mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-09-30 14:43:13 +00:00
15 commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
1a4eacbce1
|
chore(deps): update dependency awssdk.extensions.netcore.setup to v4 | ||
|
|
d7e895ab1d
|
chore(deps): update dependency amazon.lambda.aspnetcoreserver.hosting to 2.2.1 (#330) | ||
|
|
9e579f84e2
|
fix(web,api): pin nanoid and sanitize auth logs (SEC-29) (#312)
* fix: bump nanoid to 3.3.16 and postcss to 8.5.26 Bump nanoid from 3.3.16 to 3.3.18 in web/ Bump postcss from 8.5.25 to 8.5.26 in web/ Closes [Dependabot 47] (https://github.com/Sea-Haven-Industries/proposal-system/security/dependabot/47) * fix(api): sanitize request path in internal API key logs (SEC-29) Strip CR/LF from Request.Path before logging invalid-key and disallowed-path warnings so CodeQL alerts 4 and 5 close without changing 401/403 behavior. * fix(api): log user id instead of email on cognito role sync (SEC-29) Keep AuthResponse.Email unchanged so CodeQL alert 1 closes without altering the callback payload. * fix(api): use sanitized path on both internal key logs (SEC-29) The 401 branch referenced an out-of-scope identifier and the 403 branch skipped SanitizeForLog. Cover newline-in-path logs and Cognito role-sync user-id logging with tests. |
||
|
|
1e740d3204
|
chore(deps): misc version bumps (#306)
Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 8.0.29 to 8.0.30 Bumps Microsoft.EntityFrameworkCore from 8.0.29 to 8.0.30 Bumps Microsoft.EntityFrameworkCore.Design from 8.0.29 to 8.0.30 Bumps Microsoft.EntityFrameworkCore.InMemory from 8.0.29 to 8.0.30 Bumps Microsoft.EntityFrameworkCore.Sqlite from 8.0.29 to 8.0.30 Bumps Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore from 8.0.29 to 8.0.30 Bumps Microsoft.NET.Test.Sdk from 18.8.1 to 18.9.0 Bumps NSubstitute from 6.0.0 to 6.2.0 --- updated-dependencies: - dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer dependency-version: 8.0.30 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore dependency-version: 8.0.30 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.Design dependency-version: 8.0.30 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.InMemory dependency-version: 8.0.30 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.Sqlite dependency-version: 8.0.30 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore dependency-version: 8.0.30 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api - dependency-name: NSubstitute dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
0ef46251ef
|
build(deps): batch six dependabot updates across web, lambdas, and api (#272)
* build(deps): bump react-router-dom in /web in the web group Bumps the web group in /web with 1 update: [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom). Updates `react-router-dom` from 7.18.1 to 7.18.2 - [Release notes](https://github.com/remix-run/react-router/releases) - [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.2/packages/react-router-dom/CHANGELOG.md) - [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.2/packages/react-router-dom) --- updated-dependencies: - dependency-name: react-router-dom dependency-version: 7.18.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: web ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/pdf-generate Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.56...1.43.58) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.58 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps-dev): bump jsdom from 29.1.1 to 30.0.1 in /web Bumps [jsdom](https://github.com/jsdom/jsdom) from 29.1.1 to 30.0.1. - [Release notes](https://github.com/jsdom/jsdom/releases) - [Commits](https://github.com/jsdom/jsdom/compare/v29.1.1...v30.0.1) --- updated-dependencies: - dependency-name: jsdom dependency-version: 30.0.1 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/pdf-extract Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.56...1.43.58) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.58 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/aurora-pgvector-init Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.56...1.43.58) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.58 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * Bump Amazon.Lambda.AspNetCoreServer.Hosting from 1.10.0 to 2.2.0 --- updated-dependencies: - dependency-name: Amazon.Lambda.AspNetCoreServer.Hosting dependency-version: 2.2.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
d011b66467
|
build(deps): batch Dependabot updates (#232-#240, #242) (#243)
