From adc697ea4d6f991f2d40687bb2fe1729956334e9 Mon Sep 17 00:00:00 2001 From: Sahithi Ginjupalli Date: Thu, 19 Feb 2026 23:00:59 +0530 Subject: [PATCH 1/4] adding nodejs webhook df pattern --- lambda-durable-webhook-sam-nodejs/README.md | 202 ++++++++++++++ .../architecture.png | Bin 0 -> 51466 bytes .../example-pattern.json | 70 +++++ .../src/status_query/index.js | 100 +++++++ .../src/status_query/package.json | 15 ++ .../src/webhook_processor/index.js | 230 ++++++++++++++++ .../src/webhook_processor/package.json | 18 ++ .../src/webhook_validator/index.js | 62 +++++ .../src/webhook_validator/package.json | 12 + .../template.yaml | 247 ++++++++++++++++++ 10 files changed, 956 insertions(+) create mode 100644 lambda-durable-webhook-sam-nodejs/README.md create mode 100644 lambda-durable-webhook-sam-nodejs/architecture.png create mode 100644 lambda-durable-webhook-sam-nodejs/example-pattern.json create mode 100644 lambda-durable-webhook-sam-nodejs/src/status_query/index.js create mode 100644 lambda-durable-webhook-sam-nodejs/src/status_query/package.json create mode 100644 lambda-durable-webhook-sam-nodejs/src/webhook_processor/index.js create mode 100644 lambda-durable-webhook-sam-nodejs/src/webhook_processor/package.json create mode 100644 lambda-durable-webhook-sam-nodejs/src/webhook_validator/index.js create mode 100644 lambda-durable-webhook-sam-nodejs/src/webhook_validator/package.json create mode 100644 lambda-durable-webhook-sam-nodejs/template.yaml diff --git a/lambda-durable-webhook-sam-nodejs/README.md b/lambda-durable-webhook-sam-nodejs/README.md new file mode 100644 index 000000000..792882433 --- /dev/null +++ b/lambda-durable-webhook-sam-nodejs/README.md @@ -0,0 +1,202 @@ +# Webhook Receiver with AWS Lambda durable functions - NodeJS + +This serverless pattern demonstrates a serverless webhook receiver using AWS Lambda durable functions with NodeJS. The pattern receives webhook events via API Gateway, processes them durably with automatic checkpointing, and provides status query capabilities. + +## How It Works + +This pattern demonstrates a serverless webhook receiver using AWS Lambda durable functions. The pattern receives webhook events via API Gateway, processes them durably with automatic checkpointing, and provides status query capabilities. + +### Webhook Processing Workflow (3 Steps) + +The durable function processes webhooks in 3 checkpointed steps: + +1. **Validate** - Verify webhook payload and structure +2. **Process** - Execute business logic on webhook data +3. **Finalize** - Complete processing and update final status + +✅ Each step is automatically checkpointed, allowing the workflow to resume from the last successful step if interrupted. + +## Key Features + +- ✅ **Automatic Checkpointing** - Each processing step is checkpointed automatically +- ✅ **Failure Recovery** - Resumes from last checkpoint on failure +- ✅ **Asynchronous Processing** - Immediate 202 response, processing in background +- ✅ **State Persistence** - Execution state stored in DynamoDB with TTL +- ✅ **Status Query API** - Real-time status tracking via REST API + +## Important + +⚠️ **Important:** Please check the [AWS documentation](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions.html) for regions currently supported by AWS Lambda durable functions. + +Learn more about this pattern at Serverless Land Patterns: https://serverlessland.com/patterns/lambda-durable-webhook-sam-python + +## Prerequisites + +- [AWS CLI v2](https://docs.aws.amazon.com/cli/latest/userguide/install-cliv2.html) installed and configured +- [AWS SAM CLI](https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/serverless-sam-cli-install.html) installed +- [Node.js 24.x](https://nodejs.org/en/download/) runtime installed +- [Docker](https://docs.docker.com/get-docker/) (for containerized builds) + +## Required IAM Permissions + +Your AWS CLI user/role needs the following permissions for deployment: + +- **CloudFormation**: `cloudformation:DescribeStacks`, `cloudformation:DeleteStack` +- **Lambda**: `lambda:CreateFunction`, `lambda:InvokeFunction`, `lambda:GetFunction` +- **DynamoDB**: `dynamodb:Scan`, `dynamodb:GetItem`, `dynamodb:PutItem` +- **CloudWatch Logs**: `logs:DescribeLogGroups`, `logs:FilterLogEvents`, `logs:GetLogEvents`, `logs:TailLogEvents` + +## Deployment + +1. **Build the application**: + ```bash + sam build + ``` + +2. **Deploy to AWS**: + ```bash + sam deploy --guided + ``` + + Note the outputs after deployment: + - `WebhookApiUrl`: Use this for sending webhook POST requests + - `StatusQueryApiUrl`: Use this for querying execution status + +3. **Test the webhook**: + ```bash + # Send a test webhook + curl -X POST \ + -H "Content-Type: application/json" \ + -d '{ + "type": "order", + "orderId": "123456", + "data": {"amount": 100} + }' + ``` + +4. **Query webhook status**: + ```bash + # Get execution status (use executionToken from webhook response) + curl + ``` + + **Success indicators:** + - Webhook returns 202 with `executionToken` + - Status query shows progression: `STARTED` → `VALIDATING` → `PROCESSING` → `COMPLETED` + - Execution state persists in DynamoDB with TTL + - Failed webhooks show `FAILED` status with error details + +## Architecture + +![Architecture Diagram](architecture.png) + +## Components + +### 1. Webhook Processor Function (`src/webhook_processor/`) +- **Lambda durable function**: Main orchestrator with automatic checkpointing +- **3-Step Processing**: Validate → Process → Finalize +- **API Gateway Integration**: Receives POST requests at `/webhook` +- **State Persistence**: Stores execution state in DynamoDB +- **Dependencies**: `@aws-sdk/client-dynamodb`, `@aws-sdk/lib-dynamodb`, `aws-durable-execution-sdk` + +### 2. Webhook Validator Function (`src/webhook_validator/`) +- **Validation Logic**: Validates webhook payload structure and required fields +- **Extensible**: Easy to add custom validation rules +- **Dependencies**: None (pure Node.js) + +### 3. Status Query Function (`src/status_query/`) +- **Real-time Status**: Query execution status via GET `/status/{executionToken}` +- **CORS Enabled**: Supports browser-based queries +- **Dependencies**: `@aws-sdk/client-dynamodb`, `@aws-sdk/lib-dynamodb` + +## API Endpoints + +### POST /webhook +Receives webhook events for processing. + +**Request:** +```json +{ + "type": "order", + "orderId": "123456", + "data": {"amount": 100} +} +``` + +**Response (202):** +```json +{ + "message": "Webhook processing completed successfully", + "executionToken": "dev-esm-abc123", + "status": "COMPLETED", + "result": { ... } +} +``` + +### GET /status/{executionToken} +Query processing status of a webhook. + +**Response (200):** +```json +{ + "executionToken": "dev-esm-abc123", + "status": "COMPLETED", + "timestamp": "2023-...", + "currentStep": "finalize", + "result": { ... } +} +``` + +## Monitoring + +- **CloudWatch Logs**: Execution tracking for all functions +- **DynamoDB**: Persistent execution state with TTL (7 days) +- **API Gateway**: Request/response logging and metrics + +## Configuration + +Key environment variables: +- `ENVIRONMENT`: Deployment environment (dev/prod) +- `EVENTS_TABLE_NAME`: DynamoDB table for execution state +- `WEBHOOK_VALIDATOR_FUNCTION_ARN`: ARN of validation function +- `WEBHOOK_SECRET`: Optional secret for HMAC signature validation + +## Error Handling + +- **Automatic Retries**: Built-in retry logic with exponential backoff +- **State Recovery**: Resume from last checkpoint on failure +- **Error Tracking**: Failed executions stored with error details +- **Timeout Handling**: Configurable execution timeout (default: 1 hour) + +## Cost Optimization + +- **Pay-per-execution**: Only charged for active processing time +- **Automatic scaling**: Scales based on incoming webhook volume +- **TTL Storage**: Automatic cleanup of old execution records + +## NodeJS Implementation Notes + +- **Node.js 24.x runtime** (latest LTS) +- **AWS SDK v3** with modular imports for optimal performance +- **Modern async/await** syntax throughout +- **Command pattern** for DynamoDB operations +- **Individual package.json** files for each function + +## Security Considerations + +- **CORS Configuration**: Configurable for your domain requirements +- **Webhook Secrets**: Optional HMAC signature validation support +- **IAM Permissions**: Principle of least privilege for all functions + +## Cleanup + +```bash +sam delete +``` + +## Learn More + +- [AWS Lambda durable functions Documentation](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions.html) +- [Lambda durable functions Best Practices](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions-best-practices.html) +- [AWS SAM CLI Documentation](https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/serverless-sam-cli-install.html) +- [Node.js AWS SDK v3 Documentation](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/) diff --git a/lambda-durable-webhook-sam-nodejs/architecture.png b/lambda-durable-webhook-sam-nodejs/architecture.png new file mode 100644 index 0000000000000000000000000000000000000000..985ed009b084c8d0d9092b39674260a87ac1b273 GIT binary patch literal 51466 zcmd43c{G&o|35yJvJECuLk-57ErXC<#!mJn3JoJ!O4*lCmYET0>}1QDeJjL}G71sd zi6LcQ#=d0z-t>OI-n~D+bH3+%&+ng4=Q!PF?)$p0>$yIjkL!5})7Mp}qhX~1fk1Sc z8Y+e$5CswhIz>fw2Ka;vEl33ZJK<)it_&*axHJp=LScXX#&r;=`~~eE>NM~>^+OGF zHxTGN&(Y5bO+)Tw5U3?xQ{}p`x7EVFPpoC1&yt^+;DT43SH#xAN}8W*jN8Jg#sb6O z51v0$VsVI-7kI%C`0)jY z85JNN;Ga?n{w{k-?@hogzvZ~RD{4lZW9br$aFejn7#N66`lemUS; z0_`f9#5O|MZbi1)pXtm>%h_g;kSx=>`*NTG9gOy-ezYk;V{FY;H%fsNysL>lwD0yB zQ}J249z5)>g*{~Tv-=cDJ>7|lS!b^_Jj2&m9JMtuN?q<5=Mb~*<-Q$g);m_oT+vo@ zZ$0f-hrE<#;A@Y7LthrJjxl#f`(@Syb*n7566<=ih3J)tQm1>LoM#u713v%i?C0p; z(l&d&6(Mg1ZrKj;Q=;w{DKDuM-?U1&Kj4_u!+iLrOq=9VWU*BkedD!4C83E#@AXy&xlB=i3S(>tv3GVqUaOzEK7$! zug-3c{Sr*O_;t^V3ABnqP$)Hh=HbQTu&_-9llnHwtOkznD9u(B2!)Fm1$XsXPsux8 z9zeD1eCp0nn2;S;=_BGd_DB7L(nCY^@A?Nqt~E8%`=uA$Othh7^REaPX{ho`yY(i% zO$l>B9cq|!Aq5T=4ZI@TJo2q1fC^b~kH{}pT!>WsMGM%Lz8GL>XJzgz2U161V4edw zYuzoZ|AX0a3KY&%3!14wvE=+@fDXnXBuQeGphrrkIyNSj`Ie3_*ONa8B-sUppX_AX zyEKG)rcg~BzCgj>3WGn`DERTJWu6P1-%Z=WipjI6(^U)K|EP1e5$|ZwIkqU@zyz3Z z1>gq|i88~x-$^jd;o!NrI9Z}~Lt{tO%%(FH^6D;YSSmZRLclwn)$5(kfsP5(hAwJ$ zDdxTBp*_5xB+6YFsWn5!IWq_{=H7&HeDov;qBmD(>N#OtoAuFWF~+l}hfys*J;bI$ zU<9*{sFEL@Jhsb-)2w1(hrth75MbGP=KyzWRx^*ix`dUWxZ4%2`VpJ=@bdFM>7N}J zDjqySmqbmJHPIo9roRo`KARj2T#lgRW>08d)n6{q2gR&x$0E@8RJT(`=QRj=@rb6n z^eN)pE4OyQ+{eN8&tOc?5Ymqu5QlLP0^O0eBu3Md|#Skx=w!^ zY3_q+!55`DS?S#@f5qwD!M1fb#U5a>HT+wD>F?>vj+hoXMp z>~9_P5APvD1TRw;>h(Wo4q&L{MB!{GImh?l1iOtc%kKQKgwTqP0|<aP^Bwn> zpkHZ|Vud}5pA`a$jI-o**=Io(m$#(ZyR%R&y5=l$+TM@3$(Ny+5fSa$ED}sUVX0;C zw2=+8VqQSHK=yHDRQa;BXQ_-XdB*K}hK~G-2eu|h) z5Ff8mdsf!~(x(J$|I+5eM8sRF;4^%A2ol!=^{~TRFXY`n7vH;y!onSx={Ob;+{HFe zHKI_LnPKVYFoW0i%Q;l|Suy8k!2Ih)GB}Nf$Xj#4o>wnxNSpfqs6NygL7*#?eng#* z9ULY-qY!Adq@ViDq*$azu2HCqXO4dNQTduW?n1ONBPQFVUy1t?=dZD0ANftn`@8Qo zVQd1p!H3VNX?4`G?9MaO6}55;8R9&l&__8~xGH95u#_-Z$2*6dEK1|hiEyqyb(T*^ zv%vdF^f~8u(;=u9a@?EZ4!UYzv`=|S7#M}~i`YWdMkAW|523Ky?Dw1ZC^ev%?6@A$ z=<}GoMc$N$g6CgyCw&2ySch*q$P)DK_~}=_8-EeAP^&eiJFgYc+52Wp-Z@m<6dG+B zg}1G~yV1cjZw0~ab8G#k?BlYN^o0bj->kY&#(6o-=*Rnr zWyDe#wNX*zSw%U`G$n~)1dE71H9;5$zxordXM$*<}ME_}< z(+nLC6U%y<_`L>o&gNj?<11Fx*e!G6Hty2#6{KKRD(pHQ<>i`3edjCXJw7nC%yrIG z_JUxpy)|nag|gk|d4^ZIuK|JHY%V09J?wFGZ_VT&xf zAeweL*eVhh=#Y%E;BsX2_R0a9Aa@uYO!Irf+v0C4Q3!ODkXVCCyjYjR6r!mnSHk@> zy*wve^Bc^DF6U9LiTg6j%kO3<)8hGZWybmKiEoW_LewY2C-gb}q2V5nyCoPgVcCyP zo#>$(w`>;ak+3nvtq`PobF~`r_nNf~-x)j+SNVL24TiDB(t4IdVa(WTmN%GFTJm7L!wKImw3>$2x;TYxzgD4!0;DVx_;7!d-p0=SE zpUr_po0~DM?