6-domain audit (API, web, mobile, lambdas, infra, QA) with fixes: API security: scope internal API key middleware to allowed paths only, return 401 on invalid key instead of falling through, remove unvalidated JWT code path, sanitize error messages, add UpdateProposal validator, remove status field from UpdateProposalRequest to prevent over-posting, log swallowed exceptions in ProposalService. Infrastructure: enforce SSL on all S3 buckets, encrypt SQS queues, enable optional MFA on Cognito, add API Gateway access logging. Lambdas: fix _retry_request undefined variable across all 4 Lambdas, re-raise exceptions in pdf-extract/pdf-generate instead of swallowing, add idempotency guard to suggestions Lambda. Web: add ErrorBoundary, add auth loading state to ProtectedRoute, add mutation error toasts in AdminWorkspace, fix dead Cognito link. Mobile: add mutex to offline queue processing, distinguish permanent vs retryable failures, register all screens for both roles, log sync errors. Swagger/OpenAPI: add Swashbuckle with JWT bearer security definition, add ProducesResponseType attributes to key endpoints. Includes AUDIT-REPORT.md with complete findings and CLAUDE.md project instructions. |
||
|---|---|---|
| .. | ||
| fastlane | ||
| ios | ||
| patches | ||
| src | ||
| .env.example | ||
| .npmrc | ||
| app.json | ||
| babel.config.js | ||
| Gemfile | ||
| Gemfile.lock | ||
| index.js | ||
| metro.config.js | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| tsconfig.json | ||
Proposal System — Mobile (iOS)
React Native 0.85 iOS app for Sea Haven Industries field dispatchers. Submit proposals, capture vendor documents, and manage drafts with offline support.
Prerequisites
- Node.js 24+
- Ruby 3.x (for Fastlane)
- Xcode 26+ with iOS 26 SDK
- CocoaPods (installed via Bundler)
Local Development
# Install JS dependencies
npm install
# Install Ruby dependencies (Fastlane, CocoaPods)
bundle install
# Install native pods
cd ios && bundle exec pod install && cd ..
# Start Metro bundler
npm start
# Run on iOS simulator
npm run ios
Environment
The app reads configuration from src/config.ts. In development mode (__DEV__), the API URL points to http://localhost:5000/api. Run the .NET API locally or use the development proxy.
Authentication
Two login methods are supported:
- Email/Password — direct Cognito SRP auth via
amazon-cognito-identity-js - Google OAuth — Cognito Hosted UI PKCE flow via
react-native-app-auth
The iOS URL scheme com.seahavenind.proposals is registered in Info.plist for OAuth callbacks.
Code Signing
Certificates and provisioning profiles are managed by Fastlane Match using S3 storage:
- Bucket:
seahaven-ios-certificates(us-east-1) - Bundle ID:
com.seahavenind.proposals - Team ID:
9KAQYC653W
Match is configured in fastlane/Matchfile. The MATCH_PASSWORD secret decrypts signing assets.
CI/CD
The deploy-mobile.yaml workflow triggers on push to main (with mobile/** path filter) or manual workflow_dispatch. It calls the cd-mobile-ios.yaml reusable workflow which:
- Sets up
macos-26runner with Xcode 26 - Installs dependencies and pods
- Retrieves signing assets via Match (S3)
- Builds the IPA with Fastlane
- Uploads to TestFlight
Required GitHub Secrets
| Secret | Purpose |
|---|---|
AWS_DEPLOY_ROLE_ARN |
OIDC role for Match S3 access |
MATCH_PASSWORD |
Signing asset decryption passphrase |
ASC_KEY_ID |
App Store Connect API key ID |
ASC_ISSUER_ID |
App Store Connect API issuer |
ASC_KEY_CONTENT |
App Store Connect .p8 key (base64) |
Project Structure
mobile/
├── src/
│ ├── screens/ Auth, dispatcher, and admin screens
│ ├── lib/api/ API clients (auth, proposals, line items, admin)
│ ├── store/ Redux Toolkit (auth slice)
│ ├── navigation/ React Navigation (RootNavigator)
│ ├── components/ Reusable UI components
│ ├── hooks/ useAuth, useOfflineDraft, usePaginatedList
│ ├── theme/ Material Design 3 theming
│ ├── constants/ App-wide constants
│ └── config.ts Cognito + API configuration
├── ios/ Xcode project, assets, Info.plist
├── fastlane/ Fastfile, Matchfile, Appfile
├── Gemfile Ruby dependencies
└── package.json React Native 0.85.3