From 09593b1d91a16bb2721f8e90f2ab4884c29d3508 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 13 May 2026 12:59:12 -0400 Subject: [PATCH] Document CORS, cron idempotency, and SSM config in template Add comments explaining CORS dev server strategy, dual EST/EDT cron idempotency, and manual SSM parameter creation for Google Client ID. --- template.yaml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/template.yaml b/template.yaml index 9b0fbdb..c3560bb 100644 --- a/template.yaml +++ b/template.yaml @@ -202,6 +202,8 @@ Resources: Type: AWS::Serverless::HttpApi Properties: StageName: $default + # CORS only allows the production domain. For local development, use the + # Flask dev server (app.py) which proxies API requests and doesn't enforce CORS. CorsConfiguration: AllowOrigins: - !If @@ -283,6 +285,8 @@ Resources: Environment: Variables: AGGREGATE_FUNCTION_ARN: !GetAtt AggregateOrdersFunction.Arn + # Both EST and EDT schedules fire every week year-round. The handler is + # idempotent, so the "wrong timezone" firing is a harmless no-op. Events: CloseEST: Type: Schedule @@ -468,6 +472,11 @@ Resources: Value: CHANGE_ME Description: Slack channel ID for meal order notifications + # GoogleClientIdParam (/meal-order-manager/google-client-id) is managed + # manually via AWS CLI since it varies per environment. Create it with: + # aws ssm put-parameter --name /meal-order-manager/google-client-id \ + # --type String --value "" + Outputs: ApiUrl: Description: API Gateway endpoint URL