meal-order-manager/scripts/notify_slack.py
Adam Moussa 5db95ce9d1
Some checks failed
Deploy / deploy (push) Has been cancelled
Add admin panel, fix dual-domain auth, harden scrape schedule (#14)
* Add admin panel, fix dual-domain auth, harden weekly scrape schedule

Accept both seahavenind.com and seahaven.com Google Workspace domains
for employee sign-in. Add admin panel with order management (view by
week, edit quantities, add/remove items, delete orders) behind Google
auth + DynamoDB admin_emails allowlist. Shift weekly menu scrape from
8:00am to 7:30am ET and add timezone guard to prevent duplicate runs
from dual EST/EDT crons.

* Rename Secrets Manager env vars to avoid CI false positive

The reusable CI workflow greps for keywords like TOKEN and API_KEY in
Lambda environment variables. Our env vars hold Secrets Manager lookup
names, not actual secrets, but the heuristic matched the SM key name
meal-order-manager/slack-bot-token. Rename SLACK_BOT_TOKEN_SECRET to
SLACK_BOT_SM_NAME and FORM_API_KEY_SECRET to FORM_APIKEY_SM_NAME, and
reorder the Globals block so the value falls outside the grep window.
2026-05-19 16:32:19 -04:00

83 lines
2 KiB
Python

"""
Posts the weekly menu notification to Slack.
Used by GitHub Actions after uploading the form to S3.
Usage: python3 scripts/notify_slack.py <form_url>
"""
import json
import os
import sys
import urllib.request
SLACK_BOT_SM_NAME = os.environ.get(
"SLACK_BOT_SM_NAME", "meal-order-manager/slack-bot-token"
)
SLACK_CHANNEL_PARAM = os.environ.get(
"SLACK_CHANNEL_PARAM", "/meal-order-manager/slack-channel-id"
)
def get_secret(secret_id):
import boto3
return boto3.client("secretsmanager").get_secret_value(SecretId=secret_id)[
"SecretString"
]
def get_parameter(name):
import boto3
return boto3.client("ssm").get_parameter(Name=name, WithDecryption=True)[
"Parameter"
]["Value"]
def main():
if len(sys.argv) < 2:
print("Usage: notify_slack.py <form_url>", file=sys.stderr)
sys.exit(1)
form_url = sys.argv[1]
token = get_secret(SLACK_BOT_SM_NAME)
channel = get_parameter(SLACK_CHANNEL_PARAM)
text = "This week's meal order is open! Deadline: Thursday 6pm."
blocks = [
{
"type": "header",
"text": {"type": "plain_text", "text": "Meal Order Open"},
},
{
"type": "section",
"text": {
"type": "mrkdwn",
"text": (
f"*<{form_url}|Place your order>*\n\n*Deadline:* Thursday 6pm\n"
),
},
},
]
payload = json.dumps({"channel": channel, "text": text, "blocks": blocks}).encode()
req = urllib.request.Request(
"https://slack.com/api/chat.postMessage",
data=payload,
headers={
"Authorization": f"Bearer {token}",
"Content-Type": "application/json",
},
)
with urllib.request.urlopen(req) as resp:
result = json.loads(resp.read())
if result.get("ok"):
print(f"Slack notification sent to channel {channel}")
else:
print(f"Slack API error: {result.get('error')}", file=sys.stderr)
sys.exit(1)
if __name__ == "__main__":
main()