mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 06:03:14 +00:00
Some checks are pending
Deploy / deploy (push) Waiting to run
* feat(api): add procurement-api stack - read API + OpenAPI docs page Third CDK stack: API Gateway REST API (IAM SigV4) over both pipelines' tables, replacing SHOC's retired SyncController cross-account DynamoDB scan as the reconciliation/backfill path. - lambdas/api/: handler (healthcheck + docs-token gate + router dispatch), router (single route table), pagination (opaque cursor, hostile -> 400), Decimal-safe serialization, wo_repo/po_repo reads. No VendorReplies. - OpenAPI 3.1 spec as source of truth incl. top-level webhooks section documenting the outbound SHOC feed; phase-2 write endpoints x-planned (router answers 501). Self-contained /docs page, no CDN. - Auth: AWS_IAM on data routes + resource policy scoped to exactly arn:aws:iam::396287094661:role/shoc-backend-dev on GET/*; /docs and /openapi.json carve-out is token-gated in the Lambda via shared web_ui_auth (fail-closed, INFRA-74 posture). - KMS: explicit Decrypt/DescribeKey on the DynamoDB CMK from SSM (name-imported table drops the key association - INFRA-104 class). - Alarms: errors/throttles/duration(p99>=22.5s) + gateway 5xx, ALARM-only to site-alerts. No access logging in v1 (docs ?token= shim stays out of logs); cloud_watch_role=False. - Tests: handler auth-seam + routing + Decimal round-trip; moto cursor pagination incl. hostile cursors; spec<->router drift gate; bundle AST pins for the api command; pytest.ini --cov + loader siblings. - Deploy role: third stack DescribeStacks ARN + procurement-api smoke invoke ARN (re-run create-deploy-role.sh before merge). * harden(api): apply sh-security-review findings to procurement-api Fan-out (6 detectors) + review findings resolved: Correctness / DoS: - pagination: require EXACT key-set match (was subset) so a partial/foreign composite cursor can't reach DynamoDB as an inconsistent ExclusiveStartKey -> ValidationException -> 500; comments Query now pins the cursor's work_order_id to the path entity. - handler: map botocore ValidationException to 400 (defense in depth) so a crafted cursor can't drive the zero-threshold 5xx alarm. - web_ui_auth: compare tokens as bytes; a non-ASCII presented token now fails closed (401) instead of crashing hmac.compare_digest into a 500. Resolves the pre-existing xfail(strict) follow-up test; hardens the web UIs too. Docs page: - typeStr() now escapes the one spec-derived string that reached innerHTML. - spec inlined into the docs <script> block escapes "<" -> < (</script> breakout guard); /openapi.json still served byte-faithful. - Cache-Control: no-store + Referrer-Policy: no-referrer on docs responses so the ?token= URL stays out of caches/Referer. - spec-drift test asserts the committed spec carries no "</" / "<!--". IAM / IaC: - resource policy enumerates the 7 data GET resources instead of GET/* so a future GET route can't silently inherit SHOC cross-account reach. - kms:Decrypt grant gains a kms:ViaService=dynamodb condition. - stage throttling (50 rps / 100 burst) bounds the unauthenticated /docs blast radius below the 10k account default. - corrected the PATCH/POST comment (same-account callers aren't blocked by the resource policy; 501 handler + absent write grant are the gate). - documented the RETAIN log-group first-deploy rollback trap and the resource-policy-needs-redeploy gotcha in-stack. Mandatory GPT-4.1 cross-family review of the full policy surface: no BLOCK/FIX. 675 tests pass, ruff clean, cdk synth green.
