mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-09-30 11:13:14 +00:00
13 commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
d011b66467
|
build(deps): batch Dependabot updates (#232-#240, #242) (#243)
* build(deps): bump the infra group in /infra with 3 updates Bumps the infra group in /infra with 3 updates: [constructs](https://github.com/aws/constructs), [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) and [tsx](https://github.com/privatenumber/tsx). Updates `constructs` from 10.6.0 to 10.7.0 - [Release notes](https://github.com/aws/constructs/releases) - [Commits](https://github.com/aws/constructs/compare/v10.6.0...v10.7.0) Updates `aws-cdk` from 2.1130.0 to 2.1132.0 - [Release notes](https://github.com/aws/aws-cdk-cli/releases) - [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1132.0/packages/aws-cdk) Updates `tsx` from 4.23.0 to 4.23.1 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](https://github.com/privatenumber/tsx/compare/v4.23.0...v4.23.1) --- updated-dependencies: - dependency-name: constructs dependency-version: 10.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: infra - dependency-name: aws-cdk dependency-version: 2.1132.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: infra - dependency-name: tsx dependency-version: 4.23.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: infra ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/aurora-pgvector-init Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.46...1.43.51) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.51 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/suggestions Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.46...1.43.51) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.51 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/pdf-extract Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.46...1.43.51) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.51 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/pdf-generate Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.46...1.43.51) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.51 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): bump the web group in /web with 3 updates Bumps the web group in /web with 3 updates: [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react), [react-hook-form](https://github.com/react-hook-form/react-hook-form) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Updates `lucide-react` from 1.24.0 to 1.25.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.25.0/packages/lucide-react) Updates `react-hook-form` from 7.81.0 to 7.82.0 - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](https://github.com/react-hook-form/react-hook-form/compare/v7.81.0...v7.82.0) Updates `vite` from 8.1.4 to 8.1.5 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.1.5/packages/vite) --- updated-dependencies: - dependency-name: lucide-react dependency-version: 1.25.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: web - dependency-name: react-hook-form dependency-version: 7.82.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: web - dependency-name: vite dependency-version: 8.1.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: web ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): bump the mobile-npm group in /mobile with 4 updates Bumps the mobile-npm group in /mobile with 4 updates: [@react-navigation/bottom-tabs](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/bottom-tabs), [@react-navigation/native](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native), [@react-navigation/native-stack](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native-stack) and [react-native-screens](https://github.com/software-mansion/react-native-screens). Updates `@react-navigation/bottom-tabs` from 7.18.8 to 7.18.11 - [Release notes](https://github.com/react-navigation/react-navigation/releases) - [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/bottom-tabs@7.18.11/packages/bottom-tabs/CHANGELOG.md) - [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/bottom-tabs@7.18.11/packages/bottom-tabs) Updates `@react-navigation/native` from 7.3.8 to 7.3.11 - [Release notes](https://github.com/react-navigation/react-navigation/releases) - [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native@7.3.11/packages/native/CHANGELOG.md) - [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native@7.3.11/packages/native) Updates `@react-navigation/native-stack` from 7.17.10 to 7.18.3 - [Release notes](https://github.com/react-navigation/react-navigation/releases) - [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native-stack@7.18.3/packages/native-stack/CHANGELOG.md) - [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native-stack@7.18.3/packages/native-stack) Updates `react-native-screens` from 4.26.0 to 4.26.2 - [Release notes](https://github.com/software-mansion/react-native-screens/releases) - [Commits](https://github.com/software-mansion/react-native-screens/compare/4.26.0...4.26.2) --- updated-dependencies: - dependency-name: "@react-navigation/bottom-tabs" dependency-version: 7.18.