mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 07:43:13 +00:00
Some checks failed
Deploy / deploy (push) Has been cancelled
* Add admin panel, fix dual-domain auth, harden weekly scrape schedule Accept both seahavenind.com and seahaven.com Google Workspace domains for employee sign-in. Add admin panel with order management (view by week, edit quantities, add/remove items, delete orders) behind Google auth + DynamoDB admin_emails allowlist. Shift weekly menu scrape from 8:00am to 7:30am ET and add timezone guard to prevent duplicate runs from dual EST/EDT crons. * Rename Secrets Manager env vars to avoid CI false positive The reusable CI workflow greps for keywords like TOKEN and API_KEY in Lambda environment variables. Our env vars hold Secrets Manager lookup names, not actual secrets, but the heuristic matched the SM key name meal-order-manager/slack-bot-token. Rename SLACK_BOT_TOKEN_SECRET to SLACK_BOT_SM_NAME and FORM_API_KEY_SECRET to FORM_APIKEY_SM_NAME, and reorder the Globals block so the value falls outside the grep window.
7.2 KiB
7.2 KiB
meal-order-manager
Automates weekly meal ordering from Redefine Meals for Sea Haven Industries employees. Scrapes the menu, generates an order form, collects individual orders, and produces payroll deduction reports.
Architecture
Monday 7:30am ET Employees (Mon–Thu) Thursday 6pm ET
┌─────────────────┐ ┌──────────────────┐ ┌──────────────────┐
│ GitHub Actions │ │ orders.seahaven │ │ EventBridge │
│ - Scrape menu │────S3 upload───▶│ ind.com │ │ - Close form │
│ - Generate form │ + DynamoDB │ (CloudFront+S3) │──POST───┐ │ - Aggregate │
│ - Slack notify │ └──────────────────┘ │ │ - Slack summary │
└─────────────────┘ ▼ └──────────────────┘
┌──────────┐
Monday 7am ET │ API GW + │
┌──────────────────┐ │ Lambda │
│ EventBridge │ │ submit │
│ - Email payroll │ └────┬─────┘
│ deductions │ ▼
└──────────────────┘ ┌──────────┐
│ DynamoDB │
Thu 10am: Slack DM │ orders │
reminders to employees └──────────┘
who haven't ordered
Weekly Flow
| When | What | How |
|---|---|---|
| Monday 6:55am ET | Sync employee roster from Slack channel membership | EventBridge → Lambda → DynamoDB |
| Monday 7am ET | Email previous week's payroll deductions to payroll@ |
EventBridge → Lambda → SES |
| Monday 7:30am ET | Scrape menu, generate form, upload to S3, post link to Slack | GitHub Actions cron |
| Mon–Thu | Employees visit orders.seahaven.com and submit orders |
S3 static form → API Gateway → Lambda → DynamoDB |
| Thursday 10am ET | DM employees who haven't ordered yet | EventBridge → Lambda → Slack DM |
| Thursday 6pm ET | Close form, aggregate orders, post Redefine order summary to Slack | EventBridge → Lambda chain |
AWS Resources
Stack name: meal-order-manager (us-east-1)
- S3 —
meal-order-manager-form-*(static form hosting),meal-order-manager-reports-*(CSV reports) - CloudFront — HTTPS distribution with custom domain
orders.seahaven.com - DynamoDB —
meal-order-manager-orders(orders, menu, roster, config) - API Gateway — HttpApi for order submission and admin operations
- Lambda — 6 functions: submit-order, close-form, aggregate-orders, slack-notifier, sync-roster, email-report
- EventBridge — scheduled rules (dual EST/EDT) for close, reminders, payroll email
- Secrets Manager — Slack bot token, form API key
- SES — payroll deduction emails
Authentication
Google Identity Services (OAuth) with tokeninfo endpoint verification. Accepts both seahavenind.com and seahaven.com Google Workspace domains.
Admin Panel
Admins (configured in DynamoDB CONFIG/SETTINGS → admin_emails list) get an "Admin" button after Google sign-in. The panel provides:
- View all orders by week with totals
- Edit order quantities, add new menu items, remove items
- Delete orders entirely
All admin operations enforce server-side price recalculation from the menu.
API routes (all require Google auth + admin email):
| Method | Path | Description |
|---|---|---|
| GET | /api/admin/orders |
List weeks with order counts |
| GET | /api/admin/orders?week=YYYY-WNN |
Get all orders for a week |
| PUT | /api/admin/orders |
Update an order (recalculates prices) |
| DELETE | /api/admin/orders?week=...&email=... |
Delete an order |
Setup
Local development
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
playwright install chromium
Deploy to AWS
cp samconfig.toml.example samconfig.toml
# Edit samconfig.toml with your certificate ARN, etc.
sam build
sam deploy
Post-deploy
- Create the Slack bot token secret:
aws secretsmanager create-secret --name meal-order-manager/slack-bot-token --secret-string "xoxb-..." - Create the form API key secret:
aws secretsmanager create-secret --name meal-order-manager/form-api-key --secret-string "$(openssl rand -hex 32)" - Update the Slack channel SSM parameter:
aws ssm put-parameter --name /meal-order-manager/slack-channel-id --value "C0XXXXXXX" --overwrite - Verify SES sender identity for
adam@seahavenind.com - Set up DNS: CNAME
orders.seahaven.com→ CloudFront distribution domain - Roster syncs automatically from Slack channel members (runs Monday 6:55am ET), or seed manually:
python3 scripts/seed_roster.py
Local Workflow (no AWS)
The scraper, form generator, Flask server, and aggregator still work locally:
python3 src/scraper/scrape_menu.py # scrape menu
python3 src/server/generate_form.py # generate form (local mode)
python3 src/server/app.py # serve on localhost:5050
python3 src/aggregator/aggregate.py # generate CSV reports
Configuration
config.json (local dev):
menu_url— Redefine Meals menu URLorder_deadline— displayed on the formroster— employee list (name, email, slack_user_id)output_dir/orders_dir— local output paths
Project Structure
meal-order-manager/
├── .github/workflows/
│ ├── weekly-menu.yml # Monday cron: scrape + publish + notify
│ ├── ci.yml # PR checks
│ └── deploy.yml # Push to main: sam deploy
├── src/
│ ├── scraper/ # Playwright menu scraper
│ ├── server/ # Form generator + local Flask server
│ ├── aggregator/ # Order aggregation + CSV reports
│ └── shared/shared/ # Lambda layer (db, secrets, slack helpers)
├── functions/ # Lambda handlers
│ ├── submit_order/
│ ├── close_form/
│ ├── aggregate_orders/
│ ├── slack_notifier/
│ ├── sync_roster/
│ └── email_report/
├── scripts/ # CI/CD helper scripts
│ ├── upload_menu.py
│ ├── notify_slack.py
│ └── seed_roster.py
├── template.yaml # SAM template
├── samconfig.toml.example
├── slack-app-manifest.yml # Slack app manifest (paste into api.slack.com)
└── config.json