Commit graph

62 commits

Author SHA1 Message Date
Adam Moussa
adf175daef
feat(form): render admin orders as mobile cards (#86)
Some checks failed
Deploy / deploy (push) Has been cancelled
* feat(form): render admin orders as mobile cards

* fix(form): address mobile admin review findings

* fix(tests): remove unused mobile fixture state
2026-07-31 10:15:43 -04:00
Adam Moussa
602b0c7fd0
fix(form): accessibility for qty, status, and descriptions (#81)
* fix(form): add status regions, live total, and a11y CSS

Dual alert/status slots for form and admin, aria-live on the sticky
total, success heading focus target, More/Less affordance styles, and
44px coarse-pointer chip padding.

* fix(form): wire a11y labels, status helper, and desc expand

Meal-scoped qty labels at card create time, aria-pressed filter chips,
dual-node showStatus replacing all alert() calls (confirm retained),
overflow-gated More/Less, and success-heading focus after submit.

* test(form): cover a11y labels, status region, and desc toggle

Structural checks for dual status nodes and no alert(); Playwright for
init-time qty labels, aria-pressed chips, overflow More/Less, and
failed-submit text landing in role=alert.

* fix: address review comments
2026-07-31 10:15:43 -04:00
Adam Moussa
83077f7aa9
test(form): cover sticky footer at narrow widths (#85)
* test(form): cover sticky footer at narrow widths

* fix(form): address review findings

* fix(form): guard stale admin edit responses

* test(form): stub admin lookup in browser tests
2026-07-31 10:15:42 -04:00
Adam Moussa
30fa7fe352
fix(form): wrap Google user bar at phone widths (#84)
* fix(form): wrap Google user bar at phone widths

Allow the signed-in Google identity and admin controls to wrap below 480px while preserving the desktop row, with generated-form Playwright coverage for phone widths.

* fix(form): preserve 480px user bar boundary

Keep the mobile layout below 480px and lock both sides of the breakpoint with browser coverage.

* style(tests): apply ruff formatting

* test(form): guarantee Playwright browser cleanup

* test(form): strengthen phone-width coverage

* fix: add @classmethod and use cls in tests/test_generate_form.py

Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>

* fix(tests): restore class fixture discovery

---------

Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
2026-07-31 10:15:42 -04:00
Adam Moussa
216618a862
refactor(form): extract Jinja templates and lock form JS in CI (#77)
Some checks are pending
Deploy / deploy (push) Waiting to run
* refactor(form): extract Jinja templates and lock form JS in CI

Split the monolithic generate_form f-string into form.html.j2/css/js
plus admin.js, inject a single window.CONFIG blob, and add structural
plus Playwright coverage so qty delegation and clamp stay green in CI.

* Update src/server/generate_form.py

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* fix(form): isolate admin script bindings

* fix(form): address admin and form review findings

* fix(form): resolve remaining review nitpicks

* ci(workflow): restore required check context

Keep the reusable workflow caller job compatible with the organization-required ci / ci status check.

* fix(form): address remaining review findings

* fix: apply CodeRabbit auto-fixes

Fixed 1 file(s) based on 1 unresolved review comment.

