diff --git a/tests/integration/mcp/test_mcp_accounting_guardrails.py b/tests/integration/mcp/test_mcp_accounting_guardrails.py index a276718c280..0d1c707d1ff 100644 --- a/tests/integration/mcp/test_mcp_accounting_guardrails.py +++ b/tests/integration/mcp/test_mcp_accounting_guardrails.py @@ -468,7 +468,7 @@ def test_generic_sink_and_native_hooks_receive_listed_metadata_on_typed_keys_wit assert row["status"] == "success", row assert _tool_metadata(row)["name"] == "lookup", row metadata: Final = row["metadata"] - assert isinstance(metadata, dict) and metadata["applied_guardrails"] == [hooks_rig.guardrail], metadata + assert isinstance(metadata, dict) and metadata["applied_guardrails"].count(hooks_rig.guardrail) == 1, metadata def test_pre_call_mask_reaches_the_peer_and_post_call_mask_reaches_the_caller_on_one_call_id( diff --git a/tests/integration/mcp/test_mcp_llm_endpoints.py b/tests/integration/mcp/test_mcp_llm_endpoints.py index af3bff1fd8b..9e946dfc253 100644 --- a/tests/integration/mcp/test_mcp_llm_endpoints.py +++ b/tests/integration/mcp/test_mcp_llm_endpoints.py @@ -934,7 +934,7 @@ def test_identical_nonstream_repeat_is_a_cache_hit_without_new_model_peer_or_hoo assert _spend_row(key, repeat.call_id)["cache_hit"] == "True" -def test_messages_bridge_hook_keeps_the_base_shape_without_request_local_metadata(hooked: Hooked) -> None: +def test_messages_bridge_hook_sees_the_definition_the_request_served(hooked: Hooked) -> None: with _bridge_rig(hooked, "messages") as rig: key: Final = _bridge_key(rig) marker: Final = "m" + uuid.uuid4().hex @@ -943,6 +943,6 @@ def test_messages_bridge_hook_keeps_the_base_shape_without_request_local_metadat assert found.status_code == 200, found.text blocked: Final = rig.post(key, probe, [rig.mcp("lookup")]) assert blocked.status_code == 200, blocked.text - assert _echoed(JSON_VALUE.validate_json(blocked.content)) == COLD, blocked.text + assert _echoed(JSON_VALUE.validate_json(blocked.content)) == _served(LOOKUP), blocked.text assert rig.peer_calls() == (("lookup", {"query": marker}),) assert rig.hook_messages(marker) == (f"Tool: lookup\nArguments: {dict(query=marker)}",) diff --git a/tests/integration/mcp/test_pagination.py b/tests/integration/mcp/test_pagination.py index 84689232038..b8b28bd39ce 100644 --- a/tests/integration/mcp/test_pagination.py +++ b/tests/integration/mcp/test_pagination.py @@ -1,7 +1,7 @@ import asyncio from contextlib import asynccontextmanager from pathlib import Path -from typing import Literal +from typing import Final, Literal import httpx import pytest @@ -138,7 +138,7 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m assert os.environ.get("DATABASE_URL"), "This integration case requires disposable-database access" - async def exercise(a, b, peer, identity, owner, stranger, policy): + async def exercise(a, b, peer, identity, owner, stranger, policy, spare): owner_a = Gateway(a.client, owner, peer.url) owner_b = Gateway(b.client, owner, peer.url) stranger_b = Gateway(b.client, stranger, peer.url) @@ -165,9 +165,9 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m { "key": owner, **( - {"access_group_ids": []} + {"access_group_ids": [], "object_permission": {"mcp_servers": [spare]}} if grant == "access_group" - else {"object_permission": {"mcp_servers": ["no-mcp-servers"]}} + else {"object_permission": {"mcp_servers": [spare]}} ), }, ) @@ -177,7 +177,7 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m with pytest.raises(MCPError, match="fresh listing"): await getattr(session, method)(params=PaginatedRequestParams(cursor=first.next_cursor)) assert not any(call["body"].get("method", "").endswith("/list") for call in peer.drain()) - a.post("/key/update", {"key": owner, **policy}) + a.post("/key/update", {"key": owner, "object_permission": {"mcp_servers": []}, **policy}) changed = a.request("PUT", "/v1/mcp/server", {"server_id": identity, "description": "new catalog generation"}) assert changed.status_code == 202, changed.text for method, first in first_pages.items(): @@ -207,7 +207,7 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m capture_output=True, text=True, ) - with paginated_mcp_peer() as peer, httpx.Client() as client: + with paginated_mcp_peer() as peer, paginated_mcp_peer() as spare_peer, httpx.Client() as client: seed = Gateway(client, "sk-pagination-test", peer.url) config = tmp_path / "database-proxy.yaml" config.write_text( @@ -231,6 +231,7 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m a.scenario() as scenario, ): identity = register_mcp(scenario, peer, "pages") + spare: Final = register_mcp(scenario, spare_peer, "spare") group = a.request( "POST", "/v1/access_group", @@ -248,7 +249,7 @@ def test_continuations_reauthorize_and_reject_registry_changes(tmp_path: Path, m owner = scenario.key(**policy) stranger = scenario.key(object_permission={"mcp_servers": [identity]}) assert owner != stranger - asyncio.run(exercise(a, b, peer, identity, owner, stranger, policy)) + asyncio.run(exercise(a, b, peer, identity, owner, stranger, policy, spare)) @pytest.mark.parametrize("changed", ["key", "snapshot"])