Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
"""Tests for shared.ring_scheduler.update_queue_routing (ThreeCXClient faked)."""
|
|
|
|
|
|
|
|
|
|
import shared.ring_scheduler as ring_scheduler
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class FakeThreeCXClient:
|
|
|
|
|
instances = []
|
|
|
|
|
|
|
|
|
|
def __init__(self, domain, auth_mode, client_id, client_secret):
|
|
|
|
|
self.domain = domain
|
|
|
|
|
self.auth_mode = auth_mode
|
|
|
|
|
self.client_id = client_id
|
|
|
|
|
self.client_secret = client_secret
|
|
|
|
|
self.forwarding = None
|
|
|
|
|
FakeThreeCXClient.instances.append(self)
|
|
|
|
|
|
|
|
|
|
def get_queue(self, number):
|
|
|
|
|
self.queue_number = number
|
|
|
|
|
return {"Id": 42, "Number": number}
|
|
|
|
|
|
|
|
|
|
def update_queue_forwarding(self, queue_id, closed, holiday):
|
|
|
|
|
self.forwarding = {"queue_id": queue_id, "closed": closed, "holiday": holiday}
|
|
|
|
|
return 200
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_update_queue_routing_points_queue_at_extension(monkeypatch):
|
|
|
|
|
FakeThreeCXClient.instances = []
|
2026-09-21 19:13:30 +00:00
|
|
|
|
|
|
|
|
def fake_oauth(domain, client_id, client_secret):
|
|
|
|
|
return FakeThreeCXClient(domain, "oauth", client_id, client_secret)
|
|
|
|
|
|
|
|
|
|
monkeypatch.setattr(ring_scheduler, "oauth_client", fake_oauth)
|
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI
Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.
- Lift slack-bot handlers out of create_app() closures to module level so
they're unit-testable; create_app is now a thin Bolt-wiring layer. No
behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
per-package conftest loads each app.py under a unique name to avoid the
four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
the tests dir too.
- README Testing section.
Closes #85
* Add least-privilege permissions block to CI workflow
Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).
* Stop logging extension numbers in 3CX queue updates
Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00
|
|
|
|
|
|
|
|
result = ring_scheduler.update_queue_routing(
|
|
|
|
|
extension="114",
|
|
|
|
|
queue_number="800",
|
|
|
|
|
domain="test.3cx.us",
|
|
|
|
|
client_id="cid",
|
|
|
|
|
client_secret="secret",
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
assert result == {"extension": "114", "queue": "800"}
|
|
|
|
|
client = FakeThreeCXClient.instances[0]
|
|
|
|
|
assert client.auth_mode == "oauth"
|
|
|
|
|
assert client.queue_number == "800"
|
|
|
|
|
# Both closed and holiday routes point at the on-call extension.
|
|
|
|
|
assert client.forwarding == {"queue_id": 42, "closed": "114", "holiday": "114"}
|