Co-authored-by: CodeRabbit <noreply@coderabbit.ai>

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
2026-07-30 19:19:51 -04:00
Adam Moussa
3fe6e74557
Merge pull request #75 from Sea-Haven-Industries/fix/form-mobile-layout
Some checks are pending
Deploy / deploy (push) Waiting to run
fix(form): improve mobile layout for order form and admin toolbar
2026-07-30 16:26:41 -04:00
043eea1443
fix(form): use single-column layout for meals without images on mobile 2026-07-30 11:18:21 -04:00
2a985c1940
fix(form): improve mobile layout for order form and admin toolbar
Stop phone-width sideways scroll from the admin toolbar, stack meal cards
and bump touch targets on coarse pointers, and respect safe-area insets.
2026-07-29 19:19:55 -04:00
Adam Moussa
452312b5e5
Merge pull request #73 from Sea-Haven-Industries/ci/weekly-menu-timeout
Some checks failed
Deploy / deploy (push) Has been cancelled
ci(weekly-menu): add 30-minute job timeout
2026-07-29 11:54:35 -04:00
0446f31869
ci(weekly-menu): add 30-minute job timeout 2026-07-29 11:44:14 -04:00
Adam Moussa
f0b51a1fbf
Merge pull request #72 from Sea-Haven-Industries/fix/weekly-menu-pinned-deps
Some checks are pending
Deploy / deploy (push) Waiting to run
ci(weekly-menu): install pinned deps from requirements.txt
2026-07-28 19:42:22 -04:00
Adam Moussa
b79e650553 ci(weekly-menu): install pinned deps from requirements.txt 2026-07-28 19:36:12 -04:00
Adam Moussa
76bb858bcc
Merge pull request #70 from Sea-Haven-Industries/fix/weekly-menu-scoped-role
Some checks are pending
Deploy / deploy (push) Waiting to run
ci(weekly-menu): assume the scoped role, add concurrency guard, pin actions
2026-07-28 19:26:56 -04:00
Adam Moussa
3952ed88f4 ci(weekly-menu): assume the scoped role, add concurrency guard, pin actions 2026-07-28 19:25:02 -04:00
Adam Moussa
8272449ccf
ci(deps): pin org reusable workflows to v1.0.2 (#69)
Some checks are pending
Deploy / deploy (push) Waiting to run
* ci(deps): pin org reusable workflows to v1.0.2

* style(ci): normalize workflow block spacing
2026-07-28 18:15:00 -04:00
dependabot[bot]
546c2ceeed
chore(deps): bump aws-actions/configure-aws-credentials (#59)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 1 update in the / directory: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials).


Updates `aws-actions/configure-aws-credentials` from 6.2.2 to 6.2.3
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](517a711dbc...e6de054238)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 15:17:36 +00:00
dependabot[bot]
c7fb11624f
chore(deps): bump actions/setup-python from 6 to 7 (#60)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 11:15:24 -04:00
Adam Moussa
03e902da6c
chore(deps): bump boto3 from 1.43.51 to 1.43.56 in multiple files (#68)
* chore(deps): bump boto3

Bumps the minor-and-patch group in /functions/admin_authorizer with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.51 to 1.43.56
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.51...1.43.56)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.56
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump boto3

Bumps the minor-and-patch group in /functions/aggregate_orders with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.51 to 1.43.56
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.51...1.43.56)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.56
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump boto3

Bumps the minor-and-patch group in /functions/close_form with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.51 to 1.43.56
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.51...1.43.56)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.56
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump boto3

Bumps the minor-and-patch group in /functions/email_report with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.51 to 1.43.56
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.51...1.43.56)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.56
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump boto3

Bumps the minor-and-patch group in /functions/slack_notifier with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.51 to 1.43.56
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.51...1.43.56)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.56
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump boto3

Bumps the minor-and-patch group in /functions/submit_order with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.51 to 1.43.56
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.51...1.43.56)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.56
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump boto3 in /src/shared in the minor-and-patch group

Bumps the minor-and-patch group in /src/shared with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.51 to 1.43.56
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.51...1.43.56)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.56
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 15:03:46 +00:00
Adam Moussa
09052fa91a
chore: resolve open code scanning alerts (#58)
Some checks failed
Deploy / deploy (push) Has been cancelled
* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alerts #9 and #11 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.

* fix: turn off debug mode in Flask app configuration.

Resolves code scanning alert #2 (Flask app is run in debug mode)

* ci: bump reusable workflow pin to f71002a (ruff 0.15.22 pin)

