meal-order-manager/tests/test_secrets.py
Adam Moussa f48a82c476
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
feat(api): serve meals on ECS Fargate instead of Lambda (PLAT-215) (#199)
* feat(api): serve meals on ECS Fargate instead of Lambda

Keep the Flask app always-on with in-process jobs so CloudFront no longer fronts a cold-start API Gateway.

* fix(jobs): run delayed close and reminder deliveries

Wall-clock skip windows dropped the only weekly SQS attempt when Scheduler already fired in Eastern time. Dev schedules stay disabled.

* fix(api): return JSON objects and stop logging job payloads

Flask now jsonify-s handler dicts so API responses are not HTML, and the worker logs only event and status.

* fix(ci): restore the reusable workflow so the required check is named ci / ci

Inlining the job reported `ci` instead of the org ruleset's `ci / ci`.

* fix(secrets): drop unused os import so ruff check passes

* style: apply ruff format so ci-python-app lint passes

* fix(infra): give meals its own VPC because prod has none

* chore(security): re-key ALB SG checkov suppression after vpc.tf
2026-09-21 19:34:24 +00:00

55 lines
1.8 KiB
Python

"""Tests for shared.secrets caching."""
from unittest.mock import MagicMock, patch
def test_get_parameter_refetches_after_ttl():
"""SSM parameter values expire so callers can observe rotations."""
from shared import secrets
secrets._secret_cache.clear()
secrets._parameter_cache.clear()
mock_ssm = MagicMock()
mock_ssm.get_parameter.side_effect = [
{"Parameter": {"Value": "first"}},
{"Parameter": {"Value": "second"}},
]
with patch.object(secrets, "_ssm", mock_ssm):
with patch.object(secrets, "PARAM_CACHE_TTL_SECONDS", 10.0):
with patch(
"shared.secrets.time.monotonic",
side_effect=[0.0, 5.0, 15.0],
):
assert secrets.get_parameter("/test/param") == "first"
assert secrets.get_parameter("/test/param") == "first"
assert secrets.get_parameter("/test/param") == "second"
assert mock_ssm.get_parameter.call_count == 2
def test_get_secret_refetches_after_ttl():
"""Secrets Manager values expire so a long-lived task observes rotation."""
from shared import secrets
secrets._secret_cache.clear()
secrets._parameter_cache.clear()
mock_sm = MagicMock()
mock_sm.get_secret_value.side_effect = [
{"SecretString": "a"},
{"SecretString": "b"},
]
with patch.object(secrets, "_sm", mock_sm):
with patch.object(secrets, "PARAM_CACHE_TTL_SECONDS", 10.0):
with patch(
"shared.secrets.time.monotonic",
side_effect=[0.0, 5.0, 15.0],
):
assert secrets.get_secret("arn:aws:secret") == "a"
assert secrets.get_secret("arn:aws:secret") == "a"
assert secrets.get_secret("arn:aws:secret") == "b"
assert mock_sm.get_secret_value.call_count == 2