* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD
Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.
* ci: run Frontend checks and Terraform CI on PRs to main and dev
Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.
* refactor(terraform): keep live/dev and live/staging as HCP roots
Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.
* style: prettier terraform-validate.mjs
* fix(terraform): pin githubdeploy assume-role policy in import checker
Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
* fix(terraform): ignore origin response_completion_timeout in the release plan guard (SH-300)
AWS returns 0 when the timeout is unset. The provider writes null on
origin_path updates, so the first real CD plan failed closed.
* fix(ci): drop duplicate verify from the content CD workflow (SH-300)
Frontend checks already runs verify on PRs and pushes. Removing the
validate job also requires dropping needs: validate so dispatch can run.
* fix(terraform): equate origin timeout 0 and null only (SH-300)
Numeric timeout changes still fail closed. Rename the filter so it is
not read as an after_unknown allowlist.
* feat(terraform): ship dev content CD through Terraform (SH-300)
GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.
* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
* ci(terraform-isolation): re-evaluate the gate on label changes
* test(terraform-isolation): lock the ci.yaml label-event contract
* fix(terraform-isolation): do not treat terraform markdown as a mixed change
* fix(ci): do not skip Frontend checks on isolation label events
* ci(terraform-isolation): run label retriggers in a dedicated workflow
* fix: apply eslint formatting
* fix: apply additional missed eslint formatting
Governance now runs the import-plan checker tests, Terraform fmt and
validate for terraform/live/dev, the isolation gate tests, and the CDK
build, tests, and synth in both modes. A new terraform-isolation
workflow fails PRs that change terraform/** together with application
code; the terraform-isolation-override label is the reviewed exception.
Renovate gains the terraform manager.
Remove the push-to-dev trigger and the org cd-cdk.yaml caller so CI no
longer runs cdk deploy during the adoption. The workflow assumes the
pinned dev role and runs the simple scripts/deploy-web.sh against a
pinned bucket and distribution, which keeps content deploys working
after CloudFormation relinquishes the stack outputs. Staging is
untouched.
* chore(governance): make React/TS conventions mandatory via executable gates
Add AGENTS.md, QUALITY_GATES.md, ARCHITECTURE_AND_CODE_QUALITY.md, and
REVIEW_AND_PR_FRAMEWORK.md as the binding conventions and PR review
contract for humans and all coding/review agents.
Add a single 'npm run verify' command (format + lint + build + test +
governance) and 'npm run governance', which runs a dependency-free godfile
ratchet (whole-repo, baseline in scripts/governance-baseline.json) and a
changed-file maintainability gate (complexity<=20, function<=150, params<=4,
depth<=4) via ESLint. Legacy is handled by ratchets, not relaxation: 5
godfiles over 500 lines are grandfathered debt; maintainability thresholds
apply to changed TS/TSX (72 legacy violations across ~51 files otherwise).
Add a repo-owned 'governance' CI job that runs 'npm run verify' so every
gate is guaranteed from this repository, independent of the org reusable
workflow.
* fix(governance): make frontend ratchets fail closed
Self-contained CDK app (S3 + CloudFront + OIDC deploy role) deployed via the org reusable cd-cdk.yaml. Frontend served on dev.seahaven.com with the *.seahaven.com cert and a Route 53 apex alias; the SPA calls the dev backend directly at https://api.dev.seahaven.com/api.
Replace the inline 5-job ci.yml with a thin caller of the org reusable
workflow ci-typescript-frontend.yaml. The standards gate, changed-line
guard, format/lint/build, unit tests, and Playwright browser smoke now
live centrally in Sea-Haven-Industries/.github and are maintained once.
Renames ci.yml -> ci.yaml (kebab-case .yaml convention) and triggers on
pull_request and push to main and dev, so this branch keeps CI coverage.
The reusable workflow runs as a single `ci` job, so this caller emits the
`ci / ci` status context. Branch-protection rulesets for main and dev must
have their required checks switched from the old job names (Metadata and
standards, Code quality, Build, Unit tests, Browser smoke) to `ci / ci`.
