Commit graph

17 commits

Author SHA1 Message Date
dependabot[bot]
64ff6f09ca
Bump aws-cdk-lib in /cdk in the minor-and-patch group (#48)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group in /cdk with 1 update: [aws-cdk-lib](https://github.com/aws/aws-cdk).


Updates `aws-cdk-lib` from 2.257.0 to 2.258.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.257.0...v2.258.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.258.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-05 14:49:27 -04:00
Adam Moussa
7732069a73
fix(deps): pin aws-cdk-lib to ==2.257.0 (#43)
Some checks are pending
Deploy / deploy (push) Waiting to run
* fix(deps): re-pin aws-cdk-lib to ==2.253.1

* fix(deps): pin aws-cdk-lib to 2.257.0 (exact)
2026-06-05 13:22:45 -04:00
dependabot[bot]
ad17cac484
Update aws-cdk-lib requirement from >=2.255.0 to >=2.257.0 in /cdk (#36)
Updates the requirements on [aws-cdk-lib](https://github.com/aws/aws-cdk) to permit the latest version.
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.255.0...v2.257.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.257.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-03 22:48:09 +00:00
Adam Moussa
9370abf9ab
Drop three read-idle GSIs (audit M-20) (#35)
Some checks are pending
Deploy / deploy (push) Waiting to run
* Drop read-idle GSIs: by-state and status-index

Audit M-20: 30 days of CloudWatch metrics show 0 reads on both
indexes against 518 (by-state) and ~50k (status-index) WCU of write
amplification. No code path queries either index.

site-code-index follows in the next commit - CloudFormation allows
only one GSI change per table per deploy.

* Drop read-idle site-code-index GSI

Second half of the M-20 cleanup - deployed separately because
CloudFormation allows one GSI change per table per update.
2026-06-03 15:32:23 -04:00
Adam Moussa
a5d2bee748
Fix po-email-processor bundling for arm64 target (#34)
po-email-processor has been down since 2026-05-12: the bundling
command installed wheels for the build host's architecture, so CD
deploys from amd64 runners shipped x86_64 pydantic_core into an
ARM_64 function, crashing every INIT with Runtime.ImportModuleError.

Pin the pip platform to manylinux2014_aarch64 with --only-binary,
matching the pattern wo_stack already uses.

Verified live: deployed from branch, manual invoke OK; 920 emails
from the outage window backfilled via scripts/reprocess logic.
2026-06-03 14:56:02 -04:00
dependabot[bot]
d233488875
Update aws-cdk-lib requirement from >=2.253.1 to >=2.255.0 in /cdk (#28)
Updates the requirements on [aws-cdk-lib](https://github.com/aws/aws-cdk) to permit the latest version.
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.253.1...v2.255.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.255.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-19 19:20:42 +00:00
Adam Moussa
5112c1345b
Merge workorder-ingest into unified procurement repo (#22)
* Merge workorder-ingest pipeline into unified repo

Move PO lambdas under lambdas/po/, add WO pipeline under lambdas/wo/.
Two independent CloudFormation stacks in one CDK app. Fix WO stack
compliance: ARM64 architecture, 60-day log retention, aarch64 bundling,
RETAIN on Anthropic secret. Remove stale CodePipeline buildspec.

* Fix test_local.py import path and remove dead shared/models.py

test_local.py referenced the old lambdas/email_processor path. Updated
to lambdas/wo/email_processor. Removed shared/ directory entirely as
nothing imports from it.

* Escape HTML in both web UI dashboards to prevent XSS

Both Function URLs are public (auth_type=NONE) and render
email-derived content via f-strings. Attacker-crafted emails
could inject scripts. Added html.escape() on all interpolated
values in both PO and WO dashboards.

* Add pagination to WO web UI scan

get_work_orders() only fetched the first 1MB page from DynamoDB.
Loop on LastEvaluatedKey to match the PO web UI pattern.

* Fix esc(None) TypeError and javascript: scheme in PO web UI

Coerce supplier name through `or ""` before escaping to handle
nested None from DynamoDB. Add scheme allowlist on view_order_url
to block javascript:/data: hrefs from LLM-extracted URLs.

* Fix WO render_badge None guard, updated_at slice, and backfill path

Add null guard to WO render_badge matching the PO version. Use
`or ""` before slicing updated_at to handle explicit None values.
Fix backfill_sites.py sys.path to use new lambdas/po/site_extractor.

