mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 07:43:13 +00:00
* feat(api): serve meals on ECS Fargate instead of Lambda Keep the Flask app always-on with in-process jobs so CloudFront no longer fronts a cold-start API Gateway. * fix(jobs): run delayed close and reminder deliveries Wall-clock skip windows dropped the only weekly SQS attempt when Scheduler already fired in Eastern time. Dev schedules stay disabled. * fix(api): return JSON objects and stop logging job payloads Flask now jsonify-s handler dicts so API responses are not HTML, and the worker logs only event and status. * fix(ci): restore the reusable workflow so the required check is named ci / ci Inlining the job reported `ci` instead of the org ruleset's `ci / ci`. * fix(secrets): drop unused os import so ruff check passes * style: apply ruff format so ci-python-app lint passes * fix(infra): give meals its own VPC because prod has none * chore(security): re-key ALB SG checkov suppression after vpc.tf
57 lines
2.1 KiB
Python
57 lines
2.1 KiB
Python
"""Portal Cognito ID-token configuration is wired into the Fargate task."""
|
|
|
|
from pathlib import Path
|
|
|
|
ROOT = Path(__file__).resolve().parents[1]
|
|
TERRAFORM = ROOT / "terraform"
|
|
|
|
|
|
def _read(name: str) -> str:
|
|
return (TERRAFORM / name).read_text()
|
|
|
|
|
|
def test_portal_cognito_parameters_are_managed():
|
|
locals_tf = _read("locals.tf")
|
|
ssm_tf = _read("ssm.tf")
|
|
variables_tf = _read("variables.tf")
|
|
|
|
assert (
|
|
'portal_cognito_issuer_param = "${local.ssm_prefix}/portal-cognito-issuer"'
|
|
in locals_tf
|
|
)
|
|
assert (
|
|
'portal_cognito_audience_param = "${local.ssm_prefix}/portal-cognito-audience"'
|
|
in locals_tf
|
|
)
|
|
assert (
|
|
'portal_cognito_trust_param = "${local.ssm_prefix}/portal-cognito-trust"'
|
|
in locals_tf
|
|
)
|
|
assert 'resource "aws_ssm_parameter" "portal_cognito_issuer"' in ssm_tf
|
|
assert 'resource "aws_ssm_parameter" "portal_cognito_audience"' in ssm_tf
|
|
assert 'resource "aws_ssm_parameter" "portal_cognito_trust"' in ssm_tf
|
|
assert 'variable "portal_cognito_issuer"' in variables_tf
|
|
assert 'variable "portal_cognito_audience"' in variables_tf
|
|
assert 'variable "portal_cognito_extra_trust"' in variables_tf
|
|
|
|
|
|
def test_ecs_task_receives_cognito_parameter_names():
|
|
ecs_tf = _read("ecs.tf")
|
|
|
|
assert ecs_tf.count("PORTAL_COGNITO_ISSUER_PARAM") == 1
|
|
assert ecs_tf.count("PORTAL_COGNITO_AUDIENCE_PARAM") == 1
|
|
assert ecs_tf.count("PORTAL_COGNITO_TRUST_PARAM") == 1
|
|
assert "aws_ssm_parameter.portal_cognito_issuer.name" in ecs_tf
|
|
assert "aws_ssm_parameter.portal_cognito_audience.name" in ecs_tf
|
|
assert "aws_ssm_parameter.portal_cognito_trust.name" in ecs_tf
|
|
|
|
|
|
def test_submit_route_remains_public_for_google_compatibility():
|
|
locals_tf = _read("locals.tf")
|
|
submit_route = locals_tf.split("submit_order = {", 1)[1].split("}", 1)[0]
|
|
|
|
assert 'route_key = "POST /api/submit-order"' in submit_route
|
|
assert 'authorizer = "NONE"' in submit_route
|
|
assert "aws_apigatewayv2" not in "\n".join(
|
|
(TERRAFORM / name).read_text() for name in ("cloudfront.tf", "ecs.tf")
|
|
)
|