New React Backend Repository
Find a file
Alexandre Brandizzi c841e130be fix(auth): harden password reset codes against guessing and email enumeration
Forgot Password answers every address the same way and emails a code only
to an active account. Codes are stored as salted SHA-256 hashes, expire 15
minutes after issue, are replaced by a newer request, and are checked only
against the email they were issued to. Five failed checks delete the code;
attempts are reserved with one conditional UPDATE so concurrent guesses
cannot exceed the budget. VerificationCode requires the email, and email and
code are accepted in the JSON body so they stay out of URLs.

The three anonymous endpoints are rate limited to 10 requests per 15
minutes per client IP. Forwarded headers are trusted only through loopback
and private hops, since the API sits behind the EB load balancer and nginx.
The migration adds hash, salt, expiry and attempt columns and deletes the
old plaintext rows.
2026-09-25 12:21:29 -03:00
.ebextensions fix(eb): configure work-order webhook HMAC secret source (#41) 2026-07-30 11:44:43 -03:00
.github ci: consolidate required checks behind ci-complete 2026-09-19 20:47:59 +00:00
.platform/nginx/conf.d fix(media): name HEIC in the unsupported-type message and keep ticket keys out of comments 2026-09-25 02:58:15 -03:00
Api.SeaHavenIndustries fix(auth): harden password reset codes against guessing and email enumeration 2026-09-25 12:21:29 -03:00
Api.SeaHavenIndustries.Tests fix(auth): harden password reset codes against guessing and email enumeration 2026-09-25 12:21:29 -03:00
Data.SeaHavenIndustries fix(auth): harden password reset codes against guessing and email enumeration 2026-09-25 12:21:29 -03:00
docs fix(observability): preserve backend release identity (#114) 2026-09-15 16:08:14 -03:00
postman docs: add complete dev Postman API collection (#119) 2026-09-15 16:39:49 -03:00
scripts fix(media): name HEIC in the unsupported-type message and keep ticket keys out of comments 2026-09-25 02:58:15 -03:00
SeaHaven.DataServices fix(auth): harden password reset codes against guessing and email enumeration 2026-09-25 12:21:29 -03:00
SeaHaven.Services fix(auth): harden password reset codes against guessing and email enumeration 2026-09-25 12:21:29 -03:00
SeaHaven.Services.Tests feat(team-members): add member detail editing (SH-326) 2026-09-16 21:41:55 -03:00
SeaHavenIndustries chore(config): document Phase 7 feature flags in appsettings and .env.example 2026-07-13 13:23:54 -03:00
SeaHavenIndustries.Tests fix(auth): harden password reset codes against guessing and email enumeration 2026-09-25 12:21:29 -03:00
terraform fix(terraform): add CI platform hashes to the AWS provider lockfile 2026-09-19 20:07:50 +00:00
.env.example chore(repo): add PR template and README, retire stale root files 2026-09-18 19:05:30 -04:00
.gitattributes chore(repo): add PR template and README, retire stale root files 2026-09-18 19:05:30 -04:00
.gitignore feat(deploy): move dev application CD through Terraform (#102) 2026-09-03 14:12:06 +00:00
AGENTS.md ci: consolidate required checks behind ci-complete 2026-09-19 20:47:59 +00:00
ARCHITECTURE_AND_CODE_QUALITY.md chore(repo): add PR template and README, retire stale root files 2026-09-18 19:05:30 -04:00
QUALITY_GATES.md ci: consolidate required checks behind ci-complete 2026-09-19 20:47:59 +00:00
README.md ci: consolidate required checks behind ci-complete 2026-09-19 20:47:59 +00:00
REVIEW_AND_PR_FRAMEWORK.md chore(repo): add PR template and README, retire stale root files 2026-09-18 19:05:30 -04:00
SeaHavenIndustries.sln test(work-orders): add Phase 0 domain unit tests 2026-07-02 09:19:28 -03:00

SHOC Backend (shoc-backend)

CI Deploy .NET 8 SQL Server Terraform

ASP.NET Core 8 API for Sea Haven facility management (SHOC): work orders, the work-order board, dispatches and the vendor portal, uplift approvals, notifications, and the dashboard. It is the backend for shoc-frontend-new, which calls it directly over HTTPS.

