Commit graph

577 commits

Author SHA1 Message Date
Alexandre Brandizzi
dc251c42d4 fix(media): apply SH-116 media contract and lift the 1 MB proxy body cap
The Elastic Beanstalk nginx proxy kept its 1 MB default body limit, so every
media upload over ~1 MB got an nginx 413 before reaching the API. Ship a
.platform nginx override (120M) in the bundle and assert it in the bundle
contract.

Apply the client-confirmed contract: photos up to 10 MB (JPEG/PNG/HEIC),
videos up to 100 MB (MP4/MOV), at most 10 photos and 3 videos per work order,
with stable generic rejection messages. The request ceiling (110 MB) sits
between the per-kind caps and the proxy so oversize files get the generic
message. The vendor portal accepts the same photo/video types and caps.
2026-09-24 20:52:44 -03:00
Alexandre Brandizzi
f7db6b9f84
Merge pull request #167 from Sea-Haven-Industries/fix/ab/sh-387-uplift-create
Some checks failed
Backend CI / Build and test (push) Has been cancelled
Backend CI / architecture (push) Has been cancelled
Backend CI / review (push) Has been cancelled
Backend CI / ci-complete (push) Has been cancelled
Fix SH-387 uplift creation
2026-09-23 03:45:17 +00:00
Alexandre Brandizzi
5c5c01b2e8 fix(uplifts): attribute audit to requested work order
Use the operation work order when staging uplift audit logs so a dispatch linked through DispatchWorkOrders cannot write the event to its primary work order. Add coverage for the cross-work-order fallback case.
2026-09-22 21:29:35 -03:00
Alexandre Brandizzi
adb192cad7 Release uplift gate when transaction setup fails 2026-09-22 16:54:47 -03:00
Alexandre Brandizzi
d282799127 Fix SH-387 uplift creation without primary dispatch 2026-09-22 16:44:31 -03:00
Alexandre Brandizzi
b36b69df83
Merge pull request #166 from Sea-Haven-Industries/fix/ab/sh-383-mobile-video-upload
Some checks failed
Backend CI / Build and test (push) Has been cancelled
Backend CI / architecture (push) Has been cancelled
Backend CI / review (push) Has been cancelled
Backend CI / ci-complete (push) Has been cancelled
Allow mobile work order video uploads up to 200 MB
2026-09-21 20:59:00 +00:00
Alexandre Brandizzi
06b88b6006 fix(workorders): align media multipart limit 2026-09-21 15:32:53 -03:00
Alexandre Brandizzi
a615be28e5 fix(workorders): raise media upload limit to 200 MB 2026-09-21 14:58:43 -03:00
Adam Moussa
ad5d58437c
Merge pull request #164 from Sea-Haven-Industries/chore/consolidate-ci
Some checks failed
Backend CI / Build and test (push) Has been cancelled
Backend CI / architecture (push) Has been cancelled
Backend CI / review (push) Has been cancelled
Backend CI / ci-complete (push) Has been cancelled
ci: consolidate required checks behind ci-complete
2026-09-19 21:55:36 +00:00
1188a4c1cb
ci: consolidate required checks behind ci-complete 2026-09-19 20:47:59 +00:00
Adam Moussa
03a0a6514d
Merge pull request #165 from Sea-Haven-Industries/fix/terraform-aws-provider-lockfile
Some checks failed
Backend CI / Build and test (push) Waiting to run
Architecture and changed-file quality / architecture (push) Has been cancelled
Terraform CI / terraform (push) Has been cancelled
fix(terraform): add CI platform hashes to the AWS provider lockfile
2026-09-19 20:41:59 +00:00
Adam Moussa
0f6b72e68a fix(terraform): add CI platform hashes to the AWS provider lockfile 2026-09-19 20:07:50 +00:00
Adam Moussa
3db433b0bf
Merge pull request #163 from Sea-Haven-Industries/chore/dependency-review-single-job
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
chore(ci): run dependency review as one job on pull requests and merge groups
2026-09-18 23:33:14 +00:00
Adam Moussa
752f5fdea1
Merge pull request #162 from Sea-Haven-Industries/fix/governance-diff-merge-base
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
fix(governance): diff G3 and G13 from the merge base, not the base tip
2026-09-18 23:19:33 +00:00
Adam Moussa
ae35f10921
Merge pull request #161 from Sea-Haven-Industries/chore/repo-docs-and-template
chore(repo): add PR template and README, retire stale root files
2026-09-18 23:18:09 +00:00
38588ac33e
chore(ci): run dependency review as one job on pull requests and merge groups
The merge_group pass-through added in #159 produced a second, skipped check
run with the same name on every pull request, because GitHub reports a check
for a job whose if: is false. The pinned dependency-review action resolves its
refs from merge_group.base_sha and head_sha itself, so the single real job now
triggers on both events with no conditions. Pull requests and merge groups
each get one check run, and the required check is still satisfied in the
queue.
2026-09-18 19:17:02 -04:00
Alexandre Brandizzi
637ba3350b
Merge pull request #152 from Sea-Haven-Industries/feat/ab/sh-288-event-notifications
feat(notifications): assignment, comment, mention and uplift-decision items in the feed (SH-289, SH-288, SH-215)
2026-09-18 23:16:38 +00:00
24e4f2b7f7
fix(governance): diff G3 and G13 from the merge base, not the base tip
The gate computed changed files with a two-dot diff against the PR base tip,
so everything main gained after the branch point counted as this change. A
branch behind main that touched C# failed G13 whenever main had merged
Terraform in between, which is how #152 failed after #154, #156 and #158
landed. The merge queue no longer requires branches to be current, so the
false positive would have hit every stale PR. Both diffs now start at the
merge base. Push and merge-group runs are unchanged because their base is an
ancestor of the head.
2026-09-18 19:12:21 -04:00
Adam Moussa
019eb86894
Merge branch 'main' into feat/ab/sh-288-event-notifications 2026-09-18 19:11:15 -04:00
b7b22a8893
chore(repo): add PR template and README, retire stale root files
The org PR template pre-filled Summary / Validation / Tests / Notes here while
REVIEW_AND_PR_FRAMEWORK.md section 8 prescribes Summary / Changes and value /
Ticket. A repo template now overrides the org one, and the framework notes the
divergence from the org pr-policy workflow, which is not wired in.

README.md orients a reader: environments, architecture in one line, project
map, local commands, the governance gate, deployment, and a documentation map.

Cleanup: TODO.md is removed because Jira owns work status and its items are
stale or done. BACKEND_ARCHITECTURE.md is removed as superseded; the two
references now point at git history. .env.example loses its BOM and mojibake
dashes. .gitattributes keeps its one active rule.
2026-09-18 19:05:30 -04:00
Adam Moussa
10266e6e4b
Merge pull request #160 from Sea-Haven-Industries/renovate/reconfigure
chore(renovate): widen the schedule, track the EF tool pin, hold EF majors
2026-09-18 22:59:37 +00:00
Alexandre Brandizzi
e1ce3e439b
Merge pull request #149 from Sea-Haven-Industries/feat/ab/sh-292-notification-center
SH-292: Notification Center feed endpoint
2026-09-18 22:54:54 +00:00
Alexandre Brandizzi
0b3084a274
Merge pull request #155 from Sea-Haven-Industries/fix/ab/sh-379-manual-poc-override
Persist manual POC override with audit and site-follow (SH-379)
2026-09-18 22:54:51 +00:00
Alexandre Brandizzi
cd4d30af4b
Merge pull request #157 from Sea-Haven-Industries/fix/ab/sh-381-mobile-video-mime
fix(work-orders): accept mobile media whose declared MIME is foreign (SH-381)
2026-09-18 22:54:48 +00:00
Alexandre Brandizzi
a9773e67eb
Merge pull request #151 from Sea-Haven-Industries/feat/ab/sh-209-uplift-detail-context
SH-209: Expose dispatcher, technician and schedule on the uplift queue read
2026-09-18 22:53:56 +00:00
b270543d0d
chore(renovate): widen the schedule, track the EF tool pin, hold EF majors
The org window (before 6am on Monday) has produced no PRs in this repository
since the overlay landed, so the overlay now opens every weekday morning. A
regex manager tracks EF_VERSION in the Elastic Beanstalk packaging script,
which installs dotnet-ef at deploy time and would otherwise fall behind the
tool manifest and EF Core packages; it joins the nuget minor and patch group.
ASP.NET Core, EF Core and dotnet-ef majors are disabled while the target is
net8.0 so the dashboard approval list only shows updates that can be taken.
2026-09-18 18:48:12 -04:00
Adam Moussa
1888b66940
ci: run required checks on merge_group for the merge queue (#159)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
Build and test, architecture, and dependency-review are the required checks
on main. A merge queue only counts checks that ran on the merge_group event,
so each workflow now triggers on it. The architecture gate reads the merge
group's own base and head because github.event.before is empty there. The
dependency-review action cannot diff a merge group, so that event reports the
same check name from a pass-through job; the real review already gated the
pull request before it could be queued.
2026-09-18 18:16:10 -04:00
Alexandre Brandizzi
582af8fb2c fix(workorders): compare manual POC against the followed contact, not any site contact
The manual POC "follow the site" clear-rule compared the edit against every
live Site contact. A work order only ever displays one of them, so editing to
a different live contact (Site has Alice primary and Bob; WO shows Alice; edit
to Bob) matched, cleared the override, and left the row showing Alice with no
audit row written — the SH-379 symptom on a different input. A work order with
a linked WorkOrderContacts POC hit the same bug when the dispatcher typed the
Site's primary: the override cleared and the linked contact showed instead.