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mobile-npm - dependency-name: "@react-navigation/native" dependency-version: 7.3.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mobile-npm - dependency-name: "@react-navigation/native-stack" dependency-version: 7.18.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: mobile-npm - dependency-name: react-native-screens dependency-version: 4.26.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: mobile-npm ... Signed-off-by: dependabot[bot] <support@github.com> * build(deps): update boto3 requirement in /lambdas/library-ingest Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version. - [Release notes](https://github.com/boto/boto3/releases) - [Commits](https://github.com/boto/boto3/compare/1.43.46...1.43.51) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.51 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * Bump the api group with 7 updates Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 8.0.28 to 8.0.29 Bumps Microsoft.EntityFrameworkCore from 8.0.28 to 8.0.29 Bumps Microsoft.EntityFrameworkCore.Design from 8.0.28 to 8.0.29 Bumps Microsoft.EntityFrameworkCore.InMemory from 8.0.28 to 8.0.29 Bumps Microsoft.EntityFrameworkCore.Sqlite from 8.0.28 to 8.0.29 Bumps Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore from 8.0.28 to 8.0.29 Bumps Microsoft.NET.Test.Sdk from 18.7.0 to 18.8.1 --- updated-dependencies: - dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.Design dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.InMemory dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.Sqlite dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore dependency-version: 8.0.29 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.8.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api ... Signed-off-by: dependabot[bot] <support@github.com> * Bump NSubstitute from 5.3.0 to 6.0.0 --- updated-dependencies: - dependency-name: NSubstitute dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
cac4384f0d
|
feat(api): Phase 6 — optimistic concurrency (SHOC contract) + atomic audit staging (#226) | ||
|
|
dfaee830f7
|
feat(contracts): shared api-contracts adoption, zod schemas, ProblemDetails codes (#222)
* feat(web): adopt SHOC design system and shell layout (ADR 0003) Port shoc-frontend-new dev's design system with its CSS-variable single-token-source mechanism: - src/styles/theme.css: SHOC token file ported verbatim (Montserrat/ DM Sans/JetBrains Mono, primary #1c75bc, navy #262262, full radius/ shadow/sidebar/header token layers); fonts self-hosted via @fontsource - src/lib/theme/{css-vars,mui-theme}.ts: getCssVar -> createTheme adapter mirroring SHOC's mui-theme.ts (palette, typography, shadows tuple, component overrides; MUI v9 slot renames expressed as class selectors); theme.ts is now a re-export - Shell: SHOC composition (sidebar column + sticky gradient topbar + scrolling main); sidebar 244px/76px collapse with brand header row, grouped nav, SHOC active treatment (white card + 3px accent bar); topbar 100-degree gradient, surface hamburger, gradient avatar pill - Brand: SeahavenMark + BrandLockup ported (Tailwind re-expressed as sx; wordmark subtitle localized to PROPOSAL SYSTEM) - Login: SHOC auth-card treatment (centered 384px card on #f9fafb) - Old "Sea Haven Ops" Inter/#2563EB theme and Nunito remnants removed; remaining hardcoded hexes replaced with tokens; lucide-react for shell/nav icons per SHOC convention Verify: tsc clean, 26/26 vitest, vite build OK; Playwright screenshots pixel-sampled against the extracted SHOC spec (all hard values exact, no blocking deviations). * feat(contracts): adopt shared api-contracts in web, add zod schemas and ProblemDetails codes Closes WEB-M5 (web hand-duplicated wire types, standing drift risk): - shared/api-contracts: rewritten as the authoritative superset of the .NET DTOs (ProposalListItem/ProposalDetail with poNumber and submittedByName, line item requests, customers, pricing library, dashboard, audit, sites, auth, presigned upload, ApiProblem); stale Proposal/UpdateLineItemsRequest shapes removed - shared/api-contracts/src/schemas.ts: zod runtime schemas coupled to every wire type via `satisfies z.ZodType<T>` (schema/type drift is now a compile error); separate entrypoint so type-only consumers (mobile) never pull zod - web: imports @proposal-system/api-contracts (file: dep + tsconfig paths + vite preserveSymlinks); all 7 lib/api modules re-export shared types so page imports stay stable; enum unions tightened (PricingLibraryPage form state now ServiceCategory-typed) - fix(web): customer create/update sent a singular `address` field the API silently dropped (contract is addresses: string[], CustomerDtos.cs) - addresses now round-trip, extra addresses preserved on edit - api: ProblemDetails responses carry a machine-readable top-level `code` (SHOC error-code