Commit graph

20 commits

Author SHA1 Message Date
Adam Moussa
d27772381b
Remove state-listing path from wo-po-lookup site lookups (#92)
The verified-sites table's by-state GSI was deleted by its owning
stack (procurement-ingest, audit M-20, 2026-06-03, "0 reads in 30d"),
so the state-listing branch of lookup_site has failed at runtime ever
since. Per the owner's decision, remove the path end-to-end instead
of restoring the GSI: drop the by-state Query from the Lambda, remove
the state parameter from the WO_PO_Lookup lookup_site function schema
(site_code is now required), strip state listings from the agent
instruction, and update the README data-contract table. siteCode
point lookups are unaffected. A stale state parameter from an older
prepared agent version now returns a clear "no longer supported"
message.

Refs: INFRA-180
2026-07-15 18:51:53 -04:00
Adam Moussa
b3c75c88d2
Fix notion-sync header crash on non-ASCII titles (#48)
S3 user-metadata values are sent as HTTP headers, which must be
US-ASCII. Notion page titles routinely contain em dashes and other
non-ASCII characters, causing ERR_INVALID_CHAR and a daily sync
failure. Sanitize the notion-title metadata to printable ASCII.

Also treat a Bedrock ConflictException from StartIngestionJob as
benign (an ingestion job is already running and will pick up the
freshly uploaded files) instead of failing the whole invocation.
2026-06-08 15:42:40 -04:00
Adam Moussa
e7b421e4cf fix: flat DM replies, clean up debug logging
DMs now reply flat in conversation instead of threading. Channel
@mentions still thread. Removed verbose debug logging from socket-mode
service, kept minimal operational logs. Added .DS_Store to gitignore.
2026-04-30 18:37:08 -04:00
Adam Moussa
006dbf7c6b feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions
- Rename bot to Alex with friendly/professional persona (Bedrock Agent instruction rewrite)
- Replace HTTP webhook Lambda with ECS Fargate Socket Mode service (persistent WebSocket)
- Add payment/invoice lookup via PaymentsDashboard table (vendor, invoice, check search)
- Switch from manual SiteAssignments to auto-populated verified-sites table
- Add channel support via app_mention events (threaded replies)
- Add App Home tab with Block Kit capabilities view
- Add unanswered questions logging to seahaven-unanswered-questions DynamoDB table
- Fix pre-existing compliance: add arm64 + 60-day log retention to all Lambdas
- Remove webhook Lambda and seed-sites script (both obsolete)
2026-04-30 16:38:54 -04:00
Adam Moussa
d1b91ae661 Read OAuth client credentials from Secrets Manager at runtime
Removes CloudFormation dynamic references for clientId/clientSecret
env vars. Credentials are now fetched from Secrets Manager at runtime
so secret updates don't require a redeploy.
2026-04-13 20:22:21 -04:00
Adam Moussa
9463a07e50 Use Intuit discovery document for OAuth endpoints
Fetch authorization, token, and revocation endpoints from Intuit's
.well-known/openid_configuration at runtime instead of hardcoding.
Cached per Lambda instance for performance.
2026-04-13 19:59:23 -04:00
Adam Moussa
266fe833fd Fix Intuit security compliance issues
- CSRF: store OAuth state in Secure/HttpOnly cookie, validate on callback
- Cache-Control: add no-cache, no-store headers to all responses
- Sensitive info: callback errors now 302 redirect instead of returning HTML
- Logging: remove realmId and sanitize error logs to prevent QBO data leaks
2026-04-13 19:49:29 -04:00
Adam Moussa
acfe8185a9 Add QBO OAuth endpoints for QuickBooks app listing
Adds /qbo/connect, /qbo/callback, /qbo/disconnect, and /qbo/launch
routes to bot.seahaven.com for Intuit app store compliance. Also
updates qbo-lookup to persist rotated refresh tokens automatically.
2026-04-13 19:31:13 -04:00
Adam Moussa
fb026dfd72 Add Amazon site assignments lookup via DynamoDB
- Create SiteAssignments DynamoDB table with state GSI for site code and
  state-based queries
- Add lookup_site function to wo-po-lookup action group lambda
- Add seed script (scripts/seed-sites.ts) to load site CSV into DynamoDB
- Upload site list markdown to KB S3 bucket for semantic search
- Update agent instruction to include site lookup capability
