Commit graph

555 commits

Author SHA1 Message Date
Adam Moussa
10266e6e4b
Merge pull request #160 from Sea-Haven-Industries/renovate/reconfigure
chore(renovate): widen the schedule, track the EF tool pin, hold EF majors
2026-09-18 22:59:37 +00:00
Alexandre Brandizzi
e1ce3e439b
Merge pull request #149 from Sea-Haven-Industries/feat/ab/sh-292-notification-center
SH-292: Notification Center feed endpoint
2026-09-18 22:54:54 +00:00
Alexandre Brandizzi
0b3084a274
Merge pull request #155 from Sea-Haven-Industries/fix/ab/sh-379-manual-poc-override
Persist manual POC override with audit and site-follow (SH-379)
2026-09-18 22:54:51 +00:00
Alexandre Brandizzi
cd4d30af4b
Merge pull request #157 from Sea-Haven-Industries/fix/ab/sh-381-mobile-video-mime
fix(work-orders): accept mobile media whose declared MIME is foreign (SH-381)
2026-09-18 22:54:48 +00:00
Alexandre Brandizzi
a9773e67eb
Merge pull request #151 from Sea-Haven-Industries/feat/ab/sh-209-uplift-detail-context
SH-209: Expose dispatcher, technician and schedule on the uplift queue read
2026-09-18 22:53:56 +00:00
b270543d0d
chore(renovate): widen the schedule, track the EF tool pin, hold EF majors
The org window (before 6am on Monday) has produced no PRs in this repository
since the overlay landed, so the overlay now opens every weekday morning. A
regex manager tracks EF_VERSION in the Elastic Beanstalk packaging script,
which installs dotnet-ef at deploy time and would otherwise fall behind the
tool manifest and EF Core packages; it joins the nuget minor and patch group.
ASP.NET Core, EF Core and dotnet-ef majors are disabled while the target is
net8.0 so the dashboard approval list only shows updates that can be taken.
2026-09-18 18:48:12 -04:00
Adam Moussa
1888b66940
ci: run required checks on merge_group for the merge queue (#159)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
Build and test, architecture, and dependency-review are the required checks
on main. A merge queue only counts checks that ran on the merge_group event,
so each workflow now triggers on it. The architecture gate reads the merge
group's own base and head because github.event.before is empty there. The
dependency-review action cannot diff a merge group, so that event reports the
same check name from a pass-through job; the real review already gated the
pull request before it could be queued.
2026-09-18 18:16:10 -04:00
Alexandre Brandizzi
582af8fb2c fix(workorders): compare manual POC against the followed contact, not any site contact
The manual POC "follow the site" clear-rule compared the edit against every
live Site contact. A work order only ever displays one of them, so editing to
a different live contact (Site has Alice primary and Bob; WO shows Alice; edit
to Bob) matched, cleared the override, and left the row showing Alice with no
audit row written — the SH-379 symptom on a different input. A work order with
a linked WorkOrderContacts POC hit the same bug when the dispatcher typed the
Site's primary: the override cleared and the linked contact showed instead.

Compare the edit against the single contact the work order actually follows —
the linked WorkOrderContacts POC, or else the Site primary (ResolvePrimary) —
matching the board projection's override -> linked -> site precedence, and
store the override whenever the edit differs from it. The create path in
WorkOrderBoardCreateService had the same any-contact rule and gets the same
fix; a supplied PocContactId that is not a live Site contact leaves no follow
target, so the typed POC is stored.

