mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-09-30 08:53:12 +00:00
- Add OAuth client-credentials token exchange to both Lambda handlers - Fix sandbox/prod base URL (api-sb.bofa.com / api.bofa.com) - Fix issueAction casing to add_Issue / cancel_Issue per API docs - Fix transaction inquiry response parsing (accountTransactions array) - Move all BoA config (app IDs, bank ID) from env vars to SSM params - Update template.yaml with correct SSM param names and policies - Add project README with architecture, API details, and SSM param reference
2.9 KiB
2.9 KiB
Payments Dashboard
AWS SAM application that ingests payment CSVs, syncs check data with Bank of America CashPro APIs, and surfaces an outstanding-payments dashboard in Slack.
Architecture
- ProcessPaymentCsv - Lambda triggered by S3 CSV upload. Parses payments, upserts to DynamoDB, and submits new/cancelled checks to the CashPro Check Management API.
- FetchBoaTransactions - Scheduled Lambda (weekdays 9am ET). Calls the CashPro Previous Day Transaction Inquiry API and matches cleared/returned checks back to DynamoDB records.
- SlackAppHome - Lambda behind API Gateway. Renders the payments dashboard on the Slack App Home tab with outstanding aging buckets and drill-down modals.
All three Lambdas run inside a VPC with a NAT Gateway for a static outbound IP (required by BoA IP whitelisting).
BoA CashPro API Integration
Two separate CashPro APIs are used, each with its own OAuth credentials:
| API | Purpose | Endpoint |
|---|---|---|
| Check Management | Issue and cancel checks | /cashpro/checkmanagement/v1/check-issues |
| Reporting (Transaction Inquiry) | Fetch previous-day transactions | /cashpro/reporting/v1/transaction-inquiries/previous-day |
Authentication flow:
- POST to
/authn/v1/client-authenticationwithapplicationID,client_id, andclient_secret - Receive a Bearer
access_token(valid 1 hour) - Pass the token in the
Authorizationheader for subsequent API calls
Base URLs:
- Production:
https://api.bofa.com - Sandbox:
https://api-sb.bofa.com
SSM Parameters
All BoA credentials and config are stored in AWS SSM Parameter Store (SecureString):
| Parameter | Description |
|---|---|
/payments-dashboard/boa-check-mgmt-app-id |
Check Management application ID |
/payments-dashboard/boa-check-mgmt-client-id |
Check Management client ID |
/payments-dashboard/boa-check-mgmt-token |
Check Management client secret |
/payments-dashboard/boa-reporting-app-id |
Reporting application ID |
/payments-dashboard/boa-account-info-client-id |
Reporting client ID |
/payments-dashboard/boa-account-info-token |
Reporting client secret |
/payments-dashboard/boa-account-number |
BoA account number |
/payments-dashboard/boa-company-id |
CashPro company ID (check management) |
/payments-dashboard/boa-bank-id |
BoA routing number |
/payments-dashboard/slack-bot-token |
Slack Bot OAuth token |
Scripts
| Script | Purpose |
|---|---|
scripts/test-boa-sandbox.js |
One-off sandbox connectivity test for both CashPro APIs |
scripts/seed-from-csv.js |
Seed DynamoDB from a local CSV file |
scripts/seed-bank-status.js |
Seed bank clear status data into DynamoDB |
Deployment
sam build
sam deploy --guided
The BOA_BASE_URL environment variable in template.yaml controls whether Lambdas hit production (https://api.bofa.com) or sandbox (https://api-sb.bofa.com). All other BoA config is read from SSM at runtime.