* Harden WO web UI and fix JS-context XSS in both dashboards

- Use json.dumps for onclick URLs to prevent JS string breakout
- Add .lower() to WO render_badge color lookup matching PO pattern
- Add pagination to get_comments query
- Cap get_work_orders to 500 results matching PO pattern

* Apply ruff formatting to web UI handlers
2026-05-12 15:21:06 -04:00
dependabot[bot]
429611030e
Update aws-cdk-lib requirement from >=2.252.0 to >=2.253.1 in /cdk (#16)
Updates the requirements on [aws-cdk-lib](https://github.com/aws/aws-cdk) to permit the latest version.
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/v2.253.1/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.252.0...v2.253.1)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.253.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 22:27:13 +00:00
Adam Moussa
abdf2aa035
Add CI workflow (#18)
* Add CI workflow and apply ruff formatting

* Disable cdk synth — email_processor uses pre-built package dir

The email_processor Lambda bundles deps into a gitignored package/
directory. cdk synth fails in CI without a build step to recreate it.
Disabling until packaging is standardized.

* Use CDK BundlingOptions for email_processor Lambda packaging

Replaces the pre-built gitignored package/ directory with CDK's
built-in bundling. Deps are now installed inside a Docker container
during cdk synth, so the build works identically locally and in CI.
Re-enables run-cdk-synth in the CI workflow.
2026-05-08 16:01:21 -04:00
dependabot[bot]
a7ca58d9d9
Update aws-cdk-lib requirement from >=2.150.0 to >=2.252.0 in /cdk
Updates the requirements on [aws-cdk-lib](https://github.com/aws/aws-cdk) to permit the latest version.
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/compare/v2.150.0...v2.252.0)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.252.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-02 21:24:26 +00:00
dependabot[bot]
1832ce2853
Update constructs requirement from >=10.0.0 to >=10.6.0 in /cdk
Updates the requirements on [constructs](https://github.com/aws/constructs) to permit the latest version.
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.0.0...v10.6.0)

---
updated-dependencies:
- dependency-name: constructs
  dependency-version: 10.6.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-02 21:17:20 +00:00
Adam Moussa
e66062c934 Align PO schema with enriched records and improve extraction prompt
Replaces extraction prompt with domain-specific rules: trade
classification taxonomy (23 categories), site_code skip list,
zip padding, revision email type, and structured extraction for
fiscal_year, trade, and coupa_category.

Handler changes:
- New "revision" email type overwrites existing PO via put_item
- enrich_parsed() adds top-level state, ship_to_raw, data_source
- pad_zip() zero-pads short zip codes (e.g., "7001" → "07001")
- Removed invoice_total/invoice_count (Payee Central only)

Web UI: added revision badge, new detail fields (site code, state,
trade, fiscal year, coupa category, data source), line item table
now shows Qty/Unit/Price columns, list view shows Site and Trade.

CDK: fixed StreamViewType to match deployed table (NEW_IMAGE).
README: documented PO record schema and revision flow.
2026-05-01 19:53:26 -04:00
Adam Moussa
36f49ae259
Add CI/CD pipeline and fix stack name to kebab-case (#3)
* Add CI/CD pipeline and fix stack name to kebab-case

CodePipeline V2 (po-ingest-pipeline) triggers CodeBuild on push
to main, running cdk deploy via buildspec.yml. Stack name changed
from PoIngestStack to po-ingest to match naming conventions.

* Add RETAIN policy to Secrets Manager secret

Prevents the Anthropic API key from being deleted if the stack
is ever removed. Matches the RETAIN policy on all other stateful
resources (DynamoDB tables, S3 bucket).
2026-05-01 19:17:19 -04:00
Adam Moussa
f5d1eaeb5b Add address reverse-lookup fallback and pending-site-review table
When no site code is found via Claude extraction or regex cascade,
the Lambda now checks the PO address against a cold-start cache of
verified-sites (normalized street + zip match). If still no match,
the PO is written to a new pending-site-review table for manual
verification against Payee Central.
2026-04-30 15:01:09 -04:00
Adam Moussa
ec416079f5 Add verified-sites pipeline via DynamoDB Streams
Enable DynamoDB Streams on purchase-orders table and add a site-extractor
Lambda that extracts Amazon facility codes and addresses from PO ship-to
data, upserting them into a new verified-sites table. Includes a backfill
script for existing POs and upgrades existing Lambdas to arm64 + 60-day
log retention.
2026-04-30 14:26:53 -04:00
Adam Moussa
3514e74e40 Fix stack naming to follow kebab-case convention
Pin existing CloudFormation stack name via stack_name property so
the live stack is not affected. Construct ID now follows the org
kebab-case standard.
2026-04-28 14:43:48 -04:00
Adam Moussa
fc690dd958 Initial commit: PO email ingestion pipeline
CDK stack with SES receipt rule, S3 bucket, email processor Lambda
(Claude-powered extraction), web UI Lambda with Function URL, and
DynamoDB for storage. Includes reprocessing script for missed emails.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 12:12:30 -04:00