vocabulary): ValidationFailed, InvalidStateTransition, NotFound, Unauthorized, InternalError; new BusinessRuleException(code, message) maps to 422 with its code; GlobalExceptionHandlerTests cover the full mapping (wire contract) Cross-checked .NET DTOs vs TS types vs zod schemas with the orchestrator scanner (Gemini): core domains consistent; internal-only DTOs (FileDtos vendor/lambda surface, SimilarProposalDtos, UserDtos admin surface) intentionally uncovered. Verify: dotnet 166/166, web tsc + vitest 26/26 + build, mobile tsc, shared tsc all green. * fix(web): install shared api-contracts deps via postinstall Web Frontend Check failed on PR #222: tsc compiles shared/api-contracts/src/schemas.ts through the tsconfig path alias, and module resolution for its zod import walks up from shared/, never reaching web/node_modules. CI only ran npm ci in web/, so the shared package's deps were absent. A postinstall hook installs them wherever web's deps are installed (CI typecheck, web-test, deploy bundling). Passed locally only because a stray repo-root node_modules/zod satisfied the lookup. |
||
|
|
cac18d6b16
|
Bump the api group with 1 update (#192) | ||
|
|
433198c4e8
|
Bump xunit.runner.visualstudio from 2.8.2 to 3.1.5 (#162)
--- updated-dependencies: - dependency-name: xunit.runner.visualstudio dependency-version: 3.1.5 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b1a330e916
|
Bump Microsoft.NET.Test.Sdk from 17.14.1 to 18.6.0 (#160)
--- updated-dependencies: - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.6.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
3c17c33c16
|
Bump Amazon.Lambda.AspNetCoreServer.Hosting and 14 others (#149)
Some checks failed
Deploy / Deploy to AWS (push) Has been cancelled
Bumps Amazon.Lambda.AspNetCoreServer.Hosting from 1.7.2 to 1.10.0 Bumps AWSSDK.DynamoDBv2 from 3.7.400 to 3.7.513.4 Bumps AWSSDK.Extensions.NETCore.Setup from 3.7.400 to 3.7.400.2 Bumps AWSSDK.S3 from 3.7.405 to 3.7.511.8 Bumps AWSSDK.SecretsManager from 3.7.500 to 3.7.504.43 Bumps AWSSDK.SQS from 3.7.500 to 3.7.502.57 Bumps FluentAssertions from 7.2.0 to 7.2.2 Bumps FluentValidation from 11.11.0 to 11.12.0 Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 8.0.27 to 8.0.28 Bumps Microsoft.EntityFrameworkCore from 8.0.27 to 8.0.28 Bumps Microsoft.EntityFrameworkCore.Design from 8.0.11 to 8.0.28 Bumps Microsoft.EntityFrameworkCore.InMemory from 8.0.11 to 8.0.28 Bumps Microsoft.EntityFrameworkCore.Sqlite from 8.0.11 to 8.0.28 Bumps Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore from 8.0.27 to 8.0.28 Bumps Microsoft.NET.Test.Sdk from 17.12.0 to 17.14.1 --- updated-dependencies: - dependency-name: Amazon.Lambda.AspNetCoreServer.Hosting dependency-version: 1.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api - dependency-name: AWSSDK.DynamoDBv2 dependency-version: 3.7.513.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: AWSSDK.Extensions.NETCore.Setup dependency-version: 3.7.400.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: AWSSDK.S3 dependency-version: 3.7.511.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: AWSSDK.SecretsManager dependency-version: 3.7.504.43 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: AWSSDK.SQS dependency-version: 3.7.502.57 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: FluentValidation dependency-version: 11.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api - dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.Design dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: FluentAssertions dependency-version: 7.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.InMemory dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.EntityFrameworkCore.Sqlite dependency-version: 8.0.28 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 17.14.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
5d84399a0d
|
feat: pricing library — curated priced items feed the RAG corpus (#127)
Some checks are pending
Deploy / Deploy to AWS (push) Waiting to run
Adds a managed pricing library so admins can seed/curate reference priced items
directly, instead of the corpus being populated only by ingesting Sent proposals.
v1 PR5.
API:
- PricingLibraryItem entity + migration; /api/pricing-library CRUD (admin), with
GET {id} reachable by internal Lambda callers (admins role via internal key).
- Create/update publish an ADDITIVE library-ingest SQS job {pricingLibraryItemId},
wrapped so a publish failure never rolls back the save.
Lambda (library-ingest):
- Additive event-shape branch: pricingLibraryItemId -> fetch item, format markdown,
upload to pricing-library/{category}/{id}.md, trigger KB sync. The existing
proposalId path is byte-for-byte unchanged. Explicit error when neither id present;
warns when both present.
Web:
- Pricing Library management page (/admin/pricing-library): list / create / edit / delete.
GPT-4.1 cross-review on the event-shape change: no BLOCK (neither/both-id handling
applied). Verified: api 159 tests; web tsc + 26 tests; lambdas ruff + 37 pytest.