Replaces MatchesAnySiteContact with Matches(name, phone, contact); comment and
PR-body wording updated to state the followed-contact rule. Adds tests for the
second-site-contact edit, the linked-contact-differs edit, and the
second-site-contact create case.
2026-09-18 18:56:29 -03:00
Adam Moussa
51417a65b5
Merge branch 'main' into fix/ab/sh-381-mobile-video-mime 2026-09-18 17:32:06 -04:00
Adam Moussa
503faa8c25
Merge branch 'main' into fix/ab/sh-379-manual-poc-override 2026-09-18 17:31:45 -04:00
Adam Moussa
1cd3c802e3
Merge branch 'main' into feat/ab/sh-209-uplift-detail-context 2026-09-18 17:31:12 -04:00
Adam Moussa
0556822d22
Merge branch 'main' into feat/ab/sh-292-notification-center 2026-09-18 17:30:22 -04:00
Adam Moussa
4fb4159df2
fix(iam): scope staging githubdeploy uploads to the staging release prefix (#158)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
2026-09-18 17:10:13 -04:00
Alexandre Brandizzi
46eed22707 fix(work-orders): accept mobile media whose declared MIME is foreign (SH-381)
Mobile browsers attach an unreliable Content-Type to a picked file: empty or
application/octet-stream when the OS cannot classify it, and sometimes a
foreign-but-plausible type for a supported container (video/3gpp for an .mp4,
video/x-quicktime for a .mov). The media allowlist already resolved empty and
octet-stream types from the extension, but a concrete foreign type was rejected
outright, so a real .MP4/.MOV picked on a phone passed the client dialog and was
refused by the API.

Any declared type that is not itself on the allowlist now falls back to the
extension. The extension pairing and magic-byte signature still decide, so the
accepted set of files is unchanged; an allowlisted declared type stays
authoritative and must still match its own extension.
2026-09-18 16:33:24 -03:00
Adam Moussa
9eb51b528f
chore(terraform): complete staging environment adoption (#156)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
* chore(terraform): complete staging environment adoption

* test(terraform): include deploy SSM parameters in the import ownership boundary
2026-09-18 15:13:18 -04:00
Adam Moussa
facc6ef71e
fix(iam): let staging githubdeploy GetObject the release zip (#154)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
* fix(iam): let staging githubdeploy GetObject the release zip

* fix(iam): allow staging githubdeploy to cache EB processed extensions

* fix(iam): allow staging githubdeploy GetObjectAcl for EB updates

* fix(iam): grant staging githubdeploy named S3 reads on EB resources prefix

* fix(iam): allow staging githubdeploy to delete EB version cache objects

* fix(iam): scope staging githubdeploy S3 object access to the EB bucket

* fix(iam): allow staging githubdeploy PutObjectVersionAcl on EB artifacts

* fix(iam): allow staging githubdeploy GetBucketPolicy on the EB bucket

* fix(iam): scope staging githubdeploy S3 objects to SHOC and staging EB prefixes
2026-09-18 15:29:15 -03:00
Alexandre Brandizzi
cbecc7b4ea fix(workorders): persist manual POC override with audit and site-follow (SH-379)
Editing a work order's POC never reached the backend: no update path wrote
PocName/PocPhone/PocNotes, so the optimistic UI edit was lost on refetch and
the completion freeze captured the Site contact instead of the manual value,
and nothing was audited.

- Add tenant-scoped PATCH api/workorders/{id}/poc via new WorkOrderPocService
  + WorkOrderPocDataService: persists the override, stages FieldChanged audit
  entries (which also write field locks so sync never overwrites a manual POC),
  and enforces row-version concurrency and terminal-status read-only rules.
- Lock semantics (SH-190): a manual POC away from the Site's live contacts is
  stored WO-level; an edit equal to a live Site contact (or blanking name+phone)
  stores nothing so the WO follows the Site. PocCustomized exposes the state.
- Board projection, completion freeze and create now share one Site-contact
  fallback (first non-deleted contact by SiteContactOrder) so a never-overridden
  WO keeps following the Site, including at create when the wizard prefills it.
- Route contract baseline gains PATCH {id:int}/poc.
2026-09-18 14:30:54 -03:00
Adam Moussa
90303f0e40
Merge pull request #153 from Sea-Haven-Industries/chore/retire-leftover-app-cd
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
chore(cd): retire leftover Terraform app CD path
2026-09-18 13:08:07 -04:00
b696a414a5
fix(cd): grant caller id-token write for reusable deploy workflows 2026-09-18 12:42:42 -04:00
f42576e2db
chore(cd): retire leftover Terraform app CD path 2026-09-18 12:38:15 -04:00
Alexandre Brandizzi
c9fa4a49af style(notifications): fix object initializer indentation in NotificationFeedService 2026-09-18 13:09:46 -03:00
Alexandre Brandizzi
aad3facaf1 fix(notifications): ignore soft-deleted dispatches and cap conflicts by recency
No Vendor treated any non-terminal dispatch as an assigned vendor without
checking IsDeleted, so a soft-deleted dispatch hid the work order from both
No Vendor and Vendor Conflict (the conflict query already drops deleted
dispatches). GetNoVendorAsync and the vendor-reminder assigned-work-order rule
now skip soft-deleted dispatches, keeping the asserted parity between the feed
and the reminders.

