diff --git a/src/server/app.py b/src/server/app.py index cc7c576..94bfee0 100644 --- a/src/server/app.py +++ b/src/server/app.py @@ -6,6 +6,7 @@ Orders are saved as JSON files in the orders directory, one per employee per wee """ import json +import time import urllib.request from datetime import datetime from decimal import Decimal, ROUND_HALF_UP @@ -61,21 +62,36 @@ def get_roster(): return jsonify(config.get("roster", [])) -_google_client_id_cache = None +# Match functions/submit_order/handler.py: TTL so a transient SSM failure cannot +# pin client_id to "" for the process lifetime (which would skip Google auth). +_GOOGLE_CLIENT_ID_CACHE_TTL_SECONDS = 300 + +_google_client_id_cache: str | None = None +_google_client_id_cache_ts = 0.0 def _get_google_client_id() -> str: - global _google_client_id_cache - if _google_client_id_cache is None: - config = load_config() - _google_client_id_cache = config.get("google_client_id", "") - if not _google_client_id_cache: - try: - ssm = boto3.client("ssm") - resp = ssm.get_parameter(Name="/meal-order-manager/google-client-id") - _google_client_id_cache = resp["Parameter"]["Value"] - except Exception: - _google_client_id_cache = "" + global _google_client_id_cache, _google_client_id_cache_ts + now = time.monotonic() + if _google_client_id_cache is not None and ( + now - _google_client_id_cache_ts + ) <= _GOOGLE_CLIENT_ID_CACHE_TTL_SECONDS: + return _google_client_id_cache + + config = load_config() + from_config = (config.get("google_client_id") or "").strip() + if from_config: + _google_client_id_cache = from_config + _google_client_id_cache_ts = now + return _google_client_id_cache + + try: + ssm = boto3.client("ssm") + resp = ssm.get_parameter(Name="/meal-order-manager/google-client-id") + _google_client_id_cache = (resp["Parameter"].get("Value") or "").strip() + except Exception: + _google_client_id_cache = "" + _google_client_id_cache_ts = now return _google_client_id_cache