proposal-system/mobile
Adam Moussa 4f1271eb50 audit: fix all Critical and High security/reliability issues across monorepo
6-domain audit (API, web, mobile, lambdas, infra, QA) with fixes:

API security: scope internal API key middleware to allowed paths only,
return 401 on invalid key instead of falling through, remove unvalidated
JWT code path, sanitize error messages, add UpdateProposal validator,
remove status field from UpdateProposalRequest to prevent over-posting,
log swallowed exceptions in ProposalService.

Infrastructure: enforce SSL on all S3 buckets, encrypt SQS queues,
enable optional MFA on Cognito, add API Gateway access logging.

Lambdas: fix _retry_request undefined variable across all 4 Lambdas,
re-raise exceptions in pdf-extract/pdf-generate instead of swallowing,
add idempotency guard to suggestions Lambda.

Web: add ErrorBoundary, add auth loading state to ProtectedRoute,
add mutation error toasts in AdminWorkspace, fix dead Cognito link.

Mobile: add mutex to offline queue processing, distinguish permanent
vs retryable failures, register all screens for both roles, log sync
errors.

Swagger/OpenAPI: add Swashbuckle with JWT bearer security definition,
add ProducesResponseType attributes to key endpoints.

Includes AUDIT-REPORT.md with complete findings and CLAUDE.md project
instructions.
2026-05-27 18:18:44 -04:00
..
fastlane Fix RN bundle phase: align metro-config and babel-preset with RN 0.85 2026-05-19 19:21:33 -04:00
ios Fix Phase 2 audit findings: reliability, UX, and operational monitoring 2026-05-20 19:07:49 -04:00
patches Fix iOS 26 launch crash: patch netinfo removed CoreTelephony APIs 2026-05-20 11:52:43 -04:00
src audit: fix all Critical and High security/reliability issues across monorepo 2026-05-27 18:18:44 -04:00
.env.example Scaffold React Native mobile project (Phase 6) 2026-05-17 15:09:06 -04:00
.npmrc Add iOS CD pipeline and refactor workflows to org reusable callers (#24) 2026-05-18 15:30:30 -04:00
app.json Scaffold React Native mobile project (Phase 6) 2026-05-17 15:09:06 -04:00
babel.config.js Scaffold React Native mobile project (Phase 6) 2026-05-17 15:09:06 -04:00
Gemfile Fix ASC key parsing: decode base64 before passing to Fastlane 2026-05-18 18:52:15 -04:00
Gemfile.lock Fix ASC key parsing: decode base64 before passing to Fastlane 2026-05-18 18:52:15 -04:00
index.js Scaffold React Native mobile project (Phase 6) 2026-05-17 15:09:06 -04:00
metro.config.js Scaffold React Native mobile project (Phase 6) 2026-05-17 15:09:06 -04:00
package-lock.json Bump react-native-screens from 4.25.1 to 4.25.2 in /mobile (#62) 2026-05-23 04:36:15 +00:00
package.json Bump react-native-screens from 4.25.1 to 4.25.2 in /mobile (#62) 2026-05-23 04:36:15 +00:00
README.md Add email/password login, fix Cognito config, enable mobile auto-deploy 2026-05-20 11:36:51 -04:00
tsconfig.json Add iOS CD pipeline and refactor workflows to org reusable callers (#24) 2026-05-18 15:30:30 -04:00

Proposal System — Mobile (iOS)

React Native 0.85 iOS app for Sea Haven Industries field dispatchers. Submit proposals, capture vendor documents, and manage drafts with offline support.

Prerequisites

  • Node.js 24+
  • Ruby 3.x (for Fastlane)
  • Xcode 26+ with iOS 26 SDK
  • CocoaPods (installed via Bundler)

Local Development

# Install JS dependencies
npm install

# Install Ruby dependencies (Fastlane, CocoaPods)
bundle install

# Install native pods
cd ios && bundle exec pod install && cd ..

# Start Metro bundler
npm start

# Run on iOS simulator
npm run ios

Environment

The app reads configuration from src/config.ts. In development mode (__DEV__), the API URL points to http://localhost:5000/api. Run the .NET API locally or use the development proxy.

Authentication

Two login methods are supported:

  • Email/Password — direct Cognito SRP auth via amazon-cognito-identity-js
  • Google OAuth — Cognito Hosted UI PKCE flow via react-native-app-auth

The iOS URL scheme com.seahavenind.proposals is registered in Info.plist for OAuth callbacks.

Code Signing

Certificates and provisioning profiles are managed by Fastlane Match using S3 storage:

  • Bucket: seahaven-ios-certificates (us-east-1)
  • Bundle ID: com.seahavenind.proposals
  • Team ID: 9KAQYC653W

Match is configured in fastlane/Matchfile. The MATCH_PASSWORD secret decrypts signing assets.

CI/CD

The deploy-mobile.yaml workflow triggers on push to main (with mobile/** path filter) or manual workflow_dispatch. It calls the cd-mobile-ios.yaml reusable workflow which:

  1. Sets up macos-26 runner with Xcode 26
  2. Installs dependencies and pods
  3. Retrieves signing assets via Match (S3)
  4. Builds the IPA with Fastlane
  5. Uploads to TestFlight

Required GitHub Secrets

Secret Purpose
AWS_DEPLOY_ROLE_ARN OIDC role for Match S3 access
MATCH_PASSWORD Signing asset decryption passphrase
ASC_KEY_ID App Store Connect API key ID
ASC_ISSUER_ID App Store Connect API issuer
ASC_KEY_CONTENT App Store Connect .p8 key (base64)

Project Structure

mobile/
├── src/
│   ├── screens/        Auth, dispatcher, and admin screens
│   ├── lib/api/        API clients (auth, proposals, line items, admin)
│   ├── store/          Redux Toolkit (auth slice)
│   ├── navigation/     React Navigation (RootNavigator)
│   ├── components/     Reusable UI components
│   ├── hooks/          useAuth, useOfflineDraft, usePaginatedList
│   ├── theme/          Material Design 3 theming
│   ├── constants/      App-wide constants
│   └── config.ts       Cognito + API configuration
├── ios/                Xcode project, assets, Info.plist
├── fastlane/           Fastfile, Matchfile, Appfile
├── Gemfile             Ruby dependencies
└── package.json        React Native 0.85.3