diff --git a/.github/workflows/deploy_infra.yml b/.github/workflows/deploy_infra.yml index b5691d9..6db2dec 100644 --- a/.github/workflows/deploy_infra.yml +++ b/.github/workflows/deploy_infra.yml @@ -24,20 +24,21 @@ jobs: run: | echo "ENV_NAME=${{ github.event.inputs.env_name }}" >> $GITHUB_ENV echo "ENV_REGION=${{ github.event.inputs.env_region }}" >> $GITHUB_ENV - - uses: actions/checkout@v3 + - uses: actions/checkout@v5 with: fetch-depth: 0 - name: Configure aws credentials - uses: aws-actions/configure-aws-credentials@v2 + uses: aws-actions/configure-aws-credentials@v5.1.1 with: aws-region: ${{ env.ENV_REGION }} role-to-assume: arn:aws:iam::193347341732:role/GithubActionsRole - name: Set up Python 3.10 - uses: actions/setup-python@v4 + uses: actions/setup-python@v6 with: # Needs to be the same version as the execution environment of AWS Lambda, to make sure we download the correct dependencies - python-version: "3.10" + python-version: "3.13" + - uses: hashicorp/setup-terraform@v3 - name: Run Terraform run: | cd terraform/envs/${{ env.ENV_NAME }} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 76639de..a5af5c5 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -8,11 +8,11 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 - - name: Set up Python 3.10 - uses: actions/setup-python@v4 + - uses: actions/checkout@v5 + - name: Set up Python 3.13 + uses: actions/setup-python@v6 with: - python-version: "3.10" + python-version: "3.13" - name: Update pip run: | python -m pip install --upgrade pip @@ -35,22 +35,26 @@ jobs: services: motoserver: + env: + # Default LambdaImage providers (lambci, mlupin) do not support Python 3.13 + MOTO_DOCKER_LAMBDA_IMAGE: shogo82148/lambda-python:3.13 image: ghcr.io/getmoto/motoserver:latest ports: - 5000:5000 steps: - - uses: actions/checkout@v3 - - name: Set up Python 3.10 - uses: actions/setup-python@v4 + - uses: actions/checkout@v5 + - name: Set up Python 3.13 + uses: actions/setup-python@v6 with: - python-version: "3.10" + python-version: "3.13" - name: Update pip run: | python -m pip install --upgrade pip - name: Install project dependencies run: | pip install -r backend/requirements.txt + - uses: hashicorp/setup-terraform@v3 - name: Run TF run: | mkdir ~/.aws && touch ~/.aws/credentials && echo -e "[default]\naws_access_key_id = test\naws_secret_access_key = test" > ~/.aws/credentials diff --git a/integration_tests/test_admin_area.py b/integration_tests/test_admin_area.py index e970308..8fc7a62 100644 --- a/integration_tests/test_admin_area.py +++ b/integration_tests/test_admin_area.py @@ -147,14 +147,12 @@ def test_get_finance_data(self): mock_http.return_value.data = json.dumps(OPEN_COLLECTIVE_RESPONSE).encode("utf-8") resp = admin_area.lambda_handler(admin_get_finance, context=None) - assert resp == { - "finance": {'effective_balance': '$10.00', 'oc_balance': "$50.00", 'outstanding': '$40.00'}, - "payments": [ - {'amount': '$25.00', 'date_created': '20230607181200', 'username': 'a1'}, - {'date_created': 'b2', 'processed': 'yes', 'username': 'a2'}, - {'amount': '$5.00', 'date_created': '20230607181200', 'username': 'a2'}, - {'amount': '$10.00', 'date_created': '20230607191200', 'details': 'money for reasons', 'username': 'a2'}] - } + assert resp["finance"] == {'effective_balance': '$10.00', 'oc_balance': "$50.00", 'outstanding': '$40.00'} + assert len(resp["payments"]) == 4 + assert {'amount': '$25.00', 