Assign all files to the internal-dev team so every pull request needs an
approving review from an internal-dev member, giving internal engineering
oversight of changes. The org main-branch-protection ruleset enforces this
via required code-owner review; the internal-dev team has write access, so
it is an eligible code owner.
* chore: add eslint, prettier, husky and commitlint tooling
* ci: add GitHub Actions workflow for lint and build
* build: migrate from CRA to Vite with TypeScript config
* docs: add architecture plan and design system documentation
* fix: scope ESLint to new components and hooks directories
* feat: add HTTP client, query cache and shared utilities
* feat: add theme system and global application styles
* feat: add shared UI, layout and domain badge components
* feat: add auth domain, provider and login page
* feat: add app shell, file-based routing and bootstrap
* feat: add protected layout and dashboard module
* feat: add accounts CRUD module
* feat: add assets CRUD module
* feat: add contacts CRUD module
* feat: add employees CRUD module
* feat: add locations CRUD module
* feat: add calendar events module
* feat: add follow-ups CRUD module
* feat: add PM schedules CRUD module
* feat: add work orders module with dispatch modals
* feat: add vendors CRUD and portal token panel
* feat: add vendor purchase orders module
* feat: add uplifts queue module
* feat: add settings for dropdowns and task templates
* feat: add vendor portal routes and signature capture
* test: add Vitest setup and Playwright login e2e spec
* chore: remove legacy CRA pages, Redux store and JS hooks
* chore: update gitignore and env example for Vite
* docs: translate pt-BR docs and Cursor rules to English
* fix(ci): fix login e2e session mock and prettier formatting
* fix(build): use mjs router script for Node 20 CI compatibility
* chore: remove migration scripts and unused generouted router
* fix(auth): restore JWT and align CRUD with backend routes
* fix(api): add no-content helpers and align paths with backend
* fix(accounts): align detail and mutation payloads with backend
* fix(contacts): resolve detail via GetContacts and map address DTOs
* fix(work-orders): align routes, delete body, and create payload
* fix(vendors): delete vendors via REST route
* fix(pm-schedules): handle empty save and delete responses
* fix(employees): add fallbacks for detail and dropdown calls
* chore(calendar): disable routes until backend exists
* chore(env): switch tracked env vars to Vite prefixes
* fix(api): align frontend contracts with backend review findings
Correct Work Order getById query param, asset site options via Location API,
Employee JobTitleId payload, and remove stale API paths.
* fix(employees,pm-schedules): align forms with backend API contracts
Align PM Schedule form and save payload with PMSchedule_DTO fields.
Bind employee Job Title select to jobTitleId for create/update payloads.
Add regression tests for both flows.
* fix(pm-schedules): gate edit/delete for Dev API contract
Production Dev API exposes only GetList and Save.
Hide unsupported edit/delete UI and block the edit route.
Add regression tests for disabled actions.
* docs(env): document VITE_API_URL must include /api suffix
* refactor(api): extract shared API prefix URL resolution
* feat(build): fail build on misconfigured absolute VITE_API_URL
* test(api): cover API URL contract and prefix resolution
* feat(auth): disable login submit until email and password are valid
* test(auth): align login tests with disabled submit behavior
* Feat/ab/menu-and-header (#17)
* chore(deps): add lucide-react for layout icon migration
* feat(auth): add getPrimaryUserRole helper for header display
* style(theme): add sidebar active tokens and nav group typography
* refactor(menu): migrate nav icons to lucide and trim menu groups
* feat(layout): redesign sidebar, topbar, and admin shell viewport
* chore(menu): hide Reports and Documents from sidebar
---------
Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
* ci: add frontend PR quality baseline (#18)
* chore(deps): add lucide-react for layout icon migration
* feat(auth): add getPrimaryUserRole helper for header display
* style(theme): add sidebar active tokens and nav group typography
* refactor(menu): migrate nav icons to lucide and trim menu groups
* feat(layout): redesign sidebar, topbar, and admin shell viewport
* chore(menu): hide Reports and Documents from sidebar
* ci: add PR quality baseline checks
* ci: avoid self-matching standards guard
* ci: split frontend quality gates
---------
Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
---------
Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>