mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 19:33:12 +00:00
* Add pytest suite and wire it into CI Stands up the first automated tests for the repo (151 tests) and turns on the CI test step. - Lift slack-bot handlers out of create_app() closures to module level so they're unit-testable; create_app is now a thin Bolt-wiring layer. No behavior change (handler entrypoints and create_app signature unchanged). - tests/ mirrors src/: shared layer (schedule, blocks, 3CX client, ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/ admin/register/rate, pickup button, roster sync, queue scheduler). - All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via responses, Slack via fakes, time via freezegun. No real network/AWS. - pyproject.toml pytest config (pythonpath=src/shared, importlib mode); per-package conftest loads each app.py under a unique name to avoid the four-app.py collision. tests/requirements.txt for test-only deps. - ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint the tests dir too. - README Testing section. Closes #85 * Add least-privilege permissions block to CI workflow Resolves the CodeQL actions/missing-workflow-permissions alert: the CI workflow now restricts GITHUB_TOKEN to contents: read (it only checks out, lints, and runs tests). * Stop logging extension numbers in 3CX queue updates Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the queue/ring-group forwarding logs no longer include the routed extension values (closed/holiday/extension). Non-sensitive context (resource id, queue number) is retained.
32 lines
930 B
Python
32 lines
930 B
Python
"""Tests for shared.secrets — Secrets Manager fetch + client caching."""
|
|
|
|
import boto3
|
|
import pytest
|
|
from moto import mock_aws
|
|
|
|
import shared.secrets as secrets
|
|
|
|
|
|
@pytest.fixture(autouse=True)
|
|
def _reset_client():
|
|
# The module caches a module-level client; reset around each test so a
|
|
# client created under one moto context doesn't leak into another.
|
|
secrets._client = None
|
|
yield
|
|
secrets._client = None
|
|
|
|
|
|
def test_get_secret_returns_secret_string():
|
|
with mock_aws():
|
|
sm = boto3.client("secretsmanager", region_name="us-east-1")
|
|
sm.create_secret(
|
|
Name="afterhours-shift-manager/3cx-domain", SecretString="x.3cx.us"
|
|
)
|
|
assert secrets.get_secret("afterhours-shift-manager/3cx-domain") == "x.3cx.us"
|
|
|
|
|
|
def test_get_client_is_cached():
|
|
with mock_aws():
|
|
first = secrets._get_client()
|
|
second = secrets._get_client()
|
|
assert first is second
|