meal-order-manager/tests/test_openapi_contract.py

48 lines
2.1 KiB
Python
Raw Permalink Normal View History

feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206) * feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289) Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs expose the resolved vpc_id and public subnet IDs. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289) Same extends: recommended ruleset and @redocly/cli 2.52.1 as internal-portal. Documents current { error: string } JSON errors. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): document 4xx and reject invalid form-status weeks (DEV-289) Health, form-status, and roster document 400. form-status now maps current and returns 400 for a week that is not current or YYYY-WNN. Redocly treats 302 as a success response, matching the portal. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * style(test): format VPC contract assertions for ruff (DEV-289) Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289) Promote operation-4xx-response and the 2xx-or-3xx success rule to error. Replace unused health and roster 400s with 403, matching portal health. Form-status keeps its real 400 for invalid week. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): split week params and allow live menu nulls (DEV-289) Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a calendar date and reject current. Menu payloads may emit null menu_url, calories, protein, and image_url. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(infra): fail prod apply without the afterhours VPC (DEV-289) Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00
"""OpenAPI 3.1 + Redocly recommended, matching internal-portal (DEV-289)."""
import json
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206) * feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289) Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs expose the resolved vpc_id and public subnet IDs. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289) Same extends: recommended ruleset and @redocly/cli 2.52.1 as internal-portal. Documents current { error: string } JSON errors. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): document 4xx and reject invalid form-status weeks (DEV-289) Health, form-status, and roster document 400. form-status now maps current and returns 400 for a week that is not current or YYYY-WNN. Redocly treats 302 as a success response, matching the portal. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * style(test): format VPC contract assertions for ruff (DEV-289) Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289) Promote operation-4xx-response and the 2xx-or-3xx success rule to error. Replace unused health and roster 400s with 403, matching portal health. Form-status keeps its real 400 for invalid week. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): split week params and allow live menu nulls (DEV-289) Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a calendar date and reject current. Menu payloads may emit null menu_url, calories, protein, and image_url. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(infra): fail prod apply without the afterhours VPC (DEV-289) Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00
from pathlib import Path
ROOT = Path(__file__).resolve().parents[1]
def test_openapi_uses_redocly_recommended():
redocly = (ROOT / ".redocly.yaml").read_text()
package = (ROOT / "package.json").read_text()
spec = (ROOT / "openapi.yaml").read_text()
ci = (ROOT / ".github" / "workflows" / "ci.yml").read_text()
assert "extends:" in redocly
assert "- recommended" in redocly
assert "operation-2xx-response: off" in redocly
assert "operation-4xx-response: error" in redocly
assert "rule/operation-2xx-or-3xx-response" in redocly
assert "severity: error" in redocly
health = spec.split("/api/health:", 1)[1].split("\n /", 1)[0]
assert '"403":' in health
assert '"400":' not in health
roster = spec.split("/api/roster:", 1)[1].split("\n /", 1)[0]
assert '"403":' in roster
assert '"400":' not in roster
form_status = spec.split("/api/form-status/{week}:", 1)[1].split("\n /", 1)[0]
assert '"400":' in form_status
menu = spec.split("/api/menu/{week}:", 1)[1].split("\n /", 1)[0]
orders = spec.split("/api/orders/{week}:", 1)[1].split("\n /", 1)[0]
assert "MenuWeekPath" in menu
assert "MenuWeekPath" in form_status
assert "OrderWeekPath" in orders
assert "WeekPath" not in spec.split("components:", 1)[1].split("MenuWeekPath", 1)[0]
assert "`current` or `YYYY-WNN`" in spec
assert "`YYYY-WNN` or `YYYY-MM-DD`" in spec
meal = spec.split(" Meal:", 1)[1].split("\n MenuPayload:", 1)[0]
assert 'type: [string, number, "null"]' in meal
assert 'type: [string, "null"]' in meal
assert 'menu_url:\n type: [string, "null"]' in spec
assert "root: openapi.yaml" in redocly
assert '"openapi:lint"' in package
dev = json.loads(package)["devDependencies"]
assert dev["@redocly/cli"]
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206) * feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289) Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs expose the resolved vpc_id and public subnet IDs. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289) Same extends: recommended ruleset and @redocly/cli 2.52.1 as internal-portal. Documents current { error: string } JSON errors. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): document 4xx and reject invalid form-status weeks (DEV-289) Health, form-status, and roster document 400. form-status now maps current and returns 400 for a week that is not current or YYYY-WNN. Redocly treats 302 as a success response, matching the portal. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * style(test): format VPC contract assertions for ruff (DEV-289) Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289) Promote operation-4xx-response and the 2xx-or-3xx success rule to error. Replace unused health and roster 400s with 403, matching portal health. Form-status keeps its real 400 for invalid week. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): split week params and allow live menu nulls (DEV-289) Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a calendar date and reject current. Menu payloads may emit null menu_url, calories, protein, and image_url. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(infra): fail prod apply without the afterhours VPC (DEV-289) Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00
assert "npm run openapi:lint" in ci
assert "openapi: 3.1.0" in spec
assert "required: [stage, sha]" in spec
assert "{ error: string }" in spec or "`{ error: string }`" in spec