Consolidate audit-fixes branch: webhooks, integrations, and deploy hardening

Batch commit of the pending working tree on security/audit-fixes-2026-07.
Major areas:
- Outbound webhooks / Zapier: schema + signed delivery with retries, public
  v1 API (REST-hook subscribe/unsubscribe), settings UI, cron drain.
- Deploy hardening: email via SMTP2GO (Resend fully removed), verified DB TLS
  (DATABASE_SSL=require + DATABASE_CA), storage fails loud in production when
  Spaces is unconfigured instead of silently using ephemeral disk.
- Integrations & features (concurrent work): accounting (QuickBooks/Xero),
  e-signature (DocuSign/Dropbox Sign), PayPal, geocoding/maps, onboarding,
  expanded legal pages.
- DB migrations 0006–0009.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Leon Serfaty
2026-07-02 13:42:34 -04:00
co-authored by Claude Opus 4.8
parent 969d5d4c8a
commit c9968531e4
282 changed files with 41530 additions and 4013 deletions
+26
View File
@@ -0,0 +1,26 @@
// DigitalOcean Function invoked by scheduler triggers (see functions/project.yml).
// Calls the app's protected cron endpoint (`daily`, `late-fees`, `follow-ups`,
// or `webhooks`, chosen by the trigger body) with the CRON_SECRET bearer token.
// nodejs:18 has global fetch.
async function main(args) {
const base = (process.env.APP_BASE_URL || "").replace(/\/+$/, "")
const secret = process.env.CRON_SECRET
const requested = args && args.job
const allowed = ["daily", "late-fees", "follow-ups", "webhooks"]
const job = allowed.includes(requested) ? requested : "daily"
if (!base || !secret) {
return { statusCode: 500, body: "APP_BASE_URL or CRON_SECRET not configured" }
}
const res = await fetch(`${base}/api/cron/${job}`, {
method: "GET",
headers: { Authorization: `Bearer ${secret}` },
})
const body = await res.text()
console.log(`cron ${job} -> ${res.status}: ${body.slice(0, 500)}`)
return { statusCode: res.status, body }
}
exports.main = main