Commit graph

219 commits

Author SHA1 Message Date
dependabot[bot]
d52b73eba9
chore(deps): bump constructs from 10.7.2 to 10.8.1 in /infra/cdk
Bumps [constructs](https://github.com/aws/constructs) from 10.7.2 to 10.8.1.
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.7.2...v10.8.1)

---
updated-dependencies:
- dependency-name: constructs
  dependency-version: 10.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-11 02:44:46 +00:00
dependabot[bot]
a7b1f3bc40
chore(deps-dev): bump typescript from 5.9.3 to 7.0.2 in /infra/cdk (#53)
Some checks failed
Validate and deploy dev / Validate deployable source bundle (push) Has been cancelled
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Has been cancelled
* chore(deps-dev): bump typescript from 5.9.3 to 7.0.2 in /infra/cdk

Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 7.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix(cdk): migrate TypeScript config for TS 7 moduleResolution

Use Node16 module/moduleResolution and explicit .js relative import
so npm run synth succeeds under TypeScript 7.0.2.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Arthur Bassi <arthur.bassi@luby.com.br>
2026-08-04 10:36:09 -03:00
dependabot[bot]
7a72be3088
chore(deps): bump constructs from 10.7.1 to 10.7.2 in /infra/cdk (#55)
Bumps [constructs](https://github.com/aws/constructs) from 10.7.1 to 10.7.2.
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.7.1...v10.7.2)

---
updated-dependencies:
- dependency-name: constructs
  dependency-version: 10.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-08-04 10:17:22 -03:00
dependabot[bot]
466a40d8de
chore(deps-dev): bump @types/node from 22.20.1 to 26.1.2 in /infra/cdk (#54)
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 22.20.1 to 26.1.2.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.1.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 10:10:29 -03:00
dependabot[bot]
b27bf06c8e
chore(deps-dev): bump aws-cdk from 2.1133.0 to 2.1134.0 in /infra/cdk (#52)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
Bumps [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) from 2.1133.0 to 2.1134.0.
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1134.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk
  dependency-version: 2.1134.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-08-04 10:03:06 -03:00
dependabot[bot]
66e1a662c3
chore(deps): bump actions/checkout from 4 to 7 (#51)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](https://github.com/actions/checkout/compare/v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-08-04 09:56:24 -03:00
dependabot[bot]
c7e7ffa313
chore(deps): bump actions/setup-dotnet from 4 to 6 (#50)
Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 4 to 6.
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](https://github.com/actions/setup-dotnet/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/setup-dotnet
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-08-04 09:49:05 -03:00
dependabot[bot]
b2366acdfa
chore(deps): bump actions/setup-node from 6.5.0 to 7.0.0 (#49)
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.5.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](249970729c...8207627860)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 09:40:55 -03:00
Alexandre Brandizzi
669e9b2932
feat(vendors): add company roster management (SH-198) (#48)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
* feat(vendors): add company roster management

* fix(security): remove request-controlled write guards

* fix(vendors): synchronize roster company fields

* fix(vendors): source facets from companies
2026-08-03 17:53:24 -03:00
Alexandre Brandizzi
47c3fff4ba
fix(cdk): allow Beanstalk VPC discovery (#44)
Some checks failed
Validate and deploy dev / Validate deployable source bundle (push) Has been cancelled
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Has been cancelled
* fix(cdk): allow Beanstalk VPC discovery

