mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-10-06 17:01:58 +00:00
Fix optional Google auth detection
This commit is contained in:
parent
b160f4b276
commit
b90bbd60bd
2 changed files with 71 additions and 6 deletions
|
|
@ -65,7 +65,14 @@ def _get_discount_settings() -> tuple[Decimal, Decimal]:
|
||||||
|
|
||||||
|
|
||||||
def _google_auth_configured() -> bool:
|
def _google_auth_configured() -> bool:
|
||||||
return bool(os.environ.get("GOOGLE_CLIENT_ID_PARAM", ""))
|
return bool(_get_google_client_id())
|
||||||
|
|
||||||
|
|
||||||
|
def _is_parameter_not_found(exc: Exception) -> bool:
|
||||||
|
response_data = getattr(exc, "response", {})
|
||||||
|
if not isinstance(response_data, dict):
|
||||||
|
return False
|
||||||
|
return response_data.get("Error", {}).get("Code") == "ParameterNotFound"
|
||||||
|
|
||||||
|
|
||||||
def _official_menu_retail_by_name(week: str) -> dict[str, Decimal]:
|
def _official_menu_retail_by_name(week: str) -> dict[str, Decimal]:
|
||||||
|
|
@ -87,7 +94,12 @@ def _get_google_client_id() -> str:
|
||||||
if _google_client_id is None or (now - _google_client_id_ts) > CACHE_TTL_SECONDS:
|
if _google_client_id is None or (now - _google_client_id_ts) > CACHE_TTL_SECONDS:
|
||||||
param = os.environ.get("GOOGLE_CLIENT_ID_PARAM", "")
|
param = os.environ.get("GOOGLE_CLIENT_ID_PARAM", "")
|
||||||
if param:
|
if param:
|
||||||
_google_client_id = get_parameter(param, decrypt=False) or ""
|
try:
|
||||||
|
_google_client_id = get_parameter(param, decrypt=False) or ""
|
||||||
|
except Exception as exc:
|
||||||
|
if not _is_parameter_not_found(exc):
|
||||||
|
raise
|
||||||
|
_google_client_id = ""
|
||||||
else:
|
else:
|
||||||
_google_client_id = ""
|
_google_client_id = ""
|
||||||
_google_client_id_ts = now
|
_google_client_id_ts = now
|
||||||
|
|
@ -187,12 +199,20 @@ def handle_submit(event):
|
||||||
return response(400, {"error": "Invalid JSON"})
|
return response(400, {"error": "Invalid JSON"})
|
||||||
|
|
||||||
# --- Authentication ---
|
# --- Authentication ---
|
||||||
# If Google auth is configured (SSM param name is set), require a valid
|
# If Google auth is configured (SSM param contains a client ID), require a valid
|
||||||
# google_id_token. Manual fallback is only allowed when auth is NOT configured.
|
# google_id_token. Manual fallback is only allowed when auth is NOT configured.
|
||||||
# If SSM fetch fails, fail closed (503) rather than silently disabling auth.
|
# If SSM fetch fails for any other reason, fail closed (503).
|
||||||
google_token = body.get("google_id_token")
|
google_token = body.get("google_id_token")
|
||||||
|
|
||||||
if _google_auth_configured():
|
try:
|
||||||
|
google_auth_configured = _google_auth_configured()
|
||||||
|
except Exception as exc:
|
||||||
|
logger.error("SSM fetch failed for Google client ID: %s", exc)
|
||||||
|
return response(
|
||||||
|
503, {"error": "Authentication service temporarily unavailable"}
|
||||||
|
)
|
||||||
|
|
||||||
|
if google_auth_configured:
|
||||||
try:
|
try:
|
||||||
client_id = _get_google_client_id()
|
client_id = _get_google_client_id()
|
||||||
except Exception as exc:
|
except Exception as exc:
|
||||||
|
|
|
||||||
|
|
@ -409,6 +409,51 @@ def test_total_summation_multiple_items(
|
||||||
# ===========================================================================
|
# ===========================================================================
|
||||||
|
|
||||||
|
|
||||||
|
@patch("submit_order_handler._lambda")
|
||||||
|
@patch("submit_order_handler.put_order")
|
||||||
|
@patch("submit_order_handler.get_form_status", return_value="open")
|
||||||
|
@patch("submit_order_handler.current_week", return_value="2026-W20")
|
||||||
|
@patch(
|
||||||
|
"submit_order_handler.get_settings",
|
||||||
|
return_value={"bulk_discount_percent": 0, "company_subsidy_percent": 0},
|
||||||
|
)
|
||||||
|
@patch("submit_order_handler.get_secret", return_value=TEST_API_KEY)
|
||||||
|
@patch("submit_order_handler.get_parameter")
|
||||||
|
@patch("submit_order_handler.get_menu")
|
||||||
|
def test_missing_google_client_id_param_allows_manual_submission(
|
||||||
|
mock_get_menu,
|
||||||
|
mock_get_parameter,
|
||||||
|
mock_secret,
|
||||||
|
mock_settings,
|
||||||
|
mock_week,
|
||||||
|
mock_status,
|
||||||
|
mock_put,
|
||||||
|
mock_lam,
|
||||||
|
):
|
||||||
|
"""Missing Google client ID SSM parameter means auth is not configured."""
|
||||||
|
from submit_order_handler import lambda_handler
|
||||||
|
|
||||||
|
class ParameterNotFoundError(Exception):
|
||||||
|
response = {"Error": {"Code": "ParameterNotFound"}}
|
||||||
|
|
||||||
|
items = _make_items([(10.00, 1)])
|
||||||
|
mock_get_menu.return_value = _menu_doc_from_retail_pairs([(10.00, 1)])
|
||||||
|
mock_get_parameter.side_effect = ParameterNotFoundError("ParameterNotFound")
|
||||||
|
|
||||||
|
with patch.dict(
|
||||||
|
os.environ,
|
||||||
|
{"GOOGLE_CLIENT_ID_PARAM": "/meal-order-manager/google-client-id"},
|
||||||
|
):
|
||||||
|
result = lambda_handler(_submit_event(items), None)
|
||||||
|
|
||||||
|
status, body = _parse_response(result)
|
||||||
|
|
||||||
|
assert status == 200, f"Expected 200, got {status}: {body}"
|
||||||
|
saved_order = mock_put.call_args[0][2]
|
||||||
|
assert saved_order["employee_name"] == "Test User"
|
||||||
|
assert saved_order["employee_email"] == "test.user@seahavenind.com"
|
||||||
|
|
||||||
|
|
||||||
@patch("submit_order_handler._lambda")
|
@patch("submit_order_handler._lambda")
|
||||||
@patch("submit_order_handler.put_order")
|
@patch("submit_order_handler.put_order")
|
||||||
@patch("submit_order_handler.get_form_status", return_value="open")
|
@patch("submit_order_handler.get_form_status", return_value="open")
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue