Commit graph

45 commits

Author SHA1 Message Date
Adam Moussa
86f078de72 Add CloudWatch Errors alarms to all door-unlock Lambdas (#34)
Physical access control has no error visibility — a Lambda failure
could leave unlock/lockdown/authorizer silently broken. Add ALARM-only
Errors alarms (Sum > 0, 5-min period, NOT_BREACHING) for all four
Lambdas, routed to the cross-stack site-alerts SNS topic encrypted
with alias/seahaven-alarm-topics. No OK/recovery actions per org
convention.

Refs: INFRA-101
2026-06-10 14:38:15 -04:00
Adam Moussa
4265ad90fe Gateway token authorizer + finish CI/CD migration (INFRA-99, INFRA-2) (#32)
* feat: add gateway token authorizer to door-unlock API (INFRA-99)

All three routes (GET /unlock, /lockdown, /lockdown/status) were
AuthorizationType NONE — auth relied solely on each handler checking
the ?token= query param. Add a REQUEST-type HTTP API Lambda authorizer
(door-unlock-api-authorizer) that validates the SAME ?token= value the
Yealink XML Browser keys already send, against the existing
/seahaven/door-unlock/auth-token SSM SecureString, and attach it to all
three routes.

Transparent to the phones: identity source is $request.querystring.token
(exactly what the type-17 XML Browser keys send via GET), simple response
{isAuthorized}, fail-closed, 5-min results cache. Token is cached in
module scope so warm invocations skip SSM.

GET is kept (not switched to POST): the Yealink type-17 XML Browser keys
are GET-only and render the returned Yealink XML — they cannot issue a
POST body or custom headers. POST is therefore deferred to avoid bricking
the door keys.

Handlers retain their own token check as defense-in-depth. Purely
additive change set; no existing Lambda or integration is modified.

* chore: complete CI/CD migration to GitHub Actions (INFRA-2)

GitHub Actions (ci.yaml + deploy.yaml via the Sea Haven reusable
workflows) is the proven deploy path. Remove the now-orphaned
buildspec.yml and update the README CI/CD and architecture sections.

The legacy CodePipeline was already deleted (2026-06-05); the leftover
CodeBuild project seahaven-door-unlock-api-build and its IAM role
seahaven-door-unlock-api-codebuild have now also been decommissioned.
2026-06-08 18:03:30 -04:00
Adam Moussa
fe04a199de fix: use constant-time auth token comparison (INFRA-21) (#30)
Replace plain token !== secrets.authToken checks in the unlock and
lockdown handlers with crypto.timingSafeEqual, guarding for unequal
buffer lengths first (timingSafeEqual throws on different lengths).
Prevents timing side-channel leakage of the auth token. Handler
signatures, event shape, and return contract are unchanged.
2026-06-05 17:26:12 -04:00
dependabot[bot]
0f27b2553a Bump aws-cdk-lib in the minor-and-patch group across 1 directory (#28)
Bumps the minor-and-patch group with 1 update in the / directory: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib).


Updates `aws-cdk-lib` from 2.257.0 to 2.258.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.258.0/packages/aws-cdk-lib)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.258.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-05 14:47:13 -04:00
Adam Moussa
565d4af4fd fix: raise unlock Lambda timeout to 20s (#29)
The door-unlock-api-unlock function hit its 10,000ms timeout on
2026-06-05 at 18:00 UTC during a cold start combined with a slow
LenelS2 Elements API call (REPORT: Duration 10000.00 ms, Status:
timeout). A concurrent attempt succeeded in 3639ms, confirming the
call path is healthy but lacks margin under cold-start + slow-API
conditions.

Raise the UnlockHandler timeout from 10s to 20s for additional
headroom. LockdownHandler (15s) and the poller (75s) are unchanged.
2026-06-05 14:31:00 -04:00
Adam Moussa
1a3eb51628 chore(deps): remove blanket aws-cdk-lib dependabot ignore (#27)
Per handbook Pinning Principle: exact pins are kept current by Dependabot version updates gated by CI + dependency review. Blanket ignores let pins rot (see today's fast-uri incident).
2026-06-05 13:56:52 -04:00
Adam Moussa
912a860462 fix(deps): pin aws-cdk-lib to ==2.257.0 (#26)
* fix(deps): re-pin aws-cdk-lib to ==2.253.1

* fix(deps): pin aws-cdk-lib to 2.257.0 (exact)
2026-06-05 13:01:30 -04:00
Adam Moussa
118ea41e87 Add dependency-review caller workflow (#25)
* Add dependency-review caller workflow

Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.

