mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-10-01 02:33:12 +00:00
The weekly-post pay-summary email to payroll failed with SES AccessDenied every Monday since v1.10.1: the role granted ses:SendEmail on identity/noreply@seahaven.com, but that address is not a verified SES identity — it is covered by the verified domain identity seahaven.com, which is what SES authorizes against. Grant the domain ARN instead. Pin the grant with a ses:FromAddress condition (= noreply@seahaven.com, the existing SES_SENDER) so the domain-wide identity can't be used to send-as any other @seahaven.com mailbox (BEC blast radius). Surfaced by /sh-security-review; matches the existing single-sender intent. Add a CloudWatch metric-filter alarm on the swallowed "Failed to send pay summary" log line -> site-alerts. The email send is wrapped in try/except so a delivery failure never increments the Lambda Errors metric; this is the only signal that surfaces a silent payroll failure. Closes #142 |
||
|---|---|---|
| .. | ||
| app.py | ||
| CHANGELOG.md | ||
| handler.py | ||
| requirements.txt | ||