mirror of
https://github.com/BerriAI/litellm.git
synced 2026-08-28 05:25:59 +00:00
test(proxy_behavior): codify G3 (strict-import grep) as a pytest item
Slice 6 of the management-endpoints behavior-pinning effort. Two new tests
walk every .py file under tests/proxy_behavior/ and assert:
* no ``from litellm.proxy.management_endpoints`` import — the suite is
deliberately constrained to the HTTP boundary so it survives handler
refactors;
* no ``mock``/``patch`` on ``user_api_key_auth`` — mocking auth is the
structural failure mode of the existing 11k-line mock suite, and the
point of this harness is that the real auth layer runs.
Codifying G3 as a CI test removes the "did someone forget to check the
PR-description checklist" failure mode.
Plan: https://www.notion.so/36643b8acdab8128a581ced0f6a4744d
This commit is contained in:
parent
12d5d7b6dc
commit
6f588c753b
1 changed files with 64 additions and 0 deletions
|
|
@ -0,0 +1,64 @@
|
|||
"""Codify G3 (strict-import grep) as a test.
|
||||
|
||||
The behavior-pinning suite asserts at the HTTP boundary against a real proxy
|
||||
app. Two forbidden patterns:
|
||||
|
||||
1. ``from litellm.proxy.management_endpoints`` — importing handler functions
|
||||
directly turns the suite into unit tests of the handler module rather than
|
||||
behavior tests of the API, and makes the suite brittle to refactors.
|
||||
|
||||
2. ``mock``/``patch`` on ``user_api_key_auth`` — mocking auth is the
|
||||
structural failure mode of today's mock-heavy suite. The whole point of the
|
||||
real-DB harness is that auth runs.
|
||||
|
||||
Running this as a pytest item means G3 is enforced by CI on every PR, not by
|
||||
a checklist someone might forget.
|
||||
"""
|
||||
|
||||
import pathlib
|
||||
import re
|
||||
|
||||
import pytest
|
||||
|
||||
REPO_ROOT = pathlib.Path(__file__).resolve().parents[3]
|
||||
BEHAVIOR_DIR = REPO_ROOT / "tests" / "proxy_behavior"
|
||||
|
||||
FORBIDDEN_IMPORT = re.compile(r"^\s*from\s+litellm\.proxy\.management_endpoints\b")
|
||||
FORBIDDEN_AUTH_MOCK = re.compile(
|
||||
r"(?:mock\.[A-Za-z_]+|patch[a-z_]*)\([^)]*user_api_key_auth"
|
||||
)
|
||||
|
||||
# This very file is the one place where the forbidden patterns appear as
|
||||
# regex source; exclude it from its own scan so the test is self-checkable.
|
||||
SELF = pathlib.Path(__file__).resolve()
|
||||
|
||||
|
||||
def _iter_py_files():
|
||||
for path in BEHAVIOR_DIR.rglob("*.py"):
|
||||
if path.resolve() == SELF:
|
||||
continue
|
||||
yield path
|
||||
|
||||
|
||||
def test_no_management_endpoint_imports():
|
||||
violations = []
|
||||
for path in _iter_py_files():
|
||||
for lineno, line in enumerate(path.read_text().splitlines(), start=1):
|
||||
if FORBIDDEN_IMPORT.search(line):
|
||||
violations.append(f"{path.relative_to(REPO_ROOT)}:{lineno}: {line.strip()}")
|
||||
assert not violations, (
|
||||
"tests/proxy_behavior/ must not import from litellm.proxy.management_endpoints "
|
||||
"(G3 — assert at the HTTP boundary). Violations:\n " + "\n ".join(violations)
|
||||
)
|
||||
|
||||
|
||||
def test_no_user_api_key_auth_mocking():
|
||||
violations = []
|
||||
for path in _iter_py_files():
|
||||
for lineno, line in enumerate(path.read_text().splitlines(), start=1):
|
||||
if FORBIDDEN_AUTH_MOCK.search(line):
|
||||
violations.append(f"{path.relative_to(REPO_ROOT)}:{lineno}: {line.strip()}")
|
||||
assert not violations, (
|
||||
"tests/proxy_behavior/ must not mock user_api_key_auth (G3 — auth runs for "
|
||||
"real). Violations:\n " + "\n ".join(violations)
|
||||
)
|
||||
Loading…
Add table
Reference in a new issue