from pathlib import Path from scripts.source_lookup import find_block def _write(path: Path, body: str) -> None: path.parent.mkdir(parents=True, exist_ok=True) path.write_text(body) def test_review_context_collects_variables_and_locals(tmp_path): _write(tmp_path / "main.tf", """ resource "aws_s3_bucket" "logs" { kms_key_id = var.kms_key_id acl = local.bucket_acl } """.strip() + "\n") _write(tmp_path / "variables.tf", """ variable "kms_key_id" { default = "alias/logs" } """.strip() + "\n") _write(tmp_path / "locals.tf", """ locals { bucket_acl = "private" } """.strip() + "\n") block = find_block(tmp_path, "aws_s3_bucket.logs") assert block is not None assert block.review_context["variables"] == {"kms_key_id": "alias/logs"} assert block.review_context["locals"] == {"bucket_acl": "private"} def test_review_context_collects_related_policy_docs(tmp_path): _write(tmp_path / "main.tf", """ data "aws_iam_policy_document" "bucket" { statement { actions = ["s3:GetObject"] } } resource "aws_iam_policy" "bucket" { policy = data.aws_iam_policy_document.bucket.json } """.strip() + "\n") block = find_block(tmp_path, "aws_iam_policy.bucket") assert block is not None assert block.review_context["related_blocks"] == [ 'data "aws_iam_policy_document" "bucket" {' ] def test_review_context_collects_related_security_group_rules(tmp_path): _write(tmp_path / "main.tf", """ resource "aws_security_group" "app" { name = "app" } resource "aws_security_group_rule" "ingress_https" { type = "ingress" security_group_id = aws_security_group.app.id } """.strip() + "\n") block = find_block(tmp_path, "aws_security_group.app") assert block is not None assert block.review_context["related_blocks"] == [ 'resource "aws_security_group_rule" "ingress_https" {' ]