From aa6d27c181d5d00b2a78cac2e98f720569724ce2 Mon Sep 17 00:00:00 2001 From: Tin Chi Lo Date: Tue, 23 Jun 2026 19:11:11 -0700 Subject: [PATCH] fix(mcp): clear UP037 lint gate and fix allowed-servers test under the graft adapter.py uses `from __future__ import annotations`, so the quoted "UserAPIKeyAuth" / "MCPServer" annotations in to_subject/to_server_spec/_shared_key_spec were unnecessary and pushed UP037 over the strict-rule budget; drop the quotes. test_list_tools_only_returns_allowed_servers passed a MagicMock as user_api_key_auth. The graft now builds a Subject from the principal, and the MagicMock's non-string org_id/user_id fail Subject validation, so the listing came back empty. Use a real UserAPIKeyAuth instead (MagicMock for an injected dependency was the anti-pattern here). --- .../mcp_server/outbound_credentials/adapter.py | 6 +++--- tests/mcp_tests/test_mcp_server.py | 4 +++- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/litellm/proxy/_experimental/mcp_server/outbound_credentials/adapter.py b/litellm/proxy/_experimental/mcp_server/outbound_credentials/adapter.py index 676c9e5469d..39db2314aee 100644 --- a/litellm/proxy/_experimental/mcp_server/outbound_credentials/adapter.py +++ b/litellm/proxy/_experimental/mcp_server/outbound_credentials/adapter.py @@ -34,7 +34,7 @@ if TYPE_CHECKING: def to_subject( - user_api_key_auth: Optional["UserAPIKeyAuth"], subject_token: Optional[str] + user_api_key_auth: Optional[UserAPIKeyAuth], subject_token: Optional[str] ) -> Subject: """Map v1's authenticated principal onto the resolver's Subject. @@ -51,7 +51,7 @@ def to_subject( ) -def to_server_spec(server: "MCPServer") -> Optional[ServerSpec]: +def to_server_spec(server: MCPServer) -> Optional[ServerSpec]: """Map a v1 server onto a ServerSpec for a migrated mode, or None to defer to v1. BYOK is the per-user source of the ``api_key`` mode; its scheme rides on ``auth_type`` just @@ -95,7 +95,7 @@ def to_server_spec(server: "MCPServer") -> Optional[ServerSpec]: def _shared_key_spec( - server: "MCPServer", + server: MCPServer, resource: str, header_name: str, value_prefix: str, diff --git a/tests/mcp_tests/test_mcp_server.py b/tests/mcp_tests/test_mcp_server.py index eea2f2721ab..5f8fcbf835e 100644 --- a/tests/mcp_tests/test_mcp_server.py +++ b/tests/mcp_tests/test_mcp_server.py @@ -1089,7 +1089,9 @@ async def test_list_tools_only_returns_allowed_servers(monkeypatch): mock_client_constructor, ): # Call list_tools - tools = await test_manager.list_tools(user_api_key_auth=MagicMock()) + from litellm.proxy._types import UserAPIKeyAuth + + tools = await test_manager.list_tools(user_api_key_auth=UserAPIKeyAuth()) # Should only return tools from server_a assert len(tools) == 1 # The server should use the server_name as prefix since no alias is provided