Addresses 29 FIX-severity findings and accessibility/code-quality NITs
from the 2026-05-20 audit. Key changes:
- Add confirmation dialogs for Mark as Sent and Create Revision (FIX-17)
- Restrict S3 CORS from wildcard to specific origins (FIX-38)
- Add API Gateway throttling at 100 rps / 50 burst (FIX-39)
- Separate vendor upload from SQS extraction trigger (FIX-04/05)
- Copy TotalBidAmount on proposal revision (FIX-11)
- Add CI paths-ignore and concurrency group (FIX-47)
- Add post-deploy health check (FIX-46)
- Fix N+1 query, Guid.Empty FK, pagination bounds, role sync (FIX-01/02/07/09)
- Fix dashboard OOM, status transitions, audit error handling (FIX-03/06/12)
- Fix frontend date filters, error display, currency formatting (FIX-14/16/18-23)
- Remove AOSS dashboard public access, skip empty AI suggestions (FIX-41/45)
- Add aria-labels, document.title management, deduplicate constants
- Restrict CORS localhost to development, log invalid API key attempts
[skip deploy]
AdminController: Rewrite avgTurnaround query to fetch approved times to
memory before computing TotalHours — EF Core/Npgsql cannot translate
TimeSpan.TotalHours to SQL, causing a 409 on every dashboard load.
ProposalService.ReviseAsync: Append -R{n} suffix to revision's
ProposalNumber so it doesn't violate the unique index. Previously copied
the parent's number verbatim, causing a DbUpdateException (500).
ProposalService Update/Approve/MarkSent: Add .Include(p => p.SubmittedBy)
(and ApprovedBy where relevant) so MapToResponse returns submittedByName
instead of null. GetByIdAsync already had these includes.