mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-10-06 20:21:57 +00:00
70 lines
2.6 KiB
Python
70 lines
2.6 KiB
Python
|
|
"""Deploy-guard healthcheck branch (Phase 0).
|
||
|
|
|
||
|
|
The handler must answer a top-level direct-invoke ``{"healthcheck": true}``
|
||
|
|
probe immediately -- BEFORE any S3 fetch, SES sender-auth gate, or Records
|
||
|
|
iteration -- and must do so without touching AWS or emitting any telemetry
|
||
|
|
that could trip the ``sender_auth_rejected`` metric-filter alarm.
|
||
|
|
|
||
|
|
These tests import the WO ``handler`` via the ``_wo_parser_support`` sys.path
|
||
|
|
loader idiom (region + module dir set on import); no fake_dynamo/S3 wiring is
|
||
|
|
needed because a correct healthcheck returns before any client is used.
|
||
|
|
"""
|
||
|
|
|
||
|
|
import handler
|
||
|
|
from _wo_parser_support import FakeDynamoResource
|
||
|
|
|
||
|
|
|
||
|
|
class _ExplodingS3:
|
||
|
|
"""Any attribute access is a test failure: the healthcheck branch must
|
||
|
|
return before the handler ever reaches the S3 client."""
|
||
|
|
|
||
|
|
def get_object(self, *a, **k): # noqa: N803
|
||
|
|
raise AssertionError("healthcheck branch touched S3")
|
||
|
|
|
||
|
|
|
||
|
|
def test_healthcheck_returns_ok():
|
||
|
|
assert handler.handler({"healthcheck": True}, None) == {"healthcheck": "ok"}
|
||
|
|
|
||
|
|
|
||
|
|
def test_healthcheck_precedes_s3_and_auth(monkeypatch):
|
||
|
|
# If the early-return were missing or misplaced, the handler would call
|
||
|
|
# s3.get_object / authenticate_inbound_email; both are booby-trapped.
|
||
|
|
monkeypatch.setattr(handler, "s3", _ExplodingS3())
|
||
|
|
monkeypatch.setattr(handler, "dynamodb", FakeDynamoResource())
|
||
|
|
|
||
|
|
def _boom_auth(*a, **k):
|
||
|
|
raise AssertionError("healthcheck branch reached SES auth")
|
||
|
|
|
||
|
|
monkeypatch.setattr(handler, "authenticate_inbound_email", _boom_auth)
|
||
|
|
|
||
|
|
assert handler.handler({"healthcheck": True}, None) == {"healthcheck": "ok"}
|
||
|
|
|
||
|
|
|
||
|
|
def test_healthcheck_emits_no_metric(monkeypatch):
|
||
|
|
# No EMF / ParseOutcome emission on the healthcheck path.
|
||
|
|
def _boom_metric(*a, **k):
|
||
|
|
raise AssertionError("healthcheck branch emitted a metric")
|
||
|
|
|
||
|
|
monkeypatch.setattr(handler, "emit_parse_metric", _boom_metric)
|
||
|
|
|
||
|
|
assert handler.handler({"healthcheck": True}, None) == {"healthcheck": "ok"}
|
||
|
|
|
||
|
|
|
||
|
|
def test_healthcheck_only_on_literal_true():
|
||
|
|
# A truthy-but-not-True value must NOT trigger the branch: it falls through
|
||
|
|
# to the (empty) Records loop and returns the normal 200 envelope. This
|
||
|
|
# keeps the trigger to the exact direct-invoke contract.
|
||
|
|
assert handler.handler({"healthcheck": "yes"}, None) == {
|
||
|
|
"statusCode": 200,
|
||
|
|
"body": "OK",
|
||
|
|
}
|
||
|
|
|
||
|
|
|
||
|
|
def test_records_event_ignores_healthcheck_lookalike():
|
||
|
|
# A real S3 event shape has no top-level healthcheck key; an empty Records
|
||
|
|
# list is processed normally without hitting the early return.
|
||
|
|
assert handler.handler({"Records": []}, None) == {
|
||
|
|
"statusCode": 200,
|
||
|
|
"body": "OK",
|
||
|
|
}
|