mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-09-30 21:43:14 +00:00
Some checks are pending
Deploy / Deploy to AWS (push) Waiting to run
The .NET API Lambda Function URL uses authType=AWS_IAM, but the four workload Lambdas (suggestions, pdf-extract, pdf-generate, library-ingest) sent unsigned requests with only X-Internal-Api-Key -> every internal call 403s. They also used bare fromAsset() with no pip bundling -> ImportError at cold start. Both made the SQS->Lambda->API pipeline non-functional when deployed (v1 pre-flight). - Add _sign_request_headers (botocore SigV4Auth, service "lambda"); serialize the JSON body once and send via httpx content= so the signed payload hash matches the bytes sent; preserve X-Internal-Api-Key for the app-layer check. Sign per retry attempt to avoid SigV4 timestamp expiry on slow retries. - Add CDK pip bundling (--platform manylinux2014_aarch64 --only-binary=:all:) to all four Lambdas so ARM64 wheels (reportlab, Pillow, pdfplumber) ship. - Converge _retry_request across all four (fixes possibly-undefined return in pdf-extract/pdf-generate). - Add SigV4 signing regression tests. Verified: ruff clean, infra tsc clean, aarch64 wheels resolve for all four, 23 pytest pass. GPT-4.1 cross-family review: no BLOCK (FIX + NIT applied).
23 lines
716 B
Python
23 lines
716 B
Python
"""Test helpers for Lambda tests."""
|
|
|
|
import json
|
|
|
|
|
|
def make_sqs_event(*bodies: dict) -> dict:
|
|
"""Build a minimal SQS event with the given record bodies."""
|
|
records = []
|
|
for i, body in enumerate(bodies):
|
|
records.append(
|
|
{
|
|
"messageId": f"msg-{i}",
|
|
"body": json.dumps(body),
|
|
"receiptHandle": f"handle-{i}",
|
|
"attributes": {},
|
|
"messageAttributes": {},
|
|
"md5OfBody": "",
|
|
"eventSource": "aws:sqs",
|
|
"eventSourceARN": "arn:aws:sqs:us-east-1:123456789012:test-queue",
|
|
"awsRegion": "us-east-1",
|
|
}
|
|
)
|
|
return {"Records": records}
|