Remove the Audit Status section, Agent Delegation Rules pipeline, severity levels, critical-findings list, 65% context pause rule, and AUDIT-REPORT.md references now that the 2026-05-27 audit and remediation are complete. Keep the finding-ID convention (API-C1, WEB-H3, etc.) since those IDs are still embedded in code comments and commit history, and leave all arch/ADR/ infra content untouched.
3.2 KiB
Proposal System - Claude Code Project Memory
Project Overview
Proposal management platform for Sea Haven Industries. Dispatchers submit service requests, AI generates draft line items via Bedrock RAG, admins review/approve in a pricing workspace, system produces branded PDFs.
Architecture
- api/: .NET 8 API, EF Core, PostgreSQL (Aurora Serverless v2), Cognito JWT auth
- web/: React 19 + MUI v9 SPA, Vite, CloudFront + S3
- mobile/: React Native 0.86 iOS app, offline-capable, Hermes
- lambdas/: Python 3.12 Lambdas (ARM64): pdf-extract, pdf-generate, library-ingest, suggestions, aurora-pgvector-init
- infra/: CDK TypeScript (foundation-stack, compute-stack, frontend-stack)
- shared/: Shared TypeScript API contracts
- scripts/: Local dev helpers
Auth Model
External: Cognito JWT via API Gateway (web + mobile client IDs, groups: dispatchers/admins/sysadmins) Internal: Lambdas → .NET Function URL with Secrets Manager API key via custom middleware
Key Decisions (ADRs in docs/adr/)
- ADR 0001: Bedrock KB vector store is Aurora PostgreSQL + pgvector (replaced OpenSearch Serverless;
oss-index-creatorLambda replaced byaurora-pgvector-init) - ADR 0002: SHOC merge boundary — backends stay separate services permanently (PostgreSQL + Cognito here; SQL Server + ASP.NET Identity in SHOC); consolidation converges on conventions/layers/service patterns, never on platform
- ADR 0003: SHOC dev's design system + UI/UX layout is canonical (Montserrat/DM Sans, primary #1c75bc, 244px sidebar, CSS-variable single-token-source consumed by MUI via getCssVar); the old Nunito/#0c4f6f canon and the interim "Sea Haven Ops" Inter/#2563EB theme are superseded
Request Flow
- Dispatcher submits proposal (web/mobile) → InReview (no Draft stage)
- Bedrock RAG suggests line items from pricing library
- Admin reviews in workspace, edits line items, approves
- PDF generation queued via SQS → Python Lambda → branded PDF → S3
- State machine: InReview → Approved → Sent → Revised
Infrastructure
Deploys to the seahaven-prod account (011934824531), us-east-1. (mgmt 328440206208 is frozen for workloads; staging is hard-disabled in infra/lib/config.ts until retargeted to seahaven-dev 710827005802.) Aurora PostgreSQL 15 Serverless v2 (RDS Data API + pgvector), S3, SQS+DLQ, Cognito+Google OAuth, Bedrock KB (Aurora pgvector store — ADR 0001), GitHub Actions OIDC, CloudFront+S3 OAC. Prod deploys run via the deploy.yaml pipeline (workflow_dispatch) only — no local cdk deploy to prod.
Working Rules
- Never commit secrets, credentials, .env files, or local artifacts
- If secrets found in code: document, remove safely, ensure proper config mechanism
- Preserve existing business logic unless broken, insecure, or contradicted
- Run lint/typecheck/build/test after each phase
Finding-ID Convention
Code comments and commit messages reference finding IDs from a prior security-audit remediation (e.g. API-C1, WEB-H3, LAM-H4). These IDs are embedded directly in the codebase, so keep the convention documented:
- Reference finding IDs in commit messages and code comments
- Format:
// Fix: API-C1 — scope internal key to /internal/ paths