mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 11:13:12 +00:00
* feat(api): serve meals on ECS Fargate instead of Lambda Keep the Flask app always-on with in-process jobs so CloudFront no longer fronts a cold-start API Gateway. * fix(jobs): run delayed close and reminder deliveries Wall-clock skip windows dropped the only weekly SQS attempt when Scheduler already fired in Eastern time. Dev schedules stay disabled. * fix(api): return JSON objects and stop logging job payloads Flask now jsonify-s handler dicts so API responses are not HTML, and the worker logs only event and status. * fix(ci): restore the reusable workflow so the required check is named ci / ci Inlining the job reported `ci` instead of the org ruleset's `ci / ci`. * fix(secrets): drop unused os import so ruff check passes * style: apply ruff format so ci-python-app lint passes * fix(infra): give meals its own VPC because prod has none * chore(security): re-key ALB SG checkov suppression after vpc.tf
82 lines
2.9 KiB
Python
82 lines
2.9 KiB
Python
"""Structural checks for the public menu route, portal CORS, and edge cache."""
|
|
|
|
from pathlib import Path
|
|
|
|
ROOT = Path(__file__).resolve().parents[1]
|
|
TERRAFORM = ROOT / "terraform"
|
|
SERVER = ROOT / "src" / "server"
|
|
|
|
|
|
def _read(name: str) -> str:
|
|
return (TERRAFORM / name).read_text()
|
|
|
|
|
|
def test_public_menu_route_and_hmac_publish():
|
|
locals_tf = _read("locals.tf")
|
|
|
|
assert 'route_key = "GET /api/menu/{week}"' in locals_tf
|
|
assert 'authorizer = "NONE"' in locals_tf
|
|
assert 'authorizer = "HMAC"' in locals_tf
|
|
assert 'permission_source = "GET/api/menu/*"' in locals_tf
|
|
|
|
|
|
def test_cors_allows_form_portal_and_local_origins():
|
|
app = (SERVER / "app.py").read_text()
|
|
|
|
for origin in (
|
|
"https://orders.seahaven.com",
|
|
"https://internal.seahaven.com",
|
|
"https://internal.dev.seahaven.com",
|
|
"http://localhost:5173",
|
|
"http://localhost:4173",
|
|
):
|
|
assert f'"{origin}"' in app
|
|
assert "Authorization, Content-Type, X-Meals-Publish-Key" in app
|
|
assert "GET, POST, PUT, DELETE, OPTIONS" in app
|
|
|
|
|
|
def test_cloudfront_forwards_and_caches_menu_by_origin_for_60_seconds():
|
|
cloudfront = _read("cloudfront.tf")
|
|
|
|
assert 'origin_id = "OrderApiOrigin"' in cloudfront
|
|
assert "domain_name = aws_lb.api.dns_name" in cloudfront
|
|
assert 'origin_protocol_policy = "http-only"' in cloudfront
|
|
assert 'path_pattern = "/api/menu/*"' in cloudfront
|
|
assert 'target_origin_id = "OrderApiOrigin"' in cloudfront
|
|
assert (
|
|
"cache_policy_id = aws_cloudfront_cache_policy.menu_api.id"
|
|
in cloudfront
|
|
)
|
|
assert (
|
|
"origin_request_policy_id = aws_cloudfront_origin_request_policy.menu_api.id"
|
|
in cloudfront
|
|
)
|
|
assert "default_ttl = 60" in cloudfront
|
|
assert "max_ttl = 60" in cloudfront
|
|
assert "min_ttl = 60" in cloudfront
|
|
assert 'items = ["Origin"]' in cloudfront
|
|
|
|
|
|
def test_cloudfront_forwards_portal_api_paths_without_publish_wildcard():
|
|
cloudfront = _read("cloudfront.tf")
|
|
locals_tf = _read("locals.tf")
|
|
|
|
assert 'route_key = "GET /api/orders/{week}"' in locals_tf
|
|
assert 'permission_source = "GET/api/orders/*"' in locals_tf
|
|
for pattern in (
|
|
'"/api/form-status/*"',
|
|
'"/api/orders/*"',
|
|
'"/api/submit-order"',
|
|
'"/api/admin/*"',
|
|
'"/api/roster"',
|
|
):
|
|
assert pattern in cloudfront
|
|
assert 'path_pattern = "/api/*"' not in cloudfront
|
|
assert "/api/publish" not in cloudfront
|
|
assert "custom_error_response" not in cloudfront
|
|
assert 'resource "aws_cloudfront_function" "form_spa_rewrite"' in cloudfront
|
|
assert "function_arn = aws_cloudfront_function.form_spa_rewrite.arn" in cloudfront
|
|
assert "cloudfront:DescribeFunction" in _read("hcp_iam.tf")
|
|
assert "AllViewerExceptHostHeader" in locals_tf or (
|
|
"b689b0a8-53d0-40ab-baf2-68738e2966ac" in locals_tf
|
|
)
|