Commit graph

13 commits

Author SHA1 Message Date
amoussa1229
e6ce9a90b2 docs: remove stale Web Tests row from CI table
The web-test inline job was folded into the consolidated
ci-typescript-frontend.yaml workflow (Phase 5) — the table still
listed it, making 7 rows while the intro said 6.
2026-07-14 00:58:56 +00:00
Adam Moussa
07f9d0ca51
Merge branch 'refactor/web-auth-context' into feat/web-ci-phase5 2026-07-13 20:35:14 -04:00
15f4e584f5
Merge origin/main into refactor/web-auth-context
Post-#223-squash sync. Conflicts were squash restatement (#221–#223
content in both histories as different commits): kept this branch's
auth-context refactor and Redux-dependency removals; merged README
rows (our de-Redux'd Web row + main's Mobile 0.86 fact-fix). Real
incoming changes: #220 docs/governance files, README/CLAUDE updates,
and the web postinstall CI fix.
2026-07-13 20:22:07 -04:00
191f710752
ci(web): Phase 5 — prettier check + Playwright smoke via org frontend workflow
Converts the web CI job from ci-typescript-cdk.yaml (typecheck only) to
ci-typescript-frontend.yaml: format:check, build (tsc -b included),
vitest, and a Playwright chromium smoke. Folds the standalone Web Tests
job into it (aggregator needs updated). Pure CI — no AWS secrets.

The smoke (e2e/smoke.spec.ts) drives dev-login → dashboard shell →
proposal list, plus the unauthenticated bounce, against a fully mocked
API (pathname-anchored route interception — a '**/api/**' glob would
swallow vite's /src/lib/api/* module URLs). Config mirrors SHOC's
playwright.config.ts (port 4173, chromium, dev-server webServer).

Prettier: singleQuote + printWidth 100 to match the existing codebase
style; lint intentionally not added (no ESLint config yet — run-lint
false, out of Phase 5 scope). rollback = revert this workflow file.
2026-07-13 20:14:41 -04:00
97cc26b03e
docs: web stack row reflects auth-context refactor (Redux removed, MUI v9) 2026-07-13 19:44:14 -04:00
Adam Moussa
a4b09eb0ad
docs: SHOC-alignment Phase 1 — ADRs, governance files, doc corrections (#220)
- Add ADR 0002 (SHOC merge boundary: separate backend services, shared
  conventions) and ADR 0003 (adopt SHOC design system + UI/UX layout)
- Add CODEOWNERS (internal-dev) and PR template (Summary/Test plan/Jira/
  docs-current checklist + contract-table convention)
- Fix stale facts in README/CLAUDE.md: MUI v7→v9, RN 0.85→0.86,
  OpenSearch Serverless/oss-index-creator → Aurora pgvector/
  aurora-pgvector-init (ADR 0001), test counts 149→186 (123 xUnit /
  26 vitest / 37 pytest), deploy triggers are workflow_dispatch-only,
  reusable workflow refs float on @main, aws-cdk-lib version claim
  replaced with Dependabot-maintained note
2026-07-13 17:00:45 -04:00
2549ce3afc Repo hygiene: PR labeler + README badges (INFRA-56/57) 2026-06-11 14:02:35 -04:00
Adam Moussa
f9081fabf4 docs: Phase 6 cleanup — update AUDIT-REPORT, README, remove stale docs
- AUDIT-REPORT.md: mark all Phase 6 findings fixed (API-M2/M5/M7/M9/M10/M12/M13,
  WEB-M3/M4/M8/M9/M11, LAM-M2/M3/M6/M9, INF-M1/M2/M9), update test count to 149
- README.md: Function URL NONE→AWS_IAM, add Testing and Security sections,
  expand CI table with test jobs, note SQS encryption/OpenSearch VPC/access logging
- Remove stale session docs (AUDIT-2026-05-20, HANDOFF, RETROSPECTIVE, CHATGPT prompt)
- Add .claude/agents/ to .gitignore
- Remove empty-state placeholder from SimilarProposalsPanel
2026-05-27 18:18:44 -04:00
Adam Moussa
091c5fcb44
Fix Phase 1 security and data integrity audit findings (#49)
BLOCK-01: Add API Gateway JWT authorizer with Cognito, route internal
Lambda calls through Function URL to bypass gateway auth
BLOCK-02/03: Prevent proposal number race condition with pg_advisory_xact_lock
and filter revision numbers from max-number query
BLOCK-04: Restrict VendorProposals and GeneratedPdfs to admins/sysadmins
BLOCK-05: Sum all vendor costs instead of overwriting with single vendor
BLOCK-06: Enable ValidateAudience on JWT, add Auth env vars to API Lambda
BLOCK-07: Validate ID token signature in AuthController via OIDC discovery
BLOCK-08: Use batchItemFailures in all Lambda SQS handlers
BLOCK-09: Increase SQS visibility timeout from 180s to 720s
FIX-10: Scope dispatcher queries to own proposals (IDOR fix)
2026-05-20 18:51:31 -04:00
Adam Moussa
da00d27049 Add email/password login, fix Cognito config, enable mobile auto-deploy
Apple review requires a test account login path that doesn't depend on
Google OAuth. Add amazon-cognito-identity-js for direct SRP auth with a
native email/password form on the login screen. Fill in the empty Cognito
client ID and pool ID, fix the Cognito domain prefix, and align CDK
callback URLs with the app's actual URL scheme. Enable push-triggered
mobile deploys, add CDK outputs for client IDs, fix stale README
references, and add mobile/README.md.
2026-05-20 11:36:51 -04:00
Adam Moussa
ef8a3b5f48 Clean up oss-index-creator: remove debug logging, update docs
- Remove verbose print statements from Lambda handler
- Add dependabot pip entry for oss-index-creator
- Update README with new Lambda and deployed stack state
2026-05-18 18:10:35 -04:00
Adam Moussa
7426d9a538
Add iOS CD pipeline and refactor workflows to org reusable callers (#24)
* Add iOS native project for React Native mobile app

Xcode project with bundle ID com.seahavenind.proposals,
CocoaPods configuration, and app scaffolding.

* Add Fastlane configuration for iOS builds and TestFlight distribution

Configures match with S3 storage (seahaven-ios-certificates bucket)
for code signing and a beta lane for automated TestFlight uploads.

* Add mobile CI job and iOS CD workflow (disabled)

CI: adds mobile typecheck job on PRs.
CD: deploy-mobile.yaml builds and uploads to TestFlight via
Fastlane on a macOS runner with OIDC auth for match S3 access.
Currently workflow_dispatch only — activate for V1 release.

* Refactor workflows to thin wrappers calling org reusable workflows

CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam
from the org repo. Deploy calls cd-cdk with post-deploy script
for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios.
Adds deploy concurrency groups to both deploy workflows.

* Add mobile Dependabot entries and remove assignees

Add npm and bundler ecosystems for mobile/. Remove assignees
from all entries — convention no longer in use.

* Add comprehensive README for the proposal-system monorepo

* Fix mobile TypeScript errors and add package-lock.json

Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef
type error, fix navigation type cast, add @types/react-native-vector-icons,
and generate package-lock.json for CI.

* Add .npmrc for mobile to resolve peer dependency conflicts

react-native-screens@4.x requires react-native >= 0.82 but the
project uses 0.79. legacy-peer-deps allows installation until
the next React Native upgrade.
2026-05-18 15:30:30 -04:00
0b055b3ad9 Initial scaffold: monorepo structure, CDK stacks, CI/CD, domain model
Phase 0 of proposal-system: complete project setup including:
- CDK infrastructure (3 stacks: foundation, compute, frontend)
- .NET 8 solution with Clean Architecture (Domain, Application, Infrastructure, Api)
- EF Core data model (PostgreSQL) with all entities
- Python Lambda placeholders (pdf-extract, pdf-generate, library-ingest)
- React 19 web frontend scaffold (Vite + MUI)
- React Native mobile placeholder
- Shared TypeScript API contracts
- GitHub Actions CI/CD (ci.yaml + deploy.yaml)
- OIDC deploy role (githubdeploy-proposal-system)
- Dependabot configuration
- Cognito User Pool with Google OAuth, PKCE clients, groups
2026-05-16 18:40:46 -04:00