* build(deps): bump the infra group in /infra with 3 updates Bumps the infra group in /infra with 3 updates: [constructs](https://github.com/aws/constructs), [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) and [tsx](https://github.com/privatenumber/tsx). Updates `constructs` from 10.6.0 to 10.7.0 - [Release notes](https://github.com/aws/constructs/releases) - [Commits](https://github.com/aws/constructs/compare/v10.6.0...v10.7.0) Updates `aws-cdk` from 2.1130.0 to 2.1132.0 - [Release notes](https://github.com/aws/aws-cdk-cli/releases) - [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1132.0/packages/aws-cdk) Updates `tsx` from 4.23.0 to 4.23.1 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](https://github.com/privatenumber/tsx/compare/v4.23.0...v4.23.1) --- updated-dependencies: - dependency-name: constructs dependency-version: 10.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: infra - dependency-name: aws-cdk dependency-version: 2.1132.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: infra - dependency-name: tsx dependency-version: 4.23.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: infra ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/aurora-pgvector-init Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.46...1.43.51) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.51 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/suggestions Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.46...1.43.51) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.51 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/pdf-extract Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.46...1.43.51) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.51 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/pdf-generate Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.46...1.43.51) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.51 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): bump the web group in /web with 3 updates Bumps the web group in /web with 3 updates: [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react), [react-hook-form](https://github.com/react-hook-form/react-hook-form) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Updates `lucide-react` from 1.24.0 to 1.25.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.25.0/packages/lucide-react) Updates `react-hook-form` from 7.81.0 to 7.82.0 - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](https://github.com/react-hook-form/react-hook-form/compare/v7.81.0...v7.82.0) Updates `vite` from 8.1.4 to 8.1.5 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.1.5/packages/vite) --- updated-dependencies: - dependency-name: lucide-react dependency-version: 1.25.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: web - dependency-name: react-hook-form dependency-version: 7.82.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: web - dependency-name: vite dependency-version: 8.1.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: web ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): bump the mobile-npm group in /mobile with 4 updates Bumps the mobile-npm group in /mobile with 4 updates: [@react-navigation/bottom-tabs](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/bottom-tabs), [@react-navigation/native](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native), [@react-navigation/native-stack](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native-stack) and [react-native-screens](https://github.com/software-mansion/react-native-screens). Updates `@react-navigation/bottom-tabs` from 7.18.8 to 7.18.11 - [Release notes](https://github.com/react-navigation/react-navigation/releases) - [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/bottom-tabs@7.18.11/packages/bottom-tabs/CHANGELOG.md) - [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/bottom-tabs@7.18.11/packages/bottom-tabs) Updates `@react-navigation/native` from 7.3.8 to 7.3.11 - [Release notes](https://github.com/react-navigation/react-navigation/releases) - [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native@7.3.11/packages/native/CHANGELOG.md) - [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native@7.3.11/packages/native) Updates `@react-navigation/native-stack` from 7.17.10 to 7.18.3 - [Release notes](https://github.com/react-navigation/react-navigation/releases) - [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native-stack@7.18.3/packages/native-stack/CHANGELOG.md) - [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native-stack@7.18.3/packages/native-stack) Updates `react-native-screens` from 4.26.0 to 4.26.2 - [Release notes](https://github.com/software-mansion/react-native-screens/releases) - [Commits](https://github.com/software-mansion/react-native-screens/compare/4.26.0...4.26.2) --- updated-dependencies: - dependency-name: "@react-navigation/bottom-tabs" dependency-version: 7.18.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mobile-npm - dependency-name: "@react-navigation/native" dependency-version: 7.3.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mobile-npm - dependency-name: "@react-navigation/native-stack" dependency-version: 7.18.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: mobile-npm - dependency-name: react-native-screens dependency-version: 4.26.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mobile-npm ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/library-ingest Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.46...1.43.51) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.51 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * Bump the api group with 7 updates Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 8.0.28 to 8.0.29 Bumps Microsoft.EntityFrameworkCore from 8.0.28 to 8.0.29 Bumps Microsoft.EntityFrameworkCore.Design from 8.0.28 to 8.0.29 Bumps Microsoft.EntityFrameworkCore.InMemory from 8.0.28 to 8.0.29 Bumps Microsoft.EntityFrameworkCore.Sqlite from 8.0.28 to 8.0.29 Bumps Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore from 8.0.28 to 8.0.29 Bumps Microsoft.NET.Test.Sdk from 18.7.0 to 18.8.1 --- updated-dependencies: - dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.Design dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.InMemory dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.Sqlite dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.8.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api ... Signed-off-by: dependabot[bot] <support@github.com> * Bump NSubstitute from 5.3.0 to 6.0.0 --- updated-dependencies: - dependency-name: NSubstitute dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
3c17c33c16
|
Bump Amazon.Lambda.AspNetCoreServer.Hosting and 14 others (#149)
Some checks failed
Deploy / Deploy to AWS (push) Has been cancelled
Bumps Amazon.Lambda.AspNetCoreServer.Hosting from 1.7.2 to 1.10.0 Bumps AWSSDK.DynamoDBv2 from 3.7.400 to 3.7.513.4 Bumps AWSSDK.Extensions.NETCore.Setup from 3.7.400 to 3.7.400.2 Bumps AWSSDK.S3 from 3.7.405 to 3.7.511.8 Bumps AWSSDK.SecretsManager from 3.7.500 to 3.7.504.43 Bumps AWSSDK.SQS from 3.7.500 to 3.7.502.57 Bumps FluentAssertions from 7.2.0 to 7.2.2 Bumps FluentValidation from 11.11.0 to 11.12.0 Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 8.0.27 to 8.0.28 Bumps Microsoft.EntityFrameworkCore from 8.0.27 to 8.0.28 Bumps Microsoft.EntityFrameworkCore.Design from 8.0.11 to 8.0.28 Bumps Microsoft.EntityFrameworkCore.InMemory from 8.0.11 to 8.0.28 Bumps Microsoft.EntityFrameworkCore.Sqlite from 8.0.11 to 8.0.28 Bumps Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore from 8.0.27 to 8.0.28 Bumps Microsoft.NET.Test.Sdk from 17.12.0 to 17.14.1 --- updated-dependencies: - dependency-name: Amazon.Lambda.AspNetCoreServer.Hosting dependency-version: 1.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api - dependency-name: AWSSDK.DynamoDBv2 dependency-version: 3.7.513.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: AWSSDK.Extensions.NETCore.Setup dependency-version: 3.7.400.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: AWSSDK.S3 dependency-version: 3.7.511.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: AWSSDK.SecretsManager dependency-version: 3.7.504.43 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: AWSSDK.SQS dependency-version: 3.7.502.57 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: FluentValidation dependency-version: 11.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api - dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.Design dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: FluentAssertions dependency-version: 7.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.InMemory dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.Sqlite dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 17.14.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4f1271eb50 |
audit: fix all Critical and High security/reliability issues across monorepo
