sh-mcp/eslint.config.js
Adam Moussa b5e604dabe
Some checks failed
deploy / deploy (push) Has been cancelled
Phase 2a: Cognito auth substrate (CDK) + pre-token & group-sync Lambdas (#4)
* Phase 2a: Cognito auth substrate (CDK) + pre-token & group-sync Lambdas

Stands up the real AWS auth broker the servers already validate against
(SH_MCP_ENV=aws), surface-agnostic. Nothing deployed yet (gated on Google
secrets); CI synthesizes the stack.

infra/ — root CDK app, stack sh-mcp-auth:
  - Cognito user pool, ESSENTIALS feature plan (required for the V2 pre-token
    trigger), Google external OIDC IdP (client_id/secret resolved from Secrets
    Manager at deploy via CFN dynamic reference, never inlined).
  - Resource servers + per-tier app clients whose AllowedOAuthScopes ARE the
    trust-tier boundary: ops=(read,tasks), exec=(ops+gmail/calendar, NO finance),
    finance=(finance:read ONLY, 15-min access TTL). offline refresh 30d.
  - Cognito groups sh-mcp-ops/-assistant/-finance/-admin.
  - sync-state + deny-list DynamoDB tables (overrideLogicalId pinned so a future
    refactor cannot replace+drop them; deny-list TTL attr 'expiresAt').
  - Least-priv IAM (no wildcard action/resource; Google SA secret grant scoped to
    the one secret), arm64 Lambdas, explicit 60-day log groups, alarms on the
    seahaven-alarm-topics CMK (ALARM-state actions only, two-alarm group-sync).

auth/pre-token-gen — SUPPRESS-ONLY V2 Lambda. Maps Cognito group entitlement to
  scopesToSuppress; NEVER scopesToAdd a tier scope (AllowedOAuthScopes stays the
  ceiling). Reads last_successful_sync; fail-closed to base ops:read when stale.

auth/group-sync — mirrors Google Group membership into Cognito groups every 5 min
  (jose-signed SA JWT -> Directory API, no googleapis dep); writes the freshness
  marker ONLY on full success so a partial failure keeps the pre-token Lambda
  failing closed.

37 new tests (suppress-only policy, fail-closed, reconcile diff, 16 CDK
assertions incl. Essentials/V2/per-client-scope/no-wildcard-IAM). 448 total pass;
tsc -b + infra typecheck + cdk synth + prettier clean; CI run-cdk-synth re-enabled.

App-client callback URLs are a context placeholder pending the surface decision.
Confluence map (1540098) + project memory updates owed once this deploys.

* Phase 2a: harden auth substrate per security-review + IAM cross-review

Both mandatory gates run on the 2a diff. GPT-4.1 IAM/Lambda cross-review: the
suppress-only invariant is now an executable fail-closed guard (a future edit
that sets scopesToAdd throws → no token minted). /sh-security-review fan-out +
proof-or-kill verifier: PASS (0 confirmed critical/high). The verifier refuted
the two "high" candidates (the email-case revocation "bypass" is symmetric — the
add path uses the same lowercasing filter, so an un-removable user could never
have been added; the empty-directory purge is a non-200 throw → stale marker →
fail closed). Three confirmed findings remediated:

- C2 (deny-list was inert): the sh-mcp-deny-list table was provisioned and
  documented as "hard revocation" but no code read it. The pre-token Lambda now
  reads it on every mint (DENY_LIST_TABLE env + grantReadData) and strips a
  deny-listed sub to NO tier scopes, ahead of the next group sync. Fail-OPEN on
  a DDB read error (logs deny_list_read_failed) so a blip can't lock everyone
  out — group membership + its fail-closed 30-min window stay authoritative.
- C5 (finance 30-day refresh nullified the 15-min access TTL): refresh window is
  now per-tier; finance caps at 8h, ops/exec keep 30d.
- C7 (nested Google-group members silently dropped): listGroupMembers now sets
  includeDerivedMembership and skips non-USER rows, honoring the documented
  "nested resolved" contract instead of pushing a phantom group address.

