Commit graph

3 commits

Author SHA1 Message Date
Adam Moussa
80e36bfb9a Fix Phase 3 audit findings: polish, operational maturity, and remaining FIX items
Addresses 29 FIX-severity findings and accessibility/code-quality NITs
from the 2026-05-20 audit. Key changes:

- Add confirmation dialogs for Mark as Sent and Create Revision (FIX-17)
- Restrict S3 CORS from wildcard to specific origins (FIX-38)
- Add API Gateway throttling at 100 rps / 50 burst (FIX-39)
- Separate vendor upload from SQS extraction trigger (FIX-04/05)
- Copy TotalBidAmount on proposal revision (FIX-11)
- Add CI paths-ignore and concurrency group (FIX-47)
- Add post-deploy health check (FIX-46)
- Fix N+1 query, Guid.Empty FK, pagination bounds, role sync (FIX-01/02/07/09)
- Fix dashboard OOM, status transitions, audit error handling (FIX-03/06/12)
- Fix frontend date filters, error display, currency formatting (FIX-14/16/18-23)
- Remove AOSS dashboard public access, skip empty AI suggestions (FIX-41/45)
- Add aria-labels, document.title management, deduplicate constants
- Restrict CORS localhost to development, log invalid API key attempts

[skip deploy]
2026-05-20 19:35:13 -04:00
Adam Moussa
d00c552497 Fix admin dashboard LINQ crash, revise unique constraint, and mutation response data
AdminController: Rewrite avgTurnaround query to fetch approved times to
memory before computing TotalHours — EF Core/Npgsql cannot translate
TimeSpan.TotalHours to SQL, causing a 409 on every dashboard load.

ProposalService.ReviseAsync: Append -R{n} suffix to revision's
ProposalNumber so it doesn't violate the unique index. Previously copied
the parent's number verbatim, causing a DbUpdateException (500).

ProposalService Update/Approve/MarkSent: Add .Include(p => p.SubmittedBy)
(and ApprovedBy where relevant) so MapToResponse returns submittedByName
instead of null. GetByIdAsync already had these includes.
2026-05-20 18:08:50 -04:00
d2e12d3940 Implement Backend API Core (Phase 1)
Complete API layer with Clean Architecture:
- Application DTOs (proposals, line items, customers, users, files, audit, dashboard)
- Service interfaces (IProposalService, ILineItemService, ICustomerService, IAuditService, IS3Service, IJobPublisher)
- FluentValidation validators for all create requests
- Infrastructure service implementations (ProposalService, LineItemService, CustomerService, AuditService, S3Service, SqsJobPublisher, ProposalNumberGenerator)
- Secrets Manager connection string resolver for RDS
- API controllers: Proposals (CRUD + approve/send/revise), LineItems (CRUD + bulk), Customers, Users, Files (presigned upload/download), Admin (dashboard)
- Middleware: GlobalExceptionHandler (ProblemDetails), ValidationFilter (FluentValidation pipeline)
- CurrentUserService (Cognito JWT claims -> User entity, auto-provisioning)
- Full DI configuration in Program.cs with Lambda hosting
- Role-based authorization (dispatchers, admins, sysadmins)
- CORS configured for proposals.seahaven.com + localhost
2026-05-16 18:49:48 -04:00