Compare the edit against the single contact the work order actually follows —
the linked WorkOrderContacts POC, or else the Site primary (ResolvePrimary) —
matching the board projection's override -> linked -> site precedence, and
store the override whenever the edit differs from it. The create path in
WorkOrderBoardCreateService had the same any-contact rule and gets the same
fix; a supplied PocContactId that is not a live Site contact leaves no follow
target, so the typed POC is stored.

Replaces MatchesAnySiteContact with Matches(name, phone, contact); comment and
PR-body wording updated to state the followed-contact rule. Adds tests for the
second-site-contact edit, the linked-contact-differs edit, and the
second-site-contact create case.
2026-09-18 18:56:29 -03:00
Adam Moussa
51417a65b5
Merge branch 'main' into fix/ab/sh-381-mobile-video-mime 2026-09-18 17:32:06 -04:00
Adam Moussa
503faa8c25
Merge branch 'main' into fix/ab/sh-379-manual-poc-override 2026-09-18 17:31:45 -04:00
Adam Moussa
1cd3c802e3
Merge branch 'main' into feat/ab/sh-209-uplift-detail-context 2026-09-18 17:31:12 -04:00
Adam Moussa
0556822d22
Merge branch 'main' into feat/ab/sh-292-notification-center 2026-09-18 17:30:22 -04:00
Adam Moussa
4fb4159df2
fix(iam): scope staging githubdeploy uploads to the staging release prefix (#158)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
2026-09-18 17:10:13 -04:00
Alexandre Brandizzi
46eed22707 fix(work-orders): accept mobile media whose declared MIME is foreign (SH-381)
Mobile browsers attach an unreliable Content-Type to a picked file: empty or
application/octet-stream when the OS cannot classify it, and sometimes a
foreign-but-plausible type for a supported container (video/3gpp for an .mp4,
video/x-quicktime for a .mov). The media allowlist already resolved empty and
octet-stream types from the extension, but a concrete foreign type was rejected
outright, so a real .MP4/.MOV picked on a phone passed the client dialog and was
refused by the API.

Any declared type that is not itself on the allowlist now falls back to the
extension. The extension pairing and magic-byte signature still decide, so the
accepted set of files is unchanged; an allowlisted declared type stays
authoritative and must still match its own extension.
2026-09-18 16:33:24 -03:00
Adam Moussa
9eb51b528f
chore(terraform): complete staging environment adoption (#156)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
* chore(terraform): complete staging environment adoption

* test(terraform): include deploy SSM parameters in the import ownership boundary
2026-09-18 15:13:18 -04:00
Adam Moussa
facc6ef71e
fix(iam): let staging githubdeploy GetObject the release zip (#154)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
* fix(iam): let staging githubdeploy GetObject the release zip

* fix(iam): allow staging githubdeploy to cache EB processed extensions

* fix(iam): allow staging githubdeploy GetObjectAcl for EB updates

* fix(iam): grant staging githubdeploy named S3 reads on EB resources prefix

* fix(iam): allow staging githubdeploy to delete EB version cache objects

* fix(iam): scope staging githubdeploy S3 object access to the EB bucket

* fix(iam): allow staging githubdeploy PutObjectVersionAcl on EB artifacts

* fix(iam): allow staging githubdeploy GetBucketPolicy on the EB bucket

* fix(iam): scope staging githubdeploy S3 objects to SHOC and staging EB prefixes
2026-09-18 15:29:15 -03:00
Alexandre Brandizzi
cbecc7b4ea fix(workorders): persist manual POC override with audit and site-follow (SH-379)
Editing a work order's POC never reached the backend: no update path wrote
PocName/PocPhone/PocNotes, so the optimistic UI edit was lost on refetch and
the completion freeze captured the Site contact instead of the manual value,
and nothing was audited.

