audit: fix all Critical and High security/reliability issues across monorepo
6-domain audit (API, web, mobile, lambdas, infra, QA) with fixes:
API security: scope internal API key middleware to allowed paths only,
return 401 on invalid key instead of falling through, remove unvalidated
JWT code path, sanitize error messages, add UpdateProposal validator,
remove status field from UpdateProposalRequest to prevent over-posting,
log swallowed exceptions in ProposalService.
Infrastructure: enforce SSL on all S3 buckets, encrypt SQS queues,
enable optional MFA on Cognito, add API Gateway access logging.
Lambdas: fix _retry_request undefined variable across all 4 Lambdas,
re-raise exceptions in pdf-extract/pdf-generate instead of swallowing,
add idempotency guard to suggestions Lambda.
Web: add ErrorBoundary, add auth loading state to ProtectedRoute,
add mutation error toasts in AdminWorkspace, fix dead Cognito link.
Mobile: add mutex to offline queue processing, distinguish permanent
vs retryable failures, register all screens for both roles, log sync
errors.
Swagger/OpenAPI: add Swashbuckle with JWT bearer security definition,
add ProducesResponseType attributes to key endpoints.
Includes AUDIT-REPORT.md with complete findings and CLAUDE.md project
instructions.
2026-05-27 15:33:27 -04:00
# Proposal System - Claude Code Project Memory
## Project Overview
Proposal management platform for Sea Haven Industries. Dispatchers submit service requests, AI generates draft line items via Bedrock RAG, admins review/approve in a pricing workspace, system produces branded PDFs.
## Architecture
- **api/**: .NET 8 API, EF Core, PostgreSQL, Cognito JWT auth
- **web/**: React 19 + MUI v7 SPA, Vite, CloudFront + S3
- **mobile/**: React Native 0.85 iOS app, offline-capable, Hermes
- **lambdas/**: Python 3.12 Lambdas (ARM64): pdf-extract, pdf-generate, library-ingest, suggestions, oss-index-creator
- **infra/**: CDK TypeScript (foundation-stack, compute-stack, frontend-stack)
- **shared/**: Shared TypeScript API contracts
- **scripts/**: Local dev helpers
## Auth Model
External: Cognito JWT via API Gateway (web + mobile client IDs, groups: dispatchers/admins/sysadmins)
2026-05-27 17:56:43 -04:00
Internal: Lambdas → .NET Function URL with Secrets Manager API key via custom middleware
audit: fix all Critical and High security/reliability issues across monorepo
6-domain audit (API, web, mobile, lambdas, infra, QA) with fixes:
API security: scope internal API key middleware to allowed paths only,
return 401 on invalid key instead of falling through, remove unvalidated
JWT code path, sanitize error messages, add UpdateProposal validator,
remove status field from UpdateProposalRequest to prevent over-posting,
log swallowed exceptions in ProposalService.
Infrastructure: enforce SSL on all S3 buckets, encrypt SQS queues,
enable optional MFA on Cognito, add API Gateway access logging.
Lambdas: fix _retry_request undefined variable across all 4 Lambdas,
re-raise exceptions in pdf-extract/pdf-generate instead of swallowing,
add idempotency guard to suggestions Lambda.
Web: add ErrorBoundary, add auth loading state to ProtectedRoute,
add mutation error toasts in AdminWorkspace, fix dead Cognito link.
Mobile: add mutex to offline queue processing, distinguish permanent
vs retryable failures, register all screens for both roles, log sync
errors.
Swagger/OpenAPI: add Swashbuckle with JWT bearer security definition,
add ProducesResponseType attributes to key endpoints.
Includes AUDIT-REPORT.md with complete findings and CLAUDE.md project
instructions.
2026-05-27 15:33:27 -04:00
## Request Flow
1. Dispatcher submits proposal (web/mobile) → InReview (no Draft stage)
2. Bedrock RAG suggests line items from pricing library
3. Admin reviews in workspace, edits line items, approves
4. PDF generation queued via SQS → Python Lambda → branded PDF → S3
5. State machine: InReview → Approved → Sent → Revised
## Infrastructure
AWS us-east-1, RDS PostgreSQL 15, S3, SQS+DLQ, Cognito+Google OAuth, OpenSearch Serverless, Bedrock KB, GitHub Actions OIDC, CloudFront+S3 OAC
## Agent Delegation Rules
### For audit and hardening work, use the Explore-Plan-Execute pipeline:
1. Spawn specialist subagents for parallel investigation (api-security, web-audit, mobile-audit, lambda-pipeline, infra-cicd, qa-testing)
2. Consolidate findings into AUDIT-REPORT.md before implementing
3. Prioritize: Critical > High > Medium > Low
4. Implement fixes in logical phases, commit after each phase
5. Use separate git worktrees/branches for parallel implementation where safe
### Working Rules
- Never commit secrets, credentials, .env files, or local artifacts
- If secrets found in code: document, remove safely, ensure proper config mechanism
- Preserve existing business logic unless broken, insecure, or contradicted
- Run lint/typecheck/build/test after each phase
- If context reaches 65%, pause, commit, update AUDIT-REPORT.md with HANDOFF ADDENDUM
### Severity Levels
- **Critical**: security/data exposure/auth bypass/data corruption
- **High**: broken core workflow, deployment blocker, missing authz, invalid infra
- **Medium**: reliability, validation, logging, test gaps
2026-05-27 17:56:43 -04:00
- **Low**: cleanup, DX, docs, polish
## Audit Status
AUDIT-REPORT.md completed 2026-05-27. 5 Critical, 36 High, 75+ Medium, 60+ Low findings. Phase 1-5 complete: all Critical/High fixed, 17 Medium fixed, CI runs 108 tests.
### Critical Findings (fix first)
- **API-C1**: InternalApiKeyMiddleware applies globally, bypasses JWT on any route
- **API-C2**: JWT signature validation skipped when Authority is empty
- **WEB-C1**: JWT stored in localStorage (XSS token theft)
- **LAM-C1 / INF-H1**: Function URL authType NONE, publicly accessible
- **QA-C1**: Zero test coverage, no test projects, CI runs no tests
### Remediation Conventions
- Reference finding IDs (API-C1, WEB-H3, LAM-H4, etc.) in commit messages and code comments
- Format: `// Fix: API-C1 — scope internal key to /internal/ paths`
- Update AUDIT-REPORT.md after each phase: mark fixed findings, note deferred items
- Parallel-safe worktree splits: api/ changes, web/ changes, and infra/ changes don't conflict
- Verify after each phase: `dotnet build` (api), `npx tsc --noEmit` (web), `npx cdk synth` (infra)