|
||
|
|
1fca0fa978
|
feat: proposal delivery — email customers the PDF on Mark as Sent (#126)
* feat: proposal delivery — email customers the PDF on "Mark as Sent" Makes the system's namesake feature real: marking a proposal Sent now emails the customer an expiring link to the branded PDF, and customers are managed (with contact emails) instead of hardcoded. v1 PR4. API: - Customer.ContactEmail + migration; Customer list/update endpoints. Search stays additive at GET /api/customers?query= (frozen-mobile + web compat); new paginated list at GET /api/customers/list (admin). - IEmailService (SesEmailService v2 / DevEmailService, dev-gated). MarkSentAsync resolves the customer's email, presigns the latest PDF (7d), and sends via SES. Email/presign failures are caught + audited and NEVER roll back the Sent transition. - Startup EF migration guarded by a Postgres advisory lock (concurrency-safe). Infra: - SES email identity (proposals@seahavenind.com); least-privilege ses:SendEmail/ SendRawEmail scoped to the identity ARN + ses:FromAddress condition; SES_FROM_ADDRESS env. SES starts in sandbox — production access needed for unverified recipients. Web: - Customer management page (/admin/customers): list / create / edit incl. contact email. - New-proposal form searches real customers (free-solo) instead of a hardcoded value. - Mark-as-Sent dialog notes the PDF will be emailed to the customer. GPT-4.1 cross-review (SES IAM): no BLOCK (ses:FromAddress condition applied). Verified: api build + 121 tests; web tsc + 26 tests; infra tsc; ruff clean. * Potential fix for pull request finding 'CodeQL / Exposure of private information' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * Potential fix for pull request finding 'CodeQL / Exposure of private information' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * Potential fix for pull request finding 'CodeQL / Exposure of private information' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> |
||
|
|
ab9569d7a9 |
test: add ProposalNumberGenerator, LineItemService state guard, and API client interceptor tests
- ProposalNumberGenerator tests (8 tests): format validation (SHI-YYYY-NNNN), sequence incrementing, revision skipping, year boundary isolation, uniqueness, zero-padding, high sequence rollover. Uses SQLite in-memory with Postgres function stubs to support ExecuteSqlRawAsync. - LineItemService state guard tests (18 tests): verifies line items cannot be created/bulk-updated/deleted on Approved or Sent proposals (QA-C2), confirms operations succeed on InReview and Revised statuses, validates KeyNotFoundException on missing proposals, verifies audit logging. - API client interceptor tests (14 tests): request interceptor attaches Bearer token from sessionStorage (WEB-C1), handles missing/malformed token data, response interceptor dispatches Redux logout on 401 (WEB-M2), returns friendly messages for 403/404, extracts server error details, handles network errors. - DbContextFactory updated to suppress InMemoryEventId.TransactionIgnoredWarning so BulkUpdateAsync tests work with in-memory provider. - Added SqliteDbContextFactory for tests requiring relational features. - Added Microsoft.EntityFrameworkCore.Sqlite to test project dependencies. Total: 104 .NET tests (was 77), 26 web tests (was 12). CI already wired. |
||
|
|
01fe003a6d |
fix: wire test suites into CI, fix stale tests from Phase 1-2 fixes
- Add web-test job (vitest) and python-test job (pytest) to CI workflow - dotnet reusable workflow already runs tests by default - Update InternalApiKeyMiddleware tests for API-C1/API-H1 fixes: invalid key now returns 401 (not pass-through), valid key on disallowed path returns 403 - Fix suggestions test: include status field for LAM-H4 idempotency guard - Total: 108 tests (77 .NET, 12 web, 19 Python) all passing |
||
|
|
9c04ba4756 |
fix: resolve test compile errors from merge, update AUDIT-REPORT.md
Fix CreateProposalRequest constructor calls (missing PoNumber param) and ProposalService constructor (missing ILogger param) that diverged when test-bootstrap and api-hardening worktrees merged. Mark all Critical and High findings as fixed in AUDIT-REPORT.md with remediation status for each phase. |
||
|
|
d21b1c5edb |
test: bootstrap test infrastructure with critical coverage (QA-C1 through QA-C6)
QA-C1: Create xUnit test project, add to solution, wire dependencies - api/tests/ProposalSystem.Tests with xUnit + FluentAssertions + NSubstitute - InMemory EF Core provider for isolated DB tests QA-C2: Proposal state machine transition tests (16 tests) - Valid: InReview->Approved, Approved->Sent, Sent->Revised - Invalid: InReview->Sent, Approved->Revised, Draft->Approved, etc. - Edge cases: idempotency, missing line items, revision line item copying - Audit and job publisher verification QA-C3: Authorization attribute tests (16 tests) - Controller-level [Authorize] on all controllers except AuthController - Role requirements: admins/sysadmins on admin actions - Dispatcher exclusion from admin/sysadmin routes - SysAdmin-only user management enforcement QA-C4: InternalApiKeyMiddleware tests (8 tests) - Valid key sets claims and calls next - Invalid key passes through to JWT (no 401/403) - Missing key/empty config disables middleware - Documents API-C1 vulnerability (key works on any path) QA-C5: ProtectedRoute and RoleGuard tests (12 tests, vitest) - ProtectedRoute: renders children when authenticated, redirects when not - RoleGuard: role-based access, dispatcher/admin/sysadmin enforcement - authSlice: setUser, logout, expired token handling QA-C6: Lambda SQS handler tests (19 tests, pytest) - pdf-generate: batch processing, failure reporting, malformed body - suggestions: batch processing, proposal-not-found skip, AI item preservation - API key caching, retry helpers Total: 107 tests (76 .NET + 12 web + 19 Python), all passing. |