^1rNvWkMuyusWJz*WhRGayzvz!xaGP>A3*zhH)xkGI)3FL6fwmeE;`D%;Ufu7PoNIYC=@N2HOB z;?YDrB1Myi@8@)^?_)=Nl%01(l;`tT3lH%6-6QPfTD~2F%Pi{XZ4HZ17*{JwL)j~A z7e1nRr41kbwgfkm!gc!HR{x17hx-eoKP2+uqT_2JYd9d5s9=e)=P^x~mP8mejALBd z^iG*=XnREcG%%HUyS?|Hl7eXVUozhM9Zty^hk-vxP`7|GvV69|!lNE?u@-QL!dJ!- zEB+6Z7^!K+ZoFb$6cTNgw1P(4bsP2Z|Lph`bq>>1>JixeJ_Nzttr~4A({lM7Ue^x# z6O7fYGYunpYJrjKx7j{Q_AuL63W_P>YE8Q(^=zP=TW$ILM8{syEN(6kE96*E8A9Rl ziPnzB5L9IODW*bN&O|whTTn)NTOe13v>L|L>b&Fyhsj%?;CI8!*i$P9d2>YbgI7+S z+G0DcIEbb}Hg53=gCEH%oH61(Xg`Oc_^6(Q(#UQ@*XxYfr`%2rO}ZBRO5%X|*?Vf!a7+r1X|ARE)cjkynqdunMK& zTw&}qqpgb4h>}(-V8jeI_lkkd)35pzY*;W7@!Jyxs1}1zgo?GI!bkhOre(P3hh+$6 zTb8CnGuqu6lqUjsTi8gPxqDKpVdX>_adCaQijc~t8BI{6S#(-QWN&?;tKb~3q1B>B zu2VJ+rU>+>t9=>a2>SvCu!WeWArarApTt~Y;|YD7bA~dk@cZBwI^@Fc%@a?=W3#Ip z^n8PtIlfPd^`SJX@GXTc%kfRrs#$K~+*Yz;3>sgu3#y))$Z&j{mLc(%0AtPE=DEv; z|4Bp_Fk^bN#Z^uV@Ma@Avvmtr5lIu$8U>dygVQr>dp^i#^f6)9g()5Q8AOs{EL4H} z43w=AvTLz}n`kvoQejpK2GAP5o%M{Z09Zy&Q}EMZMhJ|zDWTiLMABX(9>M)6je*O- zy1PobnZT5H9&lU0V--SpUF(C|7Hhkw!3G&x>bseUo4C__r$uff+BJ5*!IBdisjX@J z&lhonHRrrVx7_%QJP5+M3SiB|o@{;9lDIO)aKF;*l9=9c$p`wGDzeBCH_Mz*c>kLE z)J|e8BKy1>W>BzIr7^}41K+X8y+x#F140@#_X7Qk2oz4J?9u^| zIN|Vdi{B({JQ#N8TJ!6#bcPntXa#$mRQa5a{bW*iBYwi?dgFZamITjE(2g8dPsY6PK)ZQP4hJpLzJD}*X5+Q`0R>4v{)#7b5o;Q{mUF8hYdgpDl#%+ z?$~oQ$h|U7aQ@Fu^yt7Hg2ko;oLlqujnDL&K?tOL;5JHz>YAZ)v@%L#59ww21SRsz zDU>b@u6Y`TgIRHt+5&X>BoVS29t@%x2NVe2+Yu>4mH5#PjoSBnn$ERNav@@7chxPOreD#fh=14qrA zO_kyn2J;6>B<&W@7ry!!m`nFsMVWC|qB#x<82s=!=1u$k-zbgmj$)n~nN|a|2lE1= z;Bw+~L$jDx2qwFP)s`VOL!9D|O*Fn_Qi)@}8|xYYLpOaf-;`v;aGPG$xhxM3^D=wK zoIIQr`-_Q)KRFz8jvARc{>&|c`EgTQx(N58%!46Ij?-hoGmy+66mIvUTyYO~h7*^N z?0OzI;NeP*)P|&2O>_)E*z}&c6BMpRgzP@vGIw@pR>dY=iz(e1v5lUh?HXWEXyP?1 z|E(MgD6n;%$3M6tex%p{8g0BXE*?4!TItYa;f*oYB(YT$p<0S2I}G3HQfgS(fsr;q zM*U*pD#eQ7j&pm_glJllD_6$dV@?)P;gE#K5!$Pj~Q{>NDo==-Vs4P(v=?;_n^>mD(m~#Q~IF0EWuGK1N zf^eItMPpfV=Cn#2E9UY8j?7?O>ZlygoO#fl%rhulZO4bz8S!Rb6NwaEh=1ws`Q~Y` zXtP=)*yHfgkhetwyPWqJA4#nZf)R3`7AdcJilb5VEE4eVfbg8hdBfN*GVy9Z?_jAg zGChOzZ2ZLuSF?a-0#lswc-NfGFAp{tDN_z*KP6ZoYLELgD`~*&88TQzh8*r2wJkl+ zp+&Zvf82uy@OV1MvSOOHLO&T2K&(vvJ9!T!-3Yete7l~bS41A{N7lXDcIu2y{&GyuH##z526i z>B|Q$>*!!v7tXyF&7?aMpNhwN;e#!HrQQ4|LG(br0X;c?b!W7&V*fy4XlrQzSEou9 z-E5fA@_yR*b&DB#f@DUe0{U=FHhr@hm0eD8ZV1e%BTQeZy?)upWl4UuyWgdaup5Zv zI0;htGu|7gwL{^h#hPS}5E`x1oCL|kQ^>oZ59&vR)i-6U@0*tLngU4M%hj8TTb;f< z8Lh34wwlj?T(L())+^OZBfGe?t8UR8AzGIuur1oR8hDn-hs-26$o0jaJL=vp%DO&$ zVq%-O-o1u(COjcSKsA4cKiMl*>$s8FTAkL*?kgosj_!z*bZ}a8I&ft1f1?F&b?Jzc zcI$|GDwP)78nP%$TI8?X?Vj!K8)8$)Dq(1g({qUltNz(+_QuoNH>fCJlbR)P-k~P& zQT6&*mC0xN&o2b?$#U0oJv=B%bEX?BKl;7jtym5yU&}2s_G&5lY8~ZeeJFf1)#t}k zJzcjt92jMmRx_9`h)yk1aI7tQJQc=atUuneV7Fy_@N|qp^saTv!(v%oJXzJup5C%o zd}FMtnEu2^30JMHX}kTWd}z+9()OLNHLk{6(`eHC)XVwFf*Q+;ZByoo+gz`8cI%25 zHv6i3N8r1jBLXooOyn15K@(?=d_sxVds1pFA^4P(9}*ocBeih9BY;V3p;jgIlD)RI zI@Uc;H`+eoOG*j71A~lY-9uIOhUGWiT^Y493W8fOZ)I!sP;NJOjaB2f^IYYEcK$+T z)bp(7-TTstMf%P8`l#dxcH^yUhP6y3PA&s57Rvgq@w}`?-MHP2`P+hmQ|_Afe#vh) z(s*Rk6x62@ZQWmW%{Gj7&J5%U%YCsr+;TDYIXT1X^Gvg z`6-{BQDC+EZ%f(n%DNBeu08r${oOs=4Yw^X?drh2##?*z=RF!enYGPaB=1_()n$n3 zWYchr9kZMkPb_r3CKTCL6_!U=d}ike7M~Xw7ED26=Vlk)sl~hd>-IOSWIOjFofHJ; z-MxRfCyYD_YOk5FVv)_O^3s|vb1>)C4_*+1p)99gWjT7BbGjdNib7 z&`aQ{_PdT_#dO!t6#S^QdRKnqbMO9Cim>du8`hFNIH3UYi%kStPPpFtFkaQH6<4df zysMnY=Vs-YuSO8Y4=`*ctQAxD*P=>mPj1I8gLyj0G+rL#^Mufl=@<1Qy*~!~=?pr=5 zRMCNu=#dLcz52UB9eByv8jVo4ftKj3c#I|A$8U*CyQE87Uj&%r^K^09crI@?kq;W_ z)=l$Nq8ZxD^?syV#;>s#F295EUcYH0!@oz5&(MC+dm{XMi82GTZr(Q@u!B91Vu00?2i5koR=c=-FGMO7b+IIJ5imYHt9V)ur)L0_x9APKm<5uq=n%r zauN#GxB>)-TK0PTxAP>P)xw;p3~}GYwgp6y#{3SI46+x`D(^Gb_YsmXfhP(QvYJS* z+Zb$oMQ+ctXUS+rPyNazT%5};JFzA0}|i(zKMNH)PcC~ZlC{ak18w?owBA~yvVQ)knAlIe_|LU z1WvscI&&whliliP2dujf?qA^a>vg&w`}fQjvdZy_`ypv&*-o400UDVnpK+l>UutvD zKn!5KsTG4M$=xTS<=j8V){x~ZTsx-ih!LYi)hL#9Qr@s6LjT z41F{EW$SPK+(N*$f=z=+w6CHdtv%Zn!89LbNuifl3gi7vWi}@A$Cnc{UaL>sW=a`k z{~Uv@^NuOE65c1JiuJgM%-}!KxE9U(x`k|i#F=+XCK{WZX6={;N9G7^R4u5D%c-tjmv%df~!?EjDh@s{@$c5Z%JS>#JI#B>M0=q?$u3z3g3)m}GB4SGnHM$E9pd^Y*Su!6k!aWdso>27zmuOg z-R|Hny&OC^fsLP(y4bbblonT@_V+91!3G}9(>aBu`u1u!Jzt%jrK$O~X6l8dxuGC( zanxIxH@M`*ZV-pvKu%9i;ZgxYXjbOfu60yoRE(u?fpmV*=RK;f4f}G`o!Ta*fO1wN z|0Fe_<`?*p7$-BW{??Q7I)+9{#;%-MMFnu#vgA{GEuT4x5JbC@_=A?Rq#49Z4SU=e zb>>ODbi#!5-k_XFMdiDj2U6w_PM))8G$Fw&^uJE7>~qvX>)dPGyVip8lzvf}XJ9_niP=?M?&86&(R3(~@S z9TC*chBvJL(knoSSpkqyAdrRRgw`CGM*BzQIQB`u5vd}+aGo~!YW~-~fVKnNN{Zh9 z(oFhB;+RKo81&dpitBBU@tJgsIu0KNJu~e<0I_^h#cJC(2gV4d2LNG)hM-$VKFeI| zO}cFPKpRH1nF9nMx3j|q(*l$|hlWkQiB4Y{`u(}DA{+3@Q3?*P6b@2& zNq@7mg`B0S{CubgK}6ngDzD_6N2#hA7AAa9!}LF27u^VvcWG(tQw_pT{8l!u{;bO! zndcwy1Vwp{_o~6xOvC+3p}B|$W;wx3TeWNT(<_@ksk|tuXSD&Z-M5>Y(qalM{x)wq zWG^H^H!1GX$=>b9aFh=UD=}f$AuR@R$8Qsz$nx5EXLa#2dz?{jOyr9p?EMIqC7;ON zaWE0>X!e)jLr}O2AwpN6%7bxNtu?;Ce|R%Os_ql``S16Aq7@474nOeBA|2Pupz;Ga z8HJQ&Zs>WpW@@qNXusg!8hLZ)|8kP+P}k;ZTcnXY_ETv`<@;3&gAk*@m%tE|5^7W|3{c_*&&7lDOsiYX6FtQMxTI;Ej5Tg7NA!+Y(2T8)hU<%>lpg*! z>lDQYd)#+3jm3TD-aMGrc&i=aqdI5wmx?J+8t7GHk;jSkLhuy@#3M%;w4>+*%ktK`}r*ynh~OT~UpmGjW?z`5s#nSFhj`0!-^?gcN+gu^;oYUSMQ zzhb-wj2CHegjxTCKmOk=_5Y`#|F3==e-7hpF~YN7?Gm$6-ChNx3$xckwSA-Ura&tA znNuk8>_nUIb7aPwbH7@uyfZv{zHq5eMw*kjIZS_ zP@c71jC=1=`FEb-M78|G6BL!uzgev6)HF+HcD>d-_hDl04f^hphgWKLsunO2hewCH zc<=X1Zk?(k%gvHwBPBgX>?hv?FerO;Q`-E|_;~lw(1ZJ1CzG$#7vK0kRT`;al;Cw( zHTnjP4UqJJHDvwjV9F*GBF~Rj+~^lEJke>Not1_B{#`-HOricOttF6UFWHrJZL;|5 z^-{8YO~NE9{|3$g6$1k}91^FCVjM#5GppEI;l1sQlVL-?Ghs5ibXmVs ziUNOW4&AFojIJWX-xuxy+#I8N%d^)cU536B-TdLjZtM7X`-HhWSzC>jzTV*h^d9Yc zdN}tq3QKmEqGfD#O-?kCKp)5w%zq~!Jn=1UA3rZpY(xJmneVfE?dI3v+t#^JE^JbyqWOU27M1aG|x>94N#!wOiw3m2) zzSUdD5#SYeXyIjj*ME#66;A23uVM9jqYnsH|K^7lhJ6TitL-_Q4GPUHoNsi!oK+Ni z3&*(&-f*!-P*`#{Sg=}gNlvI)y3`icZ3!h!GUON_txFn~A11{?Y*d1on2K%-@9TcB z5m;lI`op1Y5 zVqK1d@aX0Go*Uh`ja_?@7_)#iy}u@R#9tC5166rRM_IEiMLUxzmzO?iWqNkTNbu`k zZ= zMGqhz&RYu)b+ zy5)*^()S%<@-BBSO4ltk*{xJtf2EFuQCnZ``79TqEPj~jSu z6b5+}deq`!MyX!m;CUeR>xc2z`)RVVV%OSg2P+v}Y~1`o1G9{cd`i^N84E0R3t5 zQ=&Cs%2)6oW!E@d)N7g|-OG37(<^pUvsZyfOyy`io&wU=vOHF<%zJO4t0&yQr?A4hO{S0&3;_)AC$&;S|PX@T^c>e~1 z8a@4p(9)u%_O))#W3GFy(|v5|K$9Vi#d|`q!lk)bthGQCgvSBp=o41&?cwGxno@P# zTv-8S2>0Z@Nzt{5CJAzt_(ZK`me@;(%8V~M>5}xJDa$36=ZoQ_tVXR`Hj8lbxgnqA zy4CqYfE1r@TT4FQvX(q$bi=A(O+9W$+~fp~mGcuG3c4I|{FXugUo5T@)d6teEw~Ki z^Pb737?&tGlk+($nIM6OI)>f`nmm>a0D;X6q$`mADXW2I)z!7LrSr(sbklO{w9>mX z;uBZ^wb1D3)}mfqP}ol8Qg7eSz9hQU_(P5fb9<}UM{Iv)MnRzTw0{qc z_2P|Q3x06!?Z9Er^6oU!3U>5cA10@`waXnkiNq#8P^M9QhaftwD>VF43G{!<9=Sap z>i?XJYv7t?$*{!FOVgCR{TuF3G3XiT36B3PDoU4@`AU03-$k~ppfH!h^{G^RRul+5)7JduLy?wF>4zRw_w=P&C+`-6=-U8cTzvCJh(U?1Sw zkUYkAboNE%DJh*dgz<&^wcWZDH9&{ftjyJ~J8NjlY#?bfO() zq&VGh+heb>@Hlr&-n{%3?H4PxNGR_q!1B)?5knFXT^nCaihBj~-I*)T#V1l+EGIho zeqwn|`LI@DpD8#325?EBzEp8;X>k6-4#+;(ey;B!FK-wU^lE4%aEB88J=$+#zl+-I z0*L*1z&kRs?qw(jZOyq&DokNwhS&jw#jU9RrOx*`5nZU^ilf-UZ*8eJFTtRz7aJk3 zt{v-+LvkcXlNR*tF-<6(V8$+t^{Cdqbt`%OcC96*+4yJut&)R5%4|Z`jqm4$@uySY zpnor6?3`CmNG}HWWWOoC!QSwr1Suv)wmN%H7YOB`-X|9Yt~#9nz0`ArR;*n8{o}2w zYiGvUB>b+&xAK`1WQFaguGObCW?$Bbwqp4&l6VphAKW}+3KM3(wqYfm%?PR7Pn;YT z?J7KZBkb4_9wI~U3cnh%4BX#X?KRSC%~m}8D&8r_rMNfFFj+faV(S-KrMSEBX2<^e z{lL{$K0BL6T51aqKVYAapltkZ+@;}go#Bgt*`7{GieF;;`#qlqZ55B;OOqZL@NHrB zz*o1vrd9PLP)qn*M0N^F%q^keM<_SJI6n4({s<)~(Q%h>##Gft zSRTxYIvygU`YcmyNBZtDei3?682{B{D~B2M>h~-nyC-?QH=Ij)^l2`zn-!e)NmFGHRXW0^5cn?ub z!!Eg}^KStj;@? zr3)^)g|;6#O-?92D$zrHI&_UOTWR%wKIZ9iwv z+-q-mAx(cz0x-EJ+<)xug6>{2dFI;*99tFR;*Uf&@cnX3F+d%5)M&!n+}&VKH+6)d z<$Mn+OHd5Wz#EBZ5J>ZnzI*aBkS|>Jl>-inea83L$rO3a?wBU*&)5N$5GLhf}$DyPB^F0tPgGxh7h--G`2$kfpTnk^;msgBI!d6+cPG5GjF zs_B*GQ#4K+=ihWkNWGnOuOVmLn&4)N8RpBy#g|GRVl$(fBo+ZV00B6T0|4Fbmurc&E~y#{p8T;~y*h!)cVp{o}Wu zKxz1>LZcaupQ8fxG91tR&*Q(9poUgJ&Q#j}zuamp4)$65$Fuh{zWVQ zw<)e;Wf2n_%?w9)k|SA-0oh9<@q7>_CIK{e%E{zp1=dICfqktzt*)H<#U%FDwaVRd zy|vbn;>`SR@Eu#5X~!he5WF5Zw&9)8i3ox7m;ppUrSjLANGxlKEH`j)0+?DEImz{t z8<*I7D}NF{EtxI8D{ObNmso2zWhY_`2bx3MP~8%{G(!p%+NOo2yGz1sa@*Hif(T<5 zmh@%cLY+qt+=Z5AZCzN8wnhT|S8hAD@u|^QAv~T#$E@0NWRuWVu+1S{(OE%q-J1C+oiti6(4DlI@c=NXm#8vHNIpekBdzu z8aCoR71zr;S$dyh1K%sy=L(G}@G>3zruDGbR0fIp)d(#u;Ugp2mbNul8e_8dBBLw| z?ILOJkXeM6;pMJhA(%WeK5YL~z?QK`spW%7X>b?&48#1ULhLXSy|7O5gV0^esnZZo%9j1tfl9fsoRhJ1uFpmTYHkM@SGy-W75L>L zvg@1KSASY-Q(i!hz8?wz-T~P?=mLi9l6Tb@TMHH|c6&PFc29+O2J9g7?}UHmXc-j* zWMJxaoySd;sa;j~;yA+!UM-YG2C>r6ug6HibE?9%WbVw0b+b*6$xlk&yM*5j4H9H}2h6d#x&Ejl z4<6)~JjTM=N{Pf>KNfag@pFskL=`&|>N#ZN*_mgB37p?jBH1+ zH2kt1w_Iwg?NQ+9*`tqtWelqDH+iV@cBpA~`P;{^t*vW}-h*R`)rM1Z9KZZo`V?gj z6gK3xgu+7MbJv)?XCmXsp&{_&uB#{Dmq7j`!S5!K92MMZBq~w3W?DgC4{XbiXWmf8 zrR|4AhOJ%w!KcxW*rJP2IBL;e{nSWLQhjD*Do=8dd3$3%0mu%RF`i6W70J&;{E(SVBcQ!1-wN0zFd43;Rii zR~kGUm1e%!P4>h92~h$dpg~G!`oQNMf$Zg&O~&(6Blmoi+R?emx{I-qn+oQN3h-cR zBDxMwOuuImST713VF>hlm{M67ixLAG!M%$vyj7`YX60piyvWe7G6h{B0%sj+y4jTh z5{L26m~vS7s2m6F#OSy|(lWMTeGY^+dYl+RExoQ%IGSBZFulvd%Y+fS>#g-rXAY6X z2plB{rkB_G#9mR+L$8#{l;gYhOeofG)S6E_MH*R$k~q*$6aWKw=|uNYHH^P59t!vL zY9UmoTEzf#3a|uD*hMRX&shDhQS9LzMw7rRQ7!r`Qr!G!5Hz+$1mB_evnz-Jpy~;wpVYJ^QE|nFX?{ zXSk4dTEJ!6fWAs!SeMyvXjyV^CkA`(*kNu-^tandJaKFiyUg>m_|sAVxmeM zwQ=$(xBpJ~oJ*rSsykF1Z1uNIA3R{42m`iN1)vY&cmi^0@+6d zrl*HTvPMbp-}FdC&Cojld+~7vccH7B ziiHjA46RL1GX}>ft9!+2z6=ip)J`;{KmP`dcoMX6ghG!D2&t9dmC7*B@OX5OGv_p` zr3 zGgA3ui}j5V6Tldg6E3k0TNmjh8g{4@#hLas;-%Z{l!{S>Gn20NzS@(ulnFUN$LnDo ziynV?^~8fl*Y_U4vj3ePwdwbC01+~kn*!b~Q8jKXUF4U0dxdb8#d=9Nj_~6_B}IwF z%c@&<3+y~-0ZU#b&~8YRJFbpaRKK}m^z<{Y)9lFe{>^ni-?sTHv3~80AAtTAAnYD_ zi#!q1M-l~4WI&{AEwVSHcw>$}UlW?y7~Vneuw*Uri|Jxx_B)a(^fYPGp-}11oXZ10ETsw5%c|TM6aXMBu+es;$NTxr_Vh-A z9eD`u?X!Aw=UH?Ha~s1S%w7$|E<7Y2`gwg?!tlg9&FJFISNsVj@mUP>(N_McaMFox ziQ)NkL+${(VgWSffx4QHAe0vMoo{ng|0?Fdb3j}KQWemzZroQWn=N^KPH{LtIOORH z-6tYm@Jy3zAFcfP**nAr4E4BIk8eqJW7LKoUa zv{3t8j}p#JMt>lKhXBBP^-^PW|3_dqf_#4EF!wjnUgsu(gG!Mx^0YqFQL%~EUqUpc z?Pev_B3a?!N7EOE+zXgZflmH!vnaacp>hE#q-4rZ%%xV+5yvGoM)r7>=(KQY_y_jN z3iv;KJ0}kAkz99~~2#ms98|GH82{=4}xF|q+=rT8FZDmdLvoKwWfek** z9wJrMC-P1omBC_pUeL?}76Q_d6@vzvx?`ur{CLn1;Yl#!Gg0Lq*`uQ>xS6A+g~?VYjsbwpDL`@usfQ)J!~kN(O2l@Ry` z0DA+VKR6$ZG`@f%e07#0!InlneOo(iYmr|pbE{JdG=aRJ)JJAaS~g2tnLhalIQu;M z7(TkkzL}k$1CCkgtge<75s?5J3@py!t?DZxq+YA<7TKUQ+!G`GM}9nuMQ{@lNk9tO znJnvlG;0Ky+7*0ux+Ot&f;8NDS$bKV1RoWvH|jYG-naf><12W-joX*3$}$=wq8>?X zVX2XrI-q@|`E$!Va6Vl8Zdz0bN^JDefgHQQIy4N!76qK#Sqn+T6WMv+{HPE_o0?TK zS0HrGJZfk8Lo%QdCIH+J>LyFoEuMj0iS2eud= z#2+fwh3dX{E42wMjxmo;_H9Fwx1F>B*SM2WdwuF;akR`aNe?O>pwn)ZCxC#{mihZwM4%XKf6(jtjmzBTmsTp zzJyZ;#Kh6zmV^jSKCEEwT#bF0mBVM*Ty@{xkhcDZtRC;vlsuYE`t_556L?=!l_VZH zSc)t!n?B$;7t1R!U%zKHoiQ)Uc2hMU^|sVxN*> zmi+r0Rw0)ETv7o7Z8N3|oAM!DOnC3u=);t!k;P?0N^F!J%2b zt2eWL^(c(Ic>cTw>sai&H0DkNJvFzaE*G0;s){XfSBvku@p70* zrsub}OU$36PwHn0)Z=$7nE#f6Bsb7}yOSvX?;}>1?|6*`N59}%DtVAb$(m{E=;cgY@mYuo?^Z_R$8PARhCc&s$7Le{P*LsJlFy_ zH)w_%vYIDD#6xmY5IjzzI=Ma)Ul1(Sf=$k)9$q+>Mnm1i=t?MWuSSN_p-&oHN#?t!YW$=l5++t|tJ&Bc z(Dkb{D&(K0QnY>{BKu~df%AhG$|$Y)0yJm8kSer0WdtCaAx(KEP(z{iG6FKXR*EK+ z-`vrAe#1_$=_SxKst;_3{^?H?%LDi;o|ZC#)XQ=J>SRkNmEdjQID>Emw>EIr*X641 zk!j2U9Qkous?r&tU9bWJ{W@|q&&RzY*q+yVo#%p}e|;R}3y6~KA1~KmL}bUd>b|DR9t_!{w3*Z;*mqJgi`-owvFv2P;ARr|@1%7zrBtY|x5+9PVt7^v?@ zYt;_r?CC@*Jh6HEF4nvG(T7*eDs)^jIKkKD0R=Jqqaff2T$hi``$YbCmnEyQ-_xs9 zT;dB%j#Bp#y%yHd^GGc>ebQz+Z$C?xty?kNfy5PBV0z>;z?2|=I%`>gJ4G$wIi9F< z$$*8i`K(0~ZFj>>c#!wI|AjIWOYnvS#Isa;uNQSbv+L2P8niIqvzh-(Zbv|Mkw(;H zo{ZPxv$-Jv@Q-v-+EAXFeEhAA z)%e^kpWK_ww6}r2OknP6P}iA*C7h1$MoI1j3D`RbMoptSV#!d2_I_|8QC zx2ay{GcKDa-7=|GTO=s!m~;dALZ!&_EU=~=6mGU(|I2KD%Xem*f@m_tg|mO|fBK38 zlrgnAYkeMlqz327BpW*{ze5~P>=8?;MZ|~s%eJL8BTf2`Bxjn&Z)%nJ(*yf1P$Z~< zT_%?QvE{LBsE(V3pMV9ZkqaewS5t5PO2MXBbD!K1GKA?zc5AnUGQbDNg}^<{03;4e z`aL~toNo!wZT})Z>4{AYyV--D1yIhhoxYGIzeA2bUb_L%W=DT<1V9$t;QY6O*@LdN z4kkcom9ai8y)^1;k*(&X5bZ-ncVxDV7~_iC@B*8**<6#ivJ>r@ifs?