# Follow-ups / ops TODOs

Local secrets live in `.env*` (gitignored — do **not** commit). On Heroku, set matching config vars.

---

## A. SAP QA endpoint + key cutover (dev / staging)

Local `.env.development` / `.env.staging` already point at the new QA host:

```
SAP_API=https://sapserviceqa.mfgsites-qa.hotwater.com/Service.asmx
SAP_ENV=QA N+1
SAP_KEY=SAP_KEY_DEV
```

`SAP_KEY` is the **Parse Key name**. The SOAP API key lives in that Key’s `cryptoKey` field — do **not** put the UUID in `SAP_KEY` env.

### Parse

- [ ] Update Parse Key named `SAP_KEY_DEV` → set `cryptoKey` to `0a92f8fc-0105-454f-9207-31baeaca7229` (dev / staging Data Cloud app used by CMS).
- [ ] Confirm `NODE_ENV=development npm run test:sap-endpoints` passes all read tests after the Parse update.

### Heroku staging (`aosmith-cms`)

- [ ] Set the new SAP URL (include `/Service.asmx`):

```bash
heroku config:set \
  SAP_API='https://sapserviceqa.mfgsites-qa.hotwater.com/Service.asmx' \
  SAP_ENV='QA N+1' \
  SAP_KEY=SAP_KEY_DEV \
  --app aosmith-cms
```

- [ ] Deploy the branch with `GetCycloneConfigProdOrder` / `GetConfigOrder` + `scripts/test-sap-endpoints.js`.
- [ ] Smoke-check staging SAP flows (customer lookup, config/prod order reads, order submit if safe in QA).

### Code already in place locally

- SAP helpers: `GetCycloneConfigProdOrder`, `GetConfigOrder`
- Read-only endpoint suite: `npm run test:sap-endpoints` (add `--writes` only with explicit `SAP_TEST_*` write env vars)

---

## B. Production follow-ups (SEC-1 secrets) — `aosmith-cms-prod`

After secrets-from-env is deployed to Heroku **production**, complete the items below. Staging session/DB vars were set earlier on `aosmith-cms`.

### 1. Set Heroku config vars (before or with deploy)

#### Session secrets

The old hardcoded secret was `keyboard dog`. Keep it as `SESSION_SECRET_PREVIOUS` so existing cookies still verify during cutover.

```bash
heroku config:set \
  SESSION_SECRET="$(grep '^SESSION_SECRET=' .env.production | cut -d= -f2-)" \
  SESSION_SECRET_PREVIOUS='keyboard dog' \
  --app aosmith-cms-prod
```

#### Parse / Data Cloud keys

```bash
heroku config:set \
  DB_APP_ID="$(grep '^DB_APP_ID=' .env.production | cut -d= -f2-)" \
  DB_APP_KEY="$(grep '^DB_APP_KEY=' .env.production | cut -d= -f2-)" \
  DB_APP_URL="$(grep '^DB_APP_URL=' .env.production | cut -d= -f2-)" \
  --app aosmith-cms-prod
```

#### Confirm other env-backed secrets are still present

- `PARSE_MASTER_KEY`
- `REDISCLOUD_URL`
- `MAILGUN_API_KEY` / `MAILGUN_DOMAIN`
- `HEROKU_API_TOKEN`
- `SAP_API` / `SAP_ENV` / `SAP_KEY` (production still uses `SAP_KEY_PROD` + current prod ASMX URL until a separate prod SAP cutover)
- `NEW_RELIC_LICENSE_KEY` (if used)

```bash
heroku config --app aosmith-cms-prod
```

### 2. Deploy and smoke-check

- [ ] Deploy the branch that loads `DB_APP_*` and `SESSION_SECRET*` from `process.env`.
- [ ] App boots without missing-env errors (`SESSION_SECRET` / `DB_APP_ID` required).
- [ ] Login / session works (old cookies still valid while `SESSION_SECRET_PREVIOUS` is set).
- [ ] Parse-backed pages (orders, devices, etc.) load.
- [ ] Mailgun / SAP / Redis paths still work for critical flows.

### 3. Finish session secret rotation (after deploy is stable)

- [ ] `heroku config:unset SESSION_SECRET_PREVIOUS --app aosmith-cms-prod`
- [ ] Remove `SESSION_SECRET_PREVIOUS` from local `.env*` (or leave unset).
- [ ] Confirm login still works with only `SESSION_SECRET`.
- [ ] Same unset on staging when ready: `heroku config:unset SESSION_SECRET_PREVIOUS --app aosmith-cms`

**Future rotations:** set current value as `SESSION_SECRET_PREVIOUS`, set new as `SESSION_SECRET`, deploy, wait, then unset previous.

### 4. Rotate other credentials (treat prior hardcoded values as compromised)

| Secret | Action |
|--------|--------|
| Parse app ID / JS key / master key | Rotate in Parse / Data Cloud; update Heroku + local `.env*` |
| Mailgun API key | Rotate in Mailgun; update Heroku + local `.env*` |
| Redis password / URL | Rotate Redis Cloud / Heroku Redis addon; update `REDISCLOUD_URL` |
| Heroku API token | Rotate if it ever lived in git or was shared |
| Session secret | Already rotated via §1 + §3; next rotate use the PREVIOUS pattern |

### 5. Residual risk (git history)

- [ ] Document for stakeholders: old secrets may still exist in git history.
- [ ] Optional: scrub history (BFG / `git filter-repo`) — only if policy requires; rotation is mandatory either way.
- [ ] Ensure `.env*` stay gitignored; `.env.example` (placeholders only) may be committed.

---

## C. Production SAP cutover (later — not done)

Production `.env.production` still uses:

```
SAP_API=http://externalservices.hotwater.com/Service.asmx
SAP_ENV=Production
SAP_KEY=SAP_KEY_PROD
```

- [ ] When AOS provides prod host + key: update Parse Key `SAP_KEY_PROD` `cryptoKey`, set Heroku `SAP_API` / `SAP_ENV` on `aosmith-cms-prod`, smoke-test, then update local `.env.production`.
