Commit graph

8 commits

Author SHA1 Message Date
Adam Moussa
3e781c5cd9
fix(deploy): write Lambda zips to an absolute output path (PLAT-79) (#110)
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
2026-09-16 18:38:05 +00:00
Adam Moussa
0e3e95c240
feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79) (#109)
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* feat(infra): migrate payments-dashboard to HCP Terraform (PLAT-79)

Replace the mgmt SAM stack with a prod-only HCP workspace using the afterhours stub-plus-zip-CD seam so GitHub Actions owns function code and Terraform owns infrastructure.

* fix(infra): pin secret and CMK ARNs for bootstrap-plan

hcptf-bootstrap-plan cannot ssm:GetParameter or DescribeSecret, so the first plan must not data-source those values.

* fix(infra): add EIP describe and DynamoDB CMK grants for first apply

Scoped apply missed ec2:DescribeAddressesAttribute and kms Encrypt/Decrypt/GenerateDataKey on the table CMK.
2026-09-16 18:29:01 +00:00
Adam Moussa
90accf2f39 Migrate secrets from SSM to Secrets Manager
API tokens and credentials must live in Secrets Manager per
secrets-and-config.md, but the four original payment Lambdas still
read 10 SecureString SSM params. Move them to three grouped secrets
(slack-bot-token plaintext, boa-check-mgmt and boa-reporting as JSON),
matching the pattern the expense Lambdas already use. IAM is scoped to
secretsmanager:GetSecretValue per secret; the VPC Lambdas reach the
public endpoint over the existing NAT path. Test/reissue scripts and
the client-ssm dependency are updated/removed accordingly.

Refs: #3
2026-06-02 20:29:18 -04:00
Adam Moussa
b242df15b5 Log BoA submissions to DDB and surface in Slack App Home
Capture response headers, body, and transactionId on every check-issue
API call; persist as boa_txn#<ts>#<action> records with 90-day TTL.
Add "Recent BoA Submissions" section to App Home showing the last 10
with click-to-copy transactionId.

Motivation: BoA support asked for a transactionId from a past
successful call and we had no way to recover it from CloudWatch
summary logs alone.

Also adds simulate-csv.cjs (dry-run preview) and stampli-uploader.sh
(launchd-invoked S3 uploader), and gitignores debug artifacts.
2026-04-20 17:40:55 -04:00
Adam Moussa
ffd46c4bda Fix BoA transaction matching, add status progression protection, enable daily schedule
- Fix transaction code mapping (475=Cleared, 255=Returned) in fetchBoaTransactions
- Match on customerReference instead of bankReference for check number matching
- Add bank-confirmed protection: CSV cannot override status once bank confirms Cleared
- Add status progression guard: CSV cannot regress status backward in lifecycle
- Cleared status is permanent — cannot be voided, cancelled, or changed
- Enable daily fetchBoaTransactions schedule (9am ET weekdays)
- Add production test script and dry run simulation script
2026-04-14 17:43:13 -04:00
Adam Moussa
957fb726ab Add OAuth token exchange to BoA sandbox test script
Use correct sandbox base URL (api-sb.bofa.com), proper OAuth
client-credentials flow with applicationID, and routing number
for transaction inquiries. Both APIs now return 200 in sandbox.
2026-04-13 16:08:57 -04:00
Adam Moussa
a9ad5f7dd1 Add BoA CashPro sandbox test script and update seed script
- Add standalone test script to validate sandbox API connectivity
  for check management and account info endpoints
- Update seed-bank-status to persist amount, issueDate, and method fields
- Add data/ to gitignore
2026-04-13 15:34:01 -04:00
Adam Moussa
fc37c6e8f9 Add seed scripts from master (seed-from-csv, seed-bank-status) 2026-04-10 17:35:57 -04:00