🌙 Dark ▾
Choose Theme
☀️
Light Clean & bright
✓
✨
Fusion Aurora cyan + violet
✓
🛒 0
🛒 Your Cart 0 items
Cart is empty
🔔 0

🔔 Notifications

✅ No notifications

Manager Dashboard

Loading site data...

⏳ Loading…
📦

⏳

Total Stock Units

💶

⏳

Inventory Value (€)

👥

⏳

Active Employees

⭐

⏳

Swagies Distributed

📤 Data Upload Center

Upload swag points, inventory orders, and budget allocations for your site

📦

0

Total Uploads

👥

0

Employees Covered

⭐

0

Swaggies Distributed

📅

—

Last Upload

📤 Upload Data File

📁

Drop Excel or CSV file here

or click to browse — Excel (.xlsx) for Swag Points, CSV/Excel for Inventory

Swag Points: Excel loader, one sheet per category (multi-sheet) | Inventory: coming soon

Each download gives you the template for your site's division. Click any button to see what it's for before downloading.

📋 Recently Received

Date Category Uploaded By Employees Swaggies Status Actions
Loading recent uploads…

🏪 Item Catalog & Stock Management

Upload SUGGLE order PDFs and review uploaded orders for your site

📦 Uploaded Orders

Date Invoice Number 👤 Entered By 💰 Total Amount ⭐ Total Swagies
No orders loaded yet.

🛒 Checkout

Review your cart and complete your order

👤
Employee
Login · Site
Available Balance
⭐ ...

🛍️ Your Items

0 items
🛒

Your cart is empty

Go to Swag Shop to add items

📋 Order Summary

Total ⭐ 0
0/500

Points will be deducted from your balance

⭐ Swag Shop

Browse items and add to cart — pay with your Swagies points

👤
Employee
Available Balance
⭐ ...
🛍️

Loading shop...

📦 Stock Levels

Full inventory stock table with utilization metrics

📊 Transaction Details

View your complete swagies allocation and purchase history

📋 Pending Handouts

Review and process pending swag orders for your site

Check Swagies balance

Look up any Amazon employee to see their live Swagies balance, assigned points, and full swag history — in one search.

Developer onkrs Phone Tool ↗
🎁

EU SwagHub Portal

Enterprise Rewards & Inventory Management Platform for Amazon EU Logistics

AWS Amplify Cognito + Federate SAML Lambda + API Gateway S3 + DynamoDB 3 Divisions · Multi-Site EU

🧠 The Living System

A secure core powering every capability — watch the signal flow

Every call flows through the secure core — authenticated, authorized, and division-scoped. Each wire is a real operation between two services; hover a wire or node to trace it.

API request Compute Write Data fetch Event / metric

🏗️ System Architecture

How the components connect — from browser to storage

🌐
Browser
User's device
▼
⚡
AWS Amplify
Static hosting · HTTPS
▼
🔐
Cognito + Federate
SAML · PKCE · Midway SSO
🚪
API Gateway
REST API · CORS
▼
⚙️
Lambda (AMZL)
Validate · Sanitize · Write
⚙️
Lambda (ATS)
Validate · Sanitize · Write
⚙️
Lambda (FC)
Validate · Sanitize · Write
▼
📦
S3 Data Bucket
Structured by division · site · date
🗄️
DynamoDB Ledger
Balances · transactions · history
▼
🔄
Consolidation Lambda
Builds per-site balances & stock levels
📡
CloudWatch
Metric filters · alarms

🧭 Division Resolution & Routing

Every upload is routed to the correct division (AMZL · ATS · FC) from the signed identity — never from a value the browser can choose

🪪
1 · Explicit division in the JWT
A division claim, or a standalone AMZL/ATS/FC token in the signed identity — the authoritative source
▼ if the JWT has no explicit division
🗂️
2 · Facility master (site-keyed)
The EU facility CSV maps the JWT site → division (DS→AMZL · SC→ATS · FC→FC). Base-only, 100% authoritative
▼ if the site isn't in the facility master
🛑
3 · Fail closed
Returns no division — never silent-defaults. A structured alert fires so the unmapped site can be added deliberately
✓

Resolved Once, Used Everywhere

One resolver decides the division a single time per request, then drives the S3 write prefix, the monthly upload gate, and every balance/stock read — so writes and reads always land in the same place.

✓

Identity, Never the Request Body

The division comes only from the JWT site and the facility master — never from a value the browser can choose. No descriptive-keyword guessing, so sites can't be mis-classified.

✓

Fail Closed, Loudly

An unmapped site resolves to no division and the upload is refused — it never silent-defaults to AMZL. A structured alert makes the unmapped tail visible for triage.

📊 Data Flow

How data moves from site upload to employee dashboard

1

Site Manager Uploads CSV

Reward allocation files with employee_id and amount columns. CSV only, strict validation.

2

Client-Side Validation

CSV Validator checks exact columns, data types, empty cells, duplicates, and scans for injection attacks before upload.

3

Secure API Upload

JWT token sent with request. Lambda extracts user identity from token, validates site ownership, checks for duplicates via MD5 hash.

4

Server-Side Validation

Lambda loads schema from S3 config, re-validates CSV, sanitizes all values, scans for security threats. Rejects invalid data.

5

Structured S3 Storage

Data saved to: {Division}/data-upload/{type}/{site}/{date}/{user}/{file}.csv with an upload manifest containing a full audit trail.

6

Consolidation & Dashboards

A consolidation step replays the uploaded files to build per-site balances and stock levels. Employees see real-time balances and history; admins see live Insights KPIs — all served from DynamoDB and S3.

🔐 Authentication Flow

Midway SSO via Amazon Federate SAML + Cognito PKCE

A

User Opens App

Landing page appears; the app stays hidden until authenticated. User clicks "Proceed to Login".

B

Cognito PKCE Flow

App generates code_verifier + code_challenge. Redirects to Cognito Hosted UI with the SAML identity provider.

C

Federate + Midway

Cognito redirects to the Amazon Federate SAML endpoint. Federate authenticates via Midway (badge or PIN).

D

Token Exchange

SAML assertion returns to Cognito. Cognito exchanges the authorization code for JWT tokens (ID + Access + Refresh).

E

Session Established

JWT stored in sessionStorage. User claims extracted (alias, email, department, job level). App becomes visible.

F

Ongoing Security

Token auto-refresh before expiry. Idle timeout with warning. Logout clears all tokens and returns to the landing page.

🔑 Access Control & Roles

Who can see what — driven by identity, enforced on every request

🪪
Signed Token
alias + job level (from the corporate directory)
▼
⚖️
Role Decision
admin alias allow-list → Admin · else job level ≥ threshold → Admin · else Restricted
▼
👑
Admin
Full portal — Management, Insights, Operations, config
🎯
Restricted
Operations only (+ this About page)
①

UI Gating (usability)

The sidebar hides sections a user isn't entitled to. This is for convenience only — no security decision lives in the browser.

②

API Authorizer (authoritative)

Every backend call passes a request authorizer that re-verifies the signed token and re-checks the role. Tampering with the browser cannot reach a restricted endpoint.

③

Fail-safe / least privilege

A missing or unreadable job-level signal resolves to Restricted, never Admin. Denied requests return 401/403. Rules apply uniformly across all sites and divisions.

📁 S3 Data Structure

Organized by division, category, site, and date

eu-swaghub-data/
├── AMZL/ ← Amazon Logistics
├── ATS/ ← Amazon Transportation
└── FC/ ← Fulfillment Centers

Each division contains:
  ├── _config/ Schema validation files
  ├── data-upload/ Validated uploads, by site & date
  │   ├── swag-points/ Reward allocations
  │   ├── budget-allocation/ Site budgets
  │   ├── inventory-order/ Received product orders
  │   └── inventory-stock/ Per-site stock deltas
  ├── data-consolidation/ Per-site balances & stock-levels
  └── _staging-uploads/ Short-lived PDF/large-file staging

🛠️ Technology Stack

Built on AWS serverless — scales automatically

⚡

AWS Amplify

Static hosting, auto-deploy

🔐

Amazon Cognito

OAuth2 PKCE, JWT tokens

🏢

Amazon Federate

SAML SSO, Midway auth

🚪

API Gateway

REST API, CORS, routing

⚙️

AWS Lambda

Python 3.12, serverless

📦

Amazon S3

Data lake, structured storage

🗄️

DynamoDB

Balances, transactions, history

📡

Amazon CloudWatch

Metric filters, alarms, logs

🛡️ Security Layers

Defense in depth — every layer validates

🔐 Authentication

Midway SSO via Federate SAML. PKCE flow prevents token interception. JWT signed by Cognito.

🛡️ Authorization (RBAC)

Role from the signed token: admin alias allow-list or job level at/above threshold → Admin, otherwise Restricted. Re-verified by a request authorizer on every API call — never trusted from the frontend.

📋 Data Validation

Strict schema: exact columns, data types, ranges. Rejects extra columns, empty cells, duplicates.

🧹 Sanitization

Trim whitespace, strip HTML/scripts, remove non-printable chars. Max cell length enforced.

🚫 Injection Prevention

Blocks formula injection (=, +, -), script tags, JS URIs, eval(), DOM manipulation attempts.

🌐 Cross-Site Protection

Users can only upload for their own site. Site code validated from the JWT location claim and filename.

📡 Transport Security

HTTPS only. CORS restricted to the app domain. Bounded request timeout.

📝 Audit Trail

Every upload creates a manifest with user, timestamp, file hash, row count. Duplicate detection via MD5.

📡 Monitoring & Alerts

CloudWatch metric filters and alarms watch the upload path — flagging any write that can't be classified to a division so it's caught, not hidden.

💬
Support & Feedback
Found a bug or have a suggestion? Tell us — it goes straight to the team.
📖
SwagHub User Guide New here or stuck? The full step-by-step guide walks you through every tab.
Open guide →
📗
SwagHub Team Wiki Onboarding a new site, admin access, offboarding, and the technical reference behind how SwagHub works.
Open wiki →
Which tab is the issue on? Pick one or more, add a note, and attach a screenshot if it helps.
Affected tab(s)
Describe the issue or idea
Screenshot (optional)
Screenshots / images only (no Excel or other files). Attach up to 10, max 2 MB each.