diff --git a/.github/workflows/test-unit-proxy-mgmt-behavior.yml b/.github/workflows/test-unit-proxy-mgmt-behavior.yml index e73997323a4..38b606901ae 100644 --- a/.github/workflows/test-unit-proxy-mgmt-behavior.yml +++ b/.github/workflows/test-unit-proxy-mgmt-behavior.yml @@ -29,6 +29,10 @@ jobs: # so the cost of disabling parallelism here is negligible. workers: 0 reruns: 0 + # Don't abort early — first CI runs need the full failure surface so we + # can correlate setup-helper failures (one bad fixture cascades to N + # tests) vs. real per-scenario failures. Will tighten back down later. + max-failures: 200 enable-postgres: true artifact-name: proxy-mgmt-behavior timeout-minutes: 15 diff --git a/tests/proxy_behavior/management/test_world_seed.py b/tests/proxy_behavior/management/test_aaa_world_seed.py similarity index 60% rename from tests/proxy_behavior/management/test_world_seed.py rename to tests/proxy_behavior/management/test_aaa_world_seed.py index 5b6abb12d1c..5c8afb03a43 100644 --- a/tests/proxy_behavior/management/test_world_seed.py +++ b/tests/proxy_behavior/management/test_aaa_world_seed.py @@ -35,3 +35,24 @@ async def test_each_actor_can_self_info(actor, proxy_client, world): f"{actor.value}: /key/info returned the wrong user_id " f"(got {info.get('user_id')!r}, expected {seeded.user_id!r})" ) + + +async def test_proxy_admin_actor_can_create_keys_for_others(proxy_client, world): + """Diagnostic: the seeded PROXY_ADMIN actor must be able to /key/generate + a key for another user. If this fails, the user_role is not propagating + through user_api_key_auth → the actor's auth context disagrees with the + DB row, and the cause is elsewhere in the auth stack (not the seed).""" + seeder = world.keys[Actor.PROXY_ADMIN] + target_user_id = world.keys[Actor.OWNER].user_id + + resp = await proxy_client.post( + "/key/generate", + headers={"Authorization": f"Bearer {seeder.cleartext}"}, + json={"key_alias": "diag-proxy-admin-seeder", "user_id": target_user_id}, + ) + assert resp.status_code == 200, ( + f"PROXY_ADMIN-seeded actor can't create keys for others: " + f"{resp.status_code} {resp.text}\n" + f" seeder user_id: {seeder.user_id}\n" + f" target user_id: {target_user_id}" + )