_*Gwo)_LiE7 zN!V|H;=@bIf2yq-ltzvvJnjr@oI5r>$Qa}P}{xT^mMX#Xv7Z9ICDu}L?emTsj_K-#%V`;TMAGGSB_UJEbYHsN*G z|FZw;b;0)|6Mq=@pU<201*k;}NJln)_xeAsVMv4!fT@8pSpmsvS-z|WCi20=5o+TV z8hcU6I7_g}IA441Jiv7WZ^KXhhu;VOra_!%=pbA z=kT${V0D19h6^xytl&dS@O1P4{a?Wfiqt>u{T(68LZB$YnVt(1KT{|&FTCq0t_*tm z;Jf5P{*P`SY~MW&upg`mVS0A0fbc00=NL`R*1@bW`J)ylzN(-cx_yd#yI3rs;21{! zb7g~<Gj)fKx3_=v_NE6V2JBBFXjCD1t>IvL`0V~5Iz3r>hDv^Z zwWl_o<8?mn2yiN~f^hz?p;MHBqqmpgJYH)Uc+u!nG_kEah}_-vCWZuI)NcA=*Q zii1+e+2;e6MG__VV!{7d^*)&heDJM~_~j@6J@13oUaB^j6$QC?dt>+T7omcgUe#=l z4v)QYXwXin)y|Sw6Dni=-0hjQ)77<^k3ThjGL-?N6Jdxp6NI;6-|}Q4adOgPo+v>D z)4j+cb@1}u!A$I7<2*Y=8;Tq`ZDoyY-QTbBqg9c^K~u3GYGoVt>et$OdbHM0e*aE; z;NB}Qqb2J_5H{k6@Sn_VX@4oa8s`$1axk&fBOS^_5xZffa|cH4I`!JGZjh~{{q?Kk zc?O0^Dc+u7#(-_@#Jf+D{1;$MF}fO}@ zdW^cNP5K5~+J`4!X*#KG~2>|3yrhD1{{?n)=E{g=dF6@895V(plgy_iQN~m z-}li{$LMArv}WLDtb6DkWDs^QDE^&ugD8QlT0VAI#!$)Q&s6C3OuC}USQm{3b9BYC zGsmzuya8@R>5n(YcA{AHMrP@P{nyI|ZOdJtp>6O;E5!+zs(C8;0Ry#4lI`~ungd5n z4W_=>O2z=X!eRU`;5RP#d8JsXlYRGQ`+gE~=Lb~6OG zpG{3OXy(rVU%fEGlQ+4?+)HUKuGU@4A~=+fK0k^n1c-%g2w*Y6ku%SluM@(ETFK#% zqU75t3;|_bD}0Y+P(RUEBu~}5P8M8TV`xdrheH_sW)DNnq%*{%N7MNZk1n+xvB0c8 zd7HnBAT6n#fgDWsRH@zb%@+)r)8|#{-8;_q?%esB|rHoF=2@o*KSd z>h?~hYOSbKyjzjqH)~7NMt6^-fepqr+6%ibx39+}I7K>}v;B(wkU3zl>x_ebi~VQlyCEeN=*Yhazn%$~iJKfFPPS|f`B zSsC6lb^}jp7FZePCicSVGG#PRl#(5i1_NF;%Yh4)Kkk>UPQ>;7pl~?H4{z4u2nNU%L;|QIIQ-q*Rpa2o5Mrps4&YB z*!A>wk*y`mbKUGsSKa7}nVagSv%EwXOHM4=*)CAJN~-$U{2NGXQlLRD(~Lg*=Y^8l zv&Gp4Xr{m+abFD9*+Y3GOE@V{PWfozKw-IB;ojsiGuLCE`%YakLWQJphb{#-AZiaxsW7z4XzRNpTVV-0(60f&wr8k5dRvrlD;fI!X`~c0FN#feZ6O(WWACkU$4hJ~ zyZzQvP!*t`D5f<9&MG&yw}uPan&HLGC3H(9oU9OSmV&mbg1-Iv5SWvSsk%aa*VDkL z1+t_^ElM-@{IUVXtoM19B%M2JBVRfs+r0qiO#s%56ZO=0;vd}Ho*`)SQ47vVzQhH& zg2N?`Kt*NX-luR2!g)vS+laHrW2BUqV#z8wKqV7RMIg!y?B!NAn2H#9+sD0<*wU9W zYa%BeKLjsGyL~Wxo6da^$Y;(T8|dfj1iic`d@>3mFHx1Z1@vz!g0dHpC>MpTy#)(7=UxXRZDo(j?2AwGM@ zEYVkdSzq!a@b_Lw#hJMyXF#0@9sw?OmFYj|z`UPEkeE?toG03Xj+zh+ntE2!I#2;0 zo#PLQ+5SZ~9tE=Idm^HUZ1;C0XD|Gb4DhDk*Hc^!mM?%e#GJ_fC7!}1&wB6Z0;?t* zBh6R@CB?e0sNoL!sHxerq{0n;{IoJjb8gSoYQhD`Uti5EA8gIEW@^SWk-Y9;#U#m8 zDo_U|{GM8N{vOMEaw4;T^$M&`Yfh>07wc^{&TH_50I9(vvp6~`241Gbpn_$Cl74sh z(WeE;+r3schohS9=5psru--p~wu)M8-2DrZ_cqoOw?8TJy!3$I!=(?9twYU*8wsL00E>c)+Yq>+a1RG)?!?|51v~foF8tE~p24=*8pa#R}!i5NBgL z`xRNAu8#$>vGB=he>pl`p_AgL;gh0>j>p{0o}F*j0G0BcaWdUxjp z6RjDojnZ66{w;TjkykVY+Qmmh;hndnmM5(k%5f?IdeU}bn4twpdD6IpyuG^Y4R{X)N7S5`upAHYW5 zqbT8z#VQ1sA-&MAERCwoQoDb}R^GaZ*Umt%ZW|QPRY54a_SOm?|~f7Hilc@P{})a@P-Z>WVl)fpRU)> z$CR0lWv>*z0HDEWIy0PVmfthJHAF~J$&#Afl;1Y8|Au8Z%_b-$;!1xTSG*H!z9{Tj zi7>m73v{pDG?sH@r5B>8f{d9VZ31>mrF zt?M1EW!U$^*6SvIGlMOI!pu;}-_K8&zSShZnEC}DTPlhHo+sTzEE5h03H*i+?ANvW zxUS(4I$(H~&=sX*i2QZKGQ|eL1eQ#_J=*m6H~Na|u_Fb%FODwIdqNSBNk4h3px^?2 zKg-}04i$#6y@PxOjmiG$$r4zj zwfll0(6)lMJca?!9Z3mSm&tzXLZ0X*VErYLBwx`)M)B+#k(656#sI}y>uH4rK9Wd% zR3p0bQv<8>6V=AI8O6EpvBIgo7VR&9k?`3$^%l^6rsNJhuMK!>>41@PKN0MQEScXg zJvel&5DBO3Cy~by0R058V2$YE4x9Lq-`%t6XykK!fdVus`*KMNpz(T=*6As2z1?1W z0|Cw?U#wY=0Egrqc6vz|wT@TK&uO)4GX%}5Mql^cgOQfV*z8WKAMRYlFg1dy%NMxv zv`p!_mWKk{)9&%J209ItA%>P4w}=znW4`9j9s4aO8ylLTqh6R->ymC6c>FGL>S_Fm z^4-B!F?&8{Jv$O;;r`eWI@b9L09y=!_azEto};FqRkNYq#01qa`+uShVF4I@E(Www zSm)G7J4HW5ssY}Ql_GU_PubkhPvp5n))5+HW@Te$Bf@ppDe?votCvNkl7%nshK;%!Oq&JRS#N#OVd(YDCq(5%atIn^jbpo3?PQ&yhs>)d49+@6l&{tTlOlzi$QQu z@~A@F;^Dc>!lC#<8=ib2@}bPI`L)|iV&9F67~%9Hi@r3!Dx~=FXeN$wPEY#Y_=OWG zkR(YGl3BB<&99PP}Cc;X1#henQlMi>`?*|y=SN$0Mg9A z zcpImxXkYRH6%?)Mts-jpvbb%iT7wkrD9poq8T+$<=(HH~mPkS2F6l)J716;w8$iwA zzK%*0nefGYfRFcVnmN*ZlP}{RD%ZZAxKeJ|9yMI&6z$<(Qb`_W> zrsuZfee#CjsXoVL;E0{OD}{HzDcluCru+IjJORaawq0>jYb$Oc$Z*3WEq29v^IL&O zi6h;_mJWkHyqETh`j++@I5oREPm^L%pwmK_z{l##cS>S6pZOoD@?!G4*vK`z!<5Pa zkk5Q3fMtN`jFF8(d4(=~W`RiG|^YI7C99qiE8cBE17!aCJ9MKnXg+q-nA5T7%eJ*u?r?#A}Du=47xkmkX zHRjP^7*p3R(!Is`kHvJCg$V~gu2ooTlfkRj)NdCURkf-!vdKhCKR}}xOqOT(56O~D>1YAK_)HCTCW1ww$})=BU-kF z3P1~^PRCXRsV@VIgHFF8w!1yGb`%%bL!jFCfr!ck@xCwR0_q5Tg7*YvkOJ*}$O=V1 z1%}@bpXN`$V3xhaI#=~ZBZe=eRIWxApa>ibAKnW=03SqFE8Z+FOxtzG3B;ypA^_@Z z0hSB*(1~H!Dn1t1bU91vpJ=iD=;g1ii->S=e_Peh1*j_`ZHknJUB!u4DhH1H$ekQl|#0tK(tACk;DHLT4g_Lrrr-Tt|w0NE>_Aq43f957r zsoUxIo9&m{*I1^F!=2jT2;mZf@c)pF{`vmiZPy1k^qxh1oKoGqh+6#+f02-Z)xw*c zi9NHJlBp&`mTb+)tz?}#2#7JQh#;}bV(fvufGYwuj}H!rd0iC4Hl!7aZ#FUV7W%EOcMJT&i>w2Xke5iSK8ga86ed9SR!z~+)G_km_P_OTV_ zEHAx2W*Kc*v*OOO1szzSMSoT(@Zr*Jd|zq0Yqo>J zB`d*B(QI67G=V;H4E>#l&gE?xZa#r(_Hapxwo zvAOwj!!mwshM`*SOCpU?KfnORot>Hmw$zsKL<*N1KPm1`9Kh=;b{J^J#dX&Au2M$b z6XLEjtN3d$wxqB+sK9u0e#yz;h*xNWPHcX}B)%?tF3x zfwEWe6|_H=ve9~(Ntz&Z;YchRhU=^yw`PyULDiv^myyC`t6C^%hfq~@kPj!wvb{(iQFu!^0qGYgE9vDv$O7otw@CFE=G8^P~c~$MeFm};`mb2qaCt03M4Q+^#M1AKaRNfoKfpX<49LQfk8{C=!sys`B@HXJF(+VhN+!ujE zZS%s_Ls^d2d|;OwDNSkE9T{ke5XILr=2z%JVAcQ+3?ibaMQihiy;q?`vYpkoWj{{58m@+r z*sEz-rlw}ArD;1PSm0A-zkg={6uN)qZ*vUhxy(S}HT}YZLow-La9^YyslxI@)+Gl} zs^CscK>Sstc#hZ~!gL0-vW!}_m-wt_s9-f)Rue5#=MXB@->YpKiDdgkl`U`#-=A@S zt`7+xhxBwVPm#?51Lsg0!~EFzq&9t3QD&{@68U=7$o`s;@T<(rPCUyLLqs*NLEo z{va+jdICIK@Y$Rm;y6nn^*T#=Hk+srVI%?kHU0#pH4f zWRNJ(rUjA!N*=XYx%^%F8)3#LHs;U!&12Y=^wZl;rPQT3MD~CjXD~4vC$+*YU7-MK zfe$*qzpg8j+2lR7ZezJ`9ZF3X|515ub6Y7h4o&ve9WfMl{cLnVtS+N8Qt`d9YK%;t z!FeeC-?MweLg`0YO$AB^(b^|KpxwV<(fTE*N|#;nTkc1o*5gA*hN$kL$Yv^}!lg1X zw4&>VZEm4?PN2Z4ce=W>e1tvfFSQyK7=zxQ0}{Qn>_VLh4lYJX9^>Z5uUpewFMX6! z|NV4ijkcHa{d6ewRZ~D9-xTo6GkWPXsJAdhpV}}+1atS+6-my&TPdEUbu;F=TmniS zsE45T=`Y64#ccB~Wl00Q#oyswj=ux*wpQ-R0GACiJn&oe$R#L>795EbxhRrXgQt%i za64n>^(A3^?t#3nNEr4|kIZ#Q?>GOZb1$V+--hkigj>&B{iJ+ltsgg$niDk|{8<2T zHy{U^*jd(6(%#oPVMMp$0j%BjLkO3_e3_TQ}n&VN;74xxO_bhPEYM3RM1=2D}9D9Ma( zk_5qzcF6cu#EeeNWuvx@{WMlnId*lb;jOO$YY5bSP%TMBD8H|)7M|o5!WYtRau(fD zXNevv4J1<29T)>a>NYVsTU0QaJ}$w3YRP2~t(`(2iv~6W>;x`|PPU@!nGvGv@n(Za z%(B+92ANQ@ZD(qTez)Hye%sdjylJqifHDSjfan1oh(2fu(Y}ijmA!kJfu;9}nXuAF zZuDIs?EOU}pidi+pq7=%I$6U$bMu1-4 z2G(H5oLhfaHnr(i?)mL3P1m*Qf4^AZ^vv~9&lM9Q;^@S75PUKbP~Bk~floipd%x1g zSb2qABN9*>F6bV5jwIwIB92cN%#tUA%T<6T4dTfAAK7T{Jl5NKc8fo@z!z;0>~n8> zlyNdDsSoIrfuH-+gpVt`$Fg zU0G><$acjqj@A#^=`8i`-u)##{J$1%-hgix5GGk;vFiqIrHF4sFx#*=i8~4&AM@I@ zR-V|Wx39y*<-a9LS1f|9j~m`)D*InVYH3M)+72MNvuV6Z`UJKSxJqQD+7xOJMNVG6 z>eLV52pfDB_Whf7Q+nlqj`?c`(E@B%I!2bLTr-pvMQ4poac(s+nTVdOXB9Z!RKl!r zcv9;;MuszlqO5RLsc+DNksx(R5H}SmATp=06yl zC0C20ZG3-UeXgivJf8aP&|l@SF_7~J0HM*Xi~Jz^0W4K7e<=b4KLW;16+wH8=7z}P zzSsix6%L4u8K90qbpiB&>r~DirxnhvS90M{1y22&YMgiEa?JjmlX|aLK8kUjx=lu< zjV9f@Ml3n{v{^z@HSsArglRmPx%XK!eF2&ZOEYfdU0!#XdIf8y{--b}fEmYQh}vj_ zsX^oekeyQ^R3J1$|2eW&9n@QYMH>K|6A7>%OUv?ay?8?xKBWH$sg@3c8YLiejMd|h zo&buqlTN1~UBHtHDK3|j47QhY$9c^L;i<6}LRcpm4MT(V!n40)?gz>%qB#Pfk>ETh zM<)auyt8@g*T|JVKM)Eprd8n!h8~6b01zks#}{gth?8 z&Q>z&<4fIF|Nd?ulA;2nc4Ubt<&NjN(GkRc`ZPk1bAEJ%!(baw0VgucZeB~TS5@a! zDhdFbcjA{Of!~5vGJBmpDv%y3!NyKqrqk4%uPk)%e!^wSD>!5;I3zYN=^<-JbAAp; zYmL(R^Qn573iVIDqZx4G|26ElMa|$F8+xW!FB}%TSp20l6{ihv_5mxZl ztV>Y#5dO(#y~3M6Z&@I@1ig?t-w$9h?Dj$(%Q;2IG1<#L(rR`{8g?r$c%IJI%Qvn7 z?Z0er6QXTCFG@BH*t6)prg6}^Pm0TGK))Gq0G$C*4rJ;8dCKBT8%amfumIt^n3a2cd(Q_m)ZnebC6d&9c_CeD%XYOq2i@l{jBl5|5%YE$+L`nWW>XI|c1Uzg znB-MXVVT9%$=uiBpJ9M9`0v7j1BhfpS4R>SJ)Y!QaIH1YJgLloC>wgsAvE#Cs}cHQ zV&tp@-VH1X3>fu1*eTt}_TYfmW1aGTqu(d@lK@%E({JuC6MC`+U^Yqoz$SN{Y4y#< zmlK(ICDG+J?J*59zXdhXE%?wE(7d7cEZXC1f-H`{TP8g~37&Vs1e8v2%)m+kp2AlB zH(mvRu+9%}CIZ=OMvI78Kk+iYi7yFM*UZ2a^XMWaK7Iw|cqnaXFj-|M8)}tHu)o+A zz`*%Elb_Aac=55RwKKn^#!Yn?_6z8OqhQ~M`9&?+AHC)&DQJ3if~^NF`QPR8J?&l& z8??*i+v5f^>LUZ_#OpS3N2fy+1sN4!=K+lgP%QvyG!7R4SEvY-=2O6{Y?`9Kl&nRA zj27zrBtUU|WH$n`_L{V)6ixQi$FhSwB(LnnHNg#(pPCSA7#-#CmWIp9D?H%|SKkme z*O2lgz%W!09SK>m@mV1u6R*p2M*;&Lh4>D><`v&GBC0XL1MOQg%n)UsKe}JA234A( z37S za8|{D+~V+<>mrLMpygBsn4918HZwyKYXnl5cYCOXf?9`)7mnFbx-&g1-IxjU7V~># z!?|4nR;TJ;$dV@!UKow5?}+4fPuehLK|$;gdve=ZYOe&Pan(!m;CaW7$V-C67c@!^ zxexuur`bIXVA?t#0ju=g(^p_*A_^uvGGER4DHnQcRigbQUetmh31>+IrUFftoz#I* zFnHbefh9b#PKYxBH>$GuH4ntMDpMBa(QNM(W;yldLjX2kf_`fqcnoun0qBmjF4rGi zBA&Dy9kmhPv;x#~d#~u1@F{jn!H=d;+gk0e#@3wxLRinmvziLgC>UMOg-K7JJe?F4ho%8gO%(+NNqFy$ z4E4}>bhg?$uabQ=i&nTqGk0jltTQrGI7bVRh9r&BsLUh_0yj9`nFTs0r}`4n1A`~An%t0C!nMwk=mwYGRmD4_gZapdHm$>oNWc91CO zeTe?}#wlM7xw$Fjm%?rjdjuju?kG>RWnUc>|8!SD;?_4wVNSAMw>Qh%b2qie4>1A0 zmuUBBaJcDH%!P)dFR3cL=cA8rUUwyfv;C#21@)&8IJeVpJ0;$5*H;qQCoVBNJ#{R@ z7Jp!sBhL3Zpe@mBL5SHN#ccm(1ywBg=ZAE5X$GIiTD*7pPJf(pF0N1YEof)^&S2S9 zj=m-l)EcBgDz}SGtSl_?3&Mdg$;P+8o_yBKj>nM6;Fj`#oE0ENO4`=*2+DJ$#Ec|_ zfuRJEEQsy z`w$;F9BQw+f@;$(DD88~uUM*!H&V~}+D36*!&Of(xw_Cxoz^hVdiqs*!L8WZnns&7QpR({D`+ zTC_m@LYqJb&m%oSvH}v<5+r|o)LhiPT1zNx#Um!CnwF7A#=$OF~CmfK{7kCuN zgaF%3Jt3x6ka=K$XPz&!QQKVTPlSWm0|Z}|B*;TqP3kEfma{!+*nc*ItWdkV2);j5 zlKrEs*7_`xQfIV>Ty}6}H+=grD;mg4jkkYTl583G@vr(g{k`e{Oj2d>jP|;q`{{UD zvF>Zv7lguT`SR6!$qqiCsSmVqf31-vO8JEZg~lDw61tsdKm*!E-he<~ko+)f+(N11 zJQ;ZWxIQKv_eBhgIe(5aOs$^{W&0??4@=cx^eci)chxb~!3O|f`9896VbX<(Ez+^m z!b&#hXlA)T_!sAc%Roa8ZUh>N6Qa&nq%K>tDnKy;E#yC`4ld3&S|GT+nBWTVc~IFW z@h1lEzMT?+SuFc44r)(3;l`3w4rUyXf|CNcc>s4z7R!D?^2b>q3uwzC+@HPbv-Hx-8apCvjU6+qKh`X1>lpOTZX&5zDJoi9nDxDKLZTZ<)_l!E z=}aoY3i&f&eXwb{Z&MHNm0~VlwFfv?KZ*1*4%m;Q!|4rx!Sb)|>L=xft;K{}usY?# zNMp_yU-tTeUCW%OO3U)B!0+RUZ`SX!8p~lL{pE|8=vm(I+>=#OJmMl_3#6$ndH;!* zZ@Ple=_UK%YddvZck&hSEUEq)gkv0^oVq9GGELmuq^N#C#OH#ZF3-e=Sp$3g*|K5A zmzY6IPTKo+BG@10=whwc1NP$*zmm}#T-Y9HTk@=dh)#7nWqEdars;?+*bc|cXVQ-D z-zgKS%;(cM`&l3^s-dink^^)Yfqf6>Y?`0vV)Sx!t=HcHkkOo}()9hl(s2ziAo|02 z4*(9OY$e~Wz`$wfOp8IO^ASLDXJZ)HTY4&sfDUx8_JrNHs8ljZEo4eXItiW&6>V(P z9QpNYM{>{jIpDr)-Ey|O9O8G=1lbt9sXf=PuF}Nxqsrx&8u?vUd)gmq0kT0N_N2}< zW#xxpfufZ2MCDPIsRUNSYFu#XM6lkGt^P7z-e)}k6B>m;&tx}+aZORiz(tAUUy>H! zg9b06pCyI8ghacD!GK6x3BeK@__ySeN+dzr^6M>d`*ITn$4HdEqDOltH@@`==eWnK zQ0UyL6TWg)0L+&W*MKMhI9=Vb1Aj!sA?ac9 z67dAabbl$!P&XmHbv##vs_n_10X0xa1gY@x(?-(bcVrsZ5{22s)D%3tZoMU*rn4?3 zlHRWV3OK5H4>Z|ug)!;GeHZyucXvLy%hD@L7{&*ejw50+(AKiO5s}*#0;`gK{dCR=ucVsgyQKss*Y*tG zm8N>-5{Wm>zXo(fUUYPNB9U^fmr86ypb=yO`^Zk#g$;~*DRWIV9 zBLDq-STN`YNiPm8l{ zdxPm!WQw!@nX`xuytn@O!m;qh>a!LHinHIU0NNQF=)W18nkD`pzi0xz#qwSRn`eHe zI0-5F{b0{sqG8I;keWY-(pOsr(+S@4x1@I$FQV|G%>T5HL@E9mS6NdO*q9xKm#2fq z{API=9xp^$ce!%YE0-xB0;7UC%5hP=XLC_~l%S^qro~ELzV&c9w2Un&A7V&SaoGjTqFdc1-_xjF=rN)z%IO|Ud22O8n z4jlrbmZvLa!b9tR_XV-BFMny&9qfI1n;=oy@zO26&DN`yyjC$36(E5pjppQrL_--K zeQbfZiljirT8*+`(aK{oz#IA|5JFRCupyur$&?@be$|k0(sopJ$`1=!a=g!PxcVq9 z!&alnB|NJ;Pp7AW1~IkIqbX@j;NBcoSYyS+{T&2iI3IMr?l`ujwXng&`r+Wprf`t! z%j4w}ZJND33C~Hpti8;MSbS2^UtK|ZB(HN$d?cY0`#*U*NWDm2`OH)q&d%Kk;xRut zI1;er8I=VsykVi#CN_(sf-}trcCASgy-z0h2rUOo^*|xCyA$Q?=M*0sahi2&jQpf> zcKls;)Z%FnUXvJXpl*hta&J!1=J3Ge%CX|_y)xS`b*%>+!wpSIa#_7vtT0*H~Dc{Ld)iuS;Mvl|3NmMpj#=NNajI|GJPc{-= zS3V<|*uB4ep>kTk5N#X^MK``F37YEIM7IWD%^LWyMxygj3gdmK!g>IC6IoMKXI*h* zw#l)xe$UfWgJJ)Me!`4k5^jI3qb5?X0e=JkOT4RE)prmS~c6i<4zPP01aC&Q9WR;^<0S|_5Xe0@Mz^%Wye=4^IN8- zrZ+qg3w&8?14jG3pl49do!a%(YO`TcgTO5JfO(=&Pifu$poy3lp2FNdEM!S@nxFEIDEn3ys)YR!+*UcQO(8}o6kN#6M`IKz5Hk6M7;gy%T?ct?GX z)~jt|cY;T%c2f1nQHuF~3NzP2l^)}d6c)^qW`|v3-?WjVFP%8SN)ez0~1oz$w-Jg`Vet*^OyuM#5lRvo7C)h&Zv;tw!`L+vp0U=VE2&R{?UazUzeb5*+ zIVKg?crg8Hb{=gtb@J|n@Zd1@0ShT{WZT?Yfbl8j_{wZ^B;(QvkK3lEH6OvvK9|%O z>`Ktl#B2~&>a@UrfmXI{?;PFI&1a=9$*(-?U5Q8M@wFKF}_Q+%D6^aPL|2w z#RV;k5GtKK<|Yz><<-||FXZrPIAM=duL$@;Q`RRo z&$d(H8(^>i?hNt!rsPe2k^6JsuQHogBvO*V&bK2!_dN=Bl>!bSA;FMk)sNBbZmy$A zJFGFJ1wwYnpG8+SGDbL-yb8e$K!*v#^*;*WKNs+t*Vwgx0drw~dX=9O904mU7IsRY zSr}68l8TS#%5wws4M77c+kUrpxLRRzXGRfq8+_3I5x%2Z=-~+a3|| zZh^%Se)>)r>_`8}Z&Wt(znv0C-4wke714Y%J?YSZ(eTWAN66R#@#4vleAkYi_oS)w zx61mbtfG*O^HGg8ZFEEw;IglsWvyK0VFu<^Ni^ULQs}?!i#$e`$XHj-(xu=z8ZVkgrPMzpT-GS`-p-^@zTL8v>j95;l_if`lP$-!0*BwNckt znf_ahG%UrV_f>Yn^Ay;mxpC=w`k>VuBWl;10wqkL-{8wC>mu`z*z;!=4>F5X8oEjnr;LG= z0_iuoIIK`qQ7s-3fc3Uh@+UVi4ODzd$bUCAD5r3EE3EMTL-=t5lz03fTC2r9^J2;k zNVJRj%2VV&Y51%Vfc186S zzrIb?p)BkiC$v@1XSH?74x{yR_4Gq3tE8Rsws+e2pH{td&)DCP!!NqQ!8IJ_Z-s=- z*aUgj!3FPD;4*xs`XROo3bRe?nPok=~dSo3g-`Sbl#-kM6FzxDAt9hcg^_@q}QUOrCSNuG=aPSR5vcW z!Tptse;s5LE^qG2I|hVNmEvl?o@6$Vyd4<`XU)H^))f&`O7I# z+eQ!bv~i&DN<2sf5BHHPU?