mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-10-07 16:18:57 +00:00
Addresses 29 FIX-severity findings and accessibility/code-quality NITs from the 2026-05-20 audit. Key changes: - Add confirmation dialogs for Mark as Sent and Create Revision (FIX-17) - Restrict S3 CORS from wildcard to specific origins (FIX-38) - Add API Gateway throttling at 100 rps / 50 burst (FIX-39) - Separate vendor upload from SQS extraction trigger (FIX-04/05) - Copy TotalBidAmount on proposal revision (FIX-11) - Add CI paths-ignore and concurrency group (FIX-47) - Add post-deploy health check (FIX-46) - Fix N+1 query, Guid.Empty FK, pagination bounds, role sync (FIX-01/02/07/09) - Fix dashboard OOM, status transitions, audit error handling (FIX-03/06/12) - Fix frontend date filters, error display, currency formatting (FIX-14/16/18-23) - Remove AOSS dashboard public access, skip empty AI suggestions (FIX-41/45) - Add aria-labels, document.title management, deduplicate constants - Restrict CORS localhost to development, log invalid API key attempts [skip deploy]
34 lines
1.1 KiB
Bash
Executable file
34 lines
1.1 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
cd web
|
|
npm ci
|
|
npm run build
|
|
cd ..
|
|
|
|
BUCKET=$(aws cloudformation describe-stacks \
|
|
--stack-name proposal-system-frontend \
|
|
--query "Stacks[0].Outputs[?OutputKey=='SiteBucketName'].OutputValue" \
|
|
--output text)
|
|
aws s3 sync web/dist "s3://$BUCKET" --delete
|
|
|
|
DIST_ID=$(aws cloudformation describe-stacks \
|
|
--stack-name proposal-system-frontend \
|
|
--query "Stacks[0].Outputs[?OutputKey=='DistributionId'].OutputValue" \
|
|
--output text)
|
|
aws cloudfront create-invalidation --distribution-id "$DIST_ID" --paths "/*"
|
|
|
|
# Health check: verify API is reachable
|
|
API_URL=$(aws cloudformation describe-stacks \
|
|
--stack-name proposal-system-compute \
|
|
--query "Stacks[0].Outputs[?OutputKey=='ApiEndpoint'].OutputValue" \
|
|
--output text)
|
|
|
|
echo "Running post-deploy health check..."
|
|
HTTP_STATUS=$(curl -s -o /dev/null -w "%{http_code}" "${API_URL}/api/health" --max-time 10 || true)
|
|
if [ "$HTTP_STATUS" -eq 200 ]; then
|
|
echo "Health check passed (HTTP $HTTP_STATUS)"
|
|
else
|
|
echo "WARNING: Health check returned HTTP $HTTP_STATUS" >&2
|
|
exit 1
|
|
fi
|