Consolidate audit-fixes branch: webhooks, integrations, and deploy hardening

Batch commit of the pending working tree on security/audit-fixes-2026-07.
Major areas:
- Outbound webhooks / Zapier: schema + signed delivery with retries, public
  v1 API (REST-hook subscribe/unsubscribe), settings UI, cron drain.
- Deploy hardening: email via SMTP2GO (Resend fully removed), verified DB TLS
  (DATABASE_SSL=require + DATABASE_CA), storage fails loud in production when
  Spaces is unconfigured instead of silently using ephemeral disk.
- Integrations & features (concurrent work): accounting (QuickBooks/Xero),
  e-signature (DocuSign/Dropbox Sign), PayPal, geocoding/maps, onboarding,
  expanded legal pages.
- DB migrations 0006–0009.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Leon Serfaty
2026-07-02 13:42:34 -04:00
co-authored by Claude Opus 4.8
parent 969d5d4c8a
commit c9968531e4
282 changed files with 41530 additions and 4013 deletions
+26
View File
@@ -0,0 +1,26 @@
// DigitalOcean Function invoked by scheduler triggers (see functions/project.yml).
// Calls the app's protected cron endpoint (`daily`, `late-fees`, `follow-ups`,
// or `webhooks`, chosen by the trigger body) with the CRON_SECRET bearer token.
// nodejs:18 has global fetch.
async function main(args) {
const base = (process.env.APP_BASE_URL || "").replace(/\/+$/, "")
const secret = process.env.CRON_SECRET
const requested = args && args.job
const allowed = ["daily", "late-fees", "follow-ups", "webhooks"]
const job = allowed.includes(requested) ? requested : "daily"
if (!base || !secret) {
return { statusCode: 500, body: "APP_BASE_URL or CRON_SECRET not configured" }
}
const res = await fetch(`${base}/api/cron/${job}`, {
method: "GET",
headers: { Authorization: `Bearer ${secret}` },
})
const body = await res.text()
console.log(`cron ${job} -> ${res.status}: ${body.slice(0, 500)}`)
return { statusCode: res.status, body }
}
exports.main = main
+56
View File
@@ -0,0 +1,56 @@
# ─────────────────────────────────────────────────────────────────────────────
# DigitalOcean Functions — scheduled cron for Property Management Network.
#
# App Platform has no native cron, so the two daily jobs are driven by DO
# Functions scheduler triggers that call the app's CRON_SECRET-protected
# endpoints. Deploy separately from the App Platform app:
#
# doctl serverless deploy functions --env functions/.env
#
# Create functions/.env (gitignored) with:
# APP_BASE_URL=https://<your-app-url> # no trailing slash
# CRON_SECRET=<same value as the app's CRON_SECRET>
# ─────────────────────────────────────────────────────────────────────────────
parameters: {}
packages:
- name: cron
functions:
- name: run
runtime: 'nodejs:18'
web: false
environment:
APP_BASE_URL: ${APP_BASE_URL}
CRON_SECRET: ${CRON_SECRET}
triggers:
# Rent reminders, overdue marking, 60/30/7-day lease-expiry emails — 09:00 UTC.
- name: daily
sourceType: scheduler
sourceDetails:
cron: '0 9 * * *'
withBody:
job: daily
function: cron/run
# Late fees (5% after the grace period) — 08:00 UTC.
- name: late-fees
sourceType: scheduler
sourceDetails:
cron: '0 8 * * *'
withBody:
job: late-fees
function: cron/run
# Automated follow-ups for all users with active rules — 10:00 UTC.
- name: follow-ups
sourceType: scheduler
sourceDetails:
cron: '0 10 * * *'
withBody:
job: follow-ups
function: cron/run
# Outbound webhook delivery retries — every 5 minutes.
- name: webhooks
sourceType: scheduler
sourceDetails:
cron: '*/5 * * * *'
withBody:
job: webhooks
function: cron/run