a4
Fix shared layer packaging that broke all Lambdas (#67)
Some checks failed
Deploy / deploy (push) Has been cancelled
* Fix shared layer packaging — remove python/ wrapper that caused double nesting

SAM BuildMethod: python3.12 wraps layer content in python/ during build.
The source had an extra python/ directory, resulting in the shared package
landing at python/python/shared/ instead of python/shared/. All 4 Lambdas
are failing with ImportModuleError since the PR #62 merge.

* Update CI source-dirs to match new shared layer path
2026-05-13 14:14:21 -04:00
Adam Moussa
5fc60b6979
Merge ring-scheduler-3cx and resolve all open issues (#62)
* Add arm64, log retention, and compliance fixes

- Set arm64 architecture globally for all Lambda functions
- Add explicit CloudWatch log groups with 60-day retention
- Add missing WeeklyPostFunctionArn to stack outputs
- Add Dependabot assignees for both ecosystems
- Add samconfig.toml.example for onboarding

* Restructure src/ to per-function layout with shared Layer

Move from flat src/ to per-function directories:
- src/slack-bot/ — Slack Bolt Lambda handler
- src/weekly-post/ — Monday schedule + pay post
- src/roster-sync/ — Daily 3CX roster sync
- src/shared/ — Lambda Layer with schedule, blocks, three_cx_client

Each function has its own requirements.txt and CodeUri. Shared
modules are deployed as a SAM Layer (afterhours-shared) importable
as `from shared.X import Y`.

* Migrate secrets from SSM Parameter Store to Secrets Manager

- Slack bot token and signing secret now read from Secrets Manager
- 3CX credentials (domain, client-id, client-secret) moved to
  Secrets Manager under afterhours-shift-manager/3cx-* prefix
- Channel ID is now a non-secret CloudFormation parameter (ShiftChannel)
- Add shared secrets.py helper for Secrets Manager reads
- Remove SSM and KMS IAM policies, add secretsmanager:GetSecretValue

* Merge ring-scheduler-3cx as 4th Lambda function

- Add afterhours-ring-scheduler Lambda with 4 EventBridge rules
  (daily 8am EST/EDT + weekend 5pm EST/EDT) for 3CX ring group
  routing updates
- Extract shared ring_scheduler.py module for direct ring group
  updates from both the scheduled Lambda and the Slack bot
- Replace cross-Lambda invoke with direct update_ring_group() call
  in the Slack bot — eliminates lambda:InvokeFunction dependency
- Use RingGroup API (correct) instead of Queue API (was wrong in
  the original ring-scheduler repo)
- Eliminate YAML config fallback — DynamoDB is the sole schedule
  source
- Add RingGroupNumber CloudFormation parameter

* Add schedule post live-update and old post deletion (#40, #41)

- Store schedule message timestamp in DynamoDB (SCHEDULE_POST record)
- Delete previous week's schedule post before posting the new one
- Live-update the schedule post via chat_update after any
  pick/drop/swap/button-pickup so it always reflects current state

* Disallow past shifts and add day/night labels (#43, #42)

- Reject /oncall pick and /oncall drop for past dates
- Show ephemeral error when stale pickup buttons are clicked
- Hide pickup buttons for dates in the past
- Add explicit "Day (8am-5pm)" and "Night (5pm-8am)" labels to
  schedule lines, pickup buttons, and shift change notifications

* Add admin slash commands for shift and roster management (#39)

- /oncall admin override <date> <ext> — assign a shift
- /oncall admin open <date> — mark shift as open
- /oncall admin clear <date> — remove override, revert to weekly
- /oncall admin roster add/remove/rename — manage roster entries
- Admin access gated by admin_users list in DynamoDB CONFIG
- Help message shows admin commands for admin users

* Update README for merged architecture and new features

* Switch from RingGroup API to Queue API at extension 801

The 3CX routing was changed from ring group 800 to queue 801 in a
previous PR on ring-scheduler-3cx. Updates all callers and the SAM
template parameter default accordingly.

* Pass SAM parameter overrides in deploy workflow

* Fix review findings: IAM, routing guards, past-date check, roster safety

- Ring scheduler: use DynamoDBCrudPolicy (resolve_shift needs Query)
- Button pickup: update 3CX for active shift type, not just night
- Pick/drop/swap commands: only update 3CX when shift type is active
- Swap command: add missing past-date guard
- add_roster_entry: reject if extension already exists
- Apply ruff formatting

* Add error handling to ring scheduler 3CX call

* Fix weekend day shift commands and admin 3CX routing

- Add _find_employee_shift() to check both day/night on weekends
- Drop/swap now correctly find and operate on weekend day shifts
- Pick finds first available shift type on weekends
- Admin override/open/clear update 3CX for same-day active shifts

* Fix dependabot directories and admin weekend shift handling

Dependabot now scans per-function requirement directories instead
of the repo root. Admin override/open/clear commands accept an
optional day/night parameter for weekend day shift management.

* Fix weekend day shift active window to 8am-5pm

Before midnight-8am on weekends incorrectly reported the day shift
as active when the previous night shift is still running.

* Show shift type label for both weekend shifts in notifications

Night shift notifications on weekends were missing the type label,
making them ambiguous. Also fix schedule post text fallback to use
this_monday instead of now for the start date.

* Extract determine_shift_type into shared layer

Eliminates duplicated weekend day/night boundary logic between
the ring scheduler and Slack bot Lambdas.

* Fix weekly schedule fallback start date

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* Include weekend shift type in command confirmations

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* Apply ruff formatting to app.py

* Only show day/night shift labels on weekends in schedule display

Weekday shifts are always night — the label was redundant clutter.

* Deduplicate 3CX forwarding payload and add shift type to pick command

Extract _update_forwarding helper in ThreeCXClient to share the
payload between queue and ring group methods. Add optional day/night
argument to /oncall pick so users can target a specific weekend shift.

* Consolidate WEEKEND_DAYS and fix weekday pickup button labels

Import WEEKEND_DAYS from shared.schedule instead of redefining in
blocks.py and weekly-post/app.py. Gate pickup button day/night
labels on weekends only, matching all other display surfaces.

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-05-12 19:55:39 -04:00
Adam Moussa
f26fe978b5
Disable Slack version notification (#55) (#60)
Dependabot PRs are merging frequently, causing daily version bump
posts to flood the channel. Disable the Slack post step until #55
is resolved.
2026-05-08 20:15:37 -04:00
Adam Moussa
b750f1aaee
Add GitHub Actions deploy workflow (#58)
* Add GitHub Actions deploy workflow (OIDC)

* Add permissions block for OIDC token exchange

* Add concurrency control to prevent parallel deploys
2026-05-08 17:07:49 -04:00
Adam Moussa
c741924ee7
Add CI workflow and apply ruff formatting (#57) 2026-05-08 15:46:51 -04:00
Adam Moussa
6ac4c0ed7e
Remove wrapper workflow — using required workflow via org ruleset (#53) 2026-05-06 19:59:12 -04:00
dependabot[bot]
f7ea5f1b1a
Bump actions/checkout from 4 to 6 (#45)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-06 18:44:19 -04:00
Adam Moussa
843cfd73b3
Add Claude Code review workflow (#52) 2026-05-06 18:11:30 -04:00
Adam Moussa
fbabab9692 Fix timezone mismatch in version bump PR filter and use dynamic canvas URL
The date comparison used git's author date in its stored timezone
(e.g. -04:00) against GitHub API mergedAt values in UTC (Z suffix).
Lexicographic string comparison across different timezone formats
caused every PR from the tagged commit's day to be re-included in
subsequent versions. Normalize to UTC with format-local so both
sides match.

Also replace the hardcoded canvas URL with the CANVAS_ID env var
already available in the step.
2026-05-04 15:26:36 -04:00
Adam Moussa
a85eb0afd9
Default to patch version bumps, add minor bump option (#30)
Scheduled runs auto-bump patch (v1.7.0 -> v1.7.1). Manual triggers
get a dropdown to choose patch or minor bump.
2026-05-01 15:06:04 -04:00
Adam Moussa
55697748cb
Use semver auto-increment for daily version bumps (#29)
Replaces date-based versions (v2026.05.01) with semver minor bumps
(v1.7.0 -> v1.8.0) to stay consistent with the project's existing
version history.
2026-05-01 15:00:51 -04:00
Adam Moussa
7116458efb
Fix printf flag parsing in version bump workflow (#28) 2026-05-01 14:53:47 -04:00
Adam Moussa
f92f2ed72e
Add pull-requests read permission to version bump workflow (#27) 2026-05-01 14:51:33 -04:00
Adam Moussa
ca3b3096fc
Skip DST guard on manual workflow_dispatch triggers (#26) 2026-05-01 14:49:01 -04:00
Adam Moussa
b08a532da3
Polish version notifications and sync changelog canvas (#21) (#25)
Reworks the daily version bump workflow to:
- Pull merged PR titles via gh CLI instead of raw commit messages
- Post a polished, non-technical channel message with a link to the
  changelog canvas
- Prepend the new version entry to the Slack canvas via canvases.edit
  API so the canvas stays in sync automatically

Channel message format:
  "After-Hours Scheduler has been updated to vXXXX.XX.XX
   Here's a brief summary of what changed:
   • ...
   Click here to read the full changelog"
2026-05-01 14:47:16 -04:00
Adam Moussa
769b9e5acd
Change deploy notifications to daily version bumps (#24)
Replaces per-push notifications with a daily 6pm ET cron job that
batches all commits since the last version tag into a single Slack
message. Tags main with a date-based version (v2026.05.01) so there
is at most one version bump per day. Includes DST guard matching the
pattern used by the other scheduled Lambdas.
2026-05-01 14:37:54 -04:00
Adam Moussa
5e052d424d
Add GitHub Actions workflow for deploy notifications (#23)
Posts a Slack message to the schedule channel whenever code is pushed
to main. Uses the existing Slack bot token stored as a GitHub secret.
2026-05-01 14:32:53 -04:00