procurement-ingest/lambdas/po/email_processor/tests/test_po_healthcheck.py
Adam Moussa cb5539bd68
Some checks are pending
Deploy / deploy (push) Waiting to run
feat: deploy-pipeline guards — healthcheck, smoke gate, bundle glob + AST test (refactor phase 0) (#107)
* feat: deploy-pipeline guards — healthcheck, smoke gate, bundle glob + AST test (refactor phase 0)

Deploys of po-email-processor and workorder-email-processor had no
verification step, so an init-time ImportError in the bundled zip
could ship silently and only surface on the next real S3 event. This
adds a synchronous post-deploy smoke gate wired into the deploy
workflow: both Lambdas are invoked with {"healthcheck": true} and the
FunctionError field is checked, since an Unhandled init error still
returns HTTP 200 on RequestResponse invokes and would false-pass a
plain exit-code check.

The healthcheck branch is the first statement in each handler, before
any boto3/S3 use or ses_auth, and only fires on a top-level direct
invoke ("healthcheck" is not a key AWS ever sets on a real S3
ObjectCreated event, so mail content can't reach this path). It emits
no EMF metrics and no log text that could match the
sender-auth-rejected metric filter, so two deploys in one window
won't trip the alarm.

Separately, the PO stack's asset bundling copied a hand-maintained
four-file allowlist into the zip, so every new sibling module
handler.py imports had to be added by hand or the deploy shipped a
Lambda that ImportErrors at cold start (bit us for template_parser in
PR #105 and nearly for derived_fields in PR #2). Replaced it with a
non-recursive ./*.py glob so top-level source files ship
automatically while tests/ and the stale package/ dir still cannot,
and added an AST-based bundle-consistency test that parses each
handler's first-party imports and fails CI if the bundling command
would omit any of them (a revert to an incomplete allowlist, or code
moved into a subdirectory the glob doesn't cover).

Includes the refactor-evaluation report that scoped this phase.

* fix: review nits — unambiguous bundling-command extraction, smoke payload-parse message, dead asserts

- tests/test_bundle_consistency.py: _extract_bundling_command now collects
  all command=[...] matches and demands exactly one per stack file, instead
  of silently returning whichever ast.walk visits first if a second bundled
  function is ever added.
- scripts/post-deploy-smoke.sh: distinguish an unparseable response payload
  from a payload mismatch so the failure message says what actually happened
  (the previous "could not parse" branch was unreachable — the inline python
  always exited 0).
- test_po_healthcheck.py: drop the substring assertions on stdout that were
  dead behind the stricter `captured.out == ""` assertion; keep the stderr
  filter-pattern check.

Review follow-up on PR #107; no behavior change to any shipped code path.
2026-07-17 13:18:45 -04:00