Also corrects the sync.ts comment that overstated fail-closed as instantaneous
(it is bounded by MAX_SYNC_AGE_MS). +8 tests (deny-list unit, hard-revocation
handler path, finance refresh window, deny-list env wiring); 456 pass. tsc -b,
cdk synth, prettier, eslint all clean.
2026-06-26 14:33:46 -04:00

145 lines
5.1 KiB
JavaScript

// @ts-check
import tseslint from '@typescript-eslint/eslint-plugin';
import tsparser from '@typescript-eslint/parser';
/**
* Flat ESLint config for ESLint 9.x.
* Migrated from .eslintrc.cjs which required legacy mode.
*
* Rules mirror the original: recommended + recommended-requiring-type-checking
* plus project-specific overrides.
*/
/** @type {import('eslint').Linter.Config[]} */
const config = [
// ── Global ignores ──────────────────────────────────────────────────────────
{
ignores: [
'**/dist/**',
'**/node_modules/**',
'**/*.d.ts',
'eslint.config.js',
'vitest.config.ts',
],
},
// ── Source files (with project-based type checking) ─────────────────────────
{
files: ['packages/*/src/**/*.ts', 'servers/*/src/**/*.ts', 'auth/*/src/**/*.ts'],
languageOptions: {
parser: tsparser,
parserOptions: {
project: [
'./auth/pre-token-gen/tsconfig.json',
'./auth/group-sync/tsconfig.json',
'./packages/calendar/tsconfig.json',
'./packages/gmail/tsconfig.json',
'./packages/google-maps/tsconfig.json',
'./packages/internal-data/tsconfig.json',
'./packages/knowledge-base/tsconfig.json',
'./packages/payments/tsconfig.json',
'./packages/qbo/tsconfig.json',
'./packages/reminders/tsconfig.json',
'./packages/shared/tsconfig.json',
'./packages/tasks/tsconfig.json',
'./servers/sh-mcp-ops/tsconfig.json',
'./servers/sh-mcp-finance/tsconfig.json',
],
tsconfigRootDir: import.meta.dirname,
},
globals: {
process: 'readonly',
console: 'readonly',
},
},
plugins: {
'@typescript-eslint': tseslint,
},
rules: {
'no-undef': 'off', // TypeScript handles this
'no-unused-vars': 'off', // Use @typescript-eslint version
// Core @typescript-eslint/recommended rules
'@typescript-eslint/ban-ts-comment': 'error',
'@typescript-eslint/no-array-constructor': 'error',
'@typescript-eslint/no-duplicate-enum-values': 'error',
'@typescript-eslint/no-explicit-any': 'warn',
'@typescript-eslint/no-extra-non-null-assertion': 'error',
'@typescript-eslint/no-misused-new': 'error',
'@typescript-eslint/no-namespace': 'error',
'@typescript-eslint/no-non-null-asserted-optional-chain': 'error',
'@typescript-eslint/no-require-imports': 'error',
'@typescript-eslint/no-this-alias': 'error',
'@typescript-eslint/no-unnecessary-type-constraint': 'error',
'@typescript-eslint/no-unsafe-declaration-merging': 'error',
'@typescript-eslint/no-unused-expressions': 'error',
'@typescript-eslint/prefer-as-const': 'error',
'@typescript-eslint/prefer-namespace-keyword': 'error',
'@typescript-eslint/triple-slash-reference': 'error',
// Type-checked rules (require-type-checking)
'@typescript-eslint/no-floating-promises': 'error',
'@typescript-eslint/no-misused-promises': 'error',
'@typescript-eslint/no-unsafe-argument': 'warn',
'@typescript-eslint/no-unsafe-assignment': 'warn',
'@typescript-eslint/no-unsafe-call': 'warn',
'@typescript-eslint/no-unsafe-member-access': 'warn',
'@typescript-eslint/no-unsafe-return': 'warn',
'@typescript-eslint/require-await': 'warn',
'@typescript-eslint/restrict-template-expressions': 'warn',
// Project-specific overrides
'@typescript-eslint/explicit-function-return-type': 'warn',
'@typescript-eslint/no-unused-vars': [
'error',
{
argsIgnorePattern: '^_',
varsIgnorePattern: '^_',
},
],
'@typescript-eslint/strict-boolean-expressions': 'warn',
},
},
// ── Test files + CDK synth apps (no project-based type checking) ────────────
// test/ dirs and cdk/ apps are excluded from the package/server tsconfigs, so
// type-checked rules are disabled here to avoid "file not in project" errors.
{
files: [
'packages/*/test/**/*.ts',
'servers/*/test/**/*.ts',
'servers/*/cdk/**/*.ts',
'auth/*/test/**/*.ts',
'infra/**/*.ts',
],
languageOptions: {
parser: tsparser,
parserOptions: {
// No `project` here — avoids "file not found in project" errors for
// test files that are excluded from the package tsconfigss.
// Type-checking rules are disabled below.
},
globals: {
process: 'readonly',
console: 'readonly',
},
},
plugins: {
'@typescript-eslint': tseslint,
},
rules: {
'no-undef': 'off',
'no-unused-vars': 'off',
'@typescript-eslint/no-explicit-any': 'warn',
'@typescript-eslint/no-unused-vars': [
'error',
{
argsIgnorePattern: '^_',
varsIgnorePattern: '^_',
},
],
},
},
];
export default config;