"""Structural checks for the public menu route, portal CORS, and edge cache.""" from pathlib import Path ROOT = Path(__file__).resolve().parents[1] TERRAFORM = ROOT / "terraform" def _read(name: str) -> str: return (TERRAFORM / name).read_text() def test_public_menu_route_and_scoped_lambda_permission(): locals_tf = _read("locals.tf") assert 'route_key = "GET /api/menu/{week}"' in locals_tf assert 'authorizer = "NONE"' in locals_tf assert 'permission_source = "GET/api/menu/*"' in locals_tf def test_cors_allows_form_portal_and_local_origins(): api = _read("apigateway.tf") for origin in ( "https://orders.seahaven.com", "https://internal.seahaven.com", "https://internal.dev.seahaven.com", "http://localhost:5173", "http://localhost:4173", ): assert f'"{origin}"' in api assert 'allow_headers = ["Authorization", "Content-Type"]' in api assert 'allow_methods = ["GET", "POST", "PUT", "DELETE", "OPTIONS"]' in api assert "allow_credentials = false" in api def test_cloudfront_forwards_and_caches_menu_by_origin_for_60_seconds(): cloudfront = _read("cloudfront.tf") assert 'origin_id = "OrderApiOrigin"' in cloudfront assert ( 'domain_name = trimprefix(aws_apigatewayv2_api.order_api.api_endpoint, "https://")' in cloudfront ) assert 'path_pattern = "/api/menu/*"' in cloudfront assert 'target_origin_id = "OrderApiOrigin"' in cloudfront assert ( "cache_policy_id = aws_cloudfront_cache_policy.menu_api.id" in cloudfront ) assert ( "origin_request_policy_id = aws_cloudfront_origin_request_policy.menu_api.id" in cloudfront ) assert "default_ttl = 60" in cloudfront assert "max_ttl = 60" in cloudfront assert "min_ttl = 60" in cloudfront assert 'items = ["Origin"]' in cloudfront def test_cloudfront_forwards_portal_api_paths_without_publish_or_roster(): cloudfront = _read("cloudfront.tf") locals_tf = _read("locals.tf") assert 'route_key = "GET /api/orders/{week}"' in locals_tf assert 'permission_source = "GET/api/orders/*"' in locals_tf for pattern in ( '"/api/form-status/*"', '"/api/orders/*"', '"/api/submit-order"', '"/api/admin/*"', ): assert pattern in cloudfront assert 'path_pattern = "/api/*"' not in cloudfront assert "/api/publish" not in cloudfront assert "/api/roster" not in cloudfront assert "custom_error_response" not in cloudfront assert 'resource "aws_cloudfront_function" "form_spa_rewrite"' in cloudfront assert "function_arn = aws_cloudfront_function.form_spa_rewrite.arn" in cloudfront assert "cloudfront:DescribeFunction" in _read("hcp_iam.tf") assert "AllViewerExceptHostHeader" in locals_tf or ( "b689b0a8-53d0-40ab-baf2-68738e2966ac" in locals_tf )