Certificate installs to keychain but security find-identity shows
no signing identities. Added verbose match, explicit keychain params,
setup_ci force, profile_name in update_code_signing_settings, and
diagnostic security find-identity commands to diagnose the import.
Add update_code_signing_settings to disable automatic signing and
set development team (9KAQYC653W) + Apple Distribution identity.
Fixes Xcode error "Signing requires a development team" in CI.
The .p8 file from Apple has no PEM headers, just the raw base64
body. Add strategies for: headerless body wrapped with PEM headers,
base64-decoded DER re-wrapped as PEM, and double-decoded DER. Also
show hex bytes in diagnostics for better binary data analysis.
Secret has been re-set with properly PEM-wrapped + base64-encoded
content matching the reusable workflow's expected format.
Replace fragile BEGIN/base64 branch with multi-strategy key parser
that handles raw PEM, escaped newlines, base64-encoded PEM, mangled
line wrapping, CR/LF issues, and double-encoding. Validates key with
OpenSSL::PKey.read before passing to Fastlane via key_filepath (temp
file) instead of key_content to bypass Fastlane's own parsing. Prints
safe diagnostics (no key material) if all strategies fail.
The secret may contain either raw PEM text (with BEGIN header) or
base64-encoded PEM. Detect format and pass appropriately to fastlane
instead of blindly base64-decoding (which corrupts raw PEM content).
alias_method doesn't reliably wrap C-extension class methods. Switch to
singleton_class.prepend which correctly intercepts the call chain. Falls
back to OpenSSL::PKey.read when EC.new raises on PKCS#8 format keys.
Fastlane 2.234.0 uses OpenSSL::PKey::EC.new which fails with "invalid
curve name" on PKCS#8 keys under OpenSSL 3.x. Add monkey-patch to fall
back to OpenSSL::PKey.read which handles both formats.
The app_store_connect_api_key action fails with "invalid curve name"
when is_key_content_base64 is true on macOS runners with OpenSSL 3.x.
Decoding the key manually and passing the raw PEM content avoids the
OpenSSL incompatibility. Also reverts the Fastlane version pin since
2.235.0 doesn't exist.
Fastlane 2.234.0 fails with "invalid curve name" on macos-latest
runners due to an OpenSSL 3.x incompatibility in the ASC API key
parsing. Fixed in 2.235.0. Removed lockfile so CI regenerates it
with the correct Ruby/bundler version.
react-native 0.79 requires @react-native-community/cli as an
explicit dev dependency for CocoaPods autolinking. Also adds
paths-ignore for mobile/ on the AWS deploy workflow so mobile-only
changes don't trigger unnecessary infrastructure deploys.
Dependabot bumped @react-native/babel-preset from 0.79 to 0.85,
which is incompatible with react-native 0.79. The 0.85 preset
expects CLI infrastructure that doesn't exist in 0.79, breaking
pod install during the mobile deploy.
The log group already exists — created by the compute stack's
logRetention setting on the suggestions Lambda. Adding it to the
foundation stack caused a duplicate resource error on deploy.
oss-index-creator Lambda was missing functionName, arm64 architecture,
and explicit log retention — all required by the engineering handbook.
CI workflow was not passing node-version to reusable workflows, risking
drift. Removed unused _api_request helper from all four main Lambdas.
Added missing suggestions log group to foundation stack.
- Remove verbose print statements from Lambda handler
- Add dependabot pip entry for oss-index-creator
- Update README with new Lambda and deployed stack state
The Bedrock Knowledge Base creation was failing with 403/404 because
the OpenSearch Serverless data access policy hadn't propagated before
the KB tried to connect. Adds a CDK Custom Resource (using opensearch-py)
that creates the vector index with retry logic, ensuring the full
dependency chain: Collection → DataAccessPolicy → Index → KnowledgeBase.
* Add iOS native project for React Native mobile app
Xcode project with bundle ID com.seahavenind.proposals,
CocoaPods configuration, and app scaffolding.
* Add Fastlane configuration for iOS builds and TestFlight distribution
Configures match with S3 storage (seahaven-ios-certificates bucket)
for code signing and a beta lane for automated TestFlight uploads.
* Add mobile CI job and iOS CD workflow (disabled)
CI: adds mobile typecheck job on PRs.
CD: deploy-mobile.yaml builds and uploads to TestFlight via
Fastlane on a macOS runner with OIDC auth for match S3 access.
Currently workflow_dispatch only — activate for V1 release.
* Refactor workflows to thin wrappers calling org reusable workflows
CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam
from the org repo. Deploy calls cd-cdk with post-deploy script
for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios.
Adds deploy concurrency groups to both deploy workflows.
* Add mobile Dependabot entries and remove assignees
Add npm and bundler ecosystems for mobile/. Remove assignees
from all entries — convention no longer in use.
* Add comprehensive README for the proposal-system monorepo
* Fix mobile TypeScript errors and add package-lock.json
Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef
type error, fix navigation type cast, add @types/react-native-vector-icons,
and generate package-lock.json for CI.
* Add .npmrc for mobile to resolve peer dependency conflicts
react-native-screens@4.x requires react-native >= 0.82 but the
project uses 0.79. legacy-peer-deps allows installation until
the next React Native upgrade.
