diff --git a/backend/routes/allowlist.py b/backend/routes/allowlist.py index 232561dd154..5c280c22d80 100644 --- a/backend/routes/allowlist.py +++ b/backend/routes/allowlist.py @@ -60,6 +60,7 @@ BACKEND_PATH_PREFIXES: tuple[str, ...] = ( # Tools / agents (registry & policy admin) "/v1/tool/", "/v1/agents", + "/v1/traces", # Guardrails admin "/v2/guardrails/", # MCP server admin + BYOK OAuth flow (UI-initiated) + dynamic per-server endpoints diff --git a/litellm-rust/crates/python-bridge/src/routes/traces.rs b/litellm-rust/crates/python-bridge/src/routes/traces.rs index 6a18273ed4c..a17d465dcca 100644 --- a/litellm-rust/crates/python-bridge/src/routes/traces.rs +++ b/litellm-rust/crates/python-bridge/src/routes/traces.rs @@ -33,6 +33,7 @@ pub struct NativeTraceStorage { #[pymethods] impl NativeTraceStorage { #[new] + #[pyo3(signature = (database, url, reader_url=None))] fn new(database: String, url: &str, reader_url: Option<&str>) -> PyResult { litellm_traces::schema_statements(&database, 1, 1).map_err(map_error)?; Ok(Self { diff --git a/tests/test_litellm/proxy/agent_endpoints/auth/test_managed_authorization.py b/tests/test_litellm/proxy/agent_endpoints/auth/test_managed_authorization.py index eee985f0aca..f7c734bd6f4 100644 --- a/tests/test_litellm/proxy/agent_endpoints/auth/test_managed_authorization.py +++ b/tests/test_litellm/proxy/agent_endpoints/auth/test_managed_authorization.py @@ -365,6 +365,9 @@ async def test_unknown_invocation_target_leaves_billing_unset(monkeypatch: pytes ("/v1/realtime", "GET", True), ("/v1/realtime", "POST", False), ("/v1/realtime/client_secrets", "POST", False), + ("/live", "POST", False), + ("/v1/live", "POST", False), + ("/live/sessions/session/accept", "POST", False), ("/mcp/tools/call", "POST", True), ("/a2a/target/message/send", "POST", True), ("/v1/a2a/target/message/send", "POST", True), @@ -573,7 +576,7 @@ def test_registered_inference_routes_have_an_explicit_managed_access_decision(ro "/videos", "/batches", "/files", "/fine_tuning", "/assistants", "/threads", "/utils/", "/vector_stores", "/vector_store/", "/search", "/containers", "/skills", "/claude-code/", "/interactions", "/agents", "/responses/{", "/responses/input_tokens", - "/realtime/client_secrets", "/realtime/calls", "/realtime/transcription_sessions", + "/realtime/client_secrets", "/realtime/calls", "/realtime/transcription_sessions", "/live", )) or normalized in ("/models", "/cursor/models", "/cursor/v1/models") concrete: Final = route.split("?")[0].replace("{model}", "model").replace("{model_name:path}", "model") assert managed_agent_route_allowed(concrete, None) is not unsupported, route diff --git a/tests/test_litellm_rust/test_traces.py b/tests/test_litellm_rust/test_traces.py index 447ca2ce4bb..9e6e2e5b0cf 100644 --- a/tests/test_litellm_rust/test_traces.py +++ b/tests/test_litellm_rust/test_traces.py @@ -17,10 +17,10 @@ async def test_trace_reader_projects_connection_and_parameters(recording_server: recording_server.enqueue(ResponseSpec(body={"data": [{"trace_id": "trace-1"}]})) reader_url: Final = recording_server.base_url.replace("http://", "http://reader:p%40ss%2Fword%25@") storage: Final = NativeTraceStorage("trace_test", recording_server.base_url, reader_url + "?database=wrong") - rows: Final = json.loads(await storage.query("SELECT {trace_id:String} AS trace_id", {"trace_id": "trace-1"})) + response: Final = json.loads(await storage.query("SELECT {trace_id:String} AS trace_id", {"trace_id": "trace-1"})) request: Final = recording_server.requests[0] parameters: Final = parse_qs(urlsplit(request.path).query) - assert rows == [{"trace_id": "trace-1"}] + assert response["data"] == [{"trace_id": "trace-1"}] assert request.raw_body == b"SELECT {trace_id:String} AS trace_id" assert parameters["database"] == ["trace_test"] assert parameters["param_trace_id"] == ["trace-1"]