Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
16 commits
Select commit Hold shift + click to select a range
2d46c15
NRL-1948 be able to run unit tests without needing to login to aws - …
anjalitrace2-nhs Feb 17, 2026
a0231b1
NRL-1948 choose to use new permissions model if connection-metadata o…
anjalitrace2-nhs Feb 20, 2026
bd86b1f
NRL-1948 Attempt to fetch permissions from new structure. Up next: gi…
anjalitrace2-nhs Feb 20, 2026
b56a845
NRL-1948 Add logging and even more tests
anjalitrace2-nhs Feb 24, 2026
93d6b05
NRL-1948 Remove bad tests for polishing later and replace bad log
anjalitrace2-nhs Feb 25, 2026
e7c8761
NRL-1948 Fix logging and case-sensitive headers
anjalitrace2-nhs Feb 25, 2026
1c876ed
NRL-1948 Remove beefy from aws tests failing for now
anjalitrace2-nhs Feb 25, 2026
b00e987
NRL-1928 Rename new_permissions -> v2_permissions and lookup v2 permi…
anjalitrace2-nhs Feb 27, 2026
e6b8ec8
Merge branch 'develop' into NRL-1948-use-new-permission-model
anjalitrace2-nhs Feb 27, 2026
96e52f0
NRL-1928 Satisfy test coverage with old-style unit test for now
anjalitrace2-nhs Feb 27, 2026
0676227
NRL-1928 Remove unneeded config arg and custom code for testing.
anjalitrace2-nhs Feb 27, 2026
c982ea8
NRL-1928 Spy on logging and more shiny testing
anjalitrace2-nhs Feb 27, 2026
3c6d492
NRL-1948 Renamed logs to better reflect what's being logged and remov…
anjalitrace2-nhs Feb 27, 2026
33daa48
Make metadata test assertions better
anjalitrace2-nhs Mar 2, 2026
1e3af17
NRL-1948 Clean up logs and mock file opens for prettier tests & code
anjalitrace2-nhs Mar 2, 2026
15d1d51
Merge branch 'develop' into NRL-1948-use-new-permission-model
anjalitrace2-nhs Mar 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -109,7 +109,7 @@ publish-ci-image: ## Publish the CI image

test: check-warn ## Run the unit tests
@echo "Running unit tests"
pytest --ignore=tests/smoke $(TEST_ARGS)
PYTHONPATH=. poetry run pytest --ignore tests/smoke $(TEST_ARGS)

test-features-integration: check-warn ## Run the BDD feature tests in the integration environment
@echo "Running feature tests in the integration environment ${TF_WORKSPACE_NAME}"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,9 @@

@mock_aws
@mock_repository
def test_read_document_reference_happy_path(repository: DocumentPointerRepository):
def test_read_document_reference_happy_path(
repository: DocumentPointerRepository,
):
# Create the document pointer
doc_ref = load_document_reference("Y05868-736253002-Valid")
doc_pointer = DocumentPointer.from_document_reference(doc_ref)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,9 @@

@mock_aws
@mock_repository
def test_search_document_reference_happy_path(repository: DocumentPointerRepository):
def test_search_document_reference_happy_path(
repository: DocumentPointerRepository,
):
doc_ref = load_document_reference("Y05868-736253002-Valid")
doc_pointer = DocumentPointer.from_document_reference(doc_ref)
repository.create(doc_pointer)
Expand Down Expand Up @@ -516,7 +518,9 @@ def test_search_document_reference_happy_path_with_nicip_type(

@mock_aws
@mock_repository
def test_search_document_reference_no_results(repository: DocumentPointerRepository):
def test_search_document_reference_no_results(
repository: DocumentPointerRepository,
):
event = create_test_api_gateway_event(
headers=create_headers(),
query_string_parameters={
Expand Down Expand Up @@ -633,7 +637,9 @@ def test_search_document_reference_invalid_nhs_number(