- Update README with site assignment docs and maintenance notes
2026-04-13 19:11:39 -04:00
Adam Moussa
8b6e65bd20 Improve Slack formatting for WO/PO lookups
- Add markdown-to-Slack mrkdwn conversion in processor (** → *, ## → bold)
- Restructure lambda output with cleaner sections and date formatting
- Update agent instruction to present data concisely
2026-04-13 18:34:47 -04:00
Adam Moussa
24ebe8bdcc Add WO/PO direct lookup action group for reliable ID-based queries
Vector search couldn't match exact work order/PO numbers, so queries
always came back empty. This adds a dedicated lambda that queries
DynamoDB directly by ID, wired as a Bedrock Agent action group.
2026-04-13 17:59:47 -04:00
Adam Moussa
40216430c6 Merge master after PO sync PR merge 2026-04-13 15:38:13 -04:00
Adam Moussa
641494530b fix: concurrent uploads and overwrite-in-place sync strategy
- Upload S3 files 10x concurrently instead of sequentially
- Replace clear-then-write with overwrite-in-place + delete stale
  to avoid S3 404s during concurrent KB ingestion jobs
2026-04-13 15:36:16 -04:00
Adam Moussa
adbe19aa16 fix: concurrent uploads, overwrite-in-place, 15min timeout
- Bump Lambda timeout from 5min to 15min (9k+ POs need more time)
- Upload S3 files 25x concurrently instead of sequentially
- Replace clear-then-write with overwrite-in-place + delete stale
  to avoid S3 404s during concurrent KB ingestion jobs
2026-04-13 15:36:07 -04:00
Adam Moussa
7240147736 feat: daily work orders DynamoDB → Bedrock KB sync
Add a new Lambda and CDK construct that scans the WorkOrders and
WorkOrderComments DynamoDB tables (owned by workorder-ingest),
converts each work order + comment history to markdown, uploads
to S3 under the work-orders/ prefix, and triggers a Bedrock
Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.
2026-04-13 14:35:47 -04:00
Adam Moussa
615970eba2 feat: daily purchase-orders DynamoDB → Bedrock KB sync
Add a new Lambda and CDK construct that scans the purchase-orders
DynamoDB table (owned by po-ingest), converts each PO to markdown,
uploads to S3 under the purchase-orders/ prefix, and triggers a
Bedrock Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.
2026-04-13 14:33:53 -04:00
8b18279023 feat: daily Notion → Bedrock KB sync
Adds a scheduled Lambda that pulls all pages from the Office Operations
Notion teamspace, converts them to markdown, uploads to the KB S3 bucket
under a notion/ prefix, and triggers a Bedrock ingestion job. Runs daily
at 02:00 UTC via EventBridge. Notion API key stored in Secrets Manager at
seahaven/notion/api-key (placeholder — fill in post-deploy).
2026-04-12 22:21:39 -04:00
Adam Moussa
505b624242 Add thinking placeholder and improve location parameter handling
- Post '_Sea Haven Assistant is thinking..._' immediately on receipt,
  then update the message with the real response (chat.update)
- Broaden Maps location parameter description so agent passes facility
  names like 'Amazon BFI9' directly to Google Maps rather than asking
  the user to provide a street address
2026-04-12 00:01:33 -04:00
Adam Moussa
635e712966 Switch to Claude Sonnet 4.5 cross-region inference profile
- Update foundation model to us.anthropic.claude-sonnet-4-5-20250929-v1:0
  (cross-region inference profile required for Claude 4.x on Bedrock Agents)
- Broaden agent role IAM policy to cover wildcard-region foundation model ARN
  and inference profile ARN
- Force alias version bump via description change so CloudFormation creates
  agent version 2 with the updated model
- Remove invalid includedType: 'contractor' from Google Maps Places API request
  (caused 400 Bad Request — not a valid place type for searchText endpoint)
2026-04-11 23:52:44 -04:00
Adam Moussa
f7e63e50c9 Initial scaffold: Bedrock-backed Slack DM bot
- CDK stack for Sea Haven Industries internal Slack assistant
- Bedrock Agent (Claude 3.5 Sonnet) with QBO + Google Maps action groups
- VectorKnowledgeBase via @cdklabs/generative-ai-cdk-constructs (AOSS + S3)
- Slack webhook/processor Lambdas with DM-only filtering
- API Gateway HTTP API on bot.seahaven.com
- DynamoDB conversation log with 90-day TTL
- Secrets Manager references for Slack, QBO OAuth, and Google Maps
2026-04-11 23:15:15 -04:00