@@ -61,19 +61,22 @@ func setupReshapeHandlerIntegration(ctx context.Context, t *testing.T) (*config.
6161// reshape-recommendations path touches. AWS config is pre-populated
6262// so `h.loadAWSConfigWithRegion` returns without trying to hit real
6363// AWS. Factories are injected so AWS calls go to the fakes.
64- func buildReshapeHandler (store * config.PostgresStore , ec2Fake * fakeReshapeEC2 , recsFake * fakeReshapeRecs ) * Handler {
64+ //
65+ // resolveAccount controls which CloudAccount UUID the reshape
66+ // recommendations path is scoped to. Pass nil for the unscoped
67+ // "no-AccountIDs-filter" path (equivalent to no registered account
68+ // match). Pass a concrete resolver for scoped-branch tests.
69+ func buildReshapeHandler (store * config.PostgresStore , ec2Fake * fakeReshapeEC2 , recsFake * fakeReshapeRecs , resolveAccount func (context.Context ) (string , error )) * Handler {
70+ if resolveAccount == nil {
71+ resolveAccount = func (_ context.Context ) (string , error ) { return "" , nil }
72+ }
6573 h := & Handler {
66- config : store ,
67- auth : & mockAuthForExchange {},
68- apiKey : "test-api-key" ,
69- reshapeEC2Factory : func (_ aws.Config ) reshapeEC2Client { return ec2Fake },
70- reshapeRecsFactory : func (_ aws.Config ) reshapeRecsClient { return recsFake },
71- // Bypass STS GetCallerIdentity so the test runs without real
72- // AWS credentials. Empty cloud-account ID = no AccountIDs
73- // filter on the recs lookup, which is the legitimate
74- // "no-scope-filter" path; tests that assert scope filtering
75- // would set this to a UUID matching a seeded CloudAccount.
76- reshapeAccountResolver : func (_ context.Context ) (string , error ) { return "" , nil },
74+ config : store ,
75+ auth : & mockAuthForExchange {},
76+ apiKey : "test-api-key" ,
77+ reshapeEC2Factory : func (_ aws.Config ) reshapeEC2Client { return ec2Fake },
78+ reshapeRecsFactory : func (_ aws.Config ) reshapeRecsClient { return recsFake },
79+ reshapeAccountResolver : resolveAccount ,
7780 }
7881 // Pre-populate the AWS config cache so loadAWSConfigWithRegion
7982 // returns immediately without LoadDefaultConfig. The Region field
@@ -140,7 +143,7 @@ func TestReshapeRecommendations_Integration_EndToEnd(t *testing.T) {
140143 {ReservedInstanceID : "ri-1" , UtilizationPercent : 50.0 },
141144 },
142145 }
143- h := buildReshapeHandler (store , ec2Fake , recsFake )
146+ h := buildReshapeHandler (store , ec2Fake , recsFake , nil )
144147
145148 resp , err := h .getReshapeRecommendations (ctx , reshapeRequest ())
146149 require .NoError (t , err )
@@ -202,7 +205,7 @@ func TestReshapeRecommendations_Integration_SecondCallHitsCache(t *testing.T) {
202205 {ReservedInstanceID : "ri-1" , UtilizationPercent : 50.0 },
203206 },
204207 }
205- h := buildReshapeHandler (store , ec2Fake , recsFake )
208+ h := buildReshapeHandler (store , ec2Fake , recsFake , nil )
206209
207210 // Cold call.
208211 _ , err := h .getReshapeRecommendations (ctx , reshapeRequest ())
@@ -238,7 +241,7 @@ func TestReshapeRecommendations_Integration_NoCachedRecsReturnsPrimaryOnly(t *te
238241 {ReservedInstanceID : "ri-1" , UtilizationPercent : 50.0 },
239242 },
240243 }
241- h := buildReshapeHandler (store , ec2Fake , recsFake )
244+ h := buildReshapeHandler (store , ec2Fake , recsFake , nil )
242245
243246 resp , err := h .getReshapeRecommendations (ctx , reshapeRequest ())
244247 require .NoError (t , err , "handler must not fail when the recommendations cache is empty" )
@@ -339,13 +342,12 @@ func TestReshapeRecommendations_Integration_ScopedAccount_FiltersToAccount(t *te
339342 {ReservedInstanceID : "ri-1" , UtilizationPercent : 50.0 },
340343 },
341344 }
342- h := buildReshapeHandler (store , ec2Fake , recsFake )
343- // Override the unscoped default the helper sets: pretend the
344- // running AWS account resolves to Tenant A's CloudAccount UUID.
345- // Equivalent to h.resolveAWSCloudAccountID returning a real match.
346- h .reshapeAccountResolver = func (_ context.Context ) (string , error ) {
345+ // Pass the resolver inline: simulates the production path where the
346+ // running AWS account resolves to Tenant A's CloudAccount UUID via
347+ // h.resolveAWSCloudAccountID.
348+ h := buildReshapeHandler (store , ec2Fake , recsFake , func (_ context.Context ) (string , error ) {
347349 return accountAID , nil
348- }
350+ })
349351
350352 resp , err := h .getReshapeRecommendations (ctx , reshapeRequest ())
351353 require .NoError (t , err )
0 commit comments