mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 07:53:11 +00:00
* Fix payroll email: grant SES config-set permission + isolate failures The weekly pay-summary email to payroll has been failing with SES AccessDenied since 2026-06-08. The sending identity (seahaven.com) gained a default configuration set (seahaven-email-events), and SES authorizes SendEmail against the config-set ARN as well as the identity — but the WeeklyPostFunction role only granted ses:SendEmail on identity/*. - template.yaml: add the configuration-set ARN (scoped to the known set name) to the SES policy so sends are authorized again. - weekly-post/app.py: wrap _send_pay_email in try/except so a delivery failure can never abort the handler before the Slack schedule post. Previously the SES error also blocked the two-week schedule post. - Add a regression test covering the isolation. Cross-family GPT-4.1 IAM review: APPROVE. * Bump to v1.10.1 in CHANGELOG and sync App Home copy
97 lines
3.4 KiB
Python
97 lines
3.4 KiB
Python
"""Tests for the weekly-post Lambda handler orchestration."""
|
|
|
|
from unittest.mock import MagicMock
|
|
|
|
import pytest
|
|
from freezegun import freeze_time
|
|
|
|
# 2026-06-08 is a Monday. Frozen to ET 08:00; handler is invoked with force=True
|
|
# to bypass the 7am DST guard except where the guard itself is under test.
|
|
MON_0800 = "2026-06-08 12:00:00"
|
|
|
|
|
|
@pytest.fixture
|
|
def slack(weeklypost_app, monkeypatch):
|
|
"""Fake Slack WebClient; chat_postMessage returns a message ts."""
|
|
fake = MagicMock(name="slack")
|
|
fake.chat_postMessage.return_value = {"ts": "999.000"}
|
|
monkeypatch.setattr(weeklypost_app, "WebClient", MagicMock(return_value=fake))
|
|
monkeypatch.setattr(weeklypost_app, "get_secret", lambda _id: "xoxb-test")
|
|
return fake
|
|
|
|
|
|
@pytest.fixture
|
|
def env(monkeypatch):
|
|
monkeypatch.setenv(
|
|
"SLACK_BOT_TOKEN_SECRET", "afterhours-shift-manager/slack-bot-token"
|
|
)
|
|
monkeypatch.setenv("PAY_REPORT_USER", "U_BOSS")
|
|
monkeypatch.delenv("PAYROLL_RECIPIENTS", raising=False) # skip SES email
|
|
|
|
|
|
@freeze_time(MON_0800)
|
|
def test_posts_schedule_and_saves_post(weeklypost_app, schedule, seed, slack, env):
|
|
result = weeklypost_app.handler({"force": True}, None)
|
|
|
|
assert result["posted"] is True
|
|
assert result["message_ts"] == "999.000"
|
|
# The new schedule post was persisted for next week's cleanup.
|
|
assert schedule.get_schedule_post("C_TEST")["message_ts"] == "999.000"
|
|
slack.chat_postMessage.assert_called()
|
|
|
|
|
|
@freeze_time(MON_0800)
|
|
def test_calculates_and_dms_pay(weeklypost_app, schedule, seed, slack, env):
|
|
# Previous week (Mon 2026-06-01) had Alice on the Monday night shift.
|
|
seed.config(shift_rate="50")
|
|
seed.weekly("Monday", "114", "Alice")
|
|
|
|
result = weeklypost_app.handler({"force": True}, None)
|
|
|
|
assert result["pay_calculated"] is True
|
|
# Pay record saved under previous Monday's key.
|
|
assert schedule.get_pay_record("2026-06-01") is not None
|
|
# A DM went to the configured pay-report user.
|
|
dm_calls = [
|
|
c
|
|
for c in slack.chat_postMessage.call_args_list
|
|
if c.kwargs.get("channel") == "U_BOSS"
|
|
]
|
|
assert dm_calls
|
|
|
|
|
|
@freeze_time(MON_0800)
|
|
def test_pay_email_failure_does_not_block_schedule_post(
|
|
weeklypost_app, schedule, seed, slack, env, monkeypatch
|
|
):
|
|
# Previous week has an assigned shift, so the pay/email path runs.
|
|
seed.config(shift_rate="50")
|
|
seed.weekly("Monday", "114", "Alice")
|
|
# SES delivery blows up (e.g. a permission/identity issue).
|
|
monkeypatch.setattr(
|
|
weeklypost_app,
|
|
"_send_pay_email",
|
|
MagicMock(side_effect=Exception("SES AccessDenied")),
|
|
)
|
|
|
|
result = weeklypost_app.handler({"force": True}, None)
|
|
|
|
# The email failure is swallowed; the schedule post still goes out.
|
|
assert result["posted"] is True
|
|
assert schedule.get_schedule_post("C_TEST")["message_ts"] == "999.000"
|
|
|
|
|
|
@freeze_time(MON_0800)
|
|
def test_deletes_previous_schedule_post(weeklypost_app, schedule, seed, slack, env):
|
|
seed.schedule_post("C_TEST", "111.111")
|
|
weeklypost_app.handler({"force": True}, None)
|
|
slack.chat_delete.assert_called_once()
|
|
assert slack.chat_delete.call_args.kwargs["ts"] == "111.111"
|
|
|
|
|
|
@freeze_time(MON_0800)
|
|
def test_skips_when_not_7am_and_not_forced(weeklypost_app, schedule, slack, env):
|
|
# Frozen hour is 08:00 ET, not 07:00 → skip unless forced.
|
|
result = weeklypost_app.handler({}, None)
|
|
assert result == {"skipped": True}
|
|
slack.chat_postMessage.assert_not_called()
|