@mock_aws
@mock_repository
def test_search_document_reference_invalid_type(repository: DocumentPointerRepository):
def test_search_document_reference_invalid_type(
repository: DocumentPointerRepository,
):
event = create_test_api_gateway_event(
headers=create_headers(),
query_string_parameters={
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -268,7 +268,9 @@ def test_search_post_document_reference_happy_path_with_multiple_categories(

@mock_aws
@mock_repository
def test_search_document_reference_no_results(repository: DocumentPointerRepository):
def test_search_document_reference_no_results(
repository: DocumentPointerRepository,
):
event = create_test_api_gateway_event(
headers=create_headers(),
body=json.dumps(
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,9 @@
@mock_repository
@freeze_time("2024-03-21T12:34:56.789")
@freeze_uuid("00000000-0000-0000-0000-000000000001")
def test_create_document_reference_happy_path(repository: DocumentPointerRepository):
def test_create_document_reference_happy_path(
repository: DocumentPointerRepository,
):
doc_ref_data = load_document_reference_data("Y05868-736253002-Valid")

event = create_test_api_gateway_event(
Expand Down Expand Up @@ -1610,7 +1612,7 @@ def test_create_document_reference_with_date_and_meta_lastupdated_ignored(
@mock_repository
@freeze_time("2024-03-21T12:34:56.789")
@freeze_uuid("00000000-0000-0000-0000-000000000001")
def test_create_document_reference_with_date_overidden(
def test_create_document_reference_with_date_overridden(
repository: DocumentPointerRepository,
):
doc_ref_data = load_document_reference_data("Y05868-736253002-Valid-with-date")
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,9 @@

@mock_aws
@mock_repository
def test_delete_document_reference_happy_path(repository: DocumentPointerRepository):
def test_delete_document_reference_happy_path(
repository: DocumentPointerRepository,
):
doc_ref = load_document_reference("Y05868-736253002-Valid")
doc_pointer = DocumentPointer.from_document_reference(doc_ref)
repository.create(doc_pointer)
Expand Down Expand Up @@ -131,7 +133,9 @@ def test_delete_document_reference_invalid_producer_id():

@mock_aws
@mock_repository
def test_delete_document_reference_not_exists(repository: DocumentPointerRepository):
def test_delete_document_reference_not_exists(
repository: DocumentPointerRepository,
):
event = create_test_api_gateway_event(
headers=create_headers(), path_parameters={"id": "Y05868-99999-99999-999999"}
)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,9 @@

@mock_aws
@mock_repository
def test_read_document_reference_happy_path(repository: DocumentPointerRepository):
def test_read_document_reference_happy_path(
repository: DocumentPointerRepository,
):
# Create the document pointer
doc_ref = load_document_reference("Y05868-736253002-Valid")
doc_pointer = DocumentPointer.from_document_reference(doc_ref)
Expand Down Expand Up @@ -151,7 +153,9 @@ def test_read_document_reference_incorrect_ods_code():

@mock_aws
@mock_repository
def test_read_document_reference_invalid_json(repository: DocumentPointerRepository):
def test_read_document_reference_invalid_json(
repository: DocumentPointerRepository,
):
doc_ref = load_document_reference("Y05868-736253002-Valid")
doc_pointer = DocumentPointer.from_document_reference(doc_ref)
doc_pointer.document = "invalid json"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,9 @@

@mock_aws
@mock_repository
def test_search_document_reference_happy_path(repository: DocumentPointerRepository):
def test_search_document_reference_happy_path(
repository: DocumentPointerRepository,
):
doc_ref = load_document_reference("Y05868-736253002-Valid")
doc_pointer = DocumentPointer.from_document_reference(doc_ref)
repository.create(doc_pointer)
Expand Down Expand Up @@ -55,7 +57,9 @@ def test_search_document_reference_happy_path(repository: DocumentPointerReposit

@mock_aws
@mock_repository
def test_search_document_reference_no_results(repository: DocumentPointerRepository):
def test_search_document_reference_no_results(
repository: DocumentPointerRepository,
):
event = create_test_api_gateway_event(
headers=create_headers(),
query_string_parameters={
Expand Down Expand Up @@ -168,7 +172,9 @@ def test_search_document_reference_invalid_nhs_number(

