Close INV-11: remove hardcoded SMTP credential - #21
Open
sokanacollectiveCRM wants to merge 332 commits into
Open
Close INV-11: remove hardcoded SMTP credential#21sokanacollectiveCRM wants to merge 332 commits into
sokanacollectiveCRM wants to merge 332 commits into
Conversation
UPdate vercel config
Protect auth, webhooks, and public intake; keep staff roles in Cloud SQL; add CI/Cloud Build test gates so a merge to main can deploy. Co-authored-by: Cursor <[email protected]>
Repo-wide prettier/eslint is not clean yet; the workflow was failing on thousands of legacy files. Scope the GitHub lint job to this change set so the P0 deploy PR can pass. Co-authored-by: Cursor <[email protected]>
…dening P0 security hardening for Cloud Run deploy
Phones still need the frontend header-token fallback; this only helps browsers that honor CHIPS.
…rify Fix mobile login session cookies
Persist home intake fields on operational updates, merge them in GET/PUT responses, expand PHI field aliases, and fall back to Cloud SQL when the PHI broker is unreachable in primary mode. Co-authored-by: Cursor <[email protected]>
Co-authored-by: Cursor <[email protected]>
…me-type Fix client profile saves for home type and PHI broker fallback
* Merge full intake profile fields on client GET and PUT responses. Map missing phi_clients columns, extend operational updates, and return services, contact, health, and demographics fields so the Lead Profile form reads and persists saved values. Co-authored-by: Cursor <[email protected]> * Add intake_age_years to User entity for profile field mapping. Co-authored-by: Cursor <[email protected]> * Fix Prettier formatting in User entity for CI lint. Co-authored-by: Cursor <[email protected]> --------- Co-authored-by: Jerry Bony <[email protected]> Co-authored-by: Cursor <[email protected]>
HIPAA-13A: admin-only /clients/fetchCSV with full phi_clients columns, deny audit logs, and tests. Also always mount /api/payment-methods so Payment Schedule card-on-file works when FEATURE_QUICKBOOKS is false. Co-authored-by: Cursor <[email protected]>
Co-authored-by: Cursor <[email protected]>
…payment-methods-mount HIPAA-13A CSV admin-only + always mount payment-methods
Gate PUT /clients/:id/birth-outcomes with canAccessSensitive, reject birth-outcome keys on generic client update, and stop exposing free-text birth_outcomes in API responses. Co-authored-by: Cursor <[email protected]>
Record Cloud Run revision IDs and build metadata after live deploy verification. Co-authored-by: Cursor <[email protected]>
Co-authored-by: Cursor <[email protected]>
…payment-methods-mount INV-12: Enforce birth-outcomes assignment and retire legacy narrative
Closes INV-09 IDOR on POST /users/:id/addhours by enforcing role, assignment, and IDOR guards with negative authorization tests. Co-authored-by: Cursor <[email protected]>
…-hours-idor HIPAA-13E: Restrict service-hours writes to assigned doula or admin
* Minimize public intake emails to client number and CRM link (HIPAA-13F). Stop sending clinical and identity intake payloads over ordinary staff Gmail; staff are directed to the authenticated CRM deep-link instead. Co-authored-by: Cursor <[email protected]> * Fix Prettier formatting for HIPAA-13F PR files. Co-authored-by: Cursor <[email protected]> --------- Co-authored-by: Jerry Bony <[email protected]> Co-authored-by: Cursor <[email protected]>
) Co-authored-by: Jerry Bony <[email protected]> Co-authored-by: Cursor <[email protected]>
* Minimize doula assignment emails to client number + CRM link (HIPAA-05). Remove client name, email, and assignment notes from doula match notifications; direct doulas to authenticated activities deep-link with privacy tests. Co-authored-by: Cursor <[email protected]> * Fix Prettier formatting on HIPAA-05 docs and preflight context. Co-authored-by: Cursor <[email protected]> --------- Co-authored-by: Jerry Bony <[email protected]> Co-authored-by: Cursor <[email protected]>
… email path. Co-authored-by: Cursor <[email protected]>
Run scoped ESLint and Prettier on staged files before each commit so local checks match the pull-request lint workflow. Co-authored-by: Cursor <[email protected]>
…uth. Rotated Gmail app password is now loaded from EMAIL_PASSWORD (Secret Manager in prod); add containment tests and verification sign-off. Co-authored-by: Cursor <[email protected]>
Co-authored-by: Cursor <[email protected]>
sokanacollectiveCRM
requested review from
aanandp123,
amyzliao and
ethanpaneraa
as code owners
August 25, 2026 21:53
|
@jbony2888 is attempting to deploy a commit to the DISC NU's projects Team on Vercel. A member of the Team first needs to authorize it. |
Co-authored-by: Cursor <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
src/scripts/sendTestEmail.ts; enforceEMAIL_PASSWORDfrom environment only.smtpCredentialContainment.test.tsto prevent regression.docs/HIPAA_INV11_SMTP_CREDENTIAL_SIGNOFF.md.Test plan
npm test -- src/__tests__/smtpCredentialContainment.test.ts250 2.0.0 OKClosure references
0cf9088,072efc3docs/HIPAA_INV11_SMTP_CREDENTIAL_SIGNOFF.mdMade with Cursor