Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
"""Tests for the weekly-post Lambda handler orchestration."""
|
|
|
|
|
|
2026-09-03 22:12:55 +00:00
|
|
|
import json
|
2026-09-10 19:30:00 +00:00
|
|
|
from pathlib import Path
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
from unittest.mock import MagicMock
|
|
|
|
|
|
|
|
|
|
import pytest
|
|
|
|
|
from freezegun import freeze_time
|
|
|
|
|
|
|
|
|
|
# 2026-06-08 is a Monday. Frozen to ET 08:00; handler is invoked with force=True
|
|
|
|
|
# to bypass the 7am DST guard except where the guard itself is under test.
|
|
|
|
|
MON_0800 = "2026-06-08 12:00:00"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.fixture
|
|
|
|
|
def slack(weeklypost_app, monkeypatch):
|
|
|
|
|
"""Fake Slack WebClient; chat_postMessage returns a message ts."""
|
|
|
|
|
fake = MagicMock(name="slack")
|
|
|
|
|
fake.chat_postMessage.return_value = {"ts": "999.000"}
|
|
|
|
|
monkeypatch.setattr(weeklypost_app, "WebClient", MagicMock(return_value=fake))
|
|
|
|
|
monkeypatch.setattr(weeklypost_app, "get_secret", lambda _id: "xoxb-test")
|
|
|
|
|
return fake
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.fixture
|
|
|
|
|
def env(monkeypatch):
|
|
|
|
|
monkeypatch.setenv(
|
|
|
|
|
"SLACK_BOT_TOKEN_SECRET", "afterhours-shift-manager/slack-bot-token"
|
|
|
|
|
)
|
|
|
|
|
monkeypatch.setenv("PAY_REPORT_USER", "U_BOSS")
|
|
|
|
|
monkeypatch.delenv("PAYROLL_RECIPIENTS", raising=False) # skip SES email
|
2026-09-03 22:12:55 +00:00
|
|
|
monkeypatch.setenv(
|
|
|
|
|
"CHECKCOMPONENTS_QUEUE_URL",
|
|
|
|
|
"https://sqs.us-east-1.amazonaws.com/011934824531/paychex-checkcomponents",
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.fixture
|
|
|
|
|
def sqs(weeklypost_app, monkeypatch):
|
|
|
|
|
fake = MagicMock(name="sqs")
|
|
|
|
|
|
|
|
|
|
def client(svc, **kw):
|
|
|
|
|
if svc == "sqs":
|
|
|
|
|
return fake
|
|
|
|
|
return MagicMock(name=svc)
|
|
|
|
|
|
|
|
|
|
monkeypatch.setattr(weeklypost_app.boto3, "client", client)
|
|
|
|
|
return fake
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
@freeze_time(MON_0800)
|
2026-09-03 22:12:55 +00:00
|
|
|
def test_posts_schedule_and_saves_post(weeklypost_app, schedule, seed, slack, env, sqs):
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
result = weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
assert result["posted"] is True
|
|
|
|
|
assert result["message_ts"] == "999.000"
|
|
|
|
|
# The new schedule post was persisted for next week's cleanup.
|
|
|
|
|
assert schedule.get_schedule_post("C_TEST")["message_ts"] == "999.000"
|
|
|
|
|
slack.chat_postMessage.assert_called()
|
2026-09-03 22:12:55 +00:00
|
|
|
sqs.send_message.assert_not_called()
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
@freeze_time(MON_0800)
|
2026-09-03 22:12:55 +00:00
|
|
|
def test_calculates_and_dms_pay(weeklypost_app, schedule, seed, slack, env, sqs):
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
# Previous week (Mon 2026-06-01) had Alice on the Monday night shift.
|
|
|
|
|
seed.config(shift_rate="50")
|
|
|
|
|
seed.weekly("Monday", "114", "Alice")
|
|
|
|
|
|
|
|
|
|
result = weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
assert result["pay_calculated"] is True
|
|
|
|
|
# Pay record saved under previous Monday's key.
|
|
|
|
|
assert schedule.get_pay_record("2026-06-01") is not None
|
|
|
|
|
# A DM went to the configured pay-report user.
|
|
|
|
|
dm_calls = [
|
|
|
|
|
c
|
|
|
|
|
for c in slack.chat_postMessage.call_args_list
|
|
|
|
|
if c.kwargs.get("channel") == "U_BOSS"
|
|
|
|
|
]
|
|
|
|
|
assert dm_calls
|
2026-09-03 22:12:55 +00:00
|
|
|
sqs.send_message.assert_called_once()
|
|
|
|
|
body = json.loads(sqs.send_message.call_args.kwargs["MessageBody"])
|
|
|
|
|
assert body["type"] == "checkcomponents"
|
|
|
|
|
assert body["kind"] == "after_hours"
|
|
|
|
|
assert body["windowStart"] == "2026-06-01"
|
|
|
|
|
assert body["windowEnd"] == "2026-06-07"
|
|
|
|
|
assert "payPeriodId" not in body
|
|
|
|
|
assert body["lines"] == [{"extension": "114", "amount": "50.00"}]
|
|
|
|
|
assert schedule.get_pay_record("2026-06-01")["checkcomponents_sent"] is True
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
|
|
|
|
|
|
2026-06-15 13:24:32 -04:00
|
|
|
@freeze_time(MON_0800)
|
|
|
|
|
def test_pay_email_failure_does_not_block_schedule_post(
|
2026-09-03 22:12:55 +00:00
|
|
|
weeklypost_app, schedule, seed, slack, env, monkeypatch, sqs
|
2026-06-15 13:24:32 -04:00
|
|
|
):
|
|
|
|
|
# Previous week has an assigned shift, so the pay/email path runs.
|
|
|
|
|
seed.config(shift_rate="50")
|
|
|
|
|
seed.weekly("Monday", "114", "Alice")
|
|
|
|
|
# SES delivery blows up (e.g. a permission/identity issue).
|
|
|
|
|
monkeypatch.setattr(
|
|
|
|
|
weeklypost_app,
|
|
|
|
|
"_send_pay_email",
|
|
|
|
|
MagicMock(side_effect=Exception("SES AccessDenied")),
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
result = weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
# The email failure is swallowed; the schedule post still goes out.
|
|
|
|
|
assert result["posted"] is True
|
|
|
|
|
assert schedule.get_schedule_post("C_TEST")["message_ts"] == "999.000"
|
|
|
|
|
|
|
|
|
|
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
@freeze_time(MON_0800)
|
2026-09-03 22:12:55 +00:00
|
|
|
def test_rolls_existing_post_forward(weeklypost_app, schedule, seed, slack, env, sqs):
|
2026-07-10 16:36:47 -04:00
|
|
|
# An existing post is deleted + reposted so it lands at the bottom every
|
|
|
|
|
# Monday. The old ts is cleaned up and a new one is stored.
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
seed.schedule_post("C_TEST", "111.111")
|
2026-06-27 15:45:01 -04:00
|
|
|
result = weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
|
2026-07-10 16:36:47 -04:00
|
|
|
slack.chat_delete.assert_called_once()
|
|
|
|
|
assert slack.chat_delete.call_args.kwargs["ts"] == "111.111"
|
|
|
|
|
slack.chat_update.assert_not_called()
|
|
|
|
|
slack.chat_postMessage.assert_called_once()
|
|
|
|
|
# New ts from the repost is stored.
|
|
|
|
|
assert result["message_ts"] == "999.000"
|
|
|
|
|
assert schedule.get_schedule_post("C_TEST")["message_ts"] == "999.000"
|
2026-06-27 15:45:01 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
@freeze_time(MON_0800)
|
2026-09-03 22:12:55 +00:00
|
|
|
def test_reposts_when_delete_fails(weeklypost_app, schedule, seed, slack, env, sqs):
|
2026-07-10 16:36:47 -04:00
|
|
|
# A stored post that can no longer be deleted (e.g. was already removed
|
|
|
|
|
# manually) still reposts — the delete failure is non-fatal.
|
2026-06-27 15:45:01 -04:00
|
|
|
seed.schedule_post("C_TEST", "111.111")
|
2026-07-10 16:36:47 -04:00
|
|
|
slack.chat_delete.side_effect = Exception("message_not_found")
|
2026-06-27 15:45:01 -04:00
|
|
|
|
|
|
|
|
result = weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
slack.chat_postMessage.assert_called()
|
|
|
|
|
assert result["message_ts"] == "999.000"
|
|
|
|
|
assert schedule.get_schedule_post("C_TEST")["message_ts"] == "999.000"
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
|
|
|
|
|
|
2026-07-10 16:36:47 -04:00
|
|
|
@freeze_time(MON_0800)
|
|
|
|
|
def test_rolls_back_repost_when_save_fails(
|
2026-09-03 22:12:55 +00:00
|
|
|
weeklypost_app, schedule, seed, slack, env, monkeypatch, sqs
|
2026-07-10 16:36:47 -04:00
|
|
|
):
|
|
|
|
|
# If persisting the fresh post's ts fails after the repost has already
|
|
|
|
|
# landed, the just-posted message is deleted so an async retry can't leave
|
|
|
|
|
# an orphaned duplicate. The error still propagates.
|
|
|
|
|
seed.schedule_post("C_TEST", "111.111")
|
|
|
|
|
monkeypatch.setattr(
|
|
|
|
|
weeklypost_app.ShiftSchedule,
|
|
|
|
|
"save_schedule_post",
|
|
|
|
|
MagicMock(side_effect=Exception("dynamo down")),
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
with pytest.raises(Exception, match="dynamo down"):
|
|
|
|
|
weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
# Old post deleted for the rollover, then the fresh (999.000) post rolled
|
|
|
|
|
# back when its ts couldn't be persisted.
|
|
|
|
|
deleted_ts = [c.kwargs["ts"] for c in slack.chat_delete.call_args_list]
|
|
|
|
|
assert deleted_ts == ["111.111", "999.000"]
|
|
|
|
|
|
|
|
|
|
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
@freeze_time(MON_0800)
|
2026-09-03 22:12:55 +00:00
|
|
|
def test_skips_when_not_7am_and_not_forced(weeklypost_app, schedule, slack, env, sqs):
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
# Frozen hour is 08:00 ET, not 07:00 → skip unless forced.
|
|
|
|
|
result = weeklypost_app.handler({}, None)
|
|
|
|
|
assert result == {"skipped": True}
|
|
|
|
|
slack.chat_postMessage.assert_not_called()
|
2026-09-03 22:12:55 +00:00
|
|
|
sqs.send_message.assert_not_called()
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@freeze_time(MON_0800)
|
|
|
|
|
def test_checkcomponents_failure_does_not_block_schedule_post(
|
|
|
|
|
weeklypost_app, schedule, seed, slack, env, monkeypatch, sqs
|
|
|
|
|
):
|
|
|
|
|
seed.config(shift_rate="50")
|
|
|
|
|
seed.weekly("Monday", "114", "Alice")
|
|
|
|
|
monkeypatch.setattr(
|
|
|
|
|
weeklypost_app,
|
|
|
|
|
"_send_checkcomponents",
|
|
|
|
|
MagicMock(side_effect=Exception("SQS AccessDenied")),
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
result = weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
assert result["posted"] is True
|
|
|
|
|
assert schedule.get_schedule_post("C_TEST")["message_ts"] == "999.000"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@freeze_time(MON_0800)
|
|
|
|
|
def test_empty_queue_url_skips_checkcomponents(
|
|
|
|
|
weeklypost_app, schedule, seed, slack, env, sqs, monkeypatch
|
|
|
|
|
):
|
|
|
|
|
monkeypatch.setenv("CHECKCOMPONENTS_QUEUE_URL", "")