172 lines
6.5 KiB
Python

"""Direct-invoke healthcheck early-return tests for the PO handler.
The post-deploy smoke script invokes the Lambda synchronously with
``{"healthcheck": true}`` and asserts the response is ``{"healthcheck": "ok"}``.
That branch is pinned to run as the VERY FIRST thing handler() does -- before
any S3 fetch, before ses_auth, before the Records loop -- so it neither creates
an accept path for mail nor emits any EMF metric / log line that could trip the
``sender_auth_rejected`` substring metric-filter alarm on a deploy.
These tests import ``po_handler`` from ``_po_parser_support`` (moto imported
first, PO modules loaded by file path under unique names) exactly like the rest
of the PO suite, preserving the moto-before-handler import ordering.
"""
import pytest
from _po_parser_support import load_raw, po_handler
class _ExplodingS3:
"""Any S3 access from the healthcheck path is a contract violation."""
def get_object(self, **kwargs): # noqa: N803
raise AssertionError(f"healthcheck must not touch S3: {kwargs}")
def _exploding_auth(*args, **kwargs):
raise AssertionError("healthcheck must not call ses_auth")
def _exploding_metric(*args, **kwargs):
raise AssertionError("healthcheck must not emit any parse metric")
# --- (1) healthcheck early-return: ok payload, zero side effects ---
def test_healthcheck_returns_ok_with_zero_side_effects(
fake_dynamo, monkeypatch, capsys
):
monkeypatch.setattr(po_handler, "s3", _ExplodingS3())
monkeypatch.setattr(po_handler, "authenticate_inbound_email", _exploding_auth)
monkeypatch.setattr(po_handler, "_emit_parse_method_metric", _exploding_metric)
monkeypatch.setattr(po_handler, "_emit_derived_agreement_metric", _exploding_metric)
result = po_handler.handler({"healthcheck": True}, None)
assert result == {"healthcheck": "ok"}
# ZERO DynamoDB writes: no table was ever fetched/updated.
assert fake_dynamo.tables == {}
# ZERO EMF metric emission: EMF records go to stdout via print(); the branch
# must not have printed anything the sender_auth_rejected filter could match.
# (Empty stdout subsumes any substring check on it; stderr is checked for
# the filter pattern specifically.)
captured = capsys.readouterr()
assert captured.out == ""
assert "sender_auth_rejected" not in captured.err
def test_healthcheck_branch_precedes_records_key_lookup(monkeypatch):
"""The healthcheck return fires even when a hostile payload also carries a
top-level ``Records`` key: the branch is ordered before the loop, and the
exploding S3/auth prove the loop body never runs."""
monkeypatch.setattr(po_handler, "s3", _ExplodingS3())
monkeypatch.setattr(po_handler, "authenticate_inbound_email", _exploding_auth)
event = {
"healthcheck": True,
"Records": [
{"s3": {"bucket": {"name": "b"}, "object": {"key": "k"}}},
],
}
assert po_handler.handler(event, None) == {"healthcheck": "ok"}
@pytest.mark.parametrize(
"event",
[
{"healthcheck": False},
{"healthcheck": "true"},
{"healthcheck": 1},
{"healthcheck": {"nested": True}},
{"Healthcheck": True}, # wrong case: not the contract key
{},
],
)
def test_non_healthcheck_payloads_do_not_early_return(event):
"""Only a top-level ``healthcheck`` that is exactly ``True`` takes the
branch; anything else falls through to the (empty) Records loop and returns
the normal 200 body."""
assert po_handler.handler(event, None) == {"statusCode": 200, "body": "OK"}
# --- (2) a normal S3 mail event is completely unaffected ---
class _RecordingS3:
def __init__(self, raw):
self._raw = raw
self.calls = []
def get_object(self, Bucket, Key): # noqa: N803
self.calls.append((Bucket, Key))
class _Body:
def __init__(self, data):
self._data = data
def read(self):
return self._data
return {"Body": _Body(self._raw)}
def _s3_event():
return {
"Records": [
{
"s3": {
"bucket": {"name": "po-ingest-emails-x"},
"object": {"key": "inbound/hc"},
}
}
]
}
def test_normal_mail_event_still_processed(fake_dynamo, monkeypatch):
"""Golden-path guard: a real S3 ObjectCreated mail event is unaffected by
the healthcheck branch -- it still fetches from S3 and upserts the PO."""
recording = _RecordingS3(load_raw("new-po", "new-po-01"))
monkeypatch.setattr(po_handler, "s3", recording)
monkeypatch.setattr(po_handler, "authenticate_inbound_email", lambda *a: True)
result = po_handler.handler(_s3_event(), None)
assert result == {"statusCode": 200, "body": "OK"}
# The branch was NOT taken: S3 was fetched and the PO was written through.
assert recording.calls == [("po-ingest-emails-x", "inbound/hc")]
assert fake_dynamo.tables[po_handler.PO_TABLE].updates
def test_healthcheck_string_in_email_body_does_not_take_branch(
fake_dynamo, monkeypatch
):
"""A mail event whose EMAIL BODY contains the string 'healthcheck' must NOT
trigger the early return: the trigger is a top-level direct-invoke key that
AWS controls, and email content can never set a top-level event key. Proof:
S3 is still fetched (the branch would have skipped it)."""
raw_email = (
b"From: buyer@amazon.coupahost.com\r\n"
b"To: po@seahavenind.com\r\n"
b"Subject: FYI healthcheck notes\r\n"
b"\r\n"
b"Please run a healthcheck on this order. healthcheck healthcheck.\r\n"
)
recording = _RecordingS3(raw_email)
monkeypatch.setattr(po_handler, "s3", recording)
monkeypatch.setattr(po_handler, "authenticate_inbound_email", lambda *a: True)
# The synthetic body has no Coupa template match, so parsing would fall to
# the Bedrock extractor; stub it (returning no po_number) so the record is
# skipped cleanly. What matters here is only that S3 WAS fetched -- i.e. the
# healthcheck branch did not short-circuit on the body text.
monkeypatch.setattr(po_handler, "extract_with_claude", lambda *a: {})
result = po_handler.handler(_s3_event(), None)
# Fell through to the Records loop (no early return): S3 WAS fetched. The
# synthetic body has no PO number, so it is skipped -- return is the normal
# 200 body, never the {"healthcheck": "ok"} smoke payload.
assert result == {"statusCode": 200, "body": "OK"}
assert recording.calls == [("po-ingest-emails-x", "inbound/hc")]