Commit graph

7 commits

Author SHA1 Message Date
Adam Moussa
4cc049e958
Repo hygiene: PR labeler + README badges + dependabot (INFRA-56/57/66) (#57)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-06-11 14:44:27 -04:00
Adam Moussa
c0b68382c8
chore(deps): remove blanket aws-cdk-lib dependabot ignore (#47)
Per handbook Pinning Principle: exact pins are kept current by Dependabot version updates gated by CI + dependency review. Blanket ignores let pins rot (see today's fast-uri incident).
2026-06-05 13:57:53 -04:00
Adam Moussa
7732069a73
fix(deps): pin aws-cdk-lib to ==2.257.0 (#43)
Some checks are pending
Deploy / deploy (push) Waiting to run
* fix(deps): re-pin aws-cdk-lib to ==2.253.1

* fix(deps): pin aws-cdk-lib to 2.257.0 (exact)
2026-06-05 13:22:45 -04:00
Adam Moussa
5112c1345b
Merge workorder-ingest into unified procurement repo (#22)
* Merge workorder-ingest pipeline into unified repo

Move PO lambdas under lambdas/po/, add WO pipeline under lambdas/wo/.
Two independent CloudFormation stacks in one CDK app. Fix WO stack
compliance: ARM64 architecture, 60-day log retention, aarch64 bundling,
RETAIN on Anthropic secret. Remove stale CodePipeline buildspec.

* Fix test_local.py import path and remove dead shared/models.py

test_local.py referenced the old lambdas/email_processor path. Updated
to lambdas/wo/email_processor. Removed shared/ directory entirely as
nothing imports from it.

* Escape HTML in both web UI dashboards to prevent XSS

Both Function URLs are public (auth_type=NONE) and render
email-derived content via f-strings. Attacker-crafted emails
could inject scripts. Added html.escape() on all interpolated
values in both PO and WO dashboards.

* Add pagination to WO web UI scan

get_work_orders() only fetched the first 1MB page from DynamoDB.
Loop on LastEvaluatedKey to match the PO web UI pattern.

* Fix esc(None) TypeError and javascript: scheme in PO web UI

Coerce supplier name through `or ""` before escaping to handle
nested None from DynamoDB. Add scheme allowlist on view_order_url
to block javascript:/data: hrefs from LLM-extracted URLs.

* Fix WO render_badge None guard, updated_at slice, and backfill path

Add null guard to WO render_badge matching the PO version. Use
`or ""` before slicing updated_at to handle explicit None values.
Fix backfill_sites.py sys.path to use new lambdas/po/site_extractor.

* Harden WO web UI and fix JS-context XSS in both dashboards

- Use json.dumps for onclick URLs to prevent JS string breakout
- Add .lower() to WO render_badge color lookup matching PO pattern
- Add pagination to get_comments query
- Cap get_work_orders to 500 results matching PO pattern

* Apply ruff formatting to web UI handlers
2026-05-12 15:21:06 -04:00
Adam Moussa
d1c1cb2f8b
Update Dependabot: remove assignees, group minor/patch updates (#15) 2026-05-08 14:24:21 -04:00
Adam Moussa
18b3e082b8 Auto-assign Dependabot PRs to amoussa1229 2026-05-02 17:26:47 -04:00
Adam Moussa
bcc76dbf6a Add Dependabot version update configuration 2026-05-02 17:14:45 -04:00