149 lines
7 KiB
Python
149 lines
7 KiB
Python
"""The ONE Lambda-module loader for the whole procurement-ingest test suite.
|
|
|
|
Every test root (the repo-root ``tests/`` suite AND the two per-pipeline
|
|
``lambdas/*/email_processor/tests`` suites) loads Lambda modules through this
|
|
single ``load_lambda_module`` -- there is exactly one copy of the sys.modules
|
|
save/restore dance in the repo, and the repo-root ``conftest.py`` re-exports it.
|
|
|
|
``from conftest import ...`` is deliberately NOT used: three ``conftest.py``
|
|
files exist across the roots and pytest's per-directory sys.path prepending
|
|
makes the bare name ``conftest`` resolve nondeterministically -- exactly the
|
|
bare-name-collision class this phase eliminates. The loader lives here instead,
|
|
imported the same way from every invocation directory as ``tests.support``.
|
|
"""
|
|
|
|
import importlib.util
|
|
import sys
|
|
from pathlib import Path
|
|
|
|
REPO_ROOT = Path(__file__).resolve().parents[2]
|
|
_SHARED_DIR = REPO_ROOT / "lambdas" / "shared"
|
|
|
|
|
|
# Sibling modules imported by bare name from the handlers (the Lambda runtime
|
|
# puts each function's own directory on sys.path; the CDK bundling then cp's the
|
|
# shared modules in flat beside handler.py so those bare imports resolve too).
|
|
# template_parser/derived_fields are duplicated PER PIPELINE, so their bare
|
|
# names MUST be bound to the right pipeline's file around each handler exec --
|
|
# relying on sys.path ordering (or on whatever a previously collected suite left
|
|
# in sys.modules) silently binds a handler to the OTHER pipeline's sibling.
|
|
# ses_auth/email_parsing/emf/web_ui_auth are now single-sourced under
|
|
# lambdas/shared/ (Phase 3); the loop below resolves them from there via a
|
|
# shared-dir fallback.
|
|
#
|
|
# Phase 5 decomposed each God-handler into flat siblings (prompts/telemetry/
|
|
# extraction/enrichment/persistence). The order below is DEPENDENCY-TOPOLOGICAL,
|
|
# not alphabetical: the loader binds each bare name in sys.modules right after
|
|
# exec'ing it, so a sibling whose module body does `from <x> import ...` must
|
|
# appear AFTER <x> here or its exec ImportErrors. The load-bearing edges are
|
|
# emf < telemetry, prompts < extraction, and derived_fields + telemetry <
|
|
# enrichment. WO has no enrichment/derived_fields sibling -- the loader's
|
|
# `if not sibling_path.exists(): continue` silently skips them there, so one
|
|
# unified tuple serves both pipelines.
|
|
#
|
|
# web_ui_auth was added (no dependencies; after emf) so
|
|
# load_lambda_module("po"|"wo", "web_ui/handler") can bind the web_ui handlers'
|
|
# bare `from web_ui_auth import is_authenticated` (lambdas/po/web_ui/handler.py:15
|
|
# and the wo equivalent) via the same shared-dir fallback.
|
|
_SIBLING_MODULES = (
|
|
"ses_auth",
|
|
"email_parsing",
|
|
"emf",
|
|
"web_ui_auth",
|
|
# procurement-api siblings (lambdas/api/): pagination/serialization/router
|
|
# have no sibling deps; wo_repo/po_repo import pagination, so they follow
|
|
# it. These names exist only under lambdas/api/, so the po/wo handler
|
|
# loads skip them via the exists() check.
|
|
"pagination",
|
|
"serialization",
|
|
"router",
|
|
"wo_repo",
|
|
"po_repo",
|
|
"prompts",
|
|
"template_parser",
|
|
"derived_fields",
|
|
"telemetry",
|
|
"extraction",
|
|
"enrichment",
|
|
"persistence",
|
|
)
|
|
|
|
|
|
def _load_module(path, module_name):
|
|
if module_name in sys.modules:
|
|
return sys.modules[module_name]
|
|
spec = importlib.util.spec_from_file_location(module_name, path)
|
|
module = importlib.util.module_from_spec(spec)
|
|
sys.modules[module_name] = module
|
|
spec.loader.exec_module(module)
|
|
return module
|
|
|
|
|
|
def load_lambda_module(pipeline, name):
|
|
"""Load a Lambda module by file path under a unique, deterministic name.