* chore: retrigger checks

* chore: retrigger dep review (post-fix)

* chore: add .env to .gitignore
2026-06-05 12:34:08 -04:00
dependabot[bot]
09f301f482 Bump the minor-and-patch group with 2 updates (#24)
Bumps the minor-and-patch group with 2 updates: [@aws-sdk/client-ssm](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ssm) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `@aws-sdk/client-ssm` from 3.1059.0 to 3.1061.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ssm/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1061.0/clients/client-ssm)

Updates `aws-cdk` from 2.1125.0 to 2.1126.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1126.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-ssm"
  dependency-version: 3.1061.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1126.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-04 00:27:55 +00:00
dependabot[bot]
e18b085af3 Bump the minor-and-patch group across 1 directory with 3 updates (#22)
Bumps the minor-and-patch group with 3 updates in the / directory: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib), [@aws-sdk/client-ssm](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ssm) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk-lib` from 2.255.0 to 2.257.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.257.0/packages/aws-cdk-lib)

Updates `@aws-sdk/client-ssm` from 3.1050.0 to 3.1059.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ssm/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1059.0/clients/client-ssm)

Updates `aws-cdk` from 2.1123.0 to 2.1125.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1125.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-ssm"
  dependency-version: 3.1054.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1124.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk-lib
  dependency-version: 2.257.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-03 00:06:10 +00:00
Adam Moussa
b0b2444799 Add API access logging (audit Day 3: M-18) (#23)
Access logging to /aws/apigateway/door-unlock-api (90d) on the HTTP API default
stage. Throttling (5 burst / 2 rps) was already present.
2026-06-02 17:42:13 -04:00
dependabot[bot]
1aef1ca16c Bump the minor-and-patch group with 4 updates (#21)
Bumps the minor-and-patch group with 4 updates: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib), [@aws-sdk/client-ssm](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-ssm), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk-lib` from 2.253.1 to 2.255.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.255.0/packages/aws-cdk-lib)

Updates `@aws-sdk/client-ssm` from 3.1045.0 to 3.1050.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-ssm/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1050.0/clients/client-ssm)

Updates `@types/node` from 25.7.0 to 25.9.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `aws-cdk` from 2.1121.0 to 2.1123.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1123.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.255.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/client-ssm"
  dependency-version: 3.1050.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 25.9.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1123.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-20 00:32:00 +00:00
dependabot[bot]
c4567a213c Bump @types/node from 25.6.2 to 25.7.0 in the minor-and-patch group (#20)
Bumps the minor-and-patch group with 1 update: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).


Updates `@types/node` from 25.6.2 to 25.7.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 25.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-12 20:22:16 +00:00
dependabot[bot]
8b2a1d001d Bump the minor-and-patch group across 1 directory with 3 updates (#16)
Bumps the minor-and-patch group with 3 updates in the / directory: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk-lib` from 2.252.0 to 2.253.1
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/v2.253.1/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.253.1/packages/aws-cdk-lib)

Updates `@types/node` from 25.6.0 to 25.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `aws-cdk` from 2.1120.0 to 2.1121.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1121.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 25.6.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1121.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk-lib
  dependency-version: 2.253.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 22:27:19 +00:00
Adam Moussa
b5e75f8306 Add GitHub Actions deploy workflow (#18)
* Add GitHub Actions deploy workflow (OIDC)

* Add permissions block for OIDC token exchange

* Add concurrency control to prevent parallel deploys
2026-05-08 17:08:22 -04:00
Adam Moussa
c3d1c399f2 Add CI workflow (#17)
* Add CI workflow

* Fix TypeScript compilation for CI

Add types: ["node"] to tsconfig so tsc resolves Node.js globals
(console, process, __dirname). Add @aws-sdk/client-ssm and
source-map-support as devDependencies for type resolution.
2026-05-08 16:03:06 -04:00
Adam Moussa
1849d3db50 Update Dependabot: remove assignees, group minor/patch updates (#15) 2026-05-08 14:23:20 -04:00
Adam Moussa
222e6fd49d Remove wrapper workflow — using required workflow via org ruleset (#14) 2026-05-06 19:59:02 -04:00
dependabot[bot]
dc992880cc Bump esbuild from 0.25.0 to 0.28.0 (#8)
Bumps [esbuild](https://github.com/evanw/esbuild) from 0.25.0 to 0.28.0.
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md)
- [Commits](https://github.com/evanw/esbuild/compare/v0.25.0...v0.28.0)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version: 0.28.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-06 19:24:24 -04:00
dependabot[bot]
0e9943fadc Bump typescript from 5.7.3 to 6.0.3 (#7)
Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.7.3 to 6.0.3.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/compare/v5.7.3...v6.0.3)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-06 19:11:15 -04:00
dependabot[bot]
1b778197e2 Bump @types/node from 22.19.17 to 25.6.0 (#10)
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 22.19.17 to 25.6.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 25.6.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
2026-05-06 18:22:57 -04:00
Adam Moussa
07f81be535 Add Claude Code review workflow (#13) 2026-05-06 18:12:11 -04:00
Adam Moussa
ae8060f5c9 Merge pull request #12 from Sea-Haven-Industries/feature/dependabot-auto-assign
Auto-assign Dependabot PRs
2026-05-02 17:28:06 -04:00
Adam Moussa
23c860187f Auto-assign Dependabot PRs to amoussa1229 2026-05-02 17:26:13 -04:00
Adam Moussa
0c7f154c17 Merge pull request #11 from Sea-Haven-Industries/dependabot/npm_and_yarn/aws-cdk-2.1120.0
Bump aws-cdk from 2.1118.4 to 2.1120.0
2026-05-02 17:23:34 -04:00
Adam Moussa
d0fd4a5e8b Merge pull request #9 from Sea-Haven-Industries/dependabot/npm_and_yarn/aws-cdk-lib-2.252.0
Bump aws-cdk-lib from 2.250.0 to 2.252.0
2026-05-02 17:23:31 -04:00
dependabot[bot]
3f1060a104 Bump aws-cdk from 2.1118.4 to 2.1120.0
Bumps [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) from 2.1118.4 to 2.1120.0.
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1120.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk
  dependency-version: 2.1120.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-02 21:17:32 +00:00
dependabot[bot]
b1f5c54829 Bump aws-cdk-lib from 2.250.0 to 2.252.0
Bumps [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib) from 2.250.0 to 2.252.0.
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.252.0/packages/aws-cdk-lib)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.252.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-02 21:17:20 +00:00
Adam Moussa
97d47bd37b Merge pull request #6 from Sea-Haven-Industries/feature/add-dependabot-config
Add Dependabot version update configuration
2026-05-02 17:15:41 -04:00
Adam Moussa
e7b4ae272b Add Dependabot version update configuration 2026-05-02 17:14:19 -04:00
Adam Moussa
4068a4c34e Merge pull request #5 from Sea-Haven-Industries/feature/fix-stack-name
Rename stack to kebab-case
2026-05-01 18:57:14 -04:00
Adam Moussa
49639436f7 Rename stack to kebab-case
Requires deleting the old SeaHavenDoorUnlockStack before deploying.
2026-05-01 18:56:59 -04:00
Adam Moussa
ccbc98962b Add lockdown mode and CI/CD pipeline (#3)
* Add lockdown profile toggle endpoints with T58W linekey support

Add a new Lambda handler that toggles Elements lockdown profiles
(Bohemia and Ronkonkoma) via the Elements API, with status
verification before and after each toggle. Returns Yealink XML
to control linekey LEDs (green=inactive, red=locked down).

Also brings both Lambda handlers into compliance with system
standards: Node 22.x runtime, arm64 architecture, 60-day log
retention, and kebab-case function names.