`g$1Zs3=thQ!uNpK)5Z-e!l;->)KCA*78$6YA#EwH)H z|BPk~-c*+&;6Dm0Vz;W1kt`NV){J*7X;kt(j4_Bk$V&D&(abPq7Q5ww_!Q#iFITeW zfuHj9B-7P2HRMHL0iIFyO3i5Dp zVwmOatNP6NbKoi82i;|YmM~Xx!7vEW{;6mbqwPp8Jz7( z?Dv(rAXwk7FR;Q@;|JxrXc(y(&V3<@D>EU0TAC*>`{|KW>=*5==ezpV_8Ym@-;PZz ze>FUvR$Wx>s41u(>Xay?G-^7$%_LMa21zCCrJZcY1u;YXpPX4DwduJL!~K>5~AL7sR}fmu5drTn#S?$A&;} z0>4-Mt|##qRDb1>V|q>|K!F%V%HB-P5B)~5Ss`^0lkC1p<2n{aNUZl^{YG_z7P2SJ zqV-2A>C&vPBQS&6L5fIOf){t* zQUg8VO>U!`^lW!*%+eC@^h> zD(J_2UPlAqWo6nLe)^Q&)KsBFWJ`O^H>h;(>xUyb^DXbjD}&;8#{tmgi|?-ll9O13N@Oist*8POe5sD*F2h@_H>u(~mZc5S`wUXQ z6cVxbQO?JUxwEVj{(2<&dym^vI}DjNVH6%+UQBzkgN@S-8{TWk;K#6 z&Z&}ilSO92NXba79Wdm%7G%A3wx&ze6JtNjfm&o zxA>EM&5j~s&PReQgzE9=bwa%cR0)NIW+)p5RxhcMl4*_@*+Wrz??b~u>bOGgBinHL zQgt?cPjQ+-P@M;)mo>7%57F4uE5gffzr4em*_!_L3QlnJR}5GSfhx&U>v+t1!bK>G z53~0~-NM0SM6-3%kP}mm9!SSTY}6pTS%K(%PP+lB!Ha`Rz}A28qF(!i0)d( z^mu>pXLrF1daRk)y3uvd7enZvVcZflaf zr?lmqJHZm~0J!0XcYG3b|As&Zz&ufJhOM^lH@&tlET^- zAui+0LTa|XMdN($7T%8n6TO#j`mH;);+y%J69uiiS6nk_?!s{22Y~Zv)=xTWK#db& zh`yg;;_+b;@{W@p&KAnx`8oRI#6P~7&lXsEW=>U$EQv19h3_b6e`y}PE5)OFq$aKN zkVU`tr|e33qb4zo3*1p!ySrSkYpIu?FsnAVXwhj@UpVW3{(Vs2tm~n0>SL>>_ zF9}y@A`0pvW6+|X|GtrqXrt%gK=E7+T8#$CCZ~mxjT<~+l1I5<=o$#wFLhQ3O*7{g zqo%E>d|*}rK$YTZ;QXWSdaB^ebl20>MsTap;C(%Rp~SVeiosM)37i`^d&|L~Wr7+l zsD&w&A+TdISxsb;m>p8e0u==J3#SWNumV-4{ZU=IAQzi9!%Yx9%z-noFz@LHh;yyB z0{&gYA`%HLuprN_J78$snnFYulX^vv-Ka?lXJoN5NPbz!ZgmL)OgXd5`mNOvEz>VS ztNR?}CB#Je{!4aO^B`n+jrMasImRu+H@yXIkK;;$Sn9kANMiFJi1^!9^^e#(oMDsy zmm3uD()a^-JJkLZvXaj0}KgTbNoS^V*@b! zlVh*P()FFWx#9IB{O#q}(+Y$=z{&U(vf6eU=UoO^Il$@s<^KdUZ)@YOs8y0gkq@=$ zIO{1ex__DMw59=_VTG(ZE6#EBzh8!0UImjXdhb&sBd*u}^}ntBfaVwH={|_RvvpSm z=h}vMhy7nRK{UXKCZl~7s6o%+W&O)mC`zUrI5LSh-zqoxZpVY`um9&5lD^2^23n!l zz?k8`KIa-7cs$}POx0JTfl=Upyz06|>%!;jz*dsCy|(hb!H4$hHE6H|9}1x$lSY6de4kK|G9j$)_@rE%yRahL;3=ET-253G22h? zRwKNe#p`G0`NyEMJU>k|&S>Ai7uc6GZ&an)2{8HYRazQeO4%LTZ*_6>>c5w0)O8KL z+D;U|{TN-GCql1A&H4W{_nl!;WlOuLFp9Q-1O+5DQF0Q=v5AtiC_w~7KoH3pMQDNu zO-_+d$;{<7QEXIFRYArHFe10HZW{(RMG+HYDR(9xpfxIl+_o4P+=* z7Z4SC*5h6^s1#IrqNSFmIjfNbVR&ki_Ce>n5RnT2+5IO7&)>kI2t8O5fXAl`fXM6G zlrLVtIZFVTQX)UpX{drD4afjIkcCbu{uzSvG!72sG5Z!|C0dBh2S%>84;)L;U%#ik zcir*tZT%}$CLjU31f~E$XO}jh#%%@XP;@qK5v8KCi`)RU)I4DnL-Eqz^dRR(`~G z9AeGQA9i6qwqlCSoD7kA)POwL+hI&mp#C&g!k}&L>Q#@Op&B|lJW_r1 zg-qtOW*Q`J6G3=O+T4N=x~`+(jrr1huGuQjTc7)r=>wg)*JQ#5wg?PzYEuR{^}U@E zok~41U~#+70}}>FLO{|BH7uG^D+m2I$WEg7%ykV7glzX3%;}TqUjar5<2{CCrT`Ju z`+KI(C9gD3c#?=HK2&lC?uUATYI6o+|u@Hj=t9#5rNH$8?f(i$39WWrnu&zM^dKm=H6eJ8RmobG3|JepT2U_Ew><_Q6&mIB@8{6t&Z z?YSF9Xa8ev1z8Pa21wU31il%%;uLf8b(vY9_EFTFHyKEb`g!4pfTo~MTekgFhN!+y z{FnK5+G692PgkdjzuG4zUTLH~EdEGI*}y}A!+BzaKq6Mgx?8kQaz21Z40$W2oxi}t z^tRZa4~VM3_)GX9ikQS47h$$vA=^I$SQwI}`V4MkDCwi1l7$?Xod#1RJ;K5d&UYvV z_wb1{5by38<*GT9VAjCvLZ3_*$O&0G&uSSErv)(d5@IaTiv+x<)Dk(2K<@q%&enJ2 zIKS(hNEFC41elZ|oUfDgfT7J<*F~)_y?rfb?KH!14DpEr-mP#Rke(PIJ8~^6eZ}mj z@=POeD~kdp$RZ?yd|}|D`~!$54h}@<1(`l@iv2IxoB$YZ;iRjedbCo^)@mk?Fa4Po zhtoBkzGGJ)kEPhUEuY<@>Bk2*Uo)3h-6oERi>(3Z|etg=$Hm21By&%kkS!uxVxY8P{=mX=?*m`+dlbi=V+Drhuh(I zu5E{fw#bu(?KEuyMJCV#W%wskcJtV*zY%idAt{V?7`vzY7TSZ;Zue@$+s!_74Qy6? z4?I|g=S~B>rmj&cvZ4qlA&2NI(JFc0UpXs{ji_~<#_2klsc4Oi?ym8XJH13#mwS{e zND7&C1!O37{oztE2FY~d0Be3JPWzR!a^TWws|%G%^*rWr`4aaNopSGflKkux7z!aF z@*ejJB>>Bn|3+jKR&GC_VXaHq3m`yGS$|w6PFQpf%Hbje=M{SmrcO8$ot(tW06`x0 zwT<>P#J~mZ5B~z~iPJak?7J~1Ed7~9cSa%3iKA9s{xdUuGL$6&((6Z23HB)w13U=@ z#uXD4niM9!Au97Jv)=6{(l|jUa}N@@#g%f8K_?@qJigUOT2E}ky?tWS(ua%BBsru! zcKUY7#$lkoQ<3~M>AiM}33We8*mHbj$3}C^Hg}u>;D9e+QD2Nm*>ah!8BU_o4Pfr6 z>}AYjNLnsaRzWMW$yNTMb_kq=D{n@!_ARqRJG%s&RL zogj86+g5zLm9XSbE;4Y-KB@Y>djggFhFGE5!7vwBG5?Y7BwZC<9+WC84u7)BPDJu&}&MEe7z#d z#S7c58Gg5N%b?O-#%U`ftm=s!F&H&BH0tZP+*$EU0KVlcLjbaF01I-%K!Xm)?_R$} z4+5w&=B1T{3_wRPniSPo^;xdpkO^D>81%qw80Ff3S20+RBvHI&DxZ%x z4$dSIWEwC2e#cl)VndFfB>y*4q(GzG+Z$#gqV!Fw9^lL`@k-04VDhDcTV`Qq@h~ve zpbi1_=ie-1ixK%+Hn(?hM$TzG=;F6rai-0l%QXs`Isi5vXLFkSsf}K=Y4#Pc;)!&y z^lNOO$Tux)YhUMZE#BQ>LY4dZZ6^J%*vz^phHwc)f$w8KDbU}vkaLJ@A?HDUOHL~1 z6)JXxlq2PY_|VTZTP~ZMN`gu6Cbu0L>dh=>r}0U3sT%Nb- zu_gBBvcA>vY3&>W2$K{DA#0G5fg%tM?omT{uxSvDM2X7T%d@6Ip0%awfpFva4AUFn7C&n>vZ1xf* z42Xkn-KH`N`w&tsgtC7^AhOg6u!1eFuhqmKHahWrCB-!%yq(`?u@=$ajXNr9c4z+fp|`4VZ?JaTF)nZ3ZD?lu5)yhDeL`iA z!~h|JjyGaz04i04cW28K|4^3g^wiqR!I?nH2ybRsi@oukvD@B++#0J5#7EUX05!o) z;3$Fnq-el;eSHJa8lA2DM`%X3jqL#_*OJ6CRt99XMAy#%rUH@Umxp5o%308*gW(5$ z9GD6qiwGlN>AmKZa@8K38q}T`t4Wad54zzGFS4)C(-J|@>t2Ty)dQ5eJRlL^aZkj6 zKo{#jPnBCiMBnm@J2U5Z@Bf}2F@!_-;g+&A?)m5C}^az$V5OO1wPgunGmAfKRR)LDOcFKM)anjnXW5GBa51>fO7-8m5z@Xs%C{&_j6 z9Nw>yov04@<#(i zYfKi==MfSc>4Yt32*rqo6g1mG1^&;+XSK~OFUOUY-H^GImks5$ope6hAWsyi&MRx; zkYQm-hw!r6(p58b!OY}Zf-T?o?iu1O0r%W(NIr%=Z7h6-U={o2_)QwYzvhDN8sJz- z(vbB=J&M|Om9Hx_c9SNT`SeR-bTj~mhb|&w%$SS6TcY_a?N;BmaZb8S)C^ZL+}3;D z`N4!sWd7oX)bC04=VYvpYCa!wz{O;`p$rb|p>)BOpE zs|#zsFE08Jr9H#lc9T?GIfLt6a5y-&giA1eIR5yH8X0xj&dh*G;IDee!1o+sMC%ss24rSX>z5N^6~ zI`Rziy?s5k#CP2D((%O9pGig=&a>0cydLRX+Ec{m%Kx3Ej63&208bW3wEjab$#hf$ zTNrg1dsh%BI#R1?o<<+CQ19pyG%@nL0|jBD{Tyg+nzhK&yu&ow1G>U`Kb|Z% zHLm5POZfQR^{5@d#WU^?AT4Q_NeB_$$QDLeb`i1#cU(zEG4i^Kyrg=56*zS4{`F*w z*da2lQliGZH0}E6o{@1EuPh|IqqO=igAMt;0*jOeKoTbmQ=+Q8w=`~|px#C4-tYf? zv6#g`Ritov?H$A4$6*mWdp=k0T;$u~@oS{I?vPJ&tX3#KklWeIjjK83D%*&R($KN^ zB}@MSdUdjcLVf+8SKw&PPRS#$hgaoFp}qUh=>X6RdtHH(PtVc>EoSE22en~8AFp+P zb9)y@*CsizcgM)x6-~_7TFAtTj7=iZ@%JrVzp>WuJ z)GpcJZG+9n&Ju2o2YP#lo)@@p%+*;_t~XuYj@tF+-~ax0e#eN#qe|ii3^AQFKQv_7 z5x2|Vez33cQPTHwc4xrQ-gN7JbBRIcq+Pf__ZJM2?+c~naN*A$MqA!~1(fwDKraJ% zx{%MMg+Ao5jq^0rat$&f3!rDqf9H3WM92+}#3!nLhrm0v#mlC+Qmcn;cqelf2Ed9% zM+u3maXyOb`@Su&div}Drq^}1Y<^~=v#73YIr%a&t6Cm=@MSy1UtkntvkZF{#z__OfeXB}M|OUA z>W8mQe=5M6kUc->WvWZvd&~n}@}0)*PgNQqhWs~`6jk|rfj0x=-0*xQo<}Mk9yexn zmZhB%nN{=o9RQz|lwDnxvs46?iGK{6Ehno0g+>t7yI%uzx0xu|Nd=+ zHF#kKy6iXZPl6<+VvZt3W?hU5z6j}ZRt*@P{j`WdQm+v};RH?vG%T=>DJFo}kq#&B zDtpoV$3z8$Z<^qCxYs*ZQ3+re>{DH-B?p=*kwTqB2>@mohF`EKQ6fO~IW0*px12YDwZne zoph-}0QPpoqH!88@Bk)jw)@fhH%Ro{hHAPPY^z9+xS020n4y{0!Ed#oFy;95_@^@U ziqSC-yqh_rX_B-!7oYWgQ45eDk9rmoC=Yv*=D+8Wb$#rge6`bP&edb!qg?DFIJ%@F zvBMa_rDyORLnqUJ2{2jf5==8&1c8PCdHg|Q<*#waB=VcLCkn&_(!B!GoCuU55DtrK zG5PBy2@F{iM2*q361XJUgCt4)_fGd^@%ZEGI6@Tc-~&`Y>wNa~h1}ccv|@@y<%=J7 zYFH(+=_ntExQ=}YtAsUVLt~|)R=MT1sx#Sd+lT_J^M0++f0{q|Uy^@mt_JXu)_nn* zg4;$*f4qP`I++xle;Y-B?sEt@b{>J90l5dz7yq4b1a#YfQbUm+la_0^2p`ocEO|@^ zIy8LOZ`PGOLUPa@W>29BBRq4S)!lrG2Uy(OK9>%cFm^ zVB>({7i@ktHo|)6HyYGy*c z=wV7L>od#!wDik9Tg-lhdAZ65`-k&o%k!z0n~oQuYv^FXLMuzYKL}sg_&RGZAeiI? z9CJ0y7fS?ZQSQU0^avT6GJs3nW@TNDgb_{dwf&WFcR)MCTMb) zvq(5;bEkn2iAfn|wzXwxF2$#%PJWQQ^4;I;c|YN#e^~=Vr=n&bS1Gz} zq%;5VQ3%wIR4dw+ym%qdmo4y)^fLk(wL|HJXZKpN8&GU`D;i$ajvC_!&wuFmQ}BqdXv)VXnHN4tuxWefAU*<2|A4w)AYRl;%xT){K~Y z*XXO-qg8x8Oh|d>{EgL01vR1FmAk%c;=PYo)nd-pdAjWjXjHuM9oh0`)`o&GsH+tK zqVEWAY^`f-wrj$kTId79ETchN=kB)vCN_VbA#LP4#*0y_&tg|ZI(F~)(qVqX6qVok zc=ICC)GNg6uO_X1?YQ$0mvf0*)H+agV6tnZ$Vduwrtvom3w@UL&kd`<>uy z;7TODsp5pN$d4cb&s;{BQgxtXp_?Eq zX1j9!>($M%V_ACOTyX&bbit$M0m%H~bP1(8apBI;ux%c4G1^NtxIein;#R$z9 zC!;qZYIYuL?nMRRJN|hr&G;aHcy>ETts9M-7ky`LIbaWaEM;%GTuqNP()ecY0o|>e zWYi%tnyR-(iL1u!kI>MNrCLF#toY$U+&$XUC2_L_cZ2Zz60;9|j(>Z@@G~+7{r9ha zJ!5(bwHI^Qi;Oi8Qi3i3n?qyn=Gan$W`nw{U^?i(G z?+^)s`dE9J9pkg65ze$Vz*hh%L&sJGL{5CfJr`eRmutj*3~vY{8iC)FXnXAs|I!ig z;L5YZ-wPyru^$x}8{hfiu75mgl3elo%~8^~3Z%t>@{jc&@90OfO-)3rjq6K(6lNkc z>bscs68+%p(}(?zze&r=+$Em1!!Hvx4Z1qe2q@BF!PP!Co|A|EaHT)o<+ZCwF~AT; z=JYf_in~)>x_~;=SLnL)VoQIZ<)*2~)+ysfisuo< zZPbxsaZ2bCAtP2(*P!)86+CM8EeWhQ?{=|>{CQjM)q@xQG##7un3rn{KRtTG=11gf zJAAv18zhs1)OAraOG{Csj+jppmNlh{gZZ*7TB4OGcYQcnYS7eJt}hBx z@@QY({v#4ZxJ!W8(5ehn9!lkmQXr8a_n30w-XZfRJ3Q+x?)53@M-SD!vr|0bh;a_l zESu6rx|gPWdks~t1%mjwuC)>prl)mFjC8BdH2T~)O58idOJTAF{u3se{PWI7IrSaG zajaF1??+DnidHl>7Tv|red^vwAifTucs~g%O-jJhUu6uNvN;zh{x0+NkA*vj$YIUd z3xvCrtGwqA_)8e&|Ln*|YIG7vkPOLdx`VLxPvxEH-Fvi+X3?{ITsFj>a%+mC{3>Tj zq!QZtI%(gNU(Z_bSW$M^u`GzTUD^s^#$ke`C%*pWUuqDdG1ERWu?OgprDb*^q@ic= z2=BevhpInd!5p*JfsCU?EHCr*#8$V4Fe=rBm3p1{4t{gDRz-CpJBzAr_pZm=VtAvIuB<4)b0@5$$J~@;5stP$9SfNTJ%tb-g3@+E&2I3zhj3FP z&-$=T0%fh7yo5r{)~ZPG9^h8EG%Zh7RAIBWhnbSJ(Gx8C_>>va0i zSJk3;vI4CWe|`C1^!=4`EYGF}+h*p7{fZ7ewmvBLoFZW_Z!A-Y%W#g(9Pvn@qPcUg zKbNDaw|c?CCrVk}&jV~SL$9-Zy!?#IFe;6dx%8bni!-%blU`heDt`tI{vzNm2jfC} zPYrz^#iDduTP|M^DW>YdnX2u`eM8%fAFRBVN0hgN)m!9YJaE4aP$eKmf}#X}Q-XP` z9-|AZ-g-?zhdfKvSDmi^AnaY@_4)Dbk#cpxd3BGDsKSKr3xv~^t&NKsn%hE#YC;Ci zx;eIA)GilZZCrvW4HTZaigm-1_ppwed^g`7us7M*c|Y?a_B?;2h+Z!?dgn0bdQ zgc(+3tgzyxW~t^j;=i5V%wGzSW1ucUG55NZnysGhq^ zyPXOkz{@wwFoN~-7TL%nLRT6*-Mrj5mk~Ai1oYc0&tlHLk0`n5)muiMx)?r&VKY>LjJRHomXyjUOy{`gcZeN#Kq(rIbSHAfOvk zG?Rib_d~S`_8+GWSWHqp{R~CPkL=@hj*hmL#uUQV!p^)qiY39*uc)r)%=l(~W&cc< zW*WcZIn9@-C+Ehq#z}uC63$+R@oAAZJ$d*6=e$T&P|=jEUK&G0_I0HL`Q?R<1#B(9 zr-aY6U0o-GHz}W}plH<~>-6_+Z%gt%%@?xQ6vR|QQP;Lu6#_OWUidt)YYR-;vW}KZ z{iKLWufDcrqhQA&fAf7|oQ0zJy?d($iJE+>5qx`8%AMu=YU`e*L-$kNovJ0;T_xBI z&|lzkk9(*KISgXG2#p9h&Gh)uz>?DWeXwXgbQyFr=U*JIO0FICAb#qTM9nj+nLFHPFZ~Bb6%|~F>q!1 z=NksMk!{a&9NynFiEL|qk(?Wuy-R~Wh=E+HH%xXEktIhewd`2j9(hEXQ_+h zWh=X94#&d#wjNV-kE9U_js(V#Z;DV)QC{hDiZ>NOPYCtpgruW#Ublpr(5gpKg!>p6 zBST-cIAOU($JW->NNEW<>0?!+STCeb^E;(J;(SZCT)N;%E|Fx#2Oi7L;zH3ae$$mR zS)?S{PGy)}k3x0(fjkkchc{%F$+G-&kJhvxM&Y*9rcUkS)Mfq4XZk8Q*mcplBF@4Z zWO(hQ5eAytVGn1w6WH#5X1Im!6nNP>x!X^n8Z3PC5^v~q&J~SCNrY<$w`%?wtr(7; zF@)M7M`on;r%cFKqCaPXq#C;3Bc&%<*OvK^<@K7%bewSN_sbUGZH4G5-{c2oLoksd zlPs!|rzanbSv6|Hg^$18Q^&6Z7r zS*?vh@H_%ORngnT-jVA$q8Ry|^5-O&rzDAnXKyyhdl?#ro@1r05@E-g7CbQe z8u1+IwJynZVb1DC39*IC%e6YoPtw?17y~Qb!=bNRm2SBmuRU#D+Sc~3OsSZJk}ltg z5q`c-dswhHtV+>+WaJup&+`bd7*Nk&1NQF8xrtb~D_8c2DQR=e#>Q;>dq-a{#{tWk zhmX&sKKj8TuN;jh&xKPtL04x?cFMcuUA|Ymnr?uMTvaoLUBHxMvb@3CfyW{*Mz7X_H|6{YWTxf$)4ps7*F+Ao0f&4cCbL5 z9>m`DsZScDqznu+BR568S@{+m+t8?BR^jIyuW(A`)VB?)wsn#DTG2pZq;Ma%qFx?Y zcJC#;by^C3u`$tID)UPDS#c=2-G+iqKz??qX=NMSqPg*Uf=fidhlmQl>Z@C4CUbhs zE4}kr**{54J&2tUYn_#T&U%B89ib8>taKtzja-OIh1r5^ZOgKr7r|E>3#AAF77IlIbQZNZLlfJ7 zSI{@3bP_kE5*6murmtbC;M(E42k->rXIWmSLuEt%LGX8@Owq&{*dy-*`)HOdDvMNx zEb(yK#92PsjFTlxgHbpLB#YKWlszgPnkf{oT;Q$v6ckaA^&^#$UtM3Q7uzc*D@>V5 zaiq4{xN}x>SEX+%2(v z)$T>G=#CD4@rMF;wkJ1r@0ow)RTpf}<`4?OpfzbtsuNt0R?Ko=G#5(pVY#nNty*Q(VX>pKTM{m*aFl!vp~v#4Jx^A) zawW%eU=sKC09KuLj7rUdoI>;Rl|IsV2dCx_vbXe*(E+W+e(9VD`ApqGO*-X%wuBh! zgCLZTr#4dMrJ1;@rDnnV8CI5myGKN(b0DTI8uRIPd>9Z&Gs1w+9~y6g8lVgDyN?4S z;DIr4!mAW~kHgTYzOdub)BVE^(D^V=N#Hy~98CK{PHfMe%Ej+|=KEvMPv3J3XJY!? zfJQlpv=v+N?LN9}p|I;p$PMJ!VDUtq@5RAKGMzBpx%@-3pBrD8#yGU2Tzch?Zfi=k zy~=&a8G_8lPRiZHM!+{G-e@x+Bx|xwq)Is+T-G+}@2-do(Yk-HCMs`%{CpTgH2kuL z(dOeu1}(1q!CGb(zCT3Nt1kM&`!emo$;Lk<=28Uwk01ZZP}9>RPP7P{Aj_*)k=VUM$hO2 z-(>yao7ugwBcaMmq`@g(Mw9braB%MS1+XJr2uIa?KX_X?Fn=FcY9M~4&9{& z?ux3S%^FEs4zt6R%dp)3CbPG*gk59;x4v_zkAaVgeTW;~>8begB295)a-QCV7TouS z%a9_nX8kLB|HVtJk%fWlm=qgsGGL`+NQ+^+t&#<=$9#8_zFbUK?46v4n}FOVoJ;;3 zh{J=iv$HR3I$zkGlgqe|ZFpTd5B5PiKa_=Hnd?f}7dSmgqKtb~6SqY$YR7#EYLBc8 z)^Y^APQ{gYqhKnV0H~z^PDJt9quqieuJyk1)NnguIX&@R*VNZd!$+9pt!