From 9e9775623967398ef87fbb9762f87147f58fb363 Mon Sep 17 00:00:00 2001 From: mateo-berri <277851410+mateo-berri@users.noreply.github.com> Date: Fri, 2 Oct 2026 21:10:21 -0700 Subject: [PATCH] test(proxy): classify the federation params in the credential slot registry main's registry test (#43298) now fails the build for any credential-named deployment param without a classification. The five federation fields that carry a token, a token file path, or a signing or client secret reference are Unplanted, matching WIF_SECRET_BEARING_KEYS; the four remaining Keycloak settings name a URL, a client id, an auth method, or a scope and are NotSecret --- tests/unit/proxy/test_credential_slot_registry.py | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/tests/unit/proxy/test_credential_slot_registry.py b/tests/unit/proxy/test_credential_slot_registry.py index 98ddf38c661..02268dba361 100644 --- a/tests/unit/proxy/test_credential_slot_registry.py +++ b/tests/unit/proxy/test_credential_slot_registry.py @@ -124,6 +124,15 @@ DEPLOYMENT_PARAM_CLASSIFICATION: Final[Mapping[str, Classification]] = MappingPr "default_api_key_tpm_limit": NotSecret("rate limit number"), "default_api_key_rpm_limit": NotSecret("rate limit number"), "valkey_password": Unplanted(), + "anthropic_identity_token": Unplanted(), + "anthropic_identity_token_file": Unplanted(), + "anthropic_issuer_signing_key_ref": Unplanted(), + "anthropic_keycloak_token_url": NotSecret("Keycloak token endpoint URL"), + "anthropic_keycloak_client_id": NotSecret("Keycloak client identifier"), + "anthropic_keycloak_auth_method": NotSecret("name of the client authentication method"), + "anthropic_keycloak_client_secret_ref": Unplanted(), + "anthropic_keycloak_scope": NotSecret("OAuth scope string"), + "openai_identity_token_file": Unplanted(), } )