Commit graph

420 commits

Author SHA1 Message Date
Alexandre Brandizzi
60e006e8d7 fix(uplifts): calculate granted exposure amounts (SH-207) 2026-09-16 22:17:59 -03:00
Alexandre Brandizzi
3cb1e3e3f3 feat(uplifts): add approval queue read contract (SH-207) 2026-09-16 20:03:35 -03:00
Alexandre Brandizzi
d204536215
Merge pull request #121 from Sea-Haven-Industries/feat/ab/sh-278-vendor-area
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
SH-278: add admin-assigned vendor company Area
2026-09-16 17:05:57 -03:00
Alexandre Brandizzi
3047c2ba59
Merge branch 'dev' into feat/ab/sh-278-vendor-area 2026-09-16 17:00:27 -03:00
Alexandre Brandizzi
4b772c8db3
fix(work-orders): keep SH placeholder WO numbers and block downgrades (#123)
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
SH-320: the WO number normalizer stripped every non-digit, so a manually
entered SH placeholder (e.g. SH00001) was saved as 00000000001 on both
create and patch. Keep the SH prefix, and reject replacing a saved real
APM number with an SH placeholder.
2026-09-16 15:01:10 -03:00
Alexandre Brandizzi
776c8be5cb
fix(work-orders): resolve undetermined media MIME from the extension (SH-370) (#122)
The media allowlist refused any upload whose multipart part had an empty or
application/octet-stream Content-Type before looking at the extension or the
bytes. Browsers take that header from File.type, which mobile browsers leave
empty when the OS cannot classify a picked file, while the client-side gate
already accepts such files on extension alone. A real JPG/MP4/MOV could pass
the dialog and still be refused by the API.

Only an undetermined type now falls back to the extension. The resolved type
still goes through the SH-171 document/category rule, the extension pairing,
and the magic-byte signature check, so an octet-stream .pdf stays refused for
Completion, Before and After, and a declared type is never overridden.
2026-09-16 14:53:58 -03:00
Alexandre Brandizzi
caba84ea08
fix(work-orders): reject forged automatic lifecycle statuses on board patch (SH-357, SH-358) (#120)
Incomplete and Scheduled are derived by the server. A direct lifecycleStatus
PATCH may only restate the status derivation already produced; any other
request to move a work order into an automatic state returns the stable
AutomaticLifecycleStatus validation error and leaves status and audit untouched.
2026-09-16 14:41:23 -03:00
Alexandre Brandizzi
8515676f4d feat(vendors): add admin-assigned vendor company Area
Seed an organization-wide Area catalogue (East, Central, West, California)
with stable ids, add a nullable AreaId to VendorCompany, allow only Admins
to change it through the roster endpoints, expose areas facet metadata and
an areas[n] company-directory filter with the __unassigned__ sentinel.
2026-09-16 11:34:45 -03:00
Alexandre Brandizzi
d07ac42452
Merge pull request #118 from Sea-Haven-Industries/feat/ab/sh-138-site-contacts
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
SH-138: manage ordered site contacts
2026-09-16 10:47:23 -03:00
Alexandre Brandizzi
0248aea542 fix(locations): preserve contacts when deleting sites 2026-09-15 19:03:54 -03:00
Alexandre Brandizzi
4872fe5ba1 feat(locations): manage ordered site contacts 2026-09-15 19:03:54 -03:00
Alexandre Brandizzi
802b7a414e
SH-338: filter unscheduled work orders before pagination (#116)
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
* fix(work-orders): filter unscheduled search server-side

* fix(work-orders): preserve unscheduled status scope
2026-09-15 16:46:40 -03:00
Alexandre Brandizzi
13ce4b7e88
docs: add complete dev Postman API collection (#119)
* docs: add dev Postman starter collection

* docs: generate complete dev Postman API collection
2026-09-15 16:39:49 -03:00
Alexandre Brandizzi
1a6edd255a
feat(locations): filter sites by state (#117)
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
2026-09-15 16:32:30 -03:00
Alexandre Brandizzi
3a4af64a64
fix(observability): preserve backend release identity (#114) 2026-09-15 16:08:14 -03:00
Alexandre Brandizzi
67089c2135
SH-281: group vendor directory by company (#115)
* feat(vendors): group directory by company

