Skip to content

Initial implementation for postgres/docker/aws - #10

Merged
adelepeterson merged 16 commits into
mainfrom
feature/postgres-aws-implementation
Oct 3, 2026
Merged

adelepeterson merged 16 commits into
mainfrom
feature/postgres-aws-implementation

Conversation

@adelepeterson

Copy link
Copy Markdown
Collaborator

No description provided.

adelepeterson and others added 16 commits October 1, 2026 19:46
- Magic-link sign-in for external users (token issuance/consumption,
  AWS SES delivery with a console fallback) alongside Google/Microsoft
  Entra ID SSO for staff, via one generic OIDC strategy.
- Lock down /api/cases, /api/people, /api/reference-data to full
  (SSO) users; add professional/case_assignment/time_entry/invoice
  tables and a scoped external portal (view assigned cases, log time,
  submit invoices) for magic-link users.
- Idempotent reference-data seeding (ensureReferenceData) run at
  migrate time in every environment, replacing a lazy create-on-first-
  use workaround that only covered one of four required rows.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Bring Cases, New case, and the external portal onto a shared
  responsive layout (page headings, status pills, card/table pattern,
  2-column form grid), fixing a broken form width, a table-fill bug,
  and the underlying USWDS default styles it had been masking.
- Resolve all-ID display: links/headings now prefer a human label
  (client name, external reference) over a raw UUID, falling back to a
  date before ever showing an id.
- Expand demo seed data (external assignments, time entries, invoices)
  and fix the external-submitter email whitelist that was blocking
  magic-link login for the seeded demo vendors.
- Extract shared PageHeading/ResourceList/RecordTable/caseDisplayLabel/
  formatDateTime helpers and unify the Cases/Overview/portal card styles
  to cut duplication surfaced along the way.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
mise ignores .nvmrc/.node-version by default, so a global mise default
(e.g. Node 16) silently won over server/.nvmrc and broke npm installs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…lookup directories

Also: Downshift-based type-ahead pickers, clearable search inputs,
stage-filtered case list, and sidebar/overview wiring for each stage.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Email link scanners GET every link, spending the single-use token before
the user clicks. The emailed link now opens a client confirm page whose
Continue button POSTs the token.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assignments are rejected on closed cases, and closeCase checks state and
computes the next sequence number under a row lock, so concurrent closes
return 409 instead of a unique-violation 500.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Only an invoice still in submitted status is updated, inside the
transaction, so concurrent reviews can't both record a decision.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Drop the unbounded client-supplied effectiveAt, which could end
assignments before they began or close a case before it opened.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Emails are lowercased in one place for every login path. Account
creation is a single upsert that fills in a missing staff role, so
magic-link accounts upgrade on SSO login and concurrent first logins
don't collide.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A submitted invoice awaiting review no longer gets hidden in Closing by
an earlier approved invoice on the same case.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Fixtures no longer hand-copy the rows production provisions at migrate
time; they call ensureReferenceData and look the IDs up.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Replace per-action validation/configuration error classes with shared
AppError subclasses that the Express error middleware turns into
responses, and look up reference rows through one getReferenceId helper.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
assignExternalSubmitterToCase mirrors assignStaffToCase (same signature
and zod-validated input), rejects staff professionals, and leaves both
assignment routes as thin wrappers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Regenerate a single 0000_baseline migration, remove the unused Google
OAuth passport packages, and trim comments that narrate deleted code.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Move test addresses to example domains, drop the "Sample" prefix from
user-visible fixture names (codes unchanged), and fix stale
.env.example notes about the magic-link verify route.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Seed several counties, organizations, offices, jurisdictions, languages
and identifier types, and limit the Office dropdown to the selected
organization's offices.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@adelepeterson
adelepeterson merged commit fd08e3f into main Oct 3, 2026
3 checks passed
@adelepeterson
adelepeterson deleted the feature/postgres-aws-implementation branch October 3, 2026 03:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant