* feat(api): add IAM-authenticated menu publication
Keep weekly menu writes behind Lambda so the GitHub runtime role cannot access the shared DynamoDB table directly.
* refactor(workflow): publish weekly menus through API
Use SigV4 requests for settings and menu publication so the scheduled workflow no longer needs direct DynamoDB access.
* fix: address review comments
* style(python): apply Ruff formatting
* fix(auth): require Google authentication in cloud mode
Remove the public shared-key mechanism and fail closed on Google auth while adding submit-route throttling.
* fix(auth): address review follow-ups
Fail closed on whitespace-only Google configuration and centralize shared authentication behavior.
* test(auth): use non-secret Google client fixture
Make the public test identifier explicit so secret scanning does not misclassify it as an API key.
* test(auth): avoid OAuth-shaped fixture
Use a format-neutral audience value so secret scanning can distinguish the fixture from a real client identifier.
* chore(security): suppress public OAuth fixture
Document the scanner false positive without suppressing any runtime credential flow.
* fix(form): add status regions, live total, and a11y CSS
Dual alert/status slots for form and admin, aria-live on the sticky
total, success heading focus target, More/Less affordance styles, and
44px coarse-pointer chip padding.
* fix(form): wire a11y labels, status helper, and desc expand
Meal-scoped qty labels at card create time, aria-pressed filter chips,
dual-node showStatus replacing all alert() calls (confirm retained),
overflow-gated More/Less, and success-heading focus after submit.
* test(form): cover a11y labels, status region, and desc toggle
Structural checks for dual status nodes and no alert(); Playwright for
init-time qty labels, aria-pressed chips, overflow More/Less, and
failed-submit text landing in role=alert.
* fix: address review comments
* fix(form): wrap Google user bar at phone widths
Allow the signed-in Google identity and admin controls to wrap below 480px while preserving the desktop row, with generated-form Playwright coverage for phone widths.
* fix(form): preserve 480px user bar boundary
Keep the mobile layout below 480px and lock both sides of the breakpoint with browser coverage.
* style(tests): apply ruff formatting
* test(form): guarantee Playwright browser cleanup
* test(form): strengthen phone-width coverage
* fix: add @classmethod and use cls in tests/test_generate_form.py
Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
* fix(tests): restore class fixture discovery
---------
Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
* refactor(form): extract Jinja templates and lock form JS in CI
Split the monolithic generate_form f-string into form.html.j2/css/js
plus admin.js, inject a single window.CONFIG blob, and add structural
plus Playwright coverage so qty delegation and clamp stay green in CI.
* Update src/server/generate_form.py
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
* fix(form): isolate admin script bindings
* fix(form): address admin and form review findings
* fix(form): resolve remaining review nitpicks
* ci(workflow): restore required check context
Keep the reusable workflow caller job compatible with the organization-required ci / ci status check.
* fix(form): address remaining review findings
* fix: apply CodeRabbit auto-fixes
Fixed 1 file(s) based on 1 unresolved review comment.
Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
---------
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: CodeRabbit <noreply@coderabbit.ai>