* Add lockdown poller Lambda and fix lockdown handler responses

- Add VPC-connected poller Lambda that monitors lockdown status via
  Elements API every 15 seconds (4 polls per 1-min EventBridge schedule)
- Handle Elements API rate limits (429) with retry-after support
- Fix lockdown handler to use TextScreen XML instead of Execute XML
  (Execute shows globe icon on T58W, TextScreen renders properly)
- Fix Elements API status parsing to be case-insensitive
- Trust toggle action instead of re-checking status (eventual consistency)
- Configure push_xml.server = any in T58W template for Push XML support
- Clear action_url.setup_completed (poller replaces boot-time check)
- Update README with lockdown architecture and known LED limitation

Note: T58W line key LED color does not change to reflect lockdown
status. Execute LED commands are transient on the T58W - the phone's
XML Browser key type immediately overrides them.

* Add buildspec for CodePipeline CI/CD

* Update README with CI/CD pipeline details
2026-05-01 18:52:37 -04:00
dependabot[bot]
dbdb87ca4b Bump esbuild from 0.24.2 to 0.25.0 (#1)
Bumps [esbuild](https://github.com/evanw/esbuild) from 0.24.2 to 0.25.0.
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2024.md)
- [Commits](https://github.com/evanw/esbuild/compare/v0.24.2...v0.25.0)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version: 0.25.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-28 18:04:03 -04:00
Adam Moussa
680586c9e9 Merge pull request #2 from Sea-Haven-Industries/feature/fix-stack-naming
Fix stack and API naming to kebab-case
2026-04-28 15:16:10 -04:00
Adam Moussa
de6e34f827 Fix stack and API naming to follow kebab-case convention
Pin existing CloudFormation stack name via stackName property so
the live stack is not affected. Construct ID and API Gateway name
now follow the org kebab-case standard.
2026-04-28 14:43:48 -04:00
Adam Moussa
f4c6a2719a Apply display settings to T58W template to match T54W templates
Backlight dims to level 1 after 5 min, screensaver and power saving
disabled.
2026-04-27 13:47:49 -04:00
Adam Moussa
dbb42547fa Enable BLF list subscriptions in T58W template
Add phone_setting.blf_list_enable = 1 which was present in the T54W
template but missing from the stock T5x base. Without it, BLF and
shared parking keys show X's instead of green/red status.
2026-04-27 13:26:30 -04:00
Adam Moussa
7f985d4b75 Fix T58W template: use y1 prefix for custom y-file and clean up names
Change y000000000150.cfg → y100000000150.cfg across all three references
(deviceconfig filename, model filename, auto_provision.common_file_name)
to avoid conflicting with the stock 3CX template, consistent with the
T54W templates. Also update the second data section friendly name.
2026-04-27 13:10:24 -04:00
Adam Moussa
6f029963e9 Add Yealink T58W door unlock 3CX template
Based on the official 3CX T5x template, stripped to T58W-only with the
door unlock URL hardcoded on line key 2 (type 17/URL). Keys 3+ remain
managed by 3CX BLF as usual.
2026-04-27 13:08:57 -04:00
Adam Moussa
7c626c960e Apply display settings to SP template — both templates now match
Backlight dims to level 1 after 5 min, screensaver and power saving disabled.
2026-04-23 11:00:00 -04:00
Adam Moussa
8eb93536ad Add display settings to door-unlock template and update README
- Backlight dims to level 1 after 5 min, never fully sleeps
- Screensaver and power saving disabled
- README updated with T54W references and SP template manual steps
2026-04-22 20:01:09 -04:00
Adam Moussa
2c9b86367b Add 3CX provisioning templates for Yealink T54W with door unlock key
Two variants:
- yealinkT54W-door-unlock.ph.xml — line key 2 as door unlock URL
- yealinkT54W-door-unlock-with-sp.ph.xml — line key 2 as door unlock, keys 3-5 as shared parking SP1-3
2026-04-22 19:43:26 -04:00
Adam Moussa
d90f191032 Add README with architecture overview, SSM parameters, and phone setup instructions 2026-04-22 14:37:38 -04:00
Adam Moussa
12eb0ff9be Add door unlock API — Yealink DSS key triggers LenelS2 Elements TemporaryUnlock via API Gateway + Lambda 2026-04-22 14:36:55 -04:00