Picks up Sea-Haven-Industries/.github#88, which pins ruff in
ci-python-sam so unpinned installs no longer float to new releases
with changed default rule sets (0.16.0 broke CI with 89 pre-existing
findings). Refs Sea-Haven-Industries/.github#87.
2026-07-23 20:00:47 +00:00
Adam Moussa
4079d57757
chore: Bump boto3 from 1.43.41 and 1.43.46 to 1.43.51 (#56)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-07-20 16:56:49 +00:00
Adam Moussa
e2d1b2fce8
chore(security): add repo-local suppression for test-fixture FP (gitleaks-45) (#48)
Some checks failed
Deploy / deploy (push) Has been cancelled
Moves the false-positive suppression for tests/test_submit_order.py:45 (a dummy
test API key, proof-or-kill verified 2026-07-13) from machine-level to a tracked
repo-local .security-review/suppressions.json so the Open SWE daily-report
automation — which cannot see ~/.config on the Mac — resolves it. Machine-level
copy retained until this merges.
2026-07-13 14:30:43 -04:00
dependabot[bot]
65bbe6f8b5
Bump boto3 from 1.43.41 to 1.43.46 in /functions/email_report in the minor-and-patch group (#43)
Some checks are pending
Deploy / deploy (push) Waiting to run
* Bump boto3 in /functions/email_report in the minor-and-patch group

Bumps the minor-and-patch group in /functions/email_report with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.41 to 1.43.46
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.41...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* Bump boto3 in /src/shared in the minor-and-patch group (#47)

Bumps the minor-and-patch group in /src/shared with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.41 to 1.43.46
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.41...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump boto3 in /functions/slack_notifier in the minor-and-patch group (#46)

Bumps the minor-and-patch group in /functions/slack_notifier with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.41 to 1.43.46
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.41...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump boto3 in /functions/close_form in the minor-and-patch group (#44)

Bumps the minor-and-patch group in /functions/close_form with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.41 to 1.43.46
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.41...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump boto3 in /functions/submit_order in the minor-and-patch group (#45)

Bumps the minor-and-patch group in /functions/submit_order with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.41 to 1.43.46
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.41...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
2026-07-13 16:32:14 +00:00
dependabot[bot]
1f76e8980e
Bump boto3 in /functions/admin_authorizer in the minor-and-patch group (#40)
Bumps the minor-and-patch group in /functions/admin_authorizer with 1 update: [boto3](https://github.com/boto/boto3).


Updates `boto3` from 1.43.41 to 1.43.46
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.41...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
2026-07-13 16:28:06 +00:00
dependabot[bot]
2222ba45f4
Bump aws-actions/configure-aws-credentials in the minor-and-patch group (#41)
Bumps the minor-and-patch group with 1 update: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials).


Updates `aws-actions/configure-aws-credentials` from 6.2.1 to 6.2.2
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](254c19bd24...517a711dbc)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-13 12:25:06 -04:00
Adam Moussa
44b21f4033
fix(test): fix aggregated notifier tests + enable CI test suite (INFRA-72) (#39)
Some checks failed
Deploy / deploy (push) Has been cancelled
* fix(test): mock get_settings/get_roster in aggregated tests + enable CI tests (INFRA-72)

handle_orders_aggregated now delivers the summary via admin DMs (PR #15),
adding get_settings/get_roster calls the aggregated tests never mocked, so
they hit live DynamoDB. Mock both and assert the message content on the
send_dm path. Set run-tests: true so the suite actually runs in CI.

* fix(test): default AWS region in conftest so CI collection doesn't hit NoRegionError (INFRA-72)

Handlers build boto3 clients at module load; CI runners have no AWS config,
so test collection raised NoRegionError once the suite actually ran. Set a
region default before imports (offline client construction; calls are mocked).

* fix(test): add repo root to sys.path so CI's bare pytest collects functions.* (INFRA-72)

test_aggregate_orders imports functions.aggregate_orders.handler, which needs
the repo root on sys.path. python -m pytest injects CWD automatically but CI
runs pytest directly, so these 11 tests errored at collection in CI only.
2026-07-08 16:33:42 -04:00
Adam Moussa
a6ce388465
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#38)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-07-06 18:27:47 -04:00
Adam Moussa
77cbc8a7ec
chore(ci): SHA-pin mutable-tag third-party actions (INFRA-118) (#37) 2026-07-06 18:27:25 -04:00
Adam Moussa
b8fef8b4f4
chore(deps): pin Python requirements to == for reproducible builds (INFRA-62) (#36) 2026-07-06 18:27:02 -04:00
Adam Moussa
b99573873c
docs: link Confluence AWS Architecture Map (INFRA-53) (#35)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 17:43:54 -04:00
dependabot[bot]
dc3e27fb5a
Update playwright requirement from >=1.60.0 to >=1.61.0 (#34)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 08:07:59 -04:00
dependabot[bot]
97e036d399
Bump actions/checkout from 6 to 7 (#33)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-26 12:29:09 -04:00
Adam Moussa
c6b16678ce
Add CloudWatch alarm coverage (meal-order-manager) (#32)
Some checks failed
Deploy / deploy (push) Has been cancelled
* Add CloudWatch alarm coverage for the meal-order-manager stack

