From 5f038196a0e92bcc46b14ffe46d4a77d25f3acad Mon Sep 17 00:00:00 2001 From: Yuneng Jiang Date: Wed, 20 May 2026 13:31:43 -0700 Subject: [PATCH] ci(proxy-mgmt-behavior): force premium_user=True so /key/regenerate isn't gated MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Ninth CI run cleared every ``Your ID=None`` failure (the master_key env fix worked end-to-end) and exposed the next thin layer of failures: ``/key/regenerate`` returns 500 "Regenerating Virtual Keys is an Enterprise feature" in CI because the proxy can't see a ``LITELLM_LICENSE``. Locally my license is set, so the matrix passes. The behavior matrix is supposed to pin authz, not licensing — so flip ``proxy_server.premium_user = True`` directly, both before and after the lifespan (the lifespan re-runs ``_license_check.is_premium()`` and would otherwise reset it). With premium gating disabled, the regenerate matrix exercises the same authz path /key/update does. Whole-suite still green locally (130 tests, ~6.3s). --- tests/proxy_behavior/management/conftest.py | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/tests/proxy_behavior/management/conftest.py b/tests/proxy_behavior/management/conftest.py index e8f0be111b9..8e37a460e96 100644 --- a/tests/proxy_behavior/management/conftest.py +++ b/tests/proxy_behavior/management/conftest.py @@ -64,7 +64,21 @@ async def proxy_app(): os.environ.setdefault("CONFIG_FILE_PATH", config_path) await initialize(config=config_path) + + # /key/regenerate (and a few other Tier-1 endpoints) are gated behind + # ``premium_user`` — without a LITELLM_LICENSE the proxy returns 500 + # "Enterprise feature" for those calls. The behavior matrix isn't about + # licensing; it's about authz. Force the proxy into premium mode so the + # matrix pins the real authz behavior, not the licensing gate. + from litellm.proxy import proxy_server as _proxy_server + + _proxy_server.premium_user = True + async with proxy_startup_event(app): + # The lifespan re-runs ``premium_user = _license_check.is_premium()`` + # which flips it back. Force it again after the lifespan settles. + _proxy_server.premium_user = True + # The lifespan kicks off ``prisma_client.check_view_exists()`` as a # fire-and-forget background task. That task creates the # ``LiteLLM_VerificationTokenView`` SQL view used by ``user_api_key_auth``