{A1Evxia z)WVxbc5b}|{s55KTliox)z_9AA8PVSEv%(r$TOANA%GHc8GZ`DoImJfFI7qh{w zM1FkcOPN)1RjmAR1YDtZG;(@O?k@o01@qA;@Ch=skfdvr^zOVZt>r#~mBFOKEiIYS zYuaXO%R`iq;der#vdV>g0b{0Ocl6at9I=KDH)FnKrL z@FhdFWv{K9eO(Np5NA)Q6bVd4VqB ND9NeG7RcQ7`(GGQ`+EQY literal 0 HcmV?d00001 diff --git a/lambda-durable-webhook-sam-nodejs/example-pattern.json b/lambda-durable-webhook-sam-nodejs/example-pattern.json new file mode 100644 index 000000000..c21314a7c --- /dev/null +++ b/lambda-durable-webhook-sam-nodejs/example-pattern.json @@ -0,0 +1,70 @@ +{ + "title": "Webhook Receiver with AWS Lambda durable functions - NodeJS", + "description": "This serverless pattern demonstrates building a webhook receiver using AWS Lambda durable functions with automatic checkpointing and fault tolerance, implemented in Node.js", + "language": "Node.js", + "level": "200", + "framework": "AWS SAM", + "services": ["apigateway","lambda", "dynamoDB"], + "introBox": { + "headline": "How it works", + "text": [ + "This pattern demonstrates a serverless webhook receiver using AWS Lambda durable functions. When a webhook POST request arrives via API Gateway, it triggers a durable function that processes the webhook in 3 checkpointed steps: Validate → Process → Finalize. Each step is automatically checkpointed, allowing the workflow to resume from the last successful step if interrupted. The pattern provides immediate 202 response while processing continues in the background, stores execution state in DynamoDB with TTL, and offers real-time status tracking via a REST API." + ] + }, + "testing": { + "headline": "Testing", + "text": [ + "See the GitHub repo for detailed testing instructions." + ] + }, + "cleanup": { + "headline": "Cleanup", + "text": [ + "Delete the stack: sam delete." + ] + }, + "deploy": { + "text": [ + "sam build", + "sam deploy --guided" + ] + }, + "gitHub": { + "template": { + "repoURL": "https://github.com/aws-samples/serverless-patterns/tree/main/lambda-durable-webhook-sam-nodejs", + "templateURL":"serverless-patterns/lambda-durable-webhook-sam-nodejs", + "templateFile": "template.yaml", + "projectFolder": "lambda-durable-webhook-sam-nodejs" + } + }, + "resources": { + "headline": "Additional resources", + "bullets": [ + { + "text": "AWS Lambda durable functions Documentation", + "link": "https://docs.aws.amazon.com/lambda/latest/dg/durable-functions.html" + }, + { + "text": "Event Source Mappings with Lambda durable functions", + "link": "https://docs.aws.amazon.com/lambda/latest/dg/durable-invoking-esm.html" + }, + { + "text": "Lambda durable functions Best Practices", + "link": "https://docs.aws.amazon.com/lambda/latest/dg/durable-functions-best-practices.html" + }, + { + "text": "Node.js AWS SDK Documentation", + "link": "https://docs.aws.amazon.com/AWSJavaScriptSDK/latest/" + } + ] + }, + "authors": [ + { + "name": "Sahithi Ginjupalli", + "image": "https://drive.google.com/file/d/1YcKYuGz3LfzSxiwb2lWJfpyi49SbvOSr/view?usp=sharing", + "bio": "Cloud Engineer at AWS with a passion for diving deep into cloud and AI services to build innovative serverless applications.", + "linkedin": "ginjupalli-sahithi-37460a18b", + "twitter": "" + } + ] + } diff --git a/lambda-durable-webhook-sam-nodejs/src/status_query/index.js b/lambda-durable-webhook-sam-nodejs/src/status_query/index.js new file mode 100644 index 000000000..d1b08d816 --- /dev/null +++ b/lambda-durable-webhook-sam-nodejs/src/status_query/index.js @@ -0,0 +1,100 @@ +const { DynamoDBClient } = require('@aws-sdk/client-dynamodb'); +const { DynamoDBDocumentClient, GetCommand } = require('@aws-sdk/lib-dynamodb'); + +// Initialize AWS clients +const dynamodbClient = new DynamoDBClient({}); +const dynamodb = DynamoDBDocumentClient.from(dynamodbClient); + +/** + * Status query function for webhook processing + * Allows real-time status tracking via REST API + */ +exports.handler = async (event, context) => { + const executionToken = event.pathParameters?.executionToken; + const eventsTableName = process.env.EVENTS_TABLE_NAME; + + console.log(`Querying status for execution token: ${executionToken}`); + + if (!executionToken) { + return { + statusCode: 400, + headers: { + 'Content-Type': 'application/json', + 'Access-Control-Allow-Origin': '*' + }, + body: JSON.stringify({ + error: 'Missing executionToken parameter' + }) + }; + } + + try { + // Query execution state from DynamoDB + const result = await dynamodb.send(new GetCommand({ + TableName: eventsTableName, + Key: { executionToken } + })); + + if (!result.Item) { + return { + statusCode: 404, + headers: { + 'Content-Type': 'application/json', + 'Access-Control-Allow-Origin': '*' + }, + body: JSON.stringify({ + error: 'Execution token not found', + executionToken: executionToken + }) + }; + } + + // Format response based on current status + const execution = result.Item; + const response = { + executionToken: executionToken, + status: execution.status, + timestamp: execution.timestamp, + currentStep: execution.currentStep || 'unknown' + }; + + // Add additional fields based on status + if (execution.status === 'COMPLETED') { + response.result = execution.result; + response.completedAt = execution.completedAt; + } + + if (execution.status === 'FAILED') { + response.error = execution.error; + } + + if (execution.payload) { + response.originalPayload = execution.payload; + } + + return { + statusCode: 200, + headers: { + 'Content-Type': 'application/json', + 'Access-Control-Allow-Origin': '*' + }, + body: JSON.stringify(response) + }; + + } catch (error) { + console.error(`Error querying status for ${executionToken}:`, error.message); + + return { + statusCode: 500, + headers: { + 'Content-Type': 'application/json', + 'Access-Control-Allow-Origin': '*' + }, + body: JSON.stringify({ + error: 'Failed to query execution status', + executionToken: executionToken, + message: error.message + }) + }; + } +}; diff --git a/lambda-durable-webhook-sam-nodejs/src/status_query/package.json b/lambda-durable-webhook-sam-nodejs/src/status_query/package.json new file mode 100644 index 000000000..a8013300e --- /dev/null +++ b/lambda-durable-webhook-sam-nodejs/src/status_query/package.json @@ -0,0 +1,15 @@ +{ + "name": "status-query-function", + "version": "1.0.0", + "description": "Status query function for webhook processing", + "main": "index.js", + "scripts": { + "test": "echo \"Error: no test specified\" && exit 1" + }, + "dependencies": { + "@aws-sdk/client-dynamodb": "^3.700.0", + "@aws-sdk/lib-dynamodb": "^3.700.0" + }, + "author": "", + "license": "MIT" +} diff --git a/lambda-durable-webhook-sam-nodejs/src/webhook_processor/index.js b/lambda-durable-webhook-sam-nodejs/src/webhook_processor/index.js new file mode 100644 index 000000000..9357353ed --- /dev/null +++ b/lambda-durable-webhook-sam-nodejs/src/webhook_processor/index.js @@ -0,0 +1,230 @@ +import { withDurableExecution } from "@aws/durable-execution-sdk-js"; +import { DynamoDBClient } from '@aws-sdk/client-dynamodb'; +import { DynamoDBDocumentClient, PutCommand, UpdateCommand } from '@aws-sdk/lib-dynamodb'; +import { randomUUID } from 'crypto'; + +// Initialize AWS clients +const dynamodbClient = new DynamoDBClient({}); +const dynamodb = DynamoDBDocumentClient.from(dynamodbClient); + +export const handler = withDurableExecution( + async (event, context) => { + /** + * Webhook processor durable function with 3 checkpointed steps: + * 1. Validate webhook + * 2. Process business logic + * 3. Finalize processing + */ + + // Extract configuration from environment + const eventsTableName = process.env.EVENTS_TABLE_NAME; + const environment = process.env.ENVIRONMENT || 'dev'; + + // Parse the incoming webhook event + const webhookPayload = JSON.parse(event.body || '{}'); + + // Use executionToken from API Gateway or generate new one + const executionToken = event.executionToken || randomUUID(); + + console.log(`Processing webhook with execution token: ${executionToken}`); + console.log(`Webhook payload:`, JSON.stringify(webhookPayload, null, 2)); + + try { + // Store initial execution state + await dynamodb.send(new PutCommand({ + TableName: eventsTableName, + Item: { + executionToken: executionToken, + status: 'STARTED', + timestamp: Date.now(), + payload: webhookPayload, + ttl: Math.floor(Date.now() / 1000) + (7 * 24 * 60 * 60) // 7 days TTL + } + })); + + // Step 1: Validate webhook (checkpointed) + const validationResult = await context.step(async (stepContext) => { + stepContext.logger.info(`Validating webhook ${executionToken}`); + + // Update status to VALIDATING + await dynamodb.send(new UpdateCommand({ + TableName: eventsTableName, + Key: { executionToken }, + UpdateExpression: 'SET #status = :status, #step = :step', + ExpressionAttributeNames: { + '#status': 'status', + '#step': 'currentStep' + }, + ExpressionAttributeValues: { + ':status': 'VALIDATING', + ':step': 'validate' + } + })); + + // Call the separate webhook validator function + const { LambdaClient, InvokeCommand } = await import('@aws-sdk/client-lambda'); + const lambdaClient = new LambdaClient({}); + + const validatorFunctionArn = process.env.WEBHOOK_VALIDATOR_FUNCTION_ARN; + const invokeResponse = await lambdaClient.send(new InvokeCommand({ + FunctionName: validatorFunctionArn, + Payload: JSON.stringify({ + payload: webhookPayload, + executionToken: executionToken + }) + })); + + const validatorResult = JSON.parse(new TextDecoder().decode(invokeResponse.Payload)); + + if (!validatorResult.isValid) { + await dynamodb.send(new UpdateCommand({ + TableName: eventsTableName, + Key: { executionToken }, + UpdateExpression: 'SET #status = :status, #error = :error', + ExpressionAttributeNames: { + '#status': 'status', + '#error': 'error' + }, + ExpressionAttributeValues: { + ':status': 'FAILED', + ':error': 'Validation failed: ' + validatorResult.errors.join(', ') + } + })); + + return { + executionToken: executionToken, + status: "failed", + error: `Validation failed: ${validatorResult.errors.join(', ')}` + }; + } + + return { + executionToken: executionToken, + status: "validated", + payloadType: validatorResult.payloadType, + validatedAt: validatorResult.validatedAt + }; + }); + + // Check if validation failed + if (validationResult.status === "failed") { + return { + statusCode: 400, + body: JSON.stringify({ + executionToken: executionToken, + status: 'FAILED', + error: validationResult.error + }) + }; + } + + // Step 2: Process business logic (checkpointed) + const processingResult = await context.step(async (stepContext) => { + stepContext.logger.info(`Processing webhook ${executionToken}`); + + // Update status to PROCESSING + await dynamodb.send(new UpdateCommand({ + TableName: eventsTableName, + Key: { executionToken }, + UpdateExpression: 'SET #status = :status, #step = :step', + ExpressionAttributeNames: { + '#status': 'status', + '#step': 'currentStep' + }, + ExpressionAttributeValues: { + ':status': 'PROCESSING', + ':step': 'process' + } + })); + + // Simulate business processing logic - customize this based on your needs + return { + executionToken: executionToken, + status: "processed", + originalPayload: webhookPayload, + businessResult: `Processed webhook of type: ${webhookPayload.type || 'unknown'}`, + dataTransformed: webhookPayload.data ? JSON.stringify(webhookPayload.data).toUpperCase() : null, + processedAt: new Date().toISOString(), + metadata: { + processedBy: 'webhook-processor-nodejs', + version: '1.0.0' + } + }; + }); + + // Step 3: Finalize processing (checkpointed) + const finalResult = await context.step(async (stepContext) => { + stepContext.logger.info(`Finalizing webhook ${executionToken}`); + + // Update final status to COMPLETED + await dynamodb.send(new UpdateCommand({ + TableName: eventsTableName, + Key: { executionToken }, + UpdateExpression: 'SET #status = :status, #step = :step, #result = :result, #completedAt = :completedAt', + ExpressionAttributeNames: { + '#status': 'status', + '#step': 'currentStep', + '#result': 'result', + '#completedAt': 'completedAt' + }, + ExpressionAttributeValues: { + ':status': 'COMPLETED', + ':step': 'finalize', + ':result': processingResult, + ':completedAt': new Date().toISOString() + } + })); + + return { + executionToken: executionToken, + status: "completed", + finalResult: processingResult + }; + }); + + // Return final response + return { + statusCode: 202, + headers: { + 'Content-Type': 'application/json' + }, + body: JSON.stringify({ + message: 'Webhook processing completed successfully', + executionToken: executionToken, + status: 'COMPLETED', + result: finalResult + }) + }; + + } catch (error) { + console.error(`Error processing webhook ${executionToken}:`, error.message); + + // Update error state + await dynamodb.send(new UpdateCommand({ + TableName: eventsTableName, + Key: { executionToken }, + UpdateExpression: 'SET #status = :status, #error = :error', + ExpressionAttributeNames: { + '#status': 'status', + '#error': 'error' + }, + ExpressionAttributeValues: { + ':status': 'FAILED', + ':error': error.message + } + })); + + return { + statusCode: 500, + headers: { + 'Content-Type': 'application/json' + }, + body: JSON.stringify({ + message: 'Webhook processing failed', + executionToken: executionToken, + error: error.message + }) + }; + } + } +); diff --git a/lambda-durable-webhook-sam-nodejs/src/webhook_processor/package.json b/lambda-durable-webhook-sam-nodejs/src/webhook_processor/package.json new file mode 100644 index 000000000..751bd6573 --- /dev/null +++ b/lambda-durable-webhook-sam-nodejs/src/webhook_processor/package.json @@ -0,0 +1,18 @@ +{ + "name": "webhook-processor-function", + "version": "1.0.0", + "description": "Main webhook processor durable function", + "main": "index.js", + "scripts": { + "test": "echo \"Error: no test specified\" && exit 1" + }, + "dependencies": { + "@aws-sdk/client-dynamodb": "^3.700.0", + "@aws-sdk/client-lambda": "^3.700.0", + "@aws-sdk/lib-dynamodb": "^3.700.0", + "@aws/durable-execution-sdk-js": "^1.0.0" + }, + "type": "module", + "author": "", + "license": "MIT" +} diff --git a/lambda-durable-webhook-sam-nodejs/src/webhook_validator/index.js b/lambda-durable-webhook-sam-nodejs/src/webhook_validator/index.js new file mode 100644 index 000000000..dd14c94f8 --- /dev/null +++ b/lambda-durable-webhook-sam-nodejs/src/webhook_validator/index.js @@ -0,0 +1,62 @@ +/** + * Webhook validator function that validates incoming webhook payloads + * Called by the durable webhook processor function + */ +exports.handler = async (event, context) => { + const { payload, executionToken } = event; + + console.log(`Validating webhook for execution: ${executionToken}`); + + try { + // Basic validation rules - customize based on your webhook requirements + const validationErrors = []; + + // Check if payload exists + if (!payload || typeof payload !== 'object') { + validationErrors.push('Payload is required and must be an object'); + } else { + // Check required fields - customize these based on your webhook schema + if (!payload.type) { + validationErrors.push('Payload must include a "type" field'); + } + + // Validate webhook signature/auth if needed + // if (!payload.signature) { + // validationErrors.push('Webhook signature is required'); + // } + + // Add custom validation logic here + if (payload.type && !['order', 'payment', 'user', 'system'].includes(payload.type)) { + validationErrors.push('Invalid webhook type. Must be one of: order, payment, user, system'); + } + + // Validate payload structure based on type + if (payload.type === 'order' && !payload.orderId) { + validationErrors.push('Order webhooks must include orderId'); + } + + if (payload.type === 'payment' && !payload.transactionId) { + validationErrors.push('Payment webhooks must include transactionId'); + } + } + + const isValid = validationErrors.length === 0; + + return { + isValid: isValid, + executionToken: executionToken, + errors: validationErrors, + validatedAt: new Date().toISOString(), + payloadType: payload?.type || 'unknown' + }; + + } catch (error) { + console.error(`Error validating webhook ${executionToken}:`, error.message); + return { + isValid: false, + executionToken: executionToken, + errors: [`Validation error: ${error.message}`], + error: error.message + }; + } +}; diff --git a/lambda-durable-webhook-sam-nodejs/src/webhook_validator/package.json b/lambda-durable-webhook-sam-nodejs/src/webhook_validator/package.json new file mode 100644 index 000000000..929ff79d5 --- /dev/null +++ b/lambda-durable-webhook-sam-nodejs/src/webhook_validator/package.json @@ -0,0 +1,12 @@ +{ + "name": "webhook-validator-function", + "version": "1.0.0", + "description": "Webhook validation function", + "main": "index.js", + "scripts": { + "test": "echo \"Error: no test specified\" && exit 1" + }, + "dependencies": {}, + "author": "", + "license": "MIT" +} diff --git a/lambda-durable-webhook-sam-nodejs/template.yaml b/lambda-durable-webhook-sam-nodejs/template.yaml new file mode 100644 index 000000000..7d772809c --- /dev/null +++ b/lambda-durable-webhook-sam-nodejs/template.yaml @@ -0,0 +1,247 @@ +AWSTemplateFormatVersion: '2010-09-09' +Transform: AWS::Serverless-2016-10-31 +Description: 'Webhook Receiver Pattern using AWS Lambda durable functions with Python - NodeJS version' + +Globals: + Function: + Timeout: 900 + MemorySize: 512 + Runtime: nodejs24.x + +Parameters: + Environment: + Type: String + Default: dev + Description: Environment name + WebhookSecret: + Type: String + Default: '' + Description: Secret key for HMAC signature validation (optional) + NoEcho: true + +Resources: + # DynamoDB table for storing webhook execution events + WebhookEventsTable: + Type: AWS::DynamoDB::Table + Properties: + TableName: !Sub '${Environment}-webhook-events' + BillingMode: PAY_PER_REQUEST + AttributeDefinitions: + - AttributeName: executionToken + AttributeType: S + - AttributeName: timestamp + AttributeType: N + KeySchema: + - AttributeName: executionToken + KeyType: HASH + TimeToLiveSpecification: + AttributeName: ttl + Enabled: true + GlobalSecondaryIndexes: + - IndexName: TimestampIndex + KeySchema: + - AttributeName: timestamp + KeyType: HASH + Projection: + ProjectionType: ALL + + # Webhook Validator Function + WebhookValidatorFunction: + Type: AWS::Serverless::Function + Properties: + FunctionName: !Sub '${Environment}-webhook-validator' + CodeUri: src/webhook_validator/ + Handler: index.handler + + # Main Webhook Processor Lambda durable function + WebhookProcessorFunction: + Type: AWS::Serverless::Function + Properties: + FunctionName: !Sub '${Environment}-webhook-processor' + CodeUri: src/webhook_processor/ + Handler: index.handler + Timeout: 900 + DurableConfig: + ExecutionTimeout: 3600 + RetentionPeriodInDays: 7 + Policies: + Statement: + - Effect: Allow + Action: + - lambda:CheckpointDurableExecutions + - lambda:GetDurableExecutionState + Resource: !Sub 'arn:aws:lambda:${AWS::Region}:${AWS::AccountId}:function:${Environment}-webhook-processor' + - Effect: Allow + Action: + - lambda:InvokeFunction + Resource: + - !GetAtt WebhookValidatorFunction.Arn + - Effect: Allow + Action: + - dynamodb:GetItem + - dynamodb:PutItem + - dynamodb:UpdateItem + - dynamodb:DeleteItem + - dynamodb:Query + - dynamodb:Scan + Resource: + - !GetAtt WebhookEventsTable.Arn + - !Sub '${WebhookEventsTable.Arn}/index/*' + AutoPublishAlias: live + Environment: + Variables: + WEBHOOK_VALIDATOR_FUNCTION_ARN: !GetAtt WebhookValidatorFunction.Arn + EVENTS_TABLE_NAME: !Ref WebhookEventsTable + ENVIRONMENT: !Ref Environment + WEBHOOK_SECRET: !Ref WebhookSecret + + # API Gateway Method for Webhook (Asynchronous Invocation) + WebhookMethod: + Type: AWS::ApiGateway::Method + Properties: + RestApiId: !Ref WebhookApi + ResourceId: !Ref WebhookResource + HttpMethod: POST + AuthorizationType: NONE + Integration: + Type: AWS + IntegrationHttpMethod: POST + Uri: !Sub 'arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${WebhookProcessorFunction.Arn}:live/invocations' + RequestParameters: + integration.request.header.X-Amz-Invocation-Type: "'Event'" + RequestTemplates: + application/json: | + #set($executionToken = $context.requestId) + { + "body": "$util.escapeJavaScript($input.body)", + "executionToken": "$executionToken" + } + IntegrationResponses: + - StatusCode: 202 + ResponseTemplates: + application/json: | + { + "message": "Webhook accepted for processing", + "executionToken": "$context.requestId" + } + MethodResponses: + - StatusCode: 202 + + # API Gateway Resource for Webhook + WebhookResource: + Type: AWS::ApiGateway::Resource + Properties: + RestApiId: !Ref WebhookApi + ParentId: !GetAtt WebhookApi.RootResourceId + PathPart: webhook + + # Lambda Permission for API Gateway + WebhookLambdaPermission: + Type: AWS::Lambda::Permission + DependsOn: WebhookProcessorFunctionAliaslive + Properties: + FunctionName: !Sub '${WebhookProcessorFunction.Arn}:live' + Action: lambda:InvokeFunction + Principal: apigateway.amazonaws.com + SourceArn: !Sub 'arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${WebhookApi}/*/*' + + # Status Query Function (without Events - using manual API Gateway) + StatusQueryFunction: + Type: AWS::Serverless::Function + Properties: + FunctionName: !Sub '${Environment}-status-query' + CodeUri: src/status_query/ + Handler: index.handler + Timeout: 30 + Environment: + Variables: + EVENTS_TABLE_NAME: !Ref WebhookEventsTable + Policies: + - DynamoDBReadPolicy: + TableName: !Ref WebhookEventsTable + + # API Gateway Resource for Status Query + StatusResource: + Type: AWS::ApiGateway::Resource + Properties: + RestApiId: !Ref WebhookApi + ParentId: !GetAtt WebhookApi.RootResourceId + PathPart: status + + # API Gateway Resource for Status Token + StatusTokenResource: + Type: AWS::ApiGateway::Resource + Properties: + RestApiId: !Ref WebhookApi + ParentId: !Ref StatusResource + PathPart: '{executionToken}' + + # API Gateway Method for Status Query + StatusQueryMethod: + Type: AWS::ApiGateway::Method + Properties: + RestApiId: !Ref WebhookApi + ResourceId: !Ref StatusTokenResource + HttpMethod: GET + AuthorizationType: NONE + Integration: + Type: AWS_PROXY + IntegrationHttpMethod: POST + Uri: !Sub 'arn:aws:apigateway:${AWS::Region}:lambda:path/2015-03-31/functions/${StatusQueryFunction.Arn}/invocations' + MethodResponses: + - StatusCode: 200 + + # Lambda Permission for Status Query + StatusQueryLambdaPermission: + Type: AWS::Lambda::Permission + Properties: + FunctionName: !GetAtt StatusQueryFunction.Arn + Action: lambda:InvokeFunction + Principal: apigateway.amazonaws.com + SourceArn: !Sub 'arn:aws:execute-api:${AWS::Region}:${AWS::AccountId}:${WebhookApi}/*/*' + + # API Gateway REST API + WebhookApi: + Type: AWS::ApiGateway::RestApi + Properties: + Name: !Sub '${Environment}-webhook-api' + Description: 'Webhook API for durable functions' + EndpointConfiguration: + Types: + - REGIONAL + + # API Gateway Stage + WebhookApiStage: + Type: AWS::ApiGateway::Stage + Properties: + RestApiId: !Ref WebhookApi + DeploymentId: !Ref WebhookApiDeployment + StageName: prod + Description: 'Production stage with executionToken' + + # API Gateway Deployment (depends on all methods) + WebhookApiDeployment: + Type: AWS::ApiGateway::Deployment + DependsOn: + - WebhookMethod + - StatusQueryMethod + Properties: + RestApiId: !Ref WebhookApi + Description: !Sub 'Production stage ${AWS::StackName}' + +Outputs: + WebhookApiUrl: + Description: 'API Gateway endpoint URL for webhook' + Value: !Sub 'https://${WebhookApi}.execute-api.${AWS::Region}.amazonaws.com/prod/webhook' + + StatusQueryApiUrl: + Description: 'API Gateway endpoint URL for status queries' + Value: !Sub 'https://${WebhookApi}.execute-api.${AWS::Region}.amazonaws.com/prod/status/{executionToken}' + + WebhookEventsTable: + Description: 'DynamoDB Table for webhook events' + Value: !Ref WebhookEventsTable + + WebhookProcessorFunctionArn: + Description: 'Webhook Processor Lambda durable function ARN' + Value: !GetAtt WebhookProcessorFunction.Arn From 21edd559499b2f44b5c7cd74bad26bf6b995eb9c Mon Sep 17 00:00:00 2001 From: Sahithi Date: Tue, 3 Mar 2026 12:27:29 +0530 Subject: [PATCH 2/4] Updated README.md --- lambda-durable-webhook-sam-nodejs/README.md | 161 ++++---------------- 1 file changed, 29 insertions(+), 132 deletions(-) diff --git a/lambda-durable-webhook-sam-nodejs/README.md b/lambda-durable-webhook-sam-nodejs/README.md index 792882433..3ff630b04 100644 --- a/lambda-durable-webhook-sam-nodejs/README.md +++ b/lambda-durable-webhook-sam-nodejs/README.md @@ -2,21 +2,30 @@ This serverless pattern demonstrates a serverless webhook receiver using AWS Lambda durable functions with NodeJS. The pattern receives webhook events via API Gateway, processes them durably with automatic checkpointing, and provides status query capabilities. -## How It Works +Learn more about this pattern at Serverless Land Patterns: https://serverlessland.com/testing/patterns/lambda-durable-webhook-sam-nodejs + +To Learn more about Lambda durable functions: +- [AWS Lambda durable functions Documentation](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions.html) +- [Lambda durable functions Best Practices](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions-best-practices.html) + +Important: this application uses various AWS services and there are costs associated with these services after the Free Tier usage - please see the [AWS Pricing page](https://aws.amazon.com/pricing/) for details. You are responsible for any AWS costs incurred. No warranty is implied in this example. -This pattern demonstrates a serverless webhook receiver using AWS Lambda durable functions. The pattern receives webhook events via API Gateway, processes them durably with automatic checkpointing, and provides status query capabilities. +## Requirements -### Webhook Processing Workflow (3 Steps) +* [Create an AWS account](https://portal.aws.amazon.com/gp/aws/developer/registration/index.html) if you do not already have one and log in. The IAM user that you use must have sufficient permissions to make necessary AWS service calls and manage AWS resources. +* [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/install-cliv2.html) installed and configured +* [Git Installed](https://git-scm.com/book/en/v2/Getting-Started-Installing-Git) +* [AWS Serverless Application Model](https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/serverless-sam-cli-install.html) (AWS SAM) installed -The durable function processes webhooks in 3 checkpointed steps: +## How It Works + +This pattern demonstrates a serverless webhook receiver using AWS Lambda durable functions. The pattern receives webhook events via API Gateway, processes them durably with automatic checkpointing, and provides status query capabilities. The durable function processes webhooks in 3 checkpointed steps: 1. **Validate** - Verify webhook payload and structure 2. **Process** - Execute business logic on webhook data 3. **Finalize** - Complete processing and update final status -✅ Each step is automatically checkpointed, allowing the workflow to resume from the last successful step if interrupted. - -## Key Features +This pattern acheives the following key features: - ✅ **Automatic Checkpointing** - Each processing step is checkpointed automatically - ✅ **Failure Recovery** - Resumes from last checkpoint on failure @@ -28,24 +37,6 @@ The durable function processes webhooks in 3 checkpointed steps: ⚠️ **Important:** Please check the [AWS documentation](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions.html) for regions currently supported by AWS Lambda durable functions. -Learn more about this pattern at Serverless Land Patterns: https://serverlessland.com/patterns/lambda-durable-webhook-sam-python - -## Prerequisites - -- [AWS CLI v2](https://docs.aws.amazon.com/cli/latest/userguide/install-cliv2.html) installed and configured -- [AWS SAM CLI](https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/serverless-sam-cli-install.html) installed -- [Node.js 24.x](https://nodejs.org/en/download/) runtime installed -- [Docker](https://docs.docker.com/get-docker/) (for containerized builds) - -## Required IAM Permissions - -Your AWS CLI user/role needs the following permissions for deployment: - -- **CloudFormation**: `cloudformation:DescribeStacks`, `cloudformation:DeleteStack` -- **Lambda**: `lambda:CreateFunction`, `lambda:InvokeFunction`, `lambda:GetFunction` -- **DynamoDB**: `dynamodb:Scan`, `dynamodb:GetItem`, `dynamodb:PutItem` -- **CloudWatch Logs**: `logs:DescribeLogGroups`, `logs:FilterLogEvents`, `logs:GetLogEvents`, `logs:TailLogEvents` - ## Deployment 1. **Build the application**: @@ -54,7 +45,9 @@ Your AWS CLI user/role needs the following permissions for deployment: ``` 2. **Deploy to AWS**: - ```bash +Plese enter required `WebhookSecret` + +```bash sam deploy --guided ``` @@ -62,7 +55,9 @@ Your AWS CLI user/role needs the following permissions for deployment: - `WebhookApiUrl`: Use this for sending webhook POST requests - `StatusQueryApiUrl`: Use this for querying execution status -3. **Test the webhook**: +## Testing +To test the set-up, utilize the below curl command by replacing the WebhookApiUrl copied from the above step: + ```bash # Send a test webhook curl -X POST \ @@ -74,7 +69,8 @@ Your AWS CLI user/role needs the following permissions for deployment: }' ``` -4. **Query webhook status**: +Once the Webhook is submitted, to query the status of webhook, use the following curl command by replacing the StatusQueryApiUrl: + ```bash # Get execution status (use executionToken from webhook response) curl @@ -84,119 +80,20 @@ Your AWS CLI user/role needs the following permissions for deployment: - Webhook returns 202 with `executionToken` - Status query shows progression: `STARTED` → `VALIDATING` → `PROCESSING` → `COMPLETED` - Execution state persists in DynamoDB with TTL - - Failed webhooks show `FAILED` status with error details + +To simulate a failure scenario, perform the below curl command: ## Architecture ![Architecture Diagram](architecture.png) -## Components - -### 1. Webhook Processor Function (`src/webhook_processor/`) -- **Lambda durable function**: Main orchestrator with automatic checkpointing -- **3-Step Processing**: Validate → Process → Finalize -- **API Gateway Integration**: Receives POST requests at `/webhook` -- **State Persistence**: Stores execution state in DynamoDB -- **Dependencies**: `@aws-sdk/client-dynamodb`, `@aws-sdk/lib-dynamodb`, `aws-durable-execution-sdk` - -### 2. Webhook Validator Function (`src/webhook_validator/`) -- **Validation Logic**: Validates webhook payload structure and required fields -- **Extensible**: Easy to add custom validation rules -- **Dependencies**: None (pure Node.js) - -### 3. Status Query Function (`src/status_query/`) -- **Real-time Status**: Query execution status via GET `/status/{executionToken}` -- **CORS Enabled**: Supports browser-based queries -- **Dependencies**: `@aws-sdk/client-dynamodb`, `@aws-sdk/lib-dynamodb` - -## API Endpoints - -### POST /webhook -Receives webhook events for processing. - -**Request:** -```json -{ - "type": "order", - "orderId": "123456", - "data": {"amount": 100} -} -``` - -**Response (202):** -```json -{ - "message": "Webhook processing completed successfully", - "executionToken": "dev-esm-abc123", - "status": "COMPLETED", - "result": { ... } -} -``` - -### GET /status/{executionToken} -Query processing status of a webhook. - -**Response (200):** -```json -{ - "executionToken": "dev-esm-abc123", - "status": "COMPLETED", - "timestamp": "2023-...", - "currentStep": "finalize", - "result": { ... } -} -``` - -## Monitoring - -- **CloudWatch Logs**: Execution tracking for all functions -- **DynamoDB**: Persistent execution state with TTL (7 days) -- **API Gateway**: Request/response logging and metrics - -## Configuration - -Key environment variables: -- `ENVIRONMENT`: Deployment environment (dev/prod) -- `EVENTS_TABLE_NAME`: DynamoDB table for execution state -- `WEBHOOK_VALIDATOR_FUNCTION_ARN`: ARN of validation function -- `WEBHOOK_SECRET`: Optional secret for HMAC signature validation - -## Error Handling - -- **Automatic Retries**: Built-in retry logic with exponential backoff -- **State Recovery**: Resume from last checkpoint on failure -- **Error Tracking**: Failed executions stored with error details -- **Timeout Handling**: Configurable execution timeout (default: 1 hour) - -## Cost Optimization - -- **Pay-per-execution**: Only charged for active processing time -- **Automatic scaling**: Scales based on incoming webhook volume -- **TTL Storage**: Automatic cleanup of old execution records - -## NodeJS Implementation Notes - -- **Node.js 24.x runtime** (latest LTS) -- **AWS SDK v3** with modular imports for optimal performance -- **Modern async/await** syntax throughout -- **Command pattern** for DynamoDB operations -- **Individual package.json** files for each function - -## Security Considerations - -- **CORS Configuration**: Configurable for your domain requirements -- **Webhook Secrets**: Optional HMAC signature validation support -- **IAM Permissions**: Principle of least privilege for all functions ## Cleanup ```bash sam delete ``` +---- +Copyright 2026 Amazon.com, Inc. or its affiliates. All Rights Reserved. -## Learn More - -- [AWS Lambda durable functions Documentation](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions.html) -- [Lambda durable functions Best Practices](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions-best-practices.html) -- [AWS SAM CLI Documentation](https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/serverless-sam-cli-install.html) -- [Node.js AWS SDK v3 Documentation](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/) +SPDX-License-Identifier: MIT-0 From f4c94e1ed3da0d5e4d6cc1c5f49228f0d733fff8 Mon Sep 17 00:00:00 2001 From: Sahithi Ginjupalli Date: Wed, 4 Mar 2026 21:52:12 +0530 Subject: [PATCH 3/4] Updated README --- lambda-durable-webhook-sam-nodejs/README.md | 37 ++++-- .../src/webhook_processor/index.js | 116 +++++++++++------- .../template.yaml | 9 +- 3 files changed, 101 insertions(+), 61 deletions(-) diff --git a/lambda-durable-webhook-sam-nodejs/README.md b/lambda-durable-webhook-sam-nodejs/README.md index 3ff630b04..0e43d8f2c 100644 --- a/lambda-durable-webhook-sam-nodejs/README.md +++ b/lambda-durable-webhook-sam-nodejs/README.md @@ -17,6 +17,10 @@ Important: this application uses various AWS services and there are costs associ * [Git Installed](https://git-scm.com/book/en/v2/Getting-Started-Installing-Git) * [AWS Serverless Application Model](https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/serverless-sam-cli-install.html) (AWS SAM) installed +## Architecture + +![Architecture Diagram](architecture.png) + ## How It Works This pattern demonstrates a serverless webhook receiver using AWS Lambda durable functions. The pattern receives webhook events via API Gateway, processes them durably with automatic checkpointing, and provides status query capabilities. The durable function processes webhooks in 3 checkpointed steps: @@ -27,15 +31,17 @@ This pattern demonstrates a serverless webhook receiver using AWS Lambda durable This pattern acheives the following key features: -- ✅ **Automatic Checkpointing** - Each processing step is checkpointed automatically -- ✅ **Failure Recovery** - Resumes from last checkpoint on failure -- ✅ **Asynchronous Processing** - Immediate 202 response, processing in background -- ✅ **State Persistence** - Execution state stored in DynamoDB with TTL -- ✅ **Status Query API** - Real-time status tracking via REST API +- **Automatic Checkpointing** - Each processing step is checkpointed automatically +- **Failure Recovery** - Resumes from last checkpoint on failure +- **Asynchronous Processing** - Immediate 202 response, processing in background +- **State Persistence** - Execution state stored in DynamoDB with TTL +- **Status Query API** - Real-time status tracking via REST API + +**Note:** Each step writes status updates to DynamoDB before its main work. These writes are idempotent, so retries are safe. During replay, the DynamoDB status reflects the last successfully written state—not the current replay position. Status queries should treat intermediate states as "in progress." ## Important -⚠️ **Important:** Please check the [AWS documentation](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions.html) for regions currently supported by AWS Lambda durable functions. +**Important:** Please check the [AWS documentation](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions.html) for regions currently supported by AWS Lambda durable functions. ## Deployment @@ -81,12 +87,25 @@ Once the Webhook is submitted, to query the status of webhook, use the following - Status query shows progression: `STARTED` → `VALIDATING` → `PROCESSING` → `COMPLETED` - Execution state persists in DynamoDB with TTL -To simulate a failure scenario, perform the below curl command: +To simulate a validation failure, send an invalid payload (empty or missing required fields): -## Architecture + ```bash + # Send an invalid webhook (empty payload triggers validation failure) + curl -X POST \ + -H "Content-Type: application/json" \ + -d '{}' + ``` -![Architecture Diagram](architecture.png) +Query the status to see the failure: + + ```bash + curl + ``` + **Failure indicators:** + - Status query shows `FAILED` status + - Error message indicates validation failure reason + - Execution state persists in DynamoDB for debugging ## Cleanup diff --git a/lambda-durable-webhook-sam-nodejs/src/webhook_processor/index.js b/lambda-durable-webhook-sam-nodejs/src/webhook_processor/index.js index 9357353ed..fde5bf768 100644 --- a/lambda-durable-webhook-sam-nodejs/src/webhook_processor/index.js +++ b/lambda-durable-webhook-sam-nodejs/src/webhook_processor/index.js @@ -1,11 +1,13 @@ import { withDurableExecution } from "@aws/durable-execution-sdk-js"; import { DynamoDBClient } from '@aws-sdk/client-dynamodb'; import { DynamoDBDocumentClient, PutCommand, UpdateCommand } from '@aws-sdk/lib-dynamodb'; +import { LambdaClient, InvokeCommand } from '@aws-sdk/client-lambda'; import { randomUUID } from 'crypto'; -// Initialize AWS clients +// Initialize AWS clients at module scope for connection reuse const dynamodbClient = new DynamoDBClient({}); const dynamodb = DynamoDBDocumentClient.from(dynamodbClient); +const lambdaClient = new LambdaClient({}); export const handler = withDurableExecution( async (event, context) => { @@ -14,6 +16,11 @@ export const handler = withDurableExecution( * 1. Validate webhook * 2. Process business logic * 3. Finalize processing + * + * Design Note: Each step writes a status update to DynamoDB before doing its main work. + * DynamoDB UpdateCommand is naturally idempotent for these status writes. + * The DynamoDB status reflects the last successfully written status, not necessarily + * the current replay position. */ // Extract configuration from environment @@ -23,27 +30,38 @@ export const handler = withDurableExecution( // Parse the incoming webhook event const webhookPayload = JSON.parse(event.body || '{}'); - // Use executionToken from API Gateway or generate new one - const executionToken = event.executionToken || randomUUID(); - - console.log(`Processing webhook with execution token: ${executionToken}`); - console.log(`Webhook payload:`, JSON.stringify(webhookPayload, null, 2)); - - try { + // Step 0: Initialize execution (checkpointed) - handles non-deterministic operations + const initResult = await context.step('initialize-execution', async (stepContext) => { + // Generate executionToken inside step to ensure determinism on replay + const token = event.executionToken || randomUUID(); + const startTimestamp = Date.now(); + + stepContext.logger.info(`Initializing webhook processing with token: ${token}`); + stepContext.logger.info(`Webhook payload: ${JSON.stringify(webhookPayload)}`); + // Store initial execution state await dynamodb.send(new PutCommand({ TableName: eventsTableName, Item: { - executionToken: executionToken, + executionToken: token, status: 'STARTED', - timestamp: Date.now(), + timestamp: startTimestamp, payload: webhookPayload, - ttl: Math.floor(Date.now() / 1000) + (7 * 24 * 60 * 60) // 7 days TTL + ttl: Math.floor(startTimestamp / 1000) + (7 * 24 * 60 * 60) // 7 days TTL } })); + + return { + executionToken: token, + startTimestamp: startTimestamp + }; + }); + + const executionToken = initResult.executionToken; + try { // Step 1: Validate webhook (checkpointed) - const validationResult = await context.step(async (stepContext) => { + const validationResult = await context.step('validate-webhook', async (stepContext) => { stepContext.logger.info(`Validating webhook ${executionToken}`); // Update status to VALIDATING @@ -62,12 +80,10 @@ export const handler = withDurableExecution( })); // Call the separate webhook validator function - const { LambdaClient, InvokeCommand } = await import('@aws-sdk/client-lambda'); - const lambdaClient = new LambdaClient({}); - const validatorFunctionArn = process.env.WEBHOOK_VALIDATOR_FUNCTION_ARN; const invokeResponse = await lambdaClient.send(new InvokeCommand({ FunctionName: validatorFunctionArn, + InvocationType: 'RequestResponse', Payload: JSON.stringify({ payload: webhookPayload, executionToken: executionToken @@ -119,9 +135,12 @@ export const handler = withDurableExecution( } // Step 2: Process business logic (checkpointed) - const processingResult = await context.step(async (stepContext) => { + const processingResult = await context.step('process-webhook', async (stepContext) => { stepContext.logger.info(`Processing webhook ${executionToken}`); + // Generate timestamp once at start of step for consistency + const processedAt = new Date().toISOString(); + // Update status to PROCESSING await dynamodb.send(new UpdateCommand({ TableName: eventsTableName, @@ -138,24 +157,22 @@ export const handler = withDurableExecution( })); // Simulate business processing logic - customize this based on your needs + // Keep state minimal - store IDs and references, not full objects return { - executionToken: executionToken, + executionToken, status: "processed", - originalPayload: webhookPayload, - businessResult: `Processed webhook of type: ${webhookPayload.type || 'unknown'}`, - dataTransformed: webhookPayload.data ? JSON.stringify(webhookPayload.data).toUpperCase() : null, - processedAt: new Date().toISOString(), - metadata: { - processedBy: 'webhook-processor-nodejs', - version: '1.0.0' - } + payloadType: webhookPayload.type || 'unknown', + processedAt: processedAt }; }); // Step 3: Finalize processing (checkpointed) - const finalResult = await context.step(async (stepContext) => { + const finalResult = await context.step('finalize-webhook', async (stepContext) => { stepContext.logger.info(`Finalizing webhook ${executionToken}`); + // Generate timestamp once at start of step for consistency + const completedAt = new Date().toISOString(); + // Update final status to COMPLETED await dynamodb.send(new UpdateCommand({ TableName: eventsTableName, @@ -171,14 +188,14 @@ export const handler = withDurableExecution( ':status': 'COMPLETED', ':step': 'finalize', ':result': processingResult, - ':completedAt': new Date().toISOString() + ':completedAt': completedAt } })); return { executionToken: executionToken, status: "completed", - finalResult: processingResult + completedAt: completedAt }; }); @@ -197,22 +214,29 @@ export const handler = withDurableExecution( }; } catch (error) { - console.error(`Error processing webhook ${executionToken}:`, error.message); - - // Update error state - await dynamodb.send(new UpdateCommand({ - TableName: eventsTableName, - Key: { executionToken }, - UpdateExpression: 'SET #status = :status, #error = :error', - ExpressionAttributeNames: { - '#status': 'status', - '#error': 'error' - }, - ExpressionAttributeValues: { - ':status': 'FAILED', - ':error': error.message - } - })); + // Wrap error handling in a step to ensure proper checkpoint behavior + const errorResult = await context.step('handle-error', async (stepContext) => { + stepContext.logger.error(`Error processing webhook ${executionToken}: ${error.message}`); + + await dynamodb.send(new UpdateCommand({ + TableName: eventsTableName, + Key: { executionToken }, + UpdateExpression: 'SET #status = :status, #error = :error', + ExpressionAttributeNames: { + '#status': 'status', + '#error': 'error' + }, + ExpressionAttributeValues: { + ':status': 'FAILED', + ':error': error.message + } + })); + + return { + status: 'FAILED', + error: error.message + }; + }); return { statusCode: 500, @@ -222,9 +246,9 @@ export const handler = withDurableExecution( body: JSON.stringify({ message: 'Webhook processing failed', executionToken: executionToken, - error: error.message + ...errorResult }) }; } } -); +); \ No newline at end of file diff --git a/lambda-durable-webhook-sam-nodejs/template.yaml b/lambda-durable-webhook-sam-nodejs/template.yaml index 7d772809c..65e616b6c 100644 --- a/lambda-durable-webhook-sam-nodejs/template.yaml +++ b/lambda-durable-webhook-sam-nodejs/template.yaml @@ -65,12 +65,9 @@ Resources: ExecutionTimeout: 3600 RetentionPeriodInDays: 7 Policies: - Statement: - - Effect: Allow - Action: - - lambda:CheckpointDurableExecutions - - lambda:GetDurableExecutionState - Resource: !Sub 'arn:aws:lambda:${AWS::Region}:${AWS::AccountId}:function:${Environment}-webhook-processor' + - arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole + - arn:aws:iam::aws:policy/service-role/AWSLambdaBasicDurableExecutionRolePolicy + - Statement: - Effect: Allow Action: - lambda:InvokeFunction From 6dcb8f1499818e3f4ab129ce412a49a4bd5ea3b6 Mon Sep 17 00:00:00 2001 From: Sahithi Date: Wed, 4 Mar 2026 21:54:35 +0530 Subject: [PATCH 4/4] Update README.md --- lambda-durable-webhook-sam-nodejs/README.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/lambda-durable-webhook-sam-nodejs/README.md b/lambda-durable-webhook-sam-nodejs/README.md index 0e43d8f2c..5622d4a03 100644 --- a/lambda-durable-webhook-sam-nodejs/README.md +++ b/lambda-durable-webhook-sam-nodejs/README.md @@ -39,8 +39,6 @@ This pattern acheives the following key features: **Note:** Each step writes status updates to DynamoDB before its main work. These writes are idempotent, so retries are safe. During replay, the DynamoDB status reflects the last successfully written state—not the current replay position. Status queries should treat intermediate states as "in progress." -## Important - **Important:** Please check the [AWS documentation](https://docs.aws.amazon.com/lambda/latest/dg/durable-functions.html) for regions currently supported by AWS Lambda durable functions. ## Deployment