From 343909d63298311994ac4f41d5c083c30ce7a875 Mon Sep 17 00:00:00 2001 From: Yassin Kortam Date: Thu, 11 Jun 2026 09:52:18 -0700 Subject: [PATCH] test(auth_v2): cover deep SCIM path under keyMatch and drop stale comment Add a platform_admin POST /scim/v2/Groups assertion alongside the existing /scim/v2/Users DELETE so the multi-segment grant is pinned on a second deep path, and correct the stale keyMatch2 comment to keyMatch. --- tests/test_litellm/proxy/auth_v2/test_rbac.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/tests/test_litellm/proxy/auth_v2/test_rbac.py b/tests/test_litellm/proxy/auth_v2/test_rbac.py index 69f557762c4..7f6ca77f4b1 100644 --- a/tests/test_litellm/proxy/auth_v2/test_rbac.py +++ b/tests/test_litellm/proxy/auth_v2/test_rbac.py @@ -87,10 +87,13 @@ def test_has_role_false_without_roles(engine): def test_platform_admin_enforces_any_object_and_action(engine): assert engine.enforce(_principal(roles=[Role.PLATFORM_ADMIN]), "/anything", "POST") - # keyMatch2: /scim/v2/* covers /scim/v2/Users + # keyMatch: "/*" / "/scim/v2/*" span path separators, so deep paths are covered assert engine.enforce( _principal(roles=[Role.PLATFORM_ADMIN]), "/scim/v2/Users", "DELETE" ) + assert engine.enforce( + _principal(roles=[Role.PLATFORM_ADMIN]), "/scim/v2/Groups", "POST" + ) def test_platform_viewer_is_read_only(engine):