* chore(ci): clarify backend check name

* fix(eb): allow temporary object cleanup

* fix(cdk): allow managed environment stack update

* fix(cdk): allow Beanstalk template read

* fix(cdk): apply supported Beanstalk S3 policy

* fix(cdk): allow load balancer discovery and cancel

* fix(cdk): allow Beanstalk resource discovery
2026-07-30 11:40:06 -04:00
Adam Moussa
83ed6a1790
fix(eb): configure work-order webhook HMAC secret source (#41)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
2026-07-30 11:44:43 -03:00
Alexandre Brandizzi
85ce7c6384
Merge pull request #40 from Sea-Haven-Industries/codex/vendor-document-detail-read-model
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
feat(vendor-portal): complete dispatch detail read model
2026-07-30 11:06:09 -03:00
Alexandre Brandizzi
1a169360a3
Merge branch 'dev' into codex/vendor-document-detail-read-model 2026-07-29 22:06:48 -03:00
Alexandre Brandizzi
1a3d9ac3e0
Merge pull request #43 from Sea-Haven-Industries/fix/eb-runtime-copy-permission
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
fix(cdk): allow Beanstalk runtime bundle copy
2026-07-29 21:59:04 -03:00
brandizzi
76cdc70c18 fix(cdk): allow EB runtime manifest updates 2026-07-29 11:07:53 -03:00
brandizzi
b8db4a7e61 fix(cdk): allow EB bucket policy read 2026-07-29 11:02:30 -03:00
brandizzi
c2f2c411d8 fix(cdk): allow EB extension verification 2026-07-29 10:33:31 -03:00
brandizzi
5b719a660e fix(cdk): allow EB environment extension write 2026-07-29 09:55:58 -03:00
brandizzi
3f60730464 fix(cdk): allow EB embedded extension write 2026-07-29 09:45:45 -03:00
brandizzi
156b7bbed6 fix(cdk): allow EB runtime version ACL write 2026-07-29 09:30:48 -03:00
brandizzi
9f54399e63 fix(cdk): allow EB runtime version ACL read 2026-07-29 09:26:12 -03:00
brandizzi
424bf20f54 fix(cdk): allow EB runtime verification 2026-07-29 09:21:28 -03:00
brandizzi
42d8772951 fix(cdk): allow EB runtime cleanup 2026-07-29 09:05:44 -03:00
brandizzi
b02787087e fix(cdk): allow EB runtime bundle copy 2026-07-29 08:56:19 -03:00
Alexandre Brandizzi
68162ef0fb
Merge pull request #42 from Sea-Haven-Industries/fix/eb-aws-owned-s3-scope
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
fix(cdk): grant AWS-confirmed Beanstalk ACL read
2026-07-29 08:46:44 -03:00
brandizzi
061a084fda fix(cdk): grant AWS-confirmed EB ACL read 2026-07-29 08:01:01 -03:00
Alexandre Brandizzi
148a0750f9 feat(vendor-portal): expose dispatch payment details 2026-07-28 17:19:42 -03:00
Alexandre Brandizzi
eb796ab591 Merge remote-tracking branch 'origin/dev' into codex/vendor-document-detail-read-model 2026-07-28 16:12:10 -03:00
Alexandre Brandizzi
658bae77d3
fix(cdk): grant observed Elastic Beanstalk deploy reads (#38)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
* fix(cdk): grant observed EB deploy reads

* fix(cdk): model EB deployment capability

* fix(cdk): scope EB platform ACL read

* fix(deploy): verify exact EB release

* docs(deploy): record unresolved EB ACL gate
2026-07-28 15:04:48 -03:00
Alexandre Brandizzi
36d0a638a2 fix(vendors): return completion documents in portal detail 2026-07-28 14:19:15 -03:00
Alexandre Brandizzi
5ecb377613
fix: align vendor document API with frontend (#37)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
2026-07-28 13:57:45 -03:00
Alexandre Brandizzi
45ffa68dfa
fix: allow Elastic Beanstalk bucket setup check (#36)
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
2026-07-28 12:51:20 -03:00
Alexandre Brandizzi
8f41190a74
Merge pull request #35 from Sea-Haven-Industries/codex/sh133-s3-read-fix
Some checks are pending
Validate and deploy dev / Validate deployable source bundle (push) Waiting to run
Validate and deploy dev / Deploy shoc-backend to Elastic Beanstalk dev (push) Blocked by required conditions
Fix Elastic Beanstalk bundle validation
2026-07-28 11:19:57 -03:00
Alexandre Brandizzi
34b5f09828 fix: allow deployment bundle validation 2026-07-28 11:12:39 -03:00
Alexandre Brandizzi
8539c07f82
Merge pull request #33 from Sea-Haven-Industries/codex/sh-133-cdk-deploy
SH-133: automate dev backend deployment
2026-07-28 10:59:28 -03:00
Alexandre Brandizzi
da29dcf983 fix: make deploy artifacts immutable 2026-07-28 10:38:38 -03:00
Alexandre Brandizzi
73b525a685 ci: document CDK advisory exception 2026-07-27 19:29:37 -03:00
Alexandre Brandizzi
9057668459 ci: automate dev backend deployment 2026-07-27 19:26:07 -03:00
Alexandre Brandizzi
4bfd8bab72
Merge pull request #32 from Sea-Haven-Industries/feature/sh-133-procurement-ingest
SH-133: Complete procurement work-order ingestion
2026-07-27 17:44:31 -03:00
Alexandre Brandizzi
f701899a83 fix(work-orders): satisfy producer contract review 2026-07-27 16:33:06 -03:00
Alexandre Brandizzi
27bf81b7f8 fix(work-orders): address procurement review findings 2026-07-27 14:40:17 -03:00
Alexandre Brandizzi
8a2e260177 test: prove SH-133 webhook and admin boundaries 2026-07-25 15:45:52 -03:00
Alexandre Brandizzi
e3c37e54b4 feat: complete SH-133 procurement reconciliation 2026-07-24 22:13:25 -03:00
Alexandre Brandizzi
bdffe77e42 feat: ingest signed procurement work-order webhooks 2026-07-24 21:03:50 -03:00
Arthur Bassi
8f492c0faf
feat(work-orders): allow comment edit and resolve author audit display names (#24)
* feat(work-orders): enrich board search overdue filters and 0-based paging

* fix(work-orders): align stacked services with CI build

* fix(tests): pass userDataService in comment service unit test

* fix(work-orders): use dedicated overdue query flag

Stop treating WorkOrderType.Other as an overdue sentinel. Board and advanced search now accept overdue=true while types=Other filters real Other rows; combining both uses OR.

