"""Deploy-guard healthcheck branch (Phase 0). The handler must answer a top-level direct-invoke ``{"healthcheck": true}`` probe immediately -- BEFORE any S3 fetch, SES sender-auth gate, or Records iteration -- and must do so without touching AWS or emitting any telemetry that could trip the ``sender_auth_rejected`` metric-filter alarm. These tests import the WO ``handler`` via the ``_wo_parser_support`` shim (which loads it through the shared loader after the root conftest set the AWS env and imported moto); no fake_dynamo/S3 wiring is needed because a correct healthcheck returns before any client is used. """ from _wo_parser_support import ( FakeDynamoResource, wo_handler as handler, wo_persistence as persistence, ) class _ExplodingS3: """Any attribute access is a test failure: the healthcheck branch must return before the handler ever reaches the S3 client.""" def get_object(self, *a, **k): # noqa: N803 raise AssertionError("healthcheck branch touched S3") def test_healthcheck_returns_ok(): assert handler.handler({"healthcheck": True}, None) == {"healthcheck": "ok"} def test_healthcheck_precedes_s3_and_auth(monkeypatch): # If the early-return were missing or misplaced, the handler would call # s3.get_object / authenticate_inbound_email; both are booby-trapped. monkeypatch.setattr(handler, "s3", _ExplodingS3()) # Phase 5: the dynamodb cache lives on persistence.py; handler has no # dynamodb attribute to patch. (s3 stays on handler -- the loop owns it.) monkeypatch.setattr(persistence, "dynamodb", FakeDynamoResource()) def _boom_auth(*a, **k): raise AssertionError("healthcheck branch reached SES auth") monkeypatch.setattr(handler, "authenticate_inbound_email", _boom_auth) assert handler.handler({"healthcheck": True}, None) == {"healthcheck": "ok"} def test_healthcheck_emits_no_metric(monkeypatch): # No EMF / ParseOutcome emission on the healthcheck path. def _boom_metric(*a, **k): raise AssertionError("healthcheck branch emitted a metric") monkeypatch.setattr(handler, "emit_parse_metric", _boom_metric) assert handler.handler({"healthcheck": True}, None) == {"healthcheck": "ok"} def test_healthcheck_only_on_literal_true(): # A truthy-but-not-True value must NOT trigger the branch: it falls through # to the (empty) Records loop and returns the normal 200 envelope. This # keeps the trigger to the exact direct-invoke contract. assert handler.handler({"healthcheck": "yes"}, None) == { "statusCode": 200, "body": "OK", } def test_records_event_ignores_healthcheck_lookalike(): # A real S3 event shape has no top-level healthcheck key; an empty Records # list is processed normally without hitting the early return. assert handler.handler({"Records": []}, None) == { "statusCode": 200, "body": "OK", }