- Add tenant-scoped PATCH api/workorders/{id}/poc via new WorkOrderPocService
  + WorkOrderPocDataService: persists the override, stages FieldChanged audit
  entries (which also write field locks so sync never overwrites a manual POC),
  and enforces row-version concurrency and terminal-status read-only rules.
- Lock semantics (SH-190): a manual POC away from the Site's live contacts is
  stored WO-level; an edit equal to a live Site contact (or blanking name+phone)
  stores nothing so the WO follows the Site. PocCustomized exposes the state.
- Board projection, completion freeze and create now share one Site-contact
  fallback (first non-deleted contact by SiteContactOrder) so a never-overridden
  WO keeps following the Site, including at create when the wizard prefills it.
- Route contract baseline gains PATCH {id:int}/poc.
2026-09-18 14:30:54 -03:00
Adam Moussa
90303f0e40
Merge pull request #153 from Sea-Haven-Industries/chore/retire-leftover-app-cd
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
chore(cd): retire leftover Terraform app CD path
2026-09-18 13:08:07 -04:00
b696a414a5
fix(cd): grant caller id-token write for reusable deploy workflows 2026-09-18 12:42:42 -04:00
f42576e2db
chore(cd): retire leftover Terraform app CD path 2026-09-18 12:38:15 -04:00
Alexandre Brandizzi
9784dcf895 Merge remote-tracking branch 'origin/feat/ab/sh-292-notification-center' into feat/ab/sh-288-event-notifications 2026-09-18 13:20:22 -03:00
Alexandre Brandizzi
e668e13912 feat(notifications): feed assignments, comments, mentions and uplift decisions to the user they concern
Adds the personal producers behind GET /api/notifications without changing its shape:
new assignments (SH-288), unanswered comments on work the user takes part in (SH-289),
@mentions, and decisions on uplifts the user requested (SH-215).
2026-09-18 13:15:33 -03:00
Alexandre Brandizzi
c9fa4a49af style(notifications): fix object initializer indentation in NotificationFeedService 2026-09-18 13:09:46 -03:00
Alexandre Brandizzi
aad3facaf1 fix(notifications): ignore soft-deleted dispatches and cap conflicts by recency
No Vendor treated any non-terminal dispatch as an assigned vendor without
checking IsDeleted, so a soft-deleted dispatch hid the work order from both
No Vendor and Vendor Conflict (the conflict query already drops deleted
dispatches). GetNoVendorAsync and the vendor-reminder assigned-work-order rule
now skip soft-deleted dispatches, keeping the asserted parity between the feed
and the reminders.

Vendor Conflict applied the section cap in vendor-sweep order, so when overlaps
exceeded the limit newer conflicts could be dropped while Count still counted
every work order. VendorConflictsAsync now orders pairs by recency before the
cap, matching the other per-work-order sections.
2026-09-18 12:59:56 -03:00
Alexandre Brandizzi
ad68bccb89 Merge remote-tracking branch 'origin/dev' into feat/ab/sh-209-uplift-detail-context 2026-09-18 12:58:27 -03:00
Adam Moussa
68ad7362df
Merge pull request #150 from Sea-Haven-Industries/dev
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run
chore: promote GitHub-owned Elastic Beanstalk CD onto main
2026-09-18 11:52:35 -04:00
Alexandre Brandizzi
fa979605b4 feat(uplifts): expose dispatcher, technician and schedule on queue read (SH-209)
The uplift detail modal needs the work order's assigned dispatcher, the
requesting vendor's technician and the scheduled date. They now resolve
from the same effective work order and vendor as the existing queue row,
so the modal no longer depends on a separate work-order fetch that
account-scoped staff cannot read.
2026-09-18 12:49:25 -03:00
23f69307dd
chore: sync main into dev after #147
Some checks failed
Validate and deploy / Validate deployable source bundle (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Has been cancelled
Validate and deploy / Deploy shoc-backend-staging through Terraform (push) Has been cancelled
2026-09-18 11:44:02 -04:00
Adam Moussa
e74fff7722
Merge pull request #148 from Sea-Haven-Industries/refactor/main-branch-cd
refactor(cd): ship Elastic Beanstalk versions from GitHub on main
2026-09-18 11:43:03 -04:00
Adam Moussa
60a3fcc308
Merge pull request #147 from Sea-Haven-Industries/dev
chore: promote current dev onto main
2026-09-18 11:42:50 -04:00