* feat(work-orders): allow comment edit and resolve author audit display names

Add PATCH comment for author/Admin, return authorName, and resolve
AssignTo audit values to user display names.

* fix(work-orders): enforce author-only comment edits per SH-122

Remove the undocumented Admin override so only the original comment author can edit, matching the ticket acceptance criteria.

---------

Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-07-24 21:28:44 +00:00
Arthur Bassi
620a36af54
feat(work-orders): enrich board search overdue filters and 0-based paging (#23)
* feat(work-orders): enrich board search overdue filters and 0-based paging

* fix(work-orders): align stacked services with CI build

* fix(tests): pass userDataService in comment service unit test

* fix(work-orders): use dedicated overdue query flag

Stop treating WorkOrderType.Other as an overdue sentinel. Board and advanced search now accept overdue=true while types=Other filters real Other rows; combining both uses OR.

* test(work-orders): cover overdue date/status boundary and Other type-filter

Lock the PR #23 overdue regression boundary through the public advanced
search service. Prove overdue filtering is driven by past-due date plus
non-terminal status, not by the WorkOrderType.Other sentinel:
- Other + future/not-completed excluded from overdue
- past-due + Scheduled included; past-due + Completed/Canceled excluded
- types=[PM, Other] keeps real Other rows and does not pull past-due rows
- assert 0-based paging (Page=0) is preserved alongside overdue/type filters

---------

Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
2026-07-24 21:12:03 +00:00
Alexandre Brandizzi
833fb816ee
chore(governance): enforce backend architecture and quality gates (#31)
* docs(governance): add canonical governance docs, unified quality-gate script, and CI parity

- ARCHITECTURE_AND_CODE_QUALITY.md: canonical layering, EF allowlist,
  transaction/commit convention, cancellation, migrations, error disclosure,
  Big-O/perf, ADR exceptions (supersedes BACKEND_ARCHITECTURE.md)
- QUALITY_GATES.md: gate inventory + pass/fail/skip semantics; local==CI
- REVIEW_AND_PR_FRAMEWORK.md: exact-head review, board-backed regression
  inventory, security/perf evidence, ADR exceptions, no godfile theater
- AGENTS.md: repo-specific delta + precedence pointers
- scripts/governance-check.sh: unified G1 restore + G2 ArchitectureTests +
  G3 changed-file format (portable bash)
- .github/workflows/architecture-quality.yml: call the same local script
- ArchitectureTests.cs: add business-service interface-dependency invariant

* fix(governance): make backend gate complete

* fix(ci): enforce governance on every pull request
2026-07-24 17:41:10 -03:00
Alexandre Brandizzi
7d245eb717
refactor: enforce backend boundaries and optimize dispatch (#30)
* refactor(api): enforce service and data-service boundaries

* refactor(api): complete feature service boundaries

* refactor(identity): enforce service and data boundaries

* refactor(vendors): enforce service and data boundaries

* refactor(workorders): enforce service and data boundaries

* refactor(backend): enforce architecture and optimize dispatch

* style(backend): format changed architecture files

* fix(architecture): address backend review follow-ups

* fix(backend): sanitize exception disclosure in changed API endpoints

Replace raw exception-message disclosure (ex.Message) returned to API
callers with a stable sanitized public message plus correlated structured
internal logging, across the endpoints changed in this PR.

- Add SanitizedErrors helper: logs the original exception at Error with a
  generated correlation id and returns a stable public message referencing
  it so support can trace without exposing internals.
- Inject ILogger<T> into the 14 changed controllers and route every
  ex.Message/dbex.Message disclosure through the helper, preserving status
  codes, response shapes, and business data (e.g. OpenWorkOrders).
- Leave FluentValidation (vex.Errors) and existing fixed-message catches
  untouched; out-of-scope controllers (Account/Contact/Employee/Asset/
  PMSchedule) are unchanged.
- Add focused tests proving internal exception text is not returned and
  that Error logging carrying the original exception is invoked.

* fix(architecture): abstract job run state access

* style: format board update service

* test: use collection assertion idiom
2026-07-24 17:35:34 -03:00
Alexandre Brandizzi
8be07a9c5f
Merge pull request #22 from Sea-Haven-Industries/feature/wo-flag-color
feat(work-orders): add board flagColor with fixed palette
2026-07-24 14:32:41 -03:00
Alexandre Brandizzi
78abf84b0d fix(work-orders): finalize PR 22 integration compile fixes 2026-07-24 14:27:52 -03:00