Add CloudWatch alarms (all notifying the shared site-alerts SNS topic,
no OKActions, TreatMissingData notBreaching) across the stack:

- Lambda Errors + Throttles alarms for all 7 functions (Sum, 5min,
  threshold 0).
- Lambda Duration p99 alarms at ~80% of each function's timeout;
  API-fronted functions eval 3/3, cron/async functions eval 1/1.
  Thresholds pending sign-off.
- DynamoDB orders-table Read/WriteThrottleEvents alarms (TableName dim).
  ThrottledRequests/SystemErrors are not published at the table-only
  dimension, so they are intentionally omitted.
- API Gateway (OrderApi v2) 5xx, 4xx (threshold 20, 3/2 to absorb
  routine authorizer 401s), and p99 Latency alarms.

Update README with a Monitoring section and correct the Lambda count
to 7 (admin-authorizer was missing).

* Drop pending-sign-off wording from alarm docs

Duration/Latency thresholds are owner-approved; remove PENDING ADAM
SIGN-OFF / pending-sign-off notes from template.yaml comments and README.
2026-06-17 14:45:54 -04:00
Adam Moussa
16dbd3b765
Merge pull request #31 from Sea-Haven-Industries/fix/summary-pdf-decimal-serialization
Some checks failed
Deploy / deploy (push) Has been cancelled
Fix summary-PDF 404: persist SUMMARY records (Decimal serialization)
2026-06-12 15:12:30 -04:00
53a1e503b3 Fix put_summary float serialization so SUMMARY records persist
aggregate_orders uploads the weekly PDF/CSVs to S3 and then calls
put_summary(), but put_summary spread the summary dict (which contains
float prices/totals) straight into put_item without Decimal conversion.
boto3 rejects floats (TypeError: Float types are not supported), so the
SUMMARY DynamoDB item was never written for any week (W20-W23).

The summary-PDF download endpoint gates on get_summary(week), so it got
None and returned 404 -- 'No summary PDF for <week> yet' -- even though
the PDF was sitting in S3.

Convert via _to_decimal in put_summary, matching put_order/put_settings.
2026-06-12 15:07:15 -04:00
dependabot[bot]
526b768267
Update flask requirement from >=3.0 to >=3.1.3 (#29)
Some checks are pending
Deploy / deploy (push) Waiting to run
Updates the requirements on [flask](https://github.com/pallets/flask) to permit the latest version.
- [Release notes](https://github.com/pallets/flask/releases)
- [Changelog](https://github.com/pallets/flask/blob/main/CHANGES.rst)
- [Commits](https://github.com/pallets/flask/compare/3.0.0...3.1.3)

---
updated-dependencies:
- dependency-name: flask
  dependency-version: 3.1.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:34:38 -04:00
dependabot[bot]
24c464bbb2
Update fpdf2 requirement from >=2.7 to >=2.8.7 in /src/shared (#30)
Updates the requirements on [fpdf2](https://github.com/py-pdf/fpdf2) to permit the latest version.
- [Release notes](https://github.com/py-pdf/fpdf2/releases)
- [Changelog](https://github.com/py-pdf/fpdf2/blob/master/CHANGELOG.md)
- [Commits](https://github.com/py-pdf/fpdf2/compare/2.7.0...2.8.7)

---
updated-dependencies:
- dependency-name: fpdf2
  dependency-version: 2.8.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:33 -04:00
dependabot[bot]
cd1ac08388
Update playwright requirement from >=1.40 to >=1.60.0 (#28)
Updates the requirements on [playwright](https://github.com/microsoft/playwright-python) to permit the latest version.
- [Release notes](https://github.com/microsoft/playwright-python/releases)
- [Commits](https://github.com/microsoft/playwright-python/compare/v1.40.0...v1.60.0)