Security: add system identity claims to InternalApiKeyMiddleware so
Lambda-to-API calls resolve a proper user, inject ICurrentUserService
into GeneratedPdfsController to replace Guid.Empty, and consolidate
CurrentUserService into a single ResolveAsync lookup chain.
Quality: replace four COUNT queries in ProposalService.GetStatsAsync
with a single grouped query, convert all Lambda print() to structured
logging, and add retry helpers for Lambda-to-API HTTP calls.
* Fix NuGet versions and add InitialCreate EF Core migration
- Update AWSSDK.SQS and AWSSDK.SecretsManager to 3.7.500.0 (actual available versions)
- Update AWSSDK.Extensions.NETCore.Setup to 3.7.400
- Generate InitialCreate migration for PostgreSQL (all 8 entities)
- Build verified: 0 errors, 0 warnings
* Implement Dispatcher Frontend (Phase 2)
React 19 + MUI v7 + TypeScript + Vite SPA matching SHOC patterns:
Redux Toolkit (auth/ui slices), TanStack React Query, axios interceptors,
react-toastify, Cognito OAuth PKCE login flow, paginated proposal list,
new proposal form with customer autocomplete and vendor PDF upload,
read-only proposal detail with status stepper timeline.
* Add AuthController for Cognito code exchange and .env.example
Backend endpoint POST /api/auth/callback exchanges the OAuth
authorization code with Cognito's token endpoint, auto-provisions
the user in the DB, and returns the access token to the frontend.
* Implement Admin Frontend Experience (Phase 3)
Three-panel admin workspace: left reference panel (submission details,
vendor data), center editor (refined scope, inline line item table with
reorder/add/remove/pricing), right similar proposals panel (KB results
with pull-to-editor). Admin dashboard with stats cards and proposal
queue table. Approval flow with confirmation dialog, mark-as-sent,
and create-revision actions. Role-based sidebar navigation.
* Implement backend dev mode, internal API auth, and service layer enhancements
- Add dev-login endpoint with local JWT signing for local development
- Add InternalApiKeyMiddleware with timing-safe comparison for Lambda-to-API auth
- Add DevS3Service and NoOpJobPublisher for running without AWS services
- Implement CurrentUserService cascading user resolution (ID → sub → email → create)
- Add async ResolveAsync() to avoid synchronous DB calls in request pipeline
- Add /proposals/stats endpoint for efficient server-side status counts
- Guard status transitions: only allow Draft → InReview via update endpoint
- Add vendor proposals, generated PDFs, and similar proposals controllers
- Add ISimilarProposalService and SimilarProposalService
- Add [Authorize] to AddSimilarReference endpoint
* Implement Lambda functions for PDF processing, suggestions, and library ingest
- pdf-extract: Parse vendor PDFs with pdfplumber, fallback to Claude multimodal
- pdf-generate: Generate branded proposal PDFs with reportlab Platypus
- library-ingest: Format approved proposals as markdown and sync to Bedrock KB
- suggestions: Query KB for similar proposals, generate line items via Claude
- All Lambdas use internal API key auth and cold-start secret caching
- Fix pdf_path unbound variable in pdf-extract error handling
* Add Bedrock Knowledge Base, OpenSearch Serverless, and SQS message filtering
- Provision OpenSearch Serverless collection for vector search
- Create Bedrock Knowledge Base with Titan embedding model
- Configure S3 data source with fixed-size chunking (512 tokens, 20% overlap)
- Add suggestions Lambda with SQS event source filtering
- Scope bedrock:InvokeModel IAM to specific model ARN patterns
- Add internal API key secret in Secrets Manager
- Add log retention (2 months) to all Lambda functions
- Add docker-compose.yml for local PostgreSQL
* Apply SHOC design system styling across frontend
- Rewrite theme with SHOC palette (#0c4f6f primary, Nunito font, 4px radius)
- Add global CSS with Google Fonts import for Nunito
- Redesign Topbar with avatar initials, role subtitle, gradient header
- Redesign Sidebar with 220px width, section headers, active state border
- Restyle LoginPage with SHOC branded card and dev-mode role selector
- Update AdminDashboard KPI cards to centered SHOC style
- Add devLogin API method for local development auth flow
* Fix frontend navigation bugs, differentiate Dashboard from Proposals list
- Fix double nav selection by adding isNavActive() with ALL_NAV_PATHS set
- Fix /admin/users routing to placeholder instead of redirect to /
- Fix ProposalDetailPage Back button navigating to / instead of /proposals
- Differentiate Dashboard (KPI cards + recent 5) from ProposalListPage (full paginated table)
- Dashboard now uses dedicated /proposals/stats endpoint for accurate counts
- Fix adminApi.getPdf dead code (axios rejects before status check)
- Wire up PDF generation button in AdminWorkspace
- Adjust layout: 220px drawer, 10px content padding, 64px toolbar height
* Add appsettings.Development.json to gitignore
Prevent dev-only signing keys and connection strings from being committed.
* Fix CI failures: unused Python imports and CDK synth asset path
CDK synth job needs the .NET API published first so the Lambda asset
path exists. Python lint had 3 unused imports in pdf-generate.
* Apply ruff formatting to all Lambda Python files