'date_created': '20230607181200', 'username': 'a1'} in resp["payments"] + assert {'date_created': 'b2', 'processed': 'yes', 'username': 'a2'} in resp["payments"] + assert {'amount': '$5.00', 'date_created': '20230607181200', 'username': 'a2'} in resp["payments"] + assert {'amount': '$10.00', 'date_created': '20230607191200', 'details': 'money for reasons', 'username': 'a2'} in resp["payments"] def test_get_contributors(self): assert admin_area.github_token is None diff --git a/terraform/envs/dev/main.tf b/terraform/envs/dev/main.tf index 4363bc5..5a49385 100644 --- a/terraform/envs/dev/main.tf +++ b/terraform/envs/dev/main.tf @@ -2,7 +2,7 @@ terraform { required_providers { aws = { source = "hashicorp/aws" - version = "~> 4.16" + version = "~> 6.0" #configuration_aliases = [ aws.useast1 ] } } diff --git a/terraform/envs/prod/main.tf b/terraform/envs/prod/main.tf index b609cac..c83212b 100644 --- a/terraform/envs/prod/main.tf +++ b/terraform/envs/prod/main.tf @@ -2,7 +2,7 @@ terraform { required_providers { aws = { source = "hashicorp/aws" - version = "~> 4.16" + version = "~> 6.0" } } diff --git a/terraform/envs/test/main.tf b/terraform/envs/test/main.tf index 8687ce7..fb32535 100644 --- a/terraform/envs/test/main.tf +++ b/terraform/envs/test/main.tf @@ -2,7 +2,7 @@ terraform { required_providers { aws = { source = "hashicorp/aws" - version = "~> 4.16" + version = "~> 6.0" } } diff --git a/terraform/envs/test/provider.tf b/terraform/envs/test/provider.tf index d8cf11b..a69f9f8 100644 --- a/terraform/envs/test/provider.tf +++ b/terraform/envs/test/provider.tf @@ -6,7 +6,6 @@ provider "aws" { secret_key = "mock_secret_key" skip_credentials_validation = true skip_metadata_api_check = true - skip_requesting_account_id = true s3_use_path_style = true endpoints { @@ -22,6 +21,7 @@ provider "aws" { logs = "http://localhost:5000" route53 = "http://localhost:5000" s3 = "http://localhost:5000" + s3control = "http://localhost:5000" ssm = "http://localhost:5000" sts = "http://localhost:5000" } diff --git a/terraform/modules/infra/cloudfront.tf b/terraform/modules/infra/cloudfront.tf index 6d01be2..b2305b7 100644 --- a/terraform/modules/infra/cloudfront.tf +++ b/terraform/modules/infra/cloudfront.tf @@ -19,7 +19,7 @@ resource "aws_cloudfront_distribution" "website-cloudfront" { } origin { - domain_name = "${aws_apigatewayv2_api.payments-api.id}.execute-api.${data.aws_region.current.name}.amazonaws.com" + domain_name = "${aws_apigatewayv2_api.payments-api.id}.execute-api.${data.aws_region.current.region}.amazonaws.com" origin_id = local.apigw_origin_id custom_origin_config { http_port = "80" diff --git a/terraform/modules/infra/functions.tf b/terraform/modules/infra/functions.tf index 6b6f618..e60d562 100644 --- a/terraform/modules/infra/functions.tf +++ b/terraform/modules/infra/functions.tf @@ -10,7 +10,7 @@ variable "repo_owner_name" { resource "null_resource" "install_jwt_dependencies" { provisioner "local-exec" { - command = "pip install --platform manylinux2010_x86_64 --implementation cp --only-binary=:all: --upgrade --target ${var.lambda_root}/jwt_dependencies/python jwt cryptography" + command = "pip install --platform manylinux2014_x86_64 --implementation cp --only-binary=:all: --upgrade --target ${var.lambda_root}/jwt_dependencies/python jwt" } triggers = { @@ -152,7 +152,7 @@ resource "aws_lambda_function" "lambda_function_load_pr_info" { timeout = 60 environment { variables = { - REGION = data.aws_region.current.name + REGION = data.aws_region.current.region PR_TABLE_NAME = aws_dynamodb_table.pull-requests.name SCRIPT_INFO_TABLE_NAME = aws_dynamodb_table.script-execution-info.name REPO_OWNER_NAME = var.repo_owner_name @@ -222,7 +222,7 @@ resource "aws_lambda_function" "lambda_function_auth" { depends_on = [aws_cloudwatch_log_group.lambda_auth] environment { variables = { - REGION = data.aws_region.current.name + REGION = data.aws_region.current.region DOMAIN_NAME = var.domain REPO_OWNER_NAME = var.repo_owner_name } @@ -268,7 +268,7 @@ resource "aws_lambda_function" "lambda_function_user_area" { depends_on = [aws_cloudwatch_log_group.lambda_user_area] environment { variables = { - REGION = data.aws_region.current.name + REGION = data.aws_region.current.region REPO_OWNER_NAME = var.repo_owner_name } } @@ -349,7 +349,7 @@ resource "aws_lambda_function" "lambda_function_admin_area" { layers = [aws_lambda_layer_version.jwt_layer.arn] environment { variables = { - REGION = data.aws_region.current.name + REGION = data.aws_region.current.region REPO_OWNER_NAME = var.repo_owner_name } } diff --git a/terraform/modules/infra/main.tf b/terraform/modules/infra/main.tf index 02412f4..efeee75 100644 --- a/terraform/modules/infra/main.tf +++ b/terraform/modules/infra/main.tf @@ -2,7 +2,7 @@ terraform { required_providers { aws = { source = "hashicorp/aws" - version = "~> 4.16" + version = "~> 6.0" configuration_aliases = [ aws.useast1 ] } } diff --git a/tests/requirements.txt b/tests/requirements.txt index a790335..75021a7 100644 --- a/tests/requirements.txt +++ b/tests/requirements.txt @@ -1,4 +1,5 @@ moto +jwt pytest pytest-cov coverage \ No newline at end of file diff --git a/tests/test_admin_authentication.py b/tests/test_admin_authentication.py index 85eab05..20d6bc1 100644 --- a/tests/test_admin_authentication.py +++ b/tests/test_admin_authentication.py @@ -2,14 +2,13 @@ import copy import json -from moto import mock_dynamodb, mock_ssm +from moto import mock_aws from unittest.mock import patch, Mock from .api_events import github_user_response from .api_events import api_admin_finance_event, api_status_event -@mock_dynamodb -@mock_ssm +@mock_aws class TestAuthentication: @patch.dict("os.environ", {"REGION": "us-east-1"}) diff --git a/tests/test_authentication.py b/tests/test_authentication.py index e48e1fa..a9d3788 100644 --- a/tests/test_authentication.py +++ b/tests/test_authentication.py @@ -3,15 +3,14 @@ import json from base64 import b64decode -from moto import mock_dynamodb, mock_ssm +from moto import mock_aws from unittest.mock import patch, Mock from .api_events import api_login_event, api_pr_info_event, github_user_response from .api_events import api_status_event from .api_events import github_bad_credentials -@mock_dynamodb -@mock_ssm +@mock_aws class TestAuthentication: @patch.dict("os.environ", {"REGION": "us-east-1"}) diff --git a/tests/test_github_bot.py b/tests/test_github_bot.py index b065945..1c9b3b7 100644 --- a/tests/test_github_bot.py +++ b/tests/test_github_bot.py @@ -1,7 +1,7 @@ import boto3 import jwt import json -from moto import mock_ssm +from moto import mock_aws from unittest.mock import patch, Mock from uuid import uuid4 @@ -11,7 +11,7 @@ from cryptography.hazmat.backends import default_backend -@mock_ssm +@mock_aws class TestAuthentication: @patch.dict("os.environ", {"REGION": "us-east-1", "REPO_OWNER_NAME": "owner/repo"})