afterhours-shift-manager/src/slack-bot
Adam Moussa f7c44778b5
Some checks failed
Deploy / deploy (push) Has been cancelled
Deploy / release (push) Has been cancelled
[#142] Fix payroll email: SES domain identity + send-as pin + failure alarm (#143)
The weekly-post pay-summary email to payroll failed with SES AccessDenied
every Monday since v1.10.1: the role granted ses:SendEmail on
identity/noreply@seahaven.com, but that address is not a verified SES
identity — it is covered by the verified domain identity seahaven.com,
which is what SES authorizes against. Grant the domain ARN instead.

Pin the grant with a ses:FromAddress condition (= noreply@seahaven.com,
the existing SES_SENDER) so the domain-wide identity can't be used to
send-as any other @seahaven.com mailbox (BEC blast radius). Surfaced by
/sh-security-review; matches the existing single-sender intent.

Add a CloudWatch metric-filter alarm on the swallowed "Failed to send
pay summary" log line -> site-alerts. The email send is wrapped in
try/except so a delivery failure never increments the Lambda Errors
metric; this is the only signal that surfaces a silent payroll failure.

Closes #142
2026-06-29 15:10:02 -04:00
..
app.py [#135] Stick weekly schedule post to bottom of channel (#139) 2026-06-27 15:45:01 -04:00
CHANGELOG.md [#142] Fix payroll email: SES domain identity + send-as pin + failure alarm (#143) 2026-06-29 15:10:02 -04:00
handler.py Merge ring-scheduler-3cx and resolve all open issues (#62) 2026-05-12 19:55:39 -04:00
requirements.txt Update boto3 requirement from >=1.43.31 to >=1.43.36 in /src/slack-bot (#131) 2026-06-24 00:49:22 +00:00