Vendor Conflict applied the section cap in vendor-sweep order, so when overlaps
exceeded the limit newer conflicts could be dropped while Count still counted
every work order. VendorConflictsAsync now orders pairs by recency before the
cap, matching the other per-work-order sections.
2026-09-18 12:59:56 -03:00
Alexandre Brandizzi
ad68bccb89 Merge remote-tracking branch 'origin/dev' into feat/ab/sh-209-uplift-detail-context 2026-09-18 12:58:27 -03:00
Adam Moussa
68ad7362df
Merge pull request #150 from Sea-Haven-Industries/dev
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
chore: promote GitHub-owned Elastic Beanstalk CD onto main
2026-09-18 11:52:35 -04:00
Alexandre Brandizzi
fa979605b4 feat(uplifts): expose dispatcher, technician and schedule on queue read (SH-209)
The uplift detail modal needs the work order's assigned dispatcher, the
requesting vendor's technician and the scheduled date. They now resolve
from the same effective work order and vendor as the existing queue row,
so the modal no longer depends on a separate work-order fetch that
account-scoped staff cannot read.
2026-09-18 12:49:25 -03:00
23f69307dd
chore: sync main into dev after #147
Some checks failed
Validate and deploy / Validate deployable source bundle (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-staging through Terraform (push) Has been cancelled
2026-09-18 11:44:02 -04:00
Adam Moussa
e74fff7722
Merge pull request #148 from Sea-Haven-Industries/refactor/main-branch-cd
refactor(cd): ship Elastic Beanstalk versions from GitHub on main
2026-09-18 11:43:03 -04:00
Adam Moussa
60a3fcc308
Merge pull request #147 from Sea-Haven-Industries/dev
chore: promote current dev onto main
2026-09-18 11:42:50 -04:00
Alexandre Brandizzi
da0b29f769 feat(notifications): serve the Notification Center feed grouped by reason
Adds GET /api/notifications, a per-user read model derived from live
work-order state: Unassigned (grouped, High), No Vendor and Aveta Missing
(per work order, Medium) and Vendor Conflict, account-scoped from claims
and ordered by section severity with a fixed reason tie-break.
2026-09-18 12:40:37 -03:00
396b1c690b
fix(cd): honor reusable workflow inputs when resolving deploy target 2026-09-18 11:33:34 -04:00
7eaa7fb3f9
docs(cd): document GitHub Environment branch and tag policies 2026-09-18 11:22:50 -04:00
8f4fa36647
refactor(cd): ship Elastic Beanstalk versions from GitHub on main
Keep application and Terraform changes in separate PRs so a merge cannot race an HCP apply against an app deploy.
2026-09-17 15:54:31 -04:00
Alexandre Brandizzi
63f80990cf
Merge pull request #144 from Sea-Haven-Industries/feat/ab/sh-207-uplift-queue-flags
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging through Terraform (push) Blocked by required conditions
SH-207: Complete uplift queue list contract (closed flag, attachments, decider, pending exposure)
2026-09-17 14:30:23 -03:00
Adam Moussa
8dfb01cba7
Merge branch 'dev' into feat/ab/sh-207-uplift-queue-flags 2026-09-17 13:22:38 -04:00
Alexandre Brandizzi
d02aa11285
Merge pull request #124 from Sea-Haven-Industries/fix/ab/sh-287-backend-staging-lane
feat(deploy): rebuild protected backend staging lane
2026-09-17 14:22:11 -03:00
Adam Moussa
b9bcaea9f3
Merge branch 'dev' into feat/ab/sh-207-uplift-queue-flags 2026-09-17 13:17:04 -04:00
Alexandre Brandizzi
5e70163941
Merge branch 'dev' into fix/ab/sh-287-backend-staging-lane 2026-09-17 14:16:10 -03:00
Alexandre Brandizzi
455ff5568c
Merge pull request #139 from Sea-Haven-Industries/feat/ab/sh-326-team-member
SH-326: add team member detail editing
2026-09-17 14:14:11 -03:00
Alexandre Brandizzi
6db9ad758f
Merge branch 'dev' into fix/ab/sh-287-backend-staging-lane 2026-09-17 14:10:11 -03:00
Alexandre Brandizzi
8a4de283dc Merge remote-tracking branch 'origin/dev' into feat/ab/sh-326-team-member
# Conflicts:
#	Api.SeaHavenIndustries.Tests/TeamMemberServiceTests.cs
#	SeaHaven.DataServices/Implementation/TeamPermissionOverrideDataService.cs
2026-09-17 14:06:12 -03:00
Alexandre Brandizzi
0dc9ec288e
Merge pull request #137 from Sea-Haven-Industries/feat/ab/sh-325-create-team-member
SH-325: support pending team member creation
2026-09-17 14:00:18 -03:00
1a290ea2f7
Merge remote-tracking branch 'origin/dev' into HEAD 2026-09-17 12:50:09 -04:00
Alexandre Brandizzi
bc88ef0577 Merge remote-tracking branch 'origin/dev' into feat/ab/sh-326-team-member 2026-09-17 13:49:21 -03:00
Alexandre Brandizzi
2657be3108
Merge pull request #135 from Sea-Haven-Industries/feat/ab/sh-329-account-owner
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
SH-329: protect configured account owner
2026-09-17 13:44:13 -03:00
Adam Moussa
1f905fc7dd
Merge branch 'dev' into feat/ab/sh-329-account-owner 2026-09-17 12:36:26 -04:00
Alexandre Brandizzi
45519c1a82
Merge pull request #140 from Sea-Haven-Industries/feat/ab/sh-207-uplift-queue
SH-207: Deliver the uplift approval queue read contract
2026-09-17 13:28:16 -03:00
Alexandre Brandizzi
7b94ab9455 Merge remote-tracking branch 'origin/dev' into feat/ab/sh-207-uplift-queue 2026-09-17 13:05:07 -03:00
Alexandre Brandizzi
41957d52a7 merge: rebase queue flags onto SH-210 decisions, drop duplicated contract fields
#144 branched from the SH-210 decision-actions commit before the SH-207/SH-208
read-contract corrections landed, so it re-implemented workOrderClosed,
attachmentCount, decidedByName, and pendingExposureTotal with stale semantics:
it projected WorkerOrderNumber (the CRM external id) instead of InternalWONumber
(what the board renders) and summed raw RequestedNTE, which double-counts the new
NTE total on vendor-portal rows across sequential approvals.

Merge origin/feat/ab/sh-210-uplift-decisions (#141, what lands) in and resolve
every conflict in #141's favour, so those fields and their granted-amount
exposure math now come from #141 rather than being duplicated here. Keep only the
two deltas #144 actually adds on top of #141:

- attachmentCount counts non-deleted UpliftEvidence documents on the dispatch,
  not every completion document, so completion photos no longer inflate the chip;
- the queue read resolves the effective work order via the primary-plus-linked
  (DispatchWorkOrders) convention the sibling reads use, so a dispatch linked only
  through that table surfaces its WO context, closed flag, and exposure. Covered
  by an in-memory test and a SQLite relational test that proves the fallback
  translates to SQL.

Drop the superseded attachment-count test that asserted completion documents
count, and align the relational test to seed InternalWONumber.
2026-09-17 12:52:13 -03:00
Alexandre Brandizzi
0ae64f9ab9
Merge pull request #141 from Sea-Haven-Industries/feat/ab/sh-210-uplift-decisions
SH-210: Route uplift decisions through the work-order flow
2026-09-17 12:50:22 -03:00
Alexandre Brandizzi
046dee99bf
Merge branch 'dev' into feat/ab/sh-207-uplift-queue 2026-09-17 12:44:15 -03:00