mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-03 02:22:24 +00:00
ci(proxy-mgmt-behavior): diag — run world-seed test first + bump max-failures
Third CI run failed identically: seeded PROXY_ADMIN actor's auth resolves
to ``user_id=None`` even though the DB row has the right ``user_id``. The
suite was aborting at maxfail=10 inside test_key_delete, so test_world_seed
(which would tell us whether the seed itself is reachable) never ran in CI.
Two diagnostic moves on this push, no behavior change:
* Rename ``test_world_seed.py`` → ``test_aaa_world_seed.py`` so it's
the first collected file. If it passes in CI we know the seed is
fine and the bug lives downstream; if it fails the same way the
bug is in the auth resolution path.
* Bump ``max-failures`` to 200 for this workflow so we see the full
failure surface instead of stopping at the first cascading setup
error. Will tighten back down once the suite is green.
Adds one new test ``test_proxy_admin_actor_can_create_keys_for_others``
that explicitly exercises the PROXY_ADMIN bypass via /key/generate with
an explicit user_id — the same shape the matrix setup helper uses but
without the matrix machinery muddying the diagnostic.
This commit is contained in:
parent
15c7a59d76
commit
f576d94c8c
2 changed files with 25 additions and 0 deletions
|
|
@ -29,6 +29,10 @@ jobs:
|
|||
# so the cost of disabling parallelism here is negligible.
|
||||
workers: 0
|
||||
reruns: 0
|
||||
# Don't abort early — first CI runs need the full failure surface so we
|
||||
# can correlate setup-helper failures (one bad fixture cascades to N
|
||||
# tests) vs. real per-scenario failures. Will tighten back down later.
|
||||
max-failures: 200
|
||||
enable-postgres: true
|
||||
artifact-name: proxy-mgmt-behavior
|
||||
timeout-minutes: 15
|
||||
|
|
|
|||
|
|
@ -35,3 +35,24 @@ async def test_each_actor_can_self_info(actor, proxy_client, world):
|
|||
f"{actor.value}: /key/info returned the wrong user_id "
|
||||
f"(got {info.get('user_id')!r}, expected {seeded.user_id!r})"
|
||||
)
|
||||
|
||||
|
||||
async def test_proxy_admin_actor_can_create_keys_for_others(proxy_client, world):
|
||||
"""Diagnostic: the seeded PROXY_ADMIN actor must be able to /key/generate
|
||||
a key for another user. If this fails, the user_role is not propagating
|
||||
through user_api_key_auth → the actor's auth context disagrees with the
|
||||
DB row, and the cause is elsewhere in the auth stack (not the seed)."""
|
||||
seeder = world.keys[Actor.PROXY_ADMIN]
|
||||
target_user_id = world.keys[Actor.OWNER].user_id
|
||||
|
||||
resp = await proxy_client.post(
|
||||
"/key/generate",
|
||||
headers={"Authorization": f"Bearer {seeder.cleartext}"},
|
||||
json={"key_alias": "diag-proxy-admin-seeder", "user_id": target_user_id},
|
||||
)
|
||||
assert resp.status_code == 200, (
|
||||
f"PROXY_ADMIN-seeded actor can't create keys for others: "
|
||||
f"{resp.status_code} {resp.text}\n"
|
||||
f" seeder user_id: {seeder.user_id}\n"
|
||||
f" target user_id: {target_user_id}"
|
||||
)
|
||||
Loading…
Add table
Reference in a new issue