|
|
|
|
``pipeline`` is one of ``{"po", "wo", "shared"}`` and ``name`` is the path
|
|
under ``lambdas/<pipeline>/`` without the ``.py`` suffix (e.g.
|
|
``"email_processor/handler"``, ``"web_ui/handler"``, or ``"ses_auth"`` for
|
|
shared). The module name is ``f"{pipeline}_{name.replace('/', '_')}"`` --
|
|
this reproduces the existing unique names byte-for-byte
|
|
(``po_email_processor_handler``, ``wo_email_processor_handler``,
|
|
``shared_ses_auth``), so every existing ``sys.modules`` sibling key
|
|
(``po_email_processor_handler__persistence`` etc.) is unchanged.
|
|
|
|
The handler files all share the basename ``handler.py`` and are not
|
|
importable as packages, so a plain ``import handler`` would collide across
|
|
Lambdas. The same loader serves leaf modules (``ses_auth.py``,
|
|
``web_ui_auth.py``), which are likewise loaded by file path.
|
|
|
|
Handler modules import their siblings by bare name (e.g. ``from
|
|
template_parser import try_deterministic_parse``). Each sibling is loaded
|
|
from the handler's own directory (falling back to ``lambdas/shared/``) under
|
|
a unique module name and registered under its bare name only for the
|
|
duration of the handler exec, then the previous binding is restored -- so
|
|
this loader is deterministic regardless of collection order and of what the
|
|
per-Lambda test suites (which put their own module dir on sys.path) have
|
|
already cached in sys.modules.
|
|
|
|
The save/restore dance does NOT shrink to nothing: template_parser (and
|
|
derived_fields/prompts/telemetry/extraction/enrichment/persistence) remain
|
|
duplicated bare names ACROSS pipelines. One pytest session execs BOTH
|
|
handlers; without per-exec bare-name binding + restore, whichever pipeline
|
|
loads second silently binds to the first pipeline's sibling. Only
|
|
ses_auth/email_parsing/emf/web_ui_auth are single-sourced.
|
|
"""
|
|
path = REPO_ROOT / "lambdas" / pipeline / f"{name}.py"
|
|
module_name = f"{pipeline}_{name.replace('/', '_')}"
|
|
if module_name in sys.modules:
|
|
return sys.modules[module_name]
|
|
# Keep the handler dir on sys.path for parity with the Lambda runtime.
|
|
handler_dir = str(path.parent)
|
|
if handler_dir not in sys.path:
|
|
sys.path.insert(0, handler_dir)
|
|
if path.name != "handler.py":
|
|
# Leaf modules (e.g. ses_auth.py / web_ui_auth.py) have no sibling
|
|
# imports of the per-pipeline kind the dance guards.
|
|
return _load_module(path, module_name)
|
|
saved = {}
|
|
for sibling in _SIBLING_MODULES:
|
|
# Per-pipeline siblings (template_parser/derived_fields/...) resolve next
|
|
# to the handler; the shared, single-sourced siblings (ses_auth/
|
|
# email_parsing/emf/web_ui_auth) fall back to lambdas/shared/. No
|
|
# ambiguity: post Phase 3 the shared names exist ONLY under shared/, the
|
|
# per-pipeline names ONLY next to the handler.
|
|
sibling_path = path.parent / f"{sibling}.py"
|
|
if not sibling_path.exists():
|
|
sibling_path = _SHARED_DIR / f"{sibling}.py"
|
|
if not sibling_path.exists():
|
|
continue
|
|
saved[sibling] = sys.modules.get(sibling)
|
|
sys.modules[sibling] = _load_module(sibling_path, f"{module_name}__{sibling}")
|
|
try:
|
|
module = _load_module(path, module_name)
|
|
finally:
|
|
for sibling, previous in saved.items():
|
|
if previous is not None:
|
|
sys.modules[sibling] = previous
|
|
else:
|
|
sys.modules.pop(sibling, None)
|
|
return module
|