proposal-system/mobile
dependabot[bot] 0a991faa65
chore(deps): bump @testing-library/user-event from 14.6.1 to 14.6.3 in /web in the web group (#287)
* chore(deps): bump @testing-library/user-event in /web

Bumps the web group in /web with 1 update: [@testing-library/user-event](https://github.com/testing-library/user-event).

Updates `@testing-library/user-event` from 14.6.1 to 14.6.3
- [Release notes](https://github.com/testing-library/user-event/releases)
- [Changelog](https://github.com/testing-library/user-event/blob/main/CHANGELOG.md)
- [Commits](https://github.com/testing-library/user-event/compare/v14.6.1...v14.6.3)

---
updated-dependencies:
- dependency-name: "@testing-library/user-event"
  dependency-version: 14.6.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: web
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): update boto3 requirement in /lambdas/pdf-generate

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.61...1.43.64)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.64
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump react-native-safe-area-context

Bumps the mobile-npm group in /mobile with 1 update: [react-native-safe-area-context](https://github.com/AppAndFlow/react-native-safe-area-context).

Updates `react-native-safe-area-context` from 5.8.0 to 5.8.1
- [Release notes](https://github.com/AppAndFlow/react-native-safe-area-context/releases)
- [Commits](https://github.com/AppAndFlow/react-native-safe-area-context/compare/v5.8.0...v5.8.1)

---
updated-dependencies:
- dependency-name: react-native-safe-area-context
  dependency-version: 5.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: mobile-npm
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): update boto3 requirement in /lambdas/pdf-extract

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.62...1.43.64)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.64
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): update boto3 requirement in /lambdas/library-ingest

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.62...1.43.64)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.64
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): update boto3 requirement in /lambdas/aurora-pgvector-init

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.62...1.43.64)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.64
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump the infra group in /infra with 4 updates

Bumps the infra group in /infra with 4 updates: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib), [constructs](https://github.com/aws/constructs), [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) and [tsx](https://github.com/privatenumber/tsx).

Updates `aws-cdk-lib` from 2.262.1 to 2.263.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.263.0/packages/aws-cdk-lib)

Updates `constructs` from 10.7.1 to 10.8.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.7.1...v10.8.1)

Updates `aws-cdk` from 2.1133.0 to 2.1135.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1135.0/packages/aws-cdk)

Updates `tsx` from 4.23.1 to 4.23.6
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](https://github.com/privatenumber/tsx/compare/v4.23.1...v4.23.6)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.263.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: infra
- dependency-name: constructs
  dependency-version: 10.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: infra
- dependency-name: aws-cdk
  dependency-version: 2.1135.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: infra
- dependency-name: tsx
  dependency-version: 4.23.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: infra
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump js-yaml from 4.3.0 to 4.3.1 in /mobile

* chore(deps): update boto3 requirement in /lambdas/suggestions (#291)

Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.62...1.43.64)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.64
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump js-yaml from 4.3.0 to 4.3.1 in /mobile

Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.0...4.3.1)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 17:46:20 +00:00
..
fastlane Fix RN bundle phase: align metro-config and babel-preset with RN 0.85 2026-05-19 19:21:33 -04:00
ios Fix Phase 2 audit findings: reliability, UX, and operational monitoring 2026-05-20 19:07:49 -04:00
patches Fix iOS 26 launch crash: patch netinfo removed CoreTelephony APIs 2026-05-20 11:52:43 -04:00
src feat(api): Phase 6 — optimistic concurrency (SHOC contract) + atomic audit staging (#226) 2026-07-14 01:18:30 -04:00
.env.example Scaffold React Native mobile project (Phase 6) 2026-05-17 15:09:06 -04:00
.npmrc Add iOS CD pipeline and refactor workflows to org reusable callers (#24) 2026-05-18 15:30:30 -04:00
app.json Scaffold React Native mobile project (Phase 6) 2026-05-17 15:09:06 -04:00
babel.config.js Scaffold React Native mobile project (Phase 6) 2026-05-17 15:09:06 -04:00
Gemfile Fix ASC key parsing: decode base64 before passing to Fastlane 2026-05-18 18:52:15 -04:00
Gemfile.lock build(deps): combine open Dependabot updates into one PR 2026-07-08 16:46:43 -04:00
index.js Scaffold React Native mobile project (Phase 6) 2026-05-17 15:09:06 -04:00
metro.config.js Scaffold React Native mobile project (Phase 6) 2026-05-17 15:09:06 -04:00
package-lock.json chore(deps): bump @testing-library/user-event from 14.6.1 to 14.6.3 in /web in the web group (#287) 2026-08-10 17:46:20 +00:00
package.json chore(deps): bump @testing-library/user-event from 14.6.1 to 14.6.3 in /web in the web group (#287) 2026-08-10 17:46:20 +00:00
README.md Add email/password login, fix Cognito config, enable mobile auto-deploy 2026-05-20 11:36:51 -04:00
tsconfig.json Add iOS CD pipeline and refactor workflows to org reusable callers (#24) 2026-05-18 15:30:30 -04:00

