Addresses 29 FIX-severity findings and accessibility/code-quality NITs
from the 2026-05-20 audit. Key changes:
- Add confirmation dialogs for Mark as Sent and Create Revision (FIX-17)
- Restrict S3 CORS from wildcard to specific origins (FIX-38)
- Add API Gateway throttling at 100 rps / 50 burst (FIX-39)
- Separate vendor upload from SQS extraction trigger (FIX-04/05)
- Copy TotalBidAmount on proposal revision (FIX-11)
- Add CI paths-ignore and concurrency group (FIX-47)
- Add post-deploy health check (FIX-46)
- Fix N+1 query, Guid.Empty FK, pagination bounds, role sync (FIX-01/02/07/09)
- Fix dashboard OOM, status transitions, audit error handling (FIX-03/06/12)
- Fix frontend date filters, error display, currency formatting (FIX-14/16/18-23)
- Remove AOSS dashboard public access, skip empty AI suggestions (FIX-41/45)
- Add aria-labels, document.title management, deduplicate constants
- Restrict CORS localhost to development, log invalid API key attempts
[skip deploy]
Apple review requires a test account login path that doesn't depend on
Google OAuth. Add amazon-cognito-identity-js for direct SRP auth with a
native email/password form on the login screen. Fill in the empty Cognito
client ID and pool ID, fix the Cognito domain prefix, and align CDK
callback URLs with the app's actual URL scheme. Enable push-triggered
mobile deploys, add CDK outputs for client IDs, fix stale README
references, and add mobile/README.md.
The log group already exists — created by the compute stack's
logRetention setting on the suggestions Lambda. Adding it to the
foundation stack caused a duplicate resource error on deploy.
oss-index-creator Lambda was missing functionName, arm64 architecture,
and explicit log retention — all required by the engineering handbook.
CI workflow was not passing node-version to reusable workflows, risking
drift. Removed unused _api_request helper from all four main Lambdas.
Added missing suggestions log group to foundation stack.