6-domain audit (API, web, mobile, lambdas, infra, QA) with fixes: API security: scope internal API key middleware to allowed paths only, return 401 on invalid key instead of falling through, remove unvalidated JWT code path, sanitize error messages, add UpdateProposal validator, remove status field from UpdateProposalRequest to prevent over-posting, log swallowed exceptions in ProposalService. Infrastructure: enforce SSL on all S3 buckets, encrypt SQS queues, enable optional MFA on Cognito, add API Gateway access logging. Lambdas: fix _retry_request undefined variable across all 4 Lambdas, re-raise exceptions in pdf-extract/pdf-generate instead of swallowing, add idempotency guard to suggestions Lambda. Web: add ErrorBoundary, add auth loading state to ProtectedRoute, add mutation error toasts in AdminWorkspace, fix dead Cognito link. Mobile: add mutex to offline queue processing, distinguish permanent vs retryable failures, register all screens for both roles, log sync errors. Swagger/OpenAPI: add Swashbuckle with JWT bearer security definition, add ProducesResponseType attributes to key endpoints. Includes AUDIT-REPORT.md with complete findings and CLAUDE.md project instructions. |
||
|
|
9b502045dd |
Add site search, PO number, service category Other, and form enhancements
- Structured manual site entry with 5 separate address fields - Site search via Autocomplete with server-side filtering - Added PO number field to proposal form and AddPoNumber migration - Added Other to ServiceCategory enum with custom category text input - Label consistency: "Work Order #" → "Work Order Number", "PO Number" - Top row reflow to 3-column layout (4/4/4) - Dev PDF generation script for local testing |
||
|
|
3250d4d927
|
Bump Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore from 8.0.11 to 8.0.27 (#37)
--- updated-dependencies: - dependency-name: Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore dependency-version: 8.0.27 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
36b39c73df
|
Bump FluentValidation.AspNetCore from 11.3.0 to 11.3.1 (#18)
--- updated-dependencies: - dependency-name: FluentValidation.AspNetCore dependency-version: 11.3.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
3e43616e4a
|
Bump Microsoft.AspNetCore.Authentication.JwtBearer from 8.0.11 to 8.0.27 (#19)
--- updated-dependencies: - dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer dependency-version: 8.0.27 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ceefae2850
|
Implement Phases 2-5: Frontend, AI/RAG, PDF Generation (#22)
* Fix NuGet versions and add InitialCreate EF Core migration - Update AWSSDK.SQS and AWSSDK.SecretsManager to 3.7.500.0 (actual available versions) - Update AWSSDK.Extensions.NETCore.Setup to 3.7.400 - Generate InitialCreate migration for PostgreSQL (all 8 entities) - Build verified: 0 errors, 0 warnings * Implement Dispatcher Frontend (Phase 2) React 19 + MUI v7 + TypeScript + Vite SPA matching SHOC patterns: Redux Toolkit (auth/ui slices), TanStack React Query, axios interceptors, react-toastify, Cognito OAuth PKCE login flow, paginated proposal list, new proposal form with customer autocomplete and vendor PDF upload, read-only proposal detail with status stepper timeline. * Add AuthController for Cognito code exchange and .env.example Backend endpoint POST /api/auth/callback exchanges the OAuth authorization code with Cognito's token endpoint, auto-provisions the user in the DB, and returns the access token to the frontend. * Implement Admin Frontend Experience (Phase 3) Three-panel admin workspace: left reference panel (submission details, vendor data), center editor (refined scope, inline line item table with reorder/add/remove/pricing), right similar proposals panel (KB results with pull-to-editor). Admin dashboard with stats cards and proposal queue table. Approval flow with confirmation dialog, mark-as-sent, and create-revision actions. Role-based sidebar navigation. * Implement backend dev mode, internal API auth, and service layer enhancements - Add dev-login endpoint with local JWT signing for local development - Add InternalApiKeyMiddleware with timing-safe comparison for Lambda-to-API auth - Add DevS3Service and NoOpJobPublisher for running without AWS services - Implement CurrentUserService cascading user resolution (ID → sub → email → create) - Add async ResolveAsync() to avoid synchronous DB calls in request pipeline - Add /proposals/stats endpoint for efficient server-side status counts - Guard status transitions: only allow Draft → InReview via update endpoint - Add vendor proposals, generated PDFs, and similar