diff --git a/README.md b/README.md index 4ca505c..22f7a2c 100644 --- a/README.md +++ b/README.md @@ -62,22 +62,17 @@ Two separate CashPro APIs are used, each with its own OAuth credentials: - Production: `https://api.bofa.com` - Sandbox: `https://api-sb.bofa.com` -## SSM Parameters +## Secrets -All BoA credentials and config are stored in AWS SSM Parameter Store (SecureString): +All BoA and Slack credentials are stored in AWS Secrets Manager (per `engineering-handbook/secrets-and-config.md`). The Slack token is a plaintext secret; the two BoA secrets are JSON grouping each API's credentials: -| Parameter | Description | -|-----------|-------------| -| `/payments-dashboard/boa-check-mgmt-app-id` | Check Management application ID | -| `/payments-dashboard/boa-check-mgmt-client-id` | Check Management client ID | -| `/payments-dashboard/boa-check-mgmt-token` | Check Management client secret | -| `/payments-dashboard/boa-reporting-app-id` | Reporting application ID | -| `/payments-dashboard/boa-account-info-client-id` | Reporting client ID | -| `/payments-dashboard/boa-account-info-token` | Reporting client secret | -| `/payments-dashboard/boa-account-number` | BoA account number | -| `/payments-dashboard/boa-company-id` | CashPro company ID (check management) | -| `/payments-dashboard/boa-bank-id` | BoA routing number | -| `/payments-dashboard/slack-bot-token` | Slack Bot OAuth token | +| Secret | Type | Contents | +|--------|------|----------| +| `payments-dashboard/slack-bot-token` | plaintext | Slack Bot OAuth token (used by `processPayrollEmail`, `slackAppHome`) | +| `payments-dashboard/boa-check-mgmt` | JSON | `appId`, `clientId`, `token`, `accountNumber`, `companyId` — Check Management API (`processPaymentCsv`) | +| `payments-dashboard/boa-reporting` | JSON | `appId`, `clientId`, `token`, `accountNumber`, `bankId` — Reporting API (`fetchBoaTransactions`) | + +`boa-account-number` is duplicated into both BoA secrets. Each Lambda is granted `secretsmanager:GetSecretValue` scoped to only the secret it needs. The Expense Approval Bot uses two additional secrets (`payments-dashboard/expense-slack-token`, `payments-dashboard/expense-slack-signing-secret`). ## Scripts @@ -94,4 +89,4 @@ sam build sam deploy --guided ``` -The `BOA_BASE_URL` environment variable in `template.yaml` controls whether Lambdas hit production (`https://api.bofa.com`) or sandbox (`https://api-sb.bofa.com`). All other BoA config is read from SSM at runtime. +The `BOA_BASE_URL` environment variable in `template.yaml` controls whether Lambdas hit production (`https://api.bofa.com`) or sandbox (`https://api-sb.bofa.com`). All other BoA config is read from Secrets Manager at runtime.