Proposal System — Mobile (iOS)

React Native 0.85 iOS app for Sea Haven Industries field dispatchers. Submit proposals, capture vendor documents, and manage drafts with offline support.

Prerequisites

  • Node.js 24+
  • Ruby 3.x (for Fastlane)
  • Xcode 26+ with iOS 26 SDK
  • CocoaPods (installed via Bundler)

Local Development

# Install JS dependencies
npm install

# Install Ruby dependencies (Fastlane, CocoaPods)
bundle install

# Install native pods
cd ios && bundle exec pod install && cd ..

# Start Metro bundler
npm start

# Run on iOS simulator
npm run ios

Environment

The app reads configuration from src/config.ts. In development mode (__DEV__), the API URL points to http://localhost:5000/api. Run the .NET API locally or use the development proxy.

Authentication

Two login methods are supported:

  • Email/Password — direct Cognito SRP auth via amazon-cognito-identity-js
  • Google OAuth — Cognito Hosted UI PKCE flow via react-native-app-auth

The iOS URL scheme com.seahavenind.proposals is registered in Info.plist for OAuth callbacks.

Code Signing

Certificates and provisioning profiles are managed by Fastlane Match using S3 storage:

  • Bucket: seahaven-ios-certificates (us-east-1)
  • Bundle ID: com.seahavenind.proposals
  • Team ID: 9KAQYC653W

Match is configured in fastlane/Matchfile. The MATCH_PASSWORD secret decrypts signing assets.

CI/CD

The deploy-mobile.yaml workflow triggers on push to main (with mobile/** path filter) or manual workflow_dispatch. It calls the cd-mobile-ios.yaml reusable workflow which:

  1. Sets up macos-26 runner with Xcode 26
  2. Installs dependencies and pods
  3. Retrieves signing assets via Match (S3)
  4. Builds the IPA with Fastlane
  5. Uploads to TestFlight

Required GitHub Secrets

Secret Purpose
AWS_DEPLOY_ROLE_ARN OIDC role for Match S3 access
MATCH_PASSWORD Signing asset decryption passphrase
ASC_KEY_ID App Store Connect API key ID
ASC_ISSUER_ID App Store Connect API issuer
ASC_KEY_CONTENT App Store Connect .p8 key (base64)

Project Structure

mobile/
├── src/
│   ├── screens/        Auth, dispatcher, and admin screens
│   ├── lib/api/        API clients (auth, proposals, line items, admin)
│   ├── store/          Redux Toolkit (auth slice)
│   ├── navigation/     React Navigation (RootNavigator)
│   ├── components/     Reusable UI components
│   ├── hooks/          useAuth, useOfflineDraft, usePaginatedList
│   ├── theme/          Material Design 3 theming
│   ├── constants/      App-wide constants
│   └── config.ts       Cognito + API configuration
├── ios/                Xcode project, assets, Info.plist
├── fastlane/           Fastfile, Matchfile, Appfile
├── Gemfile             Ruby dependencies
└── package.json        React Native 0.85.3