proposals controllers - Add ISimilarProposalService and SimilarProposalService - Add [Authorize] to AddSimilarReference endpoint * Implement Lambda functions for PDF processing, suggestions, and library ingest - pdf-extract: Parse vendor PDFs with pdfplumber, fallback to Claude multimodal - pdf-generate: Generate branded proposal PDFs with reportlab Platypus - library-ingest: Format approved proposals as markdown and sync to Bedrock KB - suggestions: Query KB for similar proposals, generate line items via Claude - All Lambdas use internal API key auth and cold-start secret caching - Fix pdf_path unbound variable in pdf-extract error handling * Add Bedrock Knowledge Base, OpenSearch Serverless, and SQS message filtering - Provision OpenSearch Serverless collection for vector search - Create Bedrock Knowledge Base with Titan embedding model - Configure S3 data source with fixed-size chunking (512 tokens, 20% overlap) - Add suggestions Lambda with SQS event source filtering - Scope bedrock:InvokeModel IAM to specific model ARN patterns - Add internal API key secret in Secrets Manager - Add log retention (2 months) to all Lambda functions - Add docker-compose.yml for local PostgreSQL * Apply SHOC design system styling across frontend - Rewrite theme with SHOC palette (#0c4f6f primary, Nunito font, 4px radius) - Add global CSS with Google Fonts import for Nunito - Redesign Topbar with avatar initials, role subtitle, gradient header - Redesign Sidebar with 220px width, section headers, active state border - Restyle LoginPage with SHOC branded card and dev-mode role selector - Update AdminDashboard KPI cards to centered SHOC style - Add devLogin API method for local development auth flow * Fix frontend navigation bugs, differentiate Dashboard from Proposals list - Fix double nav selection by adding isNavActive() with ALL_NAV_PATHS set - Fix /admin/users routing to placeholder instead of redirect to / - Fix ProposalDetailPage Back button navigating to / instead of /proposals - Differentiate Dashboard (KPI cards + recent 5) from ProposalListPage (full paginated table) - Dashboard now uses dedicated /proposals/stats endpoint for accurate counts - Fix adminApi.getPdf dead code (axios rejects before status check) - Wire up PDF generation button in AdminWorkspace - Adjust layout: 220px drawer, 10px content padding, 64px toolbar height * Add appsettings.Development.json to gitignore Prevent dev-only signing keys and connection strings from being committed. * Fix CI failures: unused Python imports and CDK synth asset path CDK synth job needs the .NET API published first so the Lambda asset path exists. Python lint had 3 unused imports in pdf-generate. * Apply ruff formatting to all Lambda Python files |
||
| d2e12d3940 |
Implement Backend API Core (Phase 1)
Complete API layer with Clean Architecture: - Application DTOs (proposals, line items, customers, users, files, audit, dashboard) - Service interfaces (IProposalService, ILineItemService, ICustomerService, IAuditService, IS3Service, IJobPublisher) - FluentValidation validators for all create requests - Infrastructure service implementations (ProposalService, LineItemService, CustomerService, AuditService, S3Service, SqsJobPublisher, ProposalNumberGenerator) - Secrets Manager connection string resolver for RDS - API controllers: Proposals (CRUD + approve/send/revise), LineItems (CRUD + bulk), Customers, Users, Files (presigned upload/download), Admin (dashboard) - Middleware: GlobalExceptionHandler (ProblemDetails), ValidationFilter (FluentValidation pipeline) - CurrentUserService (Cognito JWT claims -> User entity, auto-provisioning) - Full DI configuration in Program.cs with Lambda hosting - Role-based authorization (dispatchers, admins, sysadmins) - CORS configured for proposals.seahaven.com + localhost |
|||
| 0b055b3ad9 |
Initial scaffold: monorepo structure, CDK stacks, CI/CD, domain model
Phase 0 of proposal-system: complete project setup including: - CDK infrastructure (3 stacks: foundation, compute, frontend) - .NET 8 solution with Clean Architecture (Domain, Application, Infrastructure, Api) - EF Core data model (PostgreSQL) with all entities - Python Lambda placeholders (pdf-extract, pdf-generate, library-ingest) - React 19 web frontend scaffold (Vite + MUI) - React Native mobile placeholder - Shared TypeScript API contracts - GitHub Actions CI/CD (ci.yaml + deploy.yaml) - OIDC deploy role (githubdeploy-proposal-system) - Dependabot configuration - Cognito User Pool with Google OAuth, PKCE clients, groups |