Fix optional Google auth detection

This commit is contained in:
Cursor Agent 2026-05-13 20:44:13 +00:00
parent b160f4b276
commit b90bbd60bd
No known key found for this signature in database
2 changed files with 71 additions and 6 deletions

View file

@ -65,7 +65,14 @@ def _get_discount_settings() -> tuple[Decimal, Decimal]:
def _google_auth_configured() -> bool:
return bool(os.environ.get("GOOGLE_CLIENT_ID_PARAM", ""))
return bool(_get_google_client_id())
def _is_parameter_not_found(exc: Exception) -> bool:
response_data = getattr(exc, "response", {})
if not isinstance(response_data, dict):
return False
return response_data.get("Error", {}).get("Code") == "ParameterNotFound"
def _official_menu_retail_by_name(week: str) -> dict[str, Decimal]:
@ -87,7 +94,12 @@ def _get_google_client_id() -> str:
if _google_client_id is None or (now - _google_client_id_ts) > CACHE_TTL_SECONDS:
param = os.environ.get("GOOGLE_CLIENT_ID_PARAM", "")
if param:
_google_client_id = get_parameter(param, decrypt=False) or ""
try:
_google_client_id = get_parameter(param, decrypt=False) or ""
except Exception as exc:
if not _is_parameter_not_found(exc):
raise
_google_client_id = ""
else:
_google_client_id = ""
_google_client_id_ts = now
@ -187,12 +199,20 @@ def handle_submit(event):
return response(400, {"error": "Invalid JSON"})
# --- Authentication ---
# If Google auth is configured (SSM param name is set), require a valid
# google_id_token. Manual fallback is only allowed when auth is NOT configured.
# If SSM fetch fails, fail closed (503) rather than silently disabling auth.
# If Google auth is configured (SSM param contains a client ID), require a valid
# google_id_token. Manual fallback is only allowed when auth is NOT configured.
# If SSM fetch fails for any other reason, fail closed (503).
google_token = body.get("google_id_token")
if _google_auth_configured():
try:
google_auth_configured = _google_auth_configured()
except Exception as exc:
logger.error("SSM fetch failed for Google client ID: %s", exc)
return response(
503, {"error": "Authentication service temporarily unavailable"}
)
if google_auth_configured:
try:
client_id = _get_google_client_id()
except Exception as exc:

View file

@ -409,6 +409,51 @@ def test_total_summation_multiple_items(
# ===========================================================================
@patch("submit_order_handler._lambda")
@patch("submit_order_handler.put_order")
@patch("submit_order_handler.get_form_status", return_value="open")
@patch("submit_order_handler.current_week", return_value="2026-W20")
@patch(
"submit_order_handler.get_settings",
return_value={"bulk_discount_percent": 0, "company_subsidy_percent": 0},
)
@patch("submit_order_handler.get_secret", return_value=TEST_API_KEY)
@patch("submit_order_handler.get_parameter")
@patch("submit_order_handler.get_menu")
def test_missing_google_client_id_param_allows_manual_submission(
mock_get_menu,
mock_get_parameter,
mock_secret,
mock_settings,
mock_week,
mock_status,
mock_put,
mock_lam,
):
"""Missing Google client ID SSM parameter means auth is not configured."""
from submit_order_handler import lambda_handler
class ParameterNotFoundError(Exception):
response = {"Error": {"Code": "ParameterNotFound"}}
items = _make_items([(10.00, 1)])
mock_get_menu.return_value = _menu_doc_from_retail_pairs([(10.00, 1)])
mock_get_parameter.side_effect = ParameterNotFoundError("ParameterNotFound")
with patch.dict(
os.environ,
{"GOOGLE_CLIENT_ID_PARAM": "/meal-order-manager/google-client-id"},
):
result = lambda_handler(_submit_event(items), None)
status, body = _parse_response(result)
assert status == 200, f"Expected 200, got {status}: {body}"
saved_order = mock_put.call_args[0][2]
assert saved_order["employee_name"] == "Test User"
assert saved_order["employee_email"] == "test.user@seahavenind.com"
@patch("submit_order_handler._lambda")
@patch("submit_order_handler.put_order")
@patch("submit_order_handler.get_form_status", return_value="open")