mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 08:23:12 +00:00
The rejection message now lists every type the media allowlist accepts, and a test fails if the message and the allowlist drift apart.
40 lines
1.4 KiB
Bash
Executable file
40 lines
1.4 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
#
|
|
# Validate the exact Elastic Beanstalk bundle that a release will upload.
|
|
set -euo pipefail
|
|
|
|
BUNDLE="${1:-.artifacts/elastic-beanstalk/site.zip}"
|
|
|
|
die() {
|
|
printf 'ERR %s\n' "$1" >&2
|
|
exit 1
|
|
}
|
|
|
|
[[ -f "$BUNDLE" ]] || die "bundle does not exist: $BUNDLE"
|
|
[[ "$BUNDLE" == *.zip ]] || die "bundle must be a .zip file"
|
|
|
|
contents_file="$(mktemp)"
|
|
webhook_file="$(mktemp)"
|
|
nginx_file="$(mktemp)"
|
|
trap 'rm -f "$contents_file" "$webhook_file" "$nginx_file"' EXIT
|
|
|
|
unzip -tq "$BUNDLE"
|
|
unzip -Z1 "$BUNDLE" > "$contents_file"
|
|
grep -Fxq "efbundle" "$contents_file"
|
|
grep -Fxq ".ebextensions/01_migrations.config" "$contents_file"
|
|
grep -Fxq ".ebextensions/02_webhook_config.config" "$contents_file"
|
|
grep -Fxq ".platform/nginx/conf.d/01_upload_body_size.conf" "$contents_file"
|
|
|
|
unzip -p "$BUNDLE" .ebextensions/02_webhook_config.config > "$webhook_file"
|
|
grep -Fxq ' WorkOrderWebhook__Enabled: "true"' "$webhook_file"
|
|
grep -Fxq ' WorkOrderWebhook__Region: us-east-1' "$webhook_file"
|
|
grep -Fxq \
|
|
' WorkOrderWebhook__SecretId: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB' \
|
|
"$webhook_file"
|
|
|
|
# Without this override the platform nginx caps request bodies at 1 MB.
|
|
unzip -p "$BUNDLE" .platform/nginx/conf.d/01_upload_body_size.conf > "$nginx_file"
|
|
grep -Fxq 'client_max_body_size 120M;' "$nginx_file"
|
|
|
|
printf 'PASS: Elastic Beanstalk bundle contract (%s bytes)\n' \
|
|
"$(wc -c < "$BUNDLE" | tr -d ' ')"
|