* style(vendors): format company directory query

* fix(vendors): preserve technician list contract
2026-09-15 16:02:44 -03:00
Arthur Bassi
eb9b7eb50e
Merge pull request #113 from Sea-Haven-Industries/feat/SH-191-completion-freeze
Some checks failed
Validate and deploy / Validate deployable source bundle (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Has been cancelled
feat(work-orders): capture Site/Vendor/POC snapshot on Completed
2026-09-14 11:03:06 -03:00
Arthur Bassi
073d4df963
Merge branch 'dev' into feat/SH-191-completion-freeze 2026-09-14 09:47:22 -03:00
Arthur Bassi
deeb29b512 fix(work-orders): allow Complete without a linked site
Snapshot whatever Site/Vendor/POC data exists instead of gating completion on Locations.
2026-09-10 17:56:00 -03:00
Alexandre Brandizzi
76c606eb75
Merge pull request #110 from Sea-Haven-Industries/fix/SH-337-completion-doc-allowlist
Some checks failed
Validate and deploy / Validate deployable source bundle (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Has been cancelled
fix(work-orders): enforce a file allowlist on completion-doc upload (SH-337)
2026-09-10 15:52:21 -03:00
Arthur Bassi
e0139d4601 feat(work-orders): capture Site/Vendor/POC snapshot on Completed
Freeze effective live values on first Completed transition and project them on GET.
2026-09-10 15:46:25 -03:00
Alexandre Brandizzi
6212949fff test(work-orders): scope the media-allowlist guard to photo categories
Updating this branch onto dev turned MediaRules_StillRejectPdf red, and the
test was the thing that had gone stale, not the rule. SH-171 added documents
to the SH-116 media allowlist for Extra and Aveta in 3454125 — a deliberate
widening with its own review — so asserting that media rejects a PDF outright
now contradicts shipped behaviour.

What this branch actually needs guarded is that the completion-doc allowlist
stopped there. Assert it per category instead: Completion, the category
SH-337 touches, plus Before and After, must all still refuse a PDF.
2026-09-10 14:46:54 -03:00
Alexandre Brandizzi
af6faf77e3
Merge branch 'dev' into fix/SH-337-completion-doc-allowlist 2026-09-10 14:38:06 -03:00
Alexandre Brandizzi
6d58865253
Merge pull request #111 from Sea-Haven-Industries/fix/ab/deploy-verify-health-convergence
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
fix(deploy): let EB health converge before failing the version gate
2026-09-10 14:37:57 -03:00
Adam Moussa
e330599044
Merge branch 'dev' into fix/ab/deploy-verify-health-convergence 2026-09-10 11:11:41 -04:00
Alexandre Brandizzi
9a49a5c40a fix(deploy): apply the health-convergence fix to the dev Terraform rollback
The dev Terraform rollback verify was the one gate the previous commit
missed, and it is the copy that actually ran on 34293894914. It still
decided on the first Ready poll: previous version correctly restored,
health not yet converged, reported as a failed rollback.

Split the version and health conditions the same way the other three
gates now do — a Ready poll on the wrong version fails immediately and
names the version that came up, while the correct version with unsettled
health keeps polling inside the unchanged 80 x 15s budget. Timeout now
reports the last observed status, version and health.
2026-09-10 10:55:45 -03:00
Arthur Bassi
492478f815
Merge pull request #112 from Sea-Haven-Industries/feat/SH-186-status-auto-derivation
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
feat(work-orders): derive Scheduled from concrete Schedule On
2026-09-09 17:46:18 -03:00
Arthur Bassi
1e37fb486c Merge remote-tracking branch 'origin/dev' into feat/SH-186-status-auto-derivation 2026-09-09 17:34:00 -03:00
Arthur Bassi
815e17c56f
Merge pull request #109 from Sea-Haven-Industries/feat/SH-171-wo-documents
feat(work-orders): add authorized Extra Docs content GET
2026-09-09 17:33:04 -03:00
Arthur Bassi
e849991dcf test(work-orders): seed scheduled concurrency scenario 2026-09-09 17:09:26 -03:00
Arthur Bassi
3454125d2d fix(work-orders): address document review feedback 2026-09-09 17:09:26 -03:00
Arthur Bassi
cd34a23e78 Merge remote-tracking branch 'origin/dev' into feat/SH-186-status-auto-derivation 2026-09-09 10:24:15 -03:00
Arthur Bassi
8b4aec300f feat(work-orders): re-derive lifecycle when board status is patched
Scheduled still requires a concrete date, and Incomplete/Pending with a date must promote even when only lifecycleStatus is sent.
2026-09-09 10:23:22 -03:00
Alexandre Brandizzi
d1e3fb03ce fix(deploy): let EB health converge before failing the version gate
Elastic Beanstalk reports Ready as soon as a rollout finishes, before
enhanced health has converged. Both verification gates decided on the first
Ready poll, so a release whose version had activated correctly was failed on
a health value that had not settled yet — and then rolled back.