|
|
|
|
|
seed.config(shift_rate="50")
|
|
|
|
|
seed.weekly("Monday", "114", "Alice")
|
|
|
|
|
|
|
|
|
|
result = weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
assert result["posted"] is True
|
|
|
|
|
sqs.send_message.assert_not_called()
|
|
|
|
|
assert "checkcomponents_sent" not in (schedule.get_pay_record("2026-06-01") or {})
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@freeze_time(MON_0800)
|
|
|
|
|
def test_save_failure_does_not_enqueue_checkcomponents(
|
|
|
|
|
weeklypost_app, schedule, seed, slack, env, monkeypatch, sqs
|
|
|
|
|
):
|
|
|
|
|
seed.config(shift_rate="50")
|
|
|
|
|
seed.weekly("Monday", "114", "Alice")
|
|
|
|
|
monkeypatch.setattr(
|
|
|
|
|
weeklypost_app.ShiftSchedule,
|
|
|
|
|
"save_schedule_post",
|
|
|
|
|
MagicMock(side_effect=Exception("dynamo down")),
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
with pytest.raises(Exception, match="dynamo down"):
|
|
|
|
|
weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
sqs.send_message.assert_not_called()
|
|
|
|
|
assert "checkcomponents_sent" not in (schedule.get_pay_record("2026-06-01") or {})
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@freeze_time(MON_0800)
|
|
|
|
|
def test_retry_does_not_resend_checkcomponents(
|
|
|
|
|
weeklypost_app, schedule, seed, slack, env, sqs
|
|
|
|
|
):
|
|
|
|
|
seed.config(shift_rate="50")
|
|
|
|
|
seed.weekly("Monday", "114", "Alice")
|
|
|
|
|
|
|
|
|
|
weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
weeklypost_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
sqs.send_message.assert_called_once()
|
|
|
|
|
assert schedule.get_pay_record("2026-06-01")["checkcomponents_sent"] is True
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_payload_skips_fallback_and_zero(weeklypost_app):
|
|
|
|
|
payload = weeklypost_app.build_checkcomponents_payload(
|
|
|
|
|
{
|
|
|
|
|
"week_start": "2026-06-01",
|
|
|
|
|
"totals": {
|
|
|
|
|
"Alice": {"extension": "114", "total": "75.5"},
|
|
|
|
|
"Desk": {"extension": "100", "total": "50"},
|
|
|
|
|
"Zero": {"extension": "200", "total": "0"},
|
|
|
|
|
},
|
|
|
|
|
}
|
|
|
|
|
)
|
|
|
|
|
assert payload["kind"] == "after_hours"
|
|
|
|
|
assert payload["windowStart"] == "2026-06-01"
|
|
|
|
|
assert payload["windowEnd"] == "2026-06-07"
|
|
|
|
|
assert payload["lines"] == [{"extension": "114", "amount": "75.50"}]
|
|
|
|
|
assert "payPeriodId" not in payload
|
2026-09-10 19:30:00 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_send_pay_email_skips_when_recipients_empty(weeklypost_app, monkeypatch):
|
|
|
|
|
monkeypatch.setenv("PAYROLL_RECIPIENTS", "")
|
|
|
|
|
ses = MagicMock(name="ses")
|
|
|
|
|
|
|
|
|
|
def client(svc, **kw):
|
|
|
|
|
if svc == "ses":
|
|
|
|
|
return ses
|
|
|
|
|
return MagicMock(name=svc)
|
|
|
|
|
|
|
|
|
|
monkeypatch.setattr(weeklypost_app.boto3, "client", client)
|
|
|
|
|
weeklypost_app._send_pay_email("Jun 1 to Jun 7", {"totals": {}, "breakdown": []})
|
|
|
|
|
ses.send_email.assert_not_called()
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_weekly_post_payroll_recipients_empty_and_no_ses_grant():
|
|
|
|
|
text = (Path(__file__).resolve().parents[2] / "template.yaml").read_text()
|
|
|
|
|
assert 'PAYROLL_RECIPIENTS: ""' in text
|
|
|
|
|
assert "PAYROLL_RECIPIENTS: payroll@seahaven.com" not in text
|
|
|
|
|
assert "ses:SendEmail" not in text
|