afterhours-shift-manager/tests/slack_bot/test_handle_pick.py
Adam Moussa 3a26343cb7
Add pytest suite and wire it into CI (#85) (#86)
* Add pytest suite and wire it into CI

Stands up the first automated tests for the repo (151 tests) and turns on
the CI test step.

- Lift slack-bot handlers out of create_app() closures to module level so
  they're unit-testable; create_app is now a thin Bolt-wiring layer. No
  behavior change (handler entrypoints and create_app signature unchanged).
- tests/ mirrors src/: shared layer (schedule, blocks, 3CX client,
  ring_scheduler, secrets) + all four Lambdas (pay math, drop/swap/pick/
  admin/register/rate, pickup button, roster sync, queue scheduler).
- All boundaries mocked: DynamoDB/SES/Secrets via moto, 3CX HTTP via
  responses, Slack via fakes, time via freezegun. No real network/AWS.
- pyproject.toml pytest config (pythonpath=src/shared, importlib mode);
  per-package conftest loads each app.py under a unique name to avoid the
  four-app.py collision. tests/requirements.txt for test-only deps.
- ci.yaml: run-tests: true (reusable workflow auto-installs deps) and lint
  the tests dir too.
- README Testing section.

Closes #85

* Add least-privilege permissions block to CI workflow

Resolves the CodeQL actions/missing-workflow-permissions alert: the CI
workflow now restricts GITHUB_TOKEN to contents: read (it only checks out,
lints, and runs tests).

* Stop logging extension numbers in 3CX queue updates

Resolves 3 high CodeQL py/clear-text-logging-sensitive-data alerts: the
queue/ring-group forwarding logs no longer include the routed extension
values (closed/holiday/extension). Non-sensitive context (resource id,
queue number) is retained.
2026-06-01 19:07:08 -04:00

55 lines
1.8 KiB
Python

"""Tests for slack-bot _handle_pick."""
from freezegun import freeze_time
MON = "2026-06-01 12:00:00"
@freeze_time(MON)
def test_pick_open_shift_today(
slackbot_app, schedule, seed, respond, client, routing_spy, text_of
):
seed.roster("114", "Alice", slack_user_id="U_ALICE")
# Monday night is unassigned (available) → pickable.
slackbot_app._handle_pick(
respond, schedule, "U_ALICE", "pick today", "C1", client, None
)
assert schedule.get_override("2026-06-01")["extension"] == "114"
assert "picked up" in text_of(respond).lower()
routing_spy.assert_called_once_with("114")
@freeze_time(MON)
def test_pick_already_covered(
slackbot_app, schedule, seed, respond, client, routing_spy, text_of
):
seed.roster("114", "Alice", slack_user_id="U_ALICE")
seed.weekly("Monday", "115", "Bob") # already covered
slackbot_app._handle_pick(
respond, schedule, "U_ALICE", "pick today", "C1", client, None
)
assert "already covered" in text_of(respond).lower()
routing_spy.assert_not_called()
@freeze_time(MON)
def test_pick_past_date(slackbot_app, schedule, seed, respond, client, text_of):
seed.roster("114", "Alice", slack_user_id="U_ALICE")
slackbot_app._handle_pick(
respond, schedule, "U_ALICE", "pick 2026-05-01", "C1", client, None
)
assert "past" in text_of(respond).lower()
@freeze_time(MON)
def test_pick_unregistered(slackbot_app, schedule, respond, client, text_of):
slackbot_app._handle_pick(
respond, schedule, "U_NOBODY", "pick today", "C1", client, None
)
assert "not registered" in text_of(respond).lower()
@freeze_time(MON)
def test_pick_usage(slackbot_app, schedule, respond, client, text_of):
slackbot_app._handle_pick(respond, schedule, "U_ALICE", "pick", "C1", client, None)
assert "Usage" in text_of(respond)