meal-order-manager/tests/test_terraform_menu_api.py
Adam Moussa 12f1eb881f
Some checks failed
Build Lambda Layer / build (push) Has been cancelled
fix(auth): accept federated portal Cognito tokens for meals admin (DEV-283) (#194)
* fix(auth): accept federated portal Cognito tokens for meals admin

Google Workspace federation stores email_verified=false, which 403'd the
portal Admin probe while the public menu still loaded.

* fix(iam): grant plan role CloudFront DescribeFunction
2026-09-18 15:31:17 +00:00

83 lines
2.9 KiB
Python

"""Structural checks for the public menu route, portal CORS, and edge cache."""
from pathlib import Path
ROOT = Path(__file__).resolve().parents[1]
TERRAFORM = ROOT / "terraform"
def _read(name: str) -> str:
return (TERRAFORM / name).read_text()
def test_public_menu_route_and_scoped_lambda_permission():
locals_tf = _read("locals.tf")
assert 'route_key = "GET /api/menu/{week}"' in locals_tf
assert 'authorizer = "NONE"' in locals_tf
assert 'permission_source = "GET/api/menu/*"' in locals_tf
def test_cors_allows_form_portal_and_local_origins():
api = _read("apigateway.tf")
for origin in (
"https://orders.seahaven.com",
"https://internal.seahaven.com",
"https://internal.dev.seahaven.com",
"http://localhost:5173",
"http://localhost:4173",
):
assert f'"{origin}"' in api
assert 'allow_headers = ["Authorization", "Content-Type"]' in api
assert 'allow_methods = ["GET", "POST", "PUT", "DELETE", "OPTIONS"]' in api
assert "allow_credentials = false" in api
def test_cloudfront_forwards_and_caches_menu_by_origin_for_60_seconds():
cloudfront = _read("cloudfront.tf")
assert 'origin_id = "OrderApiOrigin"' in cloudfront
assert (
'domain_name = trimprefix(aws_apigatewayv2_api.order_api.api_endpoint, "https://")'
in cloudfront
)
assert 'path_pattern = "/api/menu/*"' in cloudfront
assert 'target_origin_id = "OrderApiOrigin"' in cloudfront
assert (
"cache_policy_id = aws_cloudfront_cache_policy.menu_api.id"
in cloudfront
)
assert (
"origin_request_policy_id = aws_cloudfront_origin_request_policy.menu_api.id"
in cloudfront
)
assert "default_ttl = 60" in cloudfront
assert "max_ttl = 60" in cloudfront
assert "min_ttl = 60" in cloudfront
assert 'items = ["Origin"]' in cloudfront
def test_cloudfront_forwards_portal_api_paths_without_publish_or_roster():
cloudfront = _read("cloudfront.tf")
locals_tf = _read("locals.tf")
assert 'route_key = "GET /api/orders/{week}"' in locals_tf
assert 'permission_source = "GET/api/orders/*"' in locals_tf
for pattern in (
'"/api/form-status/*"',
'"/api/orders/*"',
'"/api/submit-order"',
'"/api/admin/*"',
):
assert pattern in cloudfront
assert 'path_pattern = "/api/*"' not in cloudfront
assert "/api/publish" not in cloudfront
assert "/api/roster" not in cloudfront
assert "custom_error_response" not in cloudfront
assert 'resource "aws_cloudfront_function" "form_spa_rewrite"' in cloudfront
assert "function_arn = aws_cloudfront_function.form_spa_rewrite.arn" in cloudfront
assert "cloudfront:DescribeFunction" in _read("hcp_iam.tf")
assert "AllViewerExceptHostHeader" in locals_tf or (
"b689b0a8-53d0-40ab-baf2-68738e2966ac" in locals_tf
)