The failure message compounded it: run 34293894914 printed 'Environment
became Ready without activating expected version a0fdd199...' when the
active version was exactly a0fdd199... The discriminator was health, not
version, which sends whoever reads the log after the wrong problem.

Separate the two conditions, keep polling while the correct version is
active but health has not settled, and report the last observed state on
timeout. An environment that stays unhealthy for the full window still
fails; this does not widen what counts as a good deploy.
2026-09-08 21:31:55 -03:00
Alexandre Brandizzi
7e4db749d0 fix(work-orders): enforce a file allowlist on completion-doc upload (SH-337)
The completion-document endpoint persisted whatever file it received: the
only checks were non-null, non-empty, and a 30 MB request limit. Its sibling
media endpoint has enforced a MIME allowlist, MIME-to-extension pairing, and
a magic-byte signature check since SH-116.

Validate before the file reaches storage, so a rejected upload leaves nothing
behind. An undetermined content type is accepted only alongside a .pdf name
and a %PDF- signature, because the browser leaves File.type empty when the OS
cannot classify the file and the completion-doc dialog already allows that.
2026-09-08 21:24:10 -03:00
Arthur Bassi
a0fdd19934
fix(work-orders): accept image/jpg MIME and expose board MediaCount (#107)
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-09-09 00:10:52 +00:00
Arthur Bassi
12354f9bf7 test(work-orders): cover SH-186 schedule status derivation 2026-09-08 16:24:45 -03:00
Arthur Bassi
f3f9ac1b58 feat(work-orders): derive lifecycle on board create and schedule PATCH 2026-09-08 16:23:13 -03:00
Arthur Bassi
ae9122243d feat(work-orders): run schedule status side-effects on board field mutations 2026-09-08 16:22:11 -03:00
Arthur Bassi
e12b3ea54b feat(work-orders): apply schedule lifecycle promote and demote 2026-09-08 16:21:14 -03:00
Arthur Bassi
335390f746 feat(work-orders): derive Scheduled from date without assignee 2026-09-08 16:19:50 -03:00
Adam Moussa
1bdbc12292
fix(deploy): treat applied HCP runs as success (#108)
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
* fix(deploy): treat applied HCP runs as success

* fix(deploy): wait on rollback apply result

* fix(deploy): compare G3 formatting against the PR merge base

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(deploy): fence rollback create-run on unlock success

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 13:26:11 -04:00
Arthur Bassi
143d613547 test(work-orders): expect media content route 2026-09-08 11:25:26 -03:00
Arthur Bassi
9d8ae5ec24 feat(work-orders): add authorized media content GET 2026-09-08 11:23:52 -03:00
Arthur Bassi
b4f2c8b763 feat(work-orders): authorize WO media content reads 2026-09-08 11:19:41 -03:00
Arthur Bassi
a25fd0bd5d feat(work-orders): stream stored WO media safely 2026-09-08 11:09:55 -03:00
Arthur Bassi
bb651bb547 feat(work-orders): add file storage OpenRead port 2026-09-08 11:08:26 -03:00
Arthur Bassi
02df093798 feat(work-orders): align completion-doc size with Extra Docs 2026-09-08 11:07:17 -03:00
Arthur Bassi
b6b8d2e58f feat(work-orders): cap media uploads at 50MB 2026-09-08 11:06:05 -03:00
Arthur Bassi
47022c7761 feat(work-orders): allow Extra Docs PDF/DOC by category 2026-09-08 11:02:40 -03:00