@mock_aws
@mock_repository
def test_search_document_reference_invalid_type(repository: DocumentPointerRepository):
def test_search_document_reference_invalid_type(
repository: DocumentPointerRepository,
):
event = create_test_api_gateway_event(
headers=create_headers(),
query_string_parameters={
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,9 @@

@mock_aws
@mock_repository
def test_search_document_reference_happy_path(repository: DocumentPointerRepository):
def test_search_document_reference_happy_path(
repository: DocumentPointerRepository,
):
doc_ref = load_document_reference("Y05868-736253002-Valid")
doc_pointer = DocumentPointer.from_document_reference(doc_ref)
repository.create(doc_pointer)
Expand Down Expand Up @@ -59,7 +61,9 @@ def test_search_document_reference_happy_path(repository: DocumentPointerReposit

@mock_aws
@mock_repository
def test_search_document_reference_no_results(repository: DocumentPointerRepository):
def test_search_document_reference_no_results(
repository: DocumentPointerRepository,
):
event = create_test_api_gateway_event(
headers=create_headers(),
body=json.dumps(
Expand Down Expand Up @@ -171,7 +175,9 @@ def test_search_document_reference_invalid_nhs_number(

@mock_aws
@mock_repository
def test_search_document_reference_invalid_type(repository: DocumentPointerRepository):
def test_search_document_reference_invalid_type(
repository: DocumentPointerRepository,
):
event = create_test_api_gateway_event(
headers=create_headers(),
body=json.dumps(
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,9 @@
@mock_aws
@mock_repository
@freeze_time("2024-03-21T12:34:56.789")
def test_update_document_reference_happy_path(repository: DocumentPointerRepository):
def test_update_document_reference_happy_path(
repository: DocumentPointerRepository,
):
doc_ref = load_document_reference("Y05868-736253002-Valid")
doc_pointer = DocumentPointer.from_document_reference(doc_ref)
repository.create(doc_pointer)
Expand Down Expand Up @@ -629,7 +631,9 @@ def test_update_document_reference_immutable_fields(repository):

@mock_aws
@mock_repository
def test_update_document_reference_cannot_change_status_to_not_current(repository):
def test_update_document_reference_cannot_change_status_to_not_current(
repository,
):
doc_ref = load_document_reference("Y05868-736253002-Valid")
doc_pointer = DocumentPointer.from_document_reference(doc_ref)
repository.create(doc_pointer)
Expand Down Expand Up @@ -677,7 +681,9 @@ def test_update_document_reference_cannot_change_status_to_not_current(repositor

@mock_aws
@mock_repository
def test_update_document_reference_with_no_context_related_for_ssp_url(repository):
def test_update_document_reference_with_no_context_related_for_ssp_url(
repository,
):
doc_ref = load_document_reference("Y05868-736253002-Valid-with-ssp-content")
doc_pointer = DocumentPointer.from_document_reference(doc_ref)
repository.create(doc_pointer)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,9 @@
@mock_aws
@mock_repository
@freeze_time("2024-03-21T12:34:56.789")
def test_upsert_document_reference_happy_path(repository: DocumentPointerRepository):
def test_upsert_document_reference_happy_path(
repository: DocumentPointerRepository,
):
doc_ref_data = load_document_reference_data("Y05868-736253002-Valid")

event = create_test_api_gateway_event(
Expand Down Expand Up @@ -1578,7 +1580,7 @@ def test_upsert_document_reference_with_date_and_meta_lastupdated_ignored(
@mock_aws
@mock_repository
@freeze_time("2024-03-21T12:34:56.789")
def test_upsert_document_reference_with_date_overidden(
def test_upsert_document_reference_with_date_overridden(
repository: DocumentPointerRepository,
):
doc_ref_data = load_document_reference_data("Y05868-736253002-Valid-with-date")
Expand Down
31 changes: 31 additions & 0 deletions layer/nrlf/core/authoriser.py
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
import json
import re
import sys
from os import path