Environment API Elastic Beanstalk environment Deployed by
dev https://api.dev.seahaven.com shoc-backend-dev every push to main
staging https://api.staging.seahaven.com shoc-backend-staging a vX.Y.Z-staging tag cut with release.yaml

Both run in us-east-1 on the .NET 8 Amazon Linux 2023 platform. Terraform in terraform/live/ owns the environments; GitHub Actions owns the application versions. There is no production environment yet.

Architecture

Controller -> I{Feature}Service -> I{Feature}DataService -> ApplicationDbContext

Controllers depend on feature service interfaces only. Business services depend on feature data-service interfaces, never on DbContext. Data services own Entity Framework Core and are the atomic commit boundary. Tenant scope is derived on the server from claims, and authorization is enforced at service entry. The rules and their reasons are in ARCHITECTURE_AND_CODE_QUALITY.md.

Project Role
Api.SeaHavenIndustries The deployed API: controllers, hosted services, infrastructure adapters, Program.cs
SeaHaven.Services Business services, DTOs, validation, helpers
SeaHaven.DataServices Feature data services over EF Core
Data.SeaHavenIndustries Entities, ApplicationDbContext, Identity, migrations
SeaHavenIndustries Legacy Blazor Server app sharing the data layer; not part of the API deployment
Api.SeaHavenIndustries.Tests, SeaHaven.Services.Tests, SeaHavenIndustries.Tests xunit test projects

Local development

Requires the .NET 8 SDK and a reachable SQL Server. Configuration comes from appsettings*.json placeholders, then user secrets, then environment variables. .env.example lists every key, including the connection string, JWT secret, SendGrid key and Sentry DSN. Do not commit real values.

dotnet restore SeaHavenIndustries.sln
dotnet build SeaHavenIndustries.sln --configuration Release
dotnet test SeaHavenIndustries.sln --configuration Release
dotnet run --project Api.SeaHavenIndustries

The full repository gate that CI runs, including architecture discovery, the changed-file maintainability check, Terraform checks and app/Terraform isolation:

BASE_REF=origin/main bash scripts/governance-check.sh

Migrations live in Data.SeaHavenIndustries/Migrations and are applied at deploy time from a bundle the packaging script builds with dotnet-ef. Adding one follows the G6 rules in QUALITY_GATES.md.

Contributing

  • Branch from main with a feature/, fix/, chore/, docs/ or refactor/ prefix and a kebab-case description.
  • Commit subjects follow Conventional Commits. PR titles end with the Jira key for product work.
  • The PR body uses the three-section layout the template pre-fills: Summary, Changes and value, Ticket. The reasoning is in REVIEW_AND_PR_FRAMEWORK.md.
  • main requires a code-owner review and the ci-complete check. PRs merge through the merge queue, so a branch does not need to be updated with main before it merges.
  • Application code and terraform/ do not change in the same PR (G13).

Deployment

deploy.yaml packages the API with scripts/package-elastic-beanstalk.sh, uploads the bundle to the Elastic Beanstalk bucket, updates the environment, verifies the exact version is active, and smoke-tests it. The bundle carries a self-contained EF Core migrations bundle that Elastic Beanstalk runs on the leader instance before the new version starts (.ebextensions/01_migrations.config). A push to main targets dev. release.yaml cuts a SemVer tag from main and calls the same workflow for staging. Both are described in the workflow headers and in terraform/live/README.md.

Renovate opens dependency PRs on the schedule in .github/renovate.json; majors wait for approval on the Dependency Dashboard issue.

Documentation