From 18c47bcf79826926954d74c77a420120a96b3434 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Wed, 6 May 2026 15:37:46 -0700 Subject: [PATCH] test(agent_session_endpoints): add view_only_admin_client fixture Used by test_view_only_admin_no_writes.py to exercise every mutating endpoint as a view-only admin and confirm they get 403. --- .../proxy/agent_session_endpoints/conftest.py | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/tests/test_litellm/proxy/agent_session_endpoints/conftest.py b/tests/test_litellm/proxy/agent_session_endpoints/conftest.py index 3ff63facb82..7c76336608e 100644 --- a/tests/test_litellm/proxy/agent_session_endpoints/conftest.py +++ b/tests/test_litellm/proxy/agent_session_endpoints/conftest.py @@ -270,6 +270,19 @@ def admin_client(fake_prisma_client): return _build_test_app(LitellmUserRoles.PROXY_ADMIN, api_key="sk-admin-key") +@pytest.fixture +def view_only_admin_client(fake_prisma_client): + """TestClient where caller is a view-only proxy admin. + + View-only admins are allowed to READ across tenants (so the support + UI can render any tenant's resources) but MUST NOT be allowed to + mutate state on any tenant's resources — see ``assert_caller_can_mutate``. + """ + return _build_test_app( + LitellmUserRoles.PROXY_ADMIN_VIEW_ONLY, api_key="sk-view-only-admin" + ) + + @pytest.fixture def other_tenant_client(fake_prisma_client): """TestClient where caller is a different tenant. Used for