Expand All @@ -10,6 +11,36 @@
from nrlf.core.model import ConnectionMetadata


def get_pointer_permissions_v2(
connection_metadata: ConnectionMetadata,
request_path: str,
):
producer_or_consumer = (
re.search("^/(producer|consumer)/", request_path).group().strip("/")
)

ods_code = connection_metadata.ods_code
app_id = connection_metadata.nrl_app_id

key = f"{producer_or_consumer}/{app_id}/{ods_code}.json"
logger.log(LogReference.V2PERMISSIONS011, key=key)

file_path = f"/opt/python/nrlf_permissions/{key}"

pointer_permissions = {}
try:
with open(file_path) as file:
pointer_permissions = json.load(file)
except Exception as exc:
logger.log(
LogReference.V2PERMISSIONS014,
exc_info=sys.exc_info(),
stacklevel=5,
error=str(exc),
)
return pointer_permissions


def get_pointer_types(
connection_metadata: ConnectionMetadata, config: Config
) -> list[str]:
Expand Down
47 changes: 40 additions & 7 deletions layer/nrlf/core/decorators.py
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,16 @@
from aws_lambda_powertools.utilities.typing import LambdaContext
from pydantic import BaseModel

from nrlf.core.authoriser import get_pointer_types, parse_permissions_file
from nrlf.core.authoriser import (
get_pointer_permissions_v2,
get_pointer_types,
parse_permissions_file,
)
from nrlf.core.codes import SpineErrorConcept
from nrlf.core.config import Config
from nrlf.core.constants import (
CLIENT_RP_DETAILS,
CONNECTION_METADATA,
NHSD_CORRELATION_ID_HEADER,
PERMISSION_ALLOW_ALL_POINTER_TYPES,
X_CORRELATION_ID_HEADER,
Expand Down Expand Up @@ -137,12 +143,39 @@ def wrapper(*args, **kwargs) -> Dict[str, Any]:
RepositoryType = Union[Type[DocumentPointerRepository], None]


def load_connection_metadata(headers: Dict[str, str], config: Config):
logger.log(LogReference.HANDLER002, headers=headers)
metadata = parse_headers(headers)
logger.log(LogReference.HANDLER003, metadata=metadata.model_dump())
def _use_v2_permissions_model(headers: Dict[str, str]) -> bool:
case_insensitive_headers = {key.lower(): value for key, value in headers.items()}
# if either or both headers are missing
return (
CLIENT_RP_DETAILS not in case_insensitive_headers.keys()
or CONNECTION_METADATA not in case_insensitive_headers.keys()
)


def _load_v2_connection_metadata(headers: Dict[str, str], path: str):
logger.log(LogReference.HANDLER004d)
metadata = parse_headers(headers, use_v2_permissions=True)

logger.log(LogReference.HANDLER004e)
pointer_permissions = get_pointer_permissions_v2(metadata, path)

metadata.pointer_types = pointer_permissions.get("types", [])

logger.log(
LogReference.HANDLER004f, pointer_types=metadata.pointer_types
) # TODO: log other permissions as they're added

return metadata


def load_connection_metadata(headers: Dict[str, str], config: Config, path=""):

if _use_v2_permissions_model(headers):
return _load_v2_connection_metadata(headers, path)

metadata = parse_headers(headers, use_v2_permissions=False)
if PERMISSION_ALLOW_ALL_POINTER_TYPES in metadata.nrl_permissions:
logger.log(LogReference.HANDLER004a)
logger.log(LogReference.HANDLER004b)
metadata.pointer_types = PointerTypes.list()
return metadata

Expand Down Expand Up @@ -262,7 +295,7 @@ def wrapper(event: APIGatewayProxyEvent, context: LambdaContext, **kwargs):

config = Config()
logger.log(LogReference.HANDLER001, config=config.model_dump())
metadata = load_connection_metadata(event.headers, config)
metadata = load_connection_metadata(event.headers, config, event.path)

if metadata.pointer_types == []:
logger.log(
Expand Down
Loading