test(mcp): fix stale bridge-hook, applied-guardrails and pagination-revoke integration tests (#45008)

* test(mcp): fix stale bridge-hook, applied-guardrails and pagination-revoke integration tests

* test(mcp): clear the spare direct grant when restoring the access-group policy

---------

Co-authored-by: yuneng <yuneng@berri.ai>
This commit is contained in:
devin-ai-integration[bot] 2026-10-07 11:28:14 -07:00 • committed by GitHub
parent 2c1847f8a2
commit 0586289817
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 11 additions and 10 deletions

View file

@ -468,7 +468,7 @@ def test_generic_sink_and_native_hooks_receive_listed_metadata_on_typed_keys_wit
assert row["status"] == "success", row
assert _tool_metadata(row)["name"] == "lookup", row
metadata: Final = row["metadata"]
assert isinstance(metadata, dict) and metadata["applied_guardrails"] == [hooks_rig.guardrail], metadata
assert isinstance(metadata, dict) and metadata["applied_guardrails"].count(hooks_rig.guardrail) == 1, metadata
def test_pre_call_mask_reaches_the_peer_and_post_call_mask_reaches_the_caller_on_one_call_id(

View file

@ -934,7 +934,7 @@ def test_identical_nonstream_repeat_is_a_cache_hit_without_new_model_peer_or_hoo
assert _spend_row(key, repeat.call_id)["cache_hit"] == "True"
def test_messages_bridge_hook_keeps_the_base_shape_without_request_local_metadata(hooked: Hooked) -> None:
def test_messages_bridge_hook_sees_the_definition_the_request_served(hooked: Hooked) -> None:
with _bridge_rig(hooked, "messages") as rig:
key: Final = _bridge_key(rig)
marker: Final = "m" + uuid.uuid4().hex
@ -943,6 +943,6 @@ def test_messages_bridge_hook_keeps_the_base_shape_without_request_local_metadat
assert found.status_code == 200, found.text
blocked: Final = rig.post(key, probe, [rig.mcp("lookup")])
assert blocked.status_code == 200, blocked.text
assert _echoed(JSON_VALUE.validate_json(blocked.content)) == COLD, blocked.text
assert _echoed(JSON_VALUE.validate_json(blocked.content)) == _served(LOOKUP), blocked.text
assert rig.peer_calls() == (("lookup", {"query": marker}),)
assert rig.hook_messages(marker) == (f"Tool: lookup\nArguments: {dict(query=marker)}",)

View file

@ -1,7 +1,7 @@
import asyncio
from contextlib import asynccontextmanager
from pathlib import Path
from typing import Literal
from typing import Final, Literal
import httpx
import pytest
@ -138,7 +138,7 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m
assert os.environ.get("DATABASE_URL"), "This integration case requires disposable-database access"
async def exercise(a, b, peer, identity, owner, stranger, policy):
async def exercise(a, b, peer, identity, owner, stranger, policy, spare):
owner_a = Gateway(a.client, owner, peer.url)
owner_b = Gateway(b.client, owner, peer.url)
stranger_b = Gateway(b.client, stranger, peer.url)
@ -165,9 +165,9 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m
{
"key": owner,
**(
{"access_group_ids": []}
{"access_group_ids": [], "object_permission": {"mcp_servers": [spare]}}
if grant == "access_group"
else {"object_permission": {"mcp_servers": ["no-mcp-servers"]}}
else {"object_permission": {"mcp_servers": [spare]}}
),
},
)
@ -177,7 +177,7 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m
with pytest.raises(MCPError, match="fresh listing"):
await getattr(session, method)(params=PaginatedRequestParams(cursor=first.next_cursor))
assert not any(call["body"].get("method", "").endswith("/list") for call in peer.drain())
a.post("/key/update", {"key": owner, **policy})
a.post("/key/update", {"key": owner, "object_permission": {"mcp_servers": []}, **policy})
changed = a.request("PUT", "/v1/mcp/server", {"server_id": identity, "description": "new catalog generation"})
assert changed.status_code == 202, changed.text
for method, first in first_pages.items():
@ -207,7 +207,7 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m
capture_output=True,
text=True,
)
with paginated_mcp_peer() as peer, httpx.Client() as client:
with paginated_mcp_peer() as peer, paginated_mcp_peer() as spare_peer, httpx.Client() as client:
seed = Gateway(client, "sk-pagination-test", peer.url)
config = tmp_path / "database-proxy.yaml"
config.write_text(
@ -231,6 +231,7 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m
a.scenario() as scenario,
):
identity = register_mcp(scenario, peer, "pages")
spare: Final = register_mcp(scenario, spare_peer, "spare")
group = a.request(
"POST",
"/v1/access_group",
@ -248,7 +249,7 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m
owner = scenario.key(**policy)
stranger = scenario.key(object_permission={"mcp_servers": [identity]})
assert owner != stranger
asyncio.run(exercise(a, b, peer, identity, owner, stranger, policy))
asyncio.run(exercise(a, b, peer, identity, owner, stranger, policy, spare))
@pytest.mark.parametrize("changed", ["key", "snapshot"])