---
updated-dependencies:
- dependency-name: playwright
  dependency-version: 1.60.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:27 -04:00
dependabot[bot]
064ee77365
Bump actions/setup-python from 5 to 6 (#27)
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 6.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 14:31:22 -04:00
Adam Moussa
6c89d96343
Repo hygiene: PR labeler + README badges + dependabot (INFRA-56/57/66) (#26) 2026-06-11 14:13:54 -04:00
Adam Moussa
921efe2c04
Attach permissions boundary to all IAM roles (#25)
Some checks are pending
Deploy / deploy (push) Waiting to run
Scope-down requirement from INFRA-97: github-cfn-execution-role
needs iam:CreateRole scoped to roles that carry the org boundary,
so every role this stack creates must declare it.

- Globals.Function.PermissionsBoundary: applies to all six
  SAM auto-generated Lambda execution roles
- AdminAuthorizerInvokeRole: adds PermissionsBoundary + Path
  /cfn-managed/ (explicit AWS::IAM::Role)

The only consumer of AdminAuthorizerInvokeRole is the HttpApi
authorizer's FunctionInvokeRole, which references it via
!GetAtt AdminAuthorizerInvokeRole.Arn — no hardcoded ARN
strings, so the path change is safe.

Refs: INFRA-103
2026-06-10 14:14:54 -04:00
Adam Moussa
75fb3280f5
Add gateway-level authorizer to admin API (INFRA-100) (#24)
Some checks failed
Deploy / deploy (push) Has been cancelled
The /api/admin/* routes (GET/PUT/DELETE /api/admin/orders and
GET /api/admin/summary-pdf) were AuthorizationType NONE, relying entirely on
the in-handler _verify_admin Google-token + admin-email check. This adds an
HTTP API Lambda authorizer that enforces the same check at the gateway, so
unauthenticated requests are rejected before reaching the integration.

- New admin_authorizer Lambda: validates the Authorization: Bearer Google ID
  token (aud + allowed Workspace domain) and the admin_emails allow-list from
  DynamoDB, returning the HTTP API simple response {isAuthorized}. Fails closed
  on missing config, unavailable client ID, bad token, or DynamoDB error.
- OrderApi gains an AdminGoogleAuthorizer with result caching disabled
  (AuthorizerResultTtlInSeconds: 0) so expired tokens / removed admins can't be
  served from cache. Wired onto all four admin events; no DefaultAuthorizer, so
  public routes (submit-order, form-status, roster) stay NONE.
- IAM role for API Gateway to invoke the authorizer; 60-day log group.
- 10 unit tests for the authorizer.

No client change: the admin panel already sends Authorization: Bearer
<google_id_token>. The in-handler _verify_admin check stays as defense-in-depth.

Cross-reviewed by GPT-4.1 (APPROVE-WITH-FIXES); both BLOCK items applied
(disable authorizer caching, fail-closed on DynamoDB error).
2026-06-08 18:05:09 -04:00
5ec63687a1 Merge branch 'feature/admin-summary-pdf-download'
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-06-05 18:51:33 -04:00
f2a0692577 Harden summary-PDF endpoint per cross-review
Address GPT-4.1 cross-review of the IAM change:

- Validate the week param (YYYY-WNN) and the DynamoDB-sourced PDF key
  shape before presigning, so a tampered SUMMARY record can't mint URLs
  for other report files (payroll CSVs).
- Narrow the IAM resource from reports/* to
  reports/*/weekly-summary-*.pdf — least privilege over the bucket.
- Reuse a module-level S3 client; name the URL TTL constant.
- Distinguish "week not found" from "PDF key missing" 404s.
- Tests: malformed-week 400 and tampered-key 500 (asserts no presign).
2026-06-05 18:44:25 -04:00
b6733703ab Add admin summary-PDF download endpoint and button
The weekly summary PDF generated at Thursday close was stored in the
reports bucket with no way to reach it from the UI — admins had to pull
it from S3 manually. Surface it in the admin panel:

- submit_order: GET /api/admin/summary-pdf?week= (admin-gated) returns
  a 5-minute presigned URL from the SUMMARY item's stamped PDF key;
  404 for weeks that haven't closed.
- template.yaml: REPORTS_BUCKET env var + read-only s3:GetObject on
  reports/* for SubmitOrderFunction (needed so the presigned URL is
  signed with sufficient permissions).
- generate_form.py: "Download summary PDF" button in the admin header;
  explains Thursday-close timing on 404.
- Tests: presign happy path, 404 open week, 400 missing week, 401
  unauthenticated.
- README updated.
2026-06-05 18:41:55 -04:00
Adam Moussa
8d625fa6b7
chore(ci): bump configure-aws-credentials to v6 (#20)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bump aws-actions/configure-aws-credentials to @v6 (org target) in the
weekly-menu workflow. v6 is the verified org standard alongside
actions/checkout@v6.

Ref: engineering-handbook cicd.md (workflow standardization).
2026-06-05 12:39:35 -04:00
Adam Moussa
e1afbdd030
Add dependency-review caller workflow (#21)
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)
2026-06-05 12:27:00 -04:00
Adam Moussa
9c1717a77c
Associate shared WAF WebACL with orders distribution (audit M-17) (#19)
Some checks failed
Deploy / deploy (push) Has been cancelled
Re-adds WebACLId (from SSM /seahaven/waf/app-web-acl-arn) now that the
github-cfn-execution-role has wafv2 perms. Deployed + verified: orders.seahaven.com
distribution now fronted by seahaven-app-waf.
2026-06-02 17:20:58 -04:00
Adam Moussa
e0b12cb93e
API access logging + throttling (audit Day 3 M-18) (#18)
Some checks are pending
Deploy / deploy (push) Waiting to run
* Add WAF + API access logging/throttling (audit Day 3: M-17, M-18)

- M-17: associate the shared seahaven-app-waf CloudFront WebACL (ARN from SSM
  /seahaven/waf/app-web-acl-arn) with the orders.seahaven.com distribution.
- M-18: enable HTTP API access logging to /aws/apigateway/meal-order-manager
  (90d) + default route throttling (100 rps, 50 burst) on OrderApi.

* Defer M-17 WAF association (deploy role lacks wafv2)

The github-cfn-execution-role (sticky CFN service role on this stack) has
cloudfront:* + ssm:* but no wafv2:*, so associating the WebACL fails with
'Unable to verify read permissions on Web ACL'. Landing M-18 (access logging +
throttling) now; WAF association re-added once the deploy role gets wafv2 perms
(tracked separately).
2026-06-02 17:01:19 -04:00
Adam Moussa
10d135e32e
Add weekly summary PDF and admin order-list download (#16) (#17)
Some checks are pending
Deploy / deploy (push) Waiting to run
Generate a per-person weekly summary PDF at Thursday close and store it
alongside the CSV reports, plus a client-side admin download that rolls
orders up into item -> total quantity for bulk ordering.

- shared/pdf.py: build_weekly_summary_pdf() via fpdf2 (pure-Python,
  ARM64-safe; first non-boto3 layer dep). Per-person employee -> item ->
  quantity, no pricing.
- aggregate_orders: write reports/{week}/weekly-summary-{week}.pdf
  (application/pdf) and stamp weekly_summary_pdf_s3_key on the SUMMARY.
  No new IAM (existing S3CrudPolicy). No email/Slack delivery.
- generate_form.py: "Download order list" admin button aggregates the
  loaded week's orders into an item->qty CSV (no per-employee breakdown,
  no prices) via a Blob download. Works for open weeks too.
- Tests: tests/test_pdf.py; aggregate happy-path now asserts 3 S3
  uploads + the pdf key.
- README updated.
2026-06-01 18:49:58 -04:00
Adam Moussa
c52f608974 Fix admin bypass: defer closed overlay until after Google auth
Some checks failed
Deploy / deploy (push) Has been cancelled
The closed overlay (z-index 2000) was blocking Google sign-in from
firing, so the admin check never ran. Now the overlay is deferred
when Google auth is configured — checkAdmin() shows or bypasses
it after auth completes.
2026-05-22 12:35:36 -04:00