test: verify /project/list and /project/info accessible to non-admin users
Some checks failed
Unit Tests: Security / security (push) Has been cancelled
Unit Tests: Proxy DB Operations / proxy-db (auth-checks, tests/proxy_unit_tests/test_auth_checks.py tests/proxy_unit_tests/test_user_api_key_auth.py, 20, 8) (push) Has been cancelled
Unit Tests: Proxy DB Operations / proxy-db (key-generation, tests/proxy_unit_tests/test_key_generate_prisma.py, 30, 0) (push) Has been cancelled
Unit Tests: Proxy DB Operations / proxy-db (proxy-utils, tests/proxy_unit_tests/test_proxy_utils.py, 20, 8) (push) Has been cancelled
Unit Tests: Proxy DB Operations / proxy-db (remaining, tests/proxy_unit_tests --ignore=tests/proxy_unit_tests/test_key_generate_prisma.py --ignore=tests/proxy_unit_tests/test_auth_checks.py --ignore=tests/proxy_unit_tests/test_user_api_key_auth.py --ignore=tests/proxy_unit_tests/test_p… (push) Has been cancelled

Add parametrized test covering internal_user, internal_user_viewer, and
proxy_admin_viewer roles against both project routes to ensure the
route-check middleware lets them through.
This commit is contained in:
Ishaan Jaffer 2026-04-24 19:52:01 -07:00
parent de8a52f294
commit 6c918acf28
No known key found for this signature in database

View file

@ -1327,6 +1327,47 @@ def test_available_roles_accessible_to_non_admin_users(user_role):
)
@pytest.mark.parametrize(
"route",
["/project/list", "/project/info"],
)
@pytest.mark.parametrize(
"user_role",
[
LitellmUserRoles.INTERNAL_USER.value,
LitellmUserRoles.INTERNAL_USER_VIEW_ONLY.value,
LitellmUserRoles.PROXY_ADMIN_VIEW_ONLY.value,
],
)
def test_project_routes_accessible_to_non_admin_users(route, user_role):
"""
/project/list and /project/info should be reachable by non-admin users.
The endpoints themselves enforce team-membership access control, so the
route-check middleware must let non-admin callers through.
"""
user_obj = LiteLLM_UserTable(
user_id="test_user",
user_email="test@example.com",
user_role=user_role,
)
valid_token = UserAPIKeyAuth(
user_id="test_user",
user_role=user_role,
)
request = MagicMock(spec=Request)
request.query_params = {}
# Should not raise — project list/info are in self_managed_routes
RouteChecks.non_proxy_admin_allowed_routes_check(
user_obj=user_obj,
_user_role=user_role,
route=route,
request=request,
valid_token=valid_token,
request_data={},
)
# ── _user_is_org_admin tests ──────────────────────────────────────────────────
from datetime import datetime