"""Structural checks for the public menu route, portal CORS, and edge cache.""" from pathlib import Path ROOT = Path(__file__).resolve().parents[1] TERRAFORM = ROOT / "terraform" SERVER = ROOT / "src" / "server" def _read(name: str) -> str: return (TERRAFORM / name).read_text() def test_public_menu_route_and_hmac_publish(): locals_tf = _read("locals.tf") assert 'route_key = "GET /api/menu/{week}"' in locals_tf assert 'authorizer = "NONE"' in locals_tf assert 'authorizer = "HMAC"' in locals_tf assert 'permission_source = "GET/api/menu/*"' in locals_tf def test_cors_allows_form_portal_and_local_origins(): app = (SERVER / "app.py").read_text() for origin in ( "https://orders.seahaven.com", "https://internal.seahaven.com", "https://internal.dev.seahaven.com", "http://localhost:5173", "http://localhost:4173", ): assert f'"{origin}"' in app assert "Authorization, Content-Type, X-Meals-Publish-Key" in app assert "GET, POST, PUT, DELETE, OPTIONS" in app def test_cloudfront_forwards_and_caches_menu_by_origin_for_60_seconds(): cloudfront = _read("cloudfront.tf") assert 'origin_id = "OrderApiOrigin"' in cloudfront assert "domain_name = aws_lb.api.dns_name" in cloudfront assert 'origin_protocol_policy = "http-only"' in cloudfront assert 'path_pattern = "/api/menu/*"' in cloudfront assert 'target_origin_id = "OrderApiOrigin"' in cloudfront assert ( "cache_policy_id = aws_cloudfront_cache_policy.menu_api.id" in cloudfront ) assert ( "origin_request_policy_id = aws_cloudfront_origin_request_policy.menu_api.id" in cloudfront ) assert "default_ttl = 60" in cloudfront assert "max_ttl = 60" in cloudfront assert "min_ttl = 60" in cloudfront assert 'items = ["Origin"]' in cloudfront def test_cloudfront_forwards_portal_api_paths_without_publish_wildcard(): cloudfront = _read("cloudfront.tf") locals_tf = _read("locals.tf") assert 'route_key = "GET /api/orders/{week}"' in locals_tf assert 'permission_source = "GET/api/orders/*"' in locals_tf for pattern in ( '"/api/form-status/*"', '"/api/orders/*"', '"/api/submit-order"', '"/api/admin/*"', '"/api/roster"', ): assert pattern in cloudfront assert 'path_pattern = "/api/*"' not in cloudfront assert "/api/publish" not in cloudfront assert "custom_error_response" not in cloudfront assert 'resource "aws_cloudfront_function" "form_spa_rewrite"' in cloudfront assert "function_arn = aws_cloudfront_function.form_spa_rewrite.arn" in cloudfront assert "cloudfront:DescribeFunction" in _read("hcp_iam.tf") assert "AllViewerExceptHostHeader" in locals_tf or ( "b689b0a8-53d0-40ab-baf2-68738e2966ac" in locals_tf )