From 5a7ec362a0af8f08ea0edb77109188efbe48db78 Mon Sep 17 00:00:00 2001 From: yucheng Date: Fri, 2 Oct 2026 22:04:18 +0000 Subject: [PATCH] test(mcp): assert the aggregate connect passes unchallenged instead of counting token probes The unselected aggregate connect test asserted only on a patched has_user_oauth_token call count, which the test-quality gate flags as mock-echo (TQ002). It now calls the preflight unpatched and asserts it returns without a sign-in challenge, so the mutant that probes every registered server is still killed by the 401 it would raise. Also applies ruff format to test_caller_sign_in.py, a file new in this PR Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .../mcp_server/test_caller_sign_in.py | 4 +--- .../test_mcp_server_tool_calls_and_headers.py | 19 +++++++++---------- 2 files changed, 10 insertions(+), 13 deletions(-) diff --git a/tests/unit/proxy/_experimental/mcp_server/test_caller_sign_in.py b/tests/unit/proxy/_experimental/mcp_server/test_caller_sign_in.py index 0e66500fad0..83371400f4c 100644 --- a/tests/unit/proxy/_experimental/mcp_server/test_caller_sign_in.py +++ b/tests/unit/proxy/_experimental/mcp_server/test_caller_sign_in.py @@ -105,9 +105,7 @@ def test_provider_returning_none_contributes_nothing(registered): def test_obo_server_contributes_jwt_issuers_and_own_scopes(monkeypatch): monkeypatch.setenv("JWT_ISSUER", "https://jwt-idp.test") - sign_in: Final = caller_sign_in_for( - _server(auth_type=MCPAuth.oauth2_token_exchange, scopes=["read"]), None - ) + sign_in: Final = caller_sign_in_for(_server(auth_type=MCPAuth.oauth2_token_exchange, scopes=["read"]), None) assert sign_in == CallerSignIn(issuers=("https://jwt-idp.test",), scopes=("read",)) diff --git a/tests/unit/proxy/_experimental/mcp_server/test_mcp_server_tool_calls_and_headers.py b/tests/unit/proxy/_experimental/mcp_server/test_mcp_server_tool_calls_and_headers.py index 4f8578e917b..673c02af603 100644 --- a/tests/unit/proxy/_experimental/mcp_server/test_mcp_server_tool_calls_and_headers.py +++ b/tests/unit/proxy/_experimental/mcp_server/test_mcp_server_tool_calls_and_headers.py @@ -10458,17 +10458,16 @@ class TestPreemptive401ModeAware: server = _make_oauth2_server(alias, oauth2_flow="authorization_code", delegate_auth_to_upstream=delegate) manager.registry[server.server_id] = server - with patch.object(manager, "has_user_oauth_token", new_callable=AsyncMock, return_value=False) as tokens: - await server_module._raise_preemptive_401_for_unauthenticated_servers( - scope={"type": "http", "method": "POST", "path": "/mcp", "headers": [(b"host", b"testserver")]}, - mcp_servers=None, - oauth2_headers=None, - mcp_server_auth_headers=None, - user_api_key_auth=UserAPIKeyAuth(api_key="sk-litellm-virtual-key"), - client_ip=None, - ) + outcome = await server_module._raise_preemptive_401_for_unauthenticated_servers( + scope={"type": "http", "method": "POST", "path": "/mcp", "headers": [(b"host", b"testserver")]}, + mcp_servers=None, + oauth2_headers=None, + mcp_server_auth_headers=None, + user_api_key_auth=UserAPIKeyAuth(api_key="sk-litellm-virtual-key"), + client_ip=None, + ) - assert tokens.await_count == 0, "an unselected aggregate connect must not probe any server for a token" + assert outcome is None, "an unselected aggregate connect must pass without a sign-in challenge" @pytest.mark.asyncio async def test_deferred_discovery_runs_before_delegate_challenge(self):