test(agent_session_endpoints): add view_only_admin_client fixture

Used by test_view_only_admin_no_writes.py to exercise every
mutating endpoint as a view-only admin and confirm they get 403.
This commit is contained in:
Ishaan Jaffer 2026-05-06 15:37:46 -07:00
parent d908e9940b
commit 18c47bcf79
No known key found for this signature in database

View file

@ -270,6 +270,19 @@ def admin_client(fake_prisma_client):
return _build_test_app(LitellmUserRoles.PROXY_ADMIN, api_key="sk-admin-key")
@pytest.fixture
def view_only_admin_client(fake_prisma_client):
"""TestClient where caller is a view-only proxy admin.
View-only admins are allowed to READ across tenants (so the support
UI can render any tenant's resources) but MUST NOT be allowed to
mutate state on any tenant's resources — see ``assert_caller_can_mutate``.
"""
return _build_test_app(
LitellmUserRoles.PROXY_ADMIN_VIEW_ONLY, api_key="sk-view-only-admin"
)
@pytest.fixture
def other_tenant_client(fake_prisma_client):
"""TestClient where caller is a different tenant. Used for