Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
"""Tests for the roster-sync Lambda handler."""
|
|
|
|
|
|
|
|
|
|
from unittest.mock import MagicMock
|
|
|
|
|
|
|
|
|
|
import pytest
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.fixture
|
|
|
|
|
def env(monkeypatch):
|
|
|
|
|
monkeypatch.setenv("TCX_SECRET_PREFIX", "afterhours-shift-manager/3cx-")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.fixture
|
|
|
|
|
def fake_3cx(rostersync_app, monkeypatch):
|
|
|
|
|
"""Patch ThreeCXClient + get_secret. Returns a setter for group members."""
|
|
|
|
|
client = MagicMock(name="ThreeCXClient")
|
|
|
|
|
monkeypatch.setattr(rostersync_app, "ThreeCXClient", MagicMock(return_value=client))
|
|
|
|
|
monkeypatch.setattr(rostersync_app, "get_secret", lambda _id: "secret")
|
|
|
|
|
|
|
|
|
|
def set_members(members):
|
|
|
|
|
client.get_group_members.return_value = members
|
|
|
|
|
|
|
|
|
|
return set_members
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_adds_removes_and_preserves_links(
|
|
|
|
|
rostersync_app, schedule, seed, env, fake_3cx
|
|
|
|
|
):
|
2026-09-21 17:50:57 +00:00
|
|
|
seed.roster("114", "Alice", slack_user_id="U_ALICE", email="alice@seahavenind.com")
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
seed.roster("115", "Bob", slack_user_id="U_BOB") # departs
|
|
|
|
|
fake_3cx(
|
|
|
|
|
[
|
|
|
|
|
{"Number": "114", "MemberName": "Alice", "Type": "Extension"},
|
|
|
|
|
{"Number": "116", "MemberName": "New Person", "Type": "Extension"},
|
|
|
|
|
{
|
|
|
|
|
"Number": "117",
|
|
|
|
|
"MemberName": "Voicemail",
|
|
|
|
|
"Type": "Extension",
|
|
|
|
|
}, # excluded
|
|
|
|
|
{
|
|
|
|
|
"Number": "118",
|
|
|
|
|
"MemberName": "Reception",
|
|
|
|
|
"Type": "RingGroup",
|
|
|
|
|
}, # excluded
|
|
|
|
|
]
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
result = rostersync_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
# 116 added, 115 removed, 117/118 ignored.
|
|
|
|
|
assert any("116" in a for a in result["added"])
|
|
|
|
|
assert any("115" in r for r in result["removed"])
|
|
|
|
|
assert schedule.get_employee_by_extension("116")["name"] == "New Person"
|
|
|
|
|
assert schedule.get_employee_by_extension("115") is None
|
|
|
|
|
assert schedule.get_employee_by_extension("117") is None
|
|
|
|
|
# Existing link preserved.
|
|
|
|
|
assert schedule.get_employee_by_extension("114")["slack_user_id"] == "U_ALICE"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_renames_changed_member_preserving_link(
|
|
|
|
|
rostersync_app, schedule, seed, env, fake_3cx
|
|
|
|
|
):
|
2026-09-21 17:50:57 +00:00
|
|
|
seed.roster(
|
|
|
|
|
"114", "Alice", slack_user_id="U_ALICE", email="alice@seahavenind.com"
|
|
|
|
|
)
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
fake_3cx([{"Number": "114", "MemberName": "Alicia", "Type": "Extension"}])
|
|
|
|
|
|
|
|
|
|
result = rostersync_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
assert any("114" in u for u in result["updated"])
|
|
|
|
|
emp = schedule.get_employee_by_extension("114")
|
|
|
|
|
assert emp["name"] == "Alicia"
|
|
|
|
|
assert emp["slack_user_id"] == "U_ALICE"
|
2026-09-21 17:50:57 +00:00
|
|
|
assert emp["email"] == "alice@seahavenind.com"
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_empty_3cx_result_does_not_wipe_roster(
|
|
|
|
|
rostersync_app, schedule, seed, env, fake_3cx
|
|
|
|
|
):
|
|
|
|
|
seed.roster("114", "Alice", slack_user_id="U_ALICE")
|
|
|
|
|
fake_3cx([])
|
|
|
|
|
|
|
|
|
|
result = rostersync_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
assert result["removed"] == []
|
|
|
|
|
assert schedule.get_employee_by_extension("114") is not None
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_skips_when_wrong_hour_and_not_forced(rostersync_app, env, fake_3cx):
|
|
|
|
|
import freezegun
|
|
|
|
|
|
|
|
|
|
# 12:00 UTC = 08:00 ET, not 6am → skip.
|
|
|
|
|
with freezegun.freeze_time("2026-06-01 12:00:00"):
|
|
|
|
|
assert rostersync_app.handler({}, None) == {"skipped": True}
|
2026-09-09 21:13:27 +00:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_stale_read_does_not_clear_api_written_slack_id(
|
|
|
|
|
rostersync_app, schedule, env, fake_3cx, monkeypatch
|
|
|
|
|
):
|
|
|
|
|
"""A roster-API row that lands after get_roster must keep its Slack id."""
|
|
|
|
|
from shared.schedule import ShiftSchedule
|
|
|
|
|
|
|
|
|
|
schedule.upsert_roster_entry("116", "New Person", "U_NEW")
|
|
|
|
|
monkeypatch.setattr(ShiftSchedule, "get_roster", lambda self: [])
|
|
|
|
|
fake_3cx([{"Number": "116", "MemberName": "New Person", "Type": "Extension"}])
|
|
|
|
|
|
|
|
|
|
result = rostersync_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
assert any("116" in a for a in result["added"])
|
|
|
|
|
emp = schedule.get_employee_by_extension("116")
|
|
|
|
|
assert emp["name"] == "New Person"
|
|
|
|
|
assert emp["slack_user_id"] == "U_NEW"
|
|
|
|
|
assert emp["extension"] == "116"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_new_extension_still_starts_with_empty_slack_id(
|
|
|
|
|
rostersync_app, schedule, env, fake_3cx
|
|
|
|
|
):
|
|
|
|
|
fake_3cx([{"Number": "116", "MemberName": "New Person", "Type": "Extension"}])
|
|
|
|
|
|
|
|
|
|
rostersync_app.handler({"force": True}, None)
|
|
|
|
|
|
|
|
|
|
emp = schedule.get_employee_by_extension("116")
|
|
|
|
|
assert emp["name"] == "New Person"